EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
How EY can help
-
EY Technology Risk Cybersecurity services help your business manage cyber threats, meet regulations and maintain resilience.
Read more
Shifting client and auditor expectations for SOC reporting
Service organizations now face a shifting threat landscape. The assumption that an organization’s software is reasonably secure because it has traditional SOC reports and no major incidents have occurred may no longer be adequate as clients and regulators may question whether hidden vulnerabilities likely exist in the environment. Boards and audit committees are pressing organizational leaders for answers on how their service providers address AI’s ability to swiftly detect and exploit overlooked weaknesses.
“As AI changes how vulnerabilities are found and exploited, cyber resilience depends on enterprise-wide governance, effective controls and evidence that those controls work in practice,” says Jaime Kipnes, EY Global and Americas Technology Risk Cybersecurity Leader.
During a single reporting cycle, service organizations should anticipate customer inquiries that go beyond simple due diligence. Instead, customers are likely to expect assurance not just about the existence of a vulnerability management program but specifically how it has adapted to AI-driven threats, what evidence supports management’s claims and how those claims are represented in tested controls in the most recent SOC reports.
Service auditors are under similar pressure, and standard-setting commentary points to more granular procedures, deeper testing and lower tolerance for high-level control descriptions. Phrases such as “vulnerabilities are tracked, prioritized and remediated based on risk” or “annual penetration testing is performed with findings remediated” may no longer suffice.
5 focus areas shaping expectations
As expectations evolve, several areas within the control environment are drawing increased scrutiny:
1. Vulnerability management: AI-accelerated threats demand that service organizations move beyond simple severity-based vulnerability identification and prioritization. Traditional approaches often lack exposure- and exploit-aware prioritization that incorporates threat intelligence, asset criticality and AI-assisted analysis.
Service organizations should be able to demonstrate how specific vulnerability findings are identified using multiple scanners and tools, prioritized quickly and addressed in a timely manner, commensurate with the elevated threat landscape. This effort will be important for both internally developed applications and acquired technology.
2. Patch management: Most organizations have a documented patching standard; however, far fewer can produce strong evidence that the standard is met across the entirety of their environment, including the long tail of legacy operating systems, databases, acquired applications and supporting tools that may drift outside asset inventories.
Patching cycles measured in weeks or months for critical exposures may no longer be acceptable; service organizations should be working toward cycles measured in days, with clear governance for exceptions when patching is unfeasible. Isolating critical systems is also an important priority.
3. Secure software development: Coverage of this area has typically been limited, consisting primarily of references to established methodologies, the involvement of security personnel and the integration of code scanning within the change management process. That depth of treatment is not likely to survive the next wave of client and regulator inquiries.
Service organizations will need to develop or enhance continuous secure development controls instead of relying solely on checkpoints. Threat modeling should be evidenced, not just asserted as part of a methodology. Static and dynamic code analysis should be tied to specific controls, with findings, dispositions and remediation timelines addressed.
4. Vendor risk management: Most service organizations have built their vendor or third-party risk programs around the categories that were considered relevant five or more years ago: large data center and cloud infrastructure organizations, managed service providers and processors of customer data. Cloud applications and software tool vendors (e.g., ticketing platforms, access management tools, build and deployment change tools) have often been treated as a low-or medium-risk tier with less focus and controls. That stratification has become untenable. The compromise of common software can lead to the compromise of every technology connected to it.
Service organizations will need to review their vendor inventories with a specific focus on software and assess each against the depth of scrutiny historically reserved for higher-tier vendors, considering how these software organizations address AI-accelerated threats
5. Penetration testing: The traditional cadence of an annual external test, possibly supplemented by a less rigorous internal exercise, was designed for a world in which sophisticated offensive capability was uncommon, expensive and slow. Those traditional conditions are evolving rapidly
Service organizations should be moving toward a layered testing program that combines continuous automated security validation against critical externally exposed surfaces; periodic deep-dive penetration tests by experienced human testers, ideally with their own AI-augmented tooling; objective-based red team exercises that probe the organization’s ability to detect and respond; and targeted assessments of newly deployed or significantly changed systems before they reach production.