Accessibility

Day 2 of the Critical Sector Auditing and Risk Analysis Workshop

Following the high-level opening conference, the second day of the critical sector auditing and risk analysis workshop for Malaysia focused on understanding different auditing approaches and their uses.

Sessions led by EU CyberNet experts Christian Schlehuber, Ilmar Toom and Nick Small, introduced participants to different auditing approaches in order to understand how structured maturity assessment can help evaluate organisational resilience. Speakers highlighted that good audits improve resilience not only compliance. 

The main take-aways included: 

  • Risk-based cybersecurity auditing must prioritise threats and vulnerabilities based on their likelihood and potential impact. This approach links security evaluations directly to organisational risk tolerance and strategic objectives, enabling decision-makers to allocate resources efficiently. 
  • Compliance-based cybersecurity auditing ensures cybersecurity aspects have been embedded into workflows. This helps to determine the maturity level of compliance. 
  • Technical-based cybersecurity auditing evaluates whether established controls are adequately designed, implemented and applied which helps to ensure coverage. 
  • Inspection and verification approaches facilitate understanding about how effective the cybersecurity measures are. 
  • The final session discussed the importance of follow-up activities after auditing such as developing plan to drive improvement and control auditing, but also understanding the value of collaborative reviews to identify opportunities for improving the auditing process itself.  

Links 



Keep reading similar articles
At CyCon 2026: Municipal Resilience in Crisis, Conflict and Systemic Disruption

EU CyberNet hosted an interactive workshop, titled “Securing Cities: Municipal Cyber Resilience in Crisis, Conflict and Systemic Disruption” at CyCon 2026 on 26 May 2026.

Critical Sector Auditing and Risk Analysis Workshop Concluded After Three Days

The critical sector auditing and risk analysis workshop for Malaysia concluded after three days with practical table-top exercise to implement different auditing approaches.

EU CyberNet Crash Course #3: Communication in Cybersecurity

The 3rd EU CyberNet Crash Course, titled “Communication in Cybersecurity” and led by Jussi Toivanen explored the fundamentals and role of communication in cyber-related crises and raising cyber awareness.

Critical Sector Auditing and Risk Analysis Workshop Opened with a High-Level Conference in Malaysia

Organised in cooperation between EU CyberNet and National Cyber Security Agency of Malaysia (NACSA), the workshop on critical sector auditing and risk analysis for Malaysia opened today, 20 May 2026 with a high-level conference.

Workshop on Critical Sector Auditing and Risk Analysis to Take Place This Week in Malaysia

EU CyberNet in cooperation with the National Cyber Security Agency (NACSA) of Malaysia and the Delegation of the European Union to Malaysia is organising a three-day programme on critical sector auditing and risk analysis from 20 to 22 May in Putrajaya, Malaysia.

EU CyberNet Stakeholder Community Day: Advancing Europe’s Cybersecurity Partnerships

Today, on 13 May 2026, EU CyberNet gathered representatives of EU institutions and its member states’ national cyber authorities and organisations in Brussels for the annual Stakeholder Community Day meeting under the title “Advancing Europe’s Cybersecurity Partnerships: Made in Europe, Delivered Globally”.