Cyber risk for companies that are not in IT.
A manufacturer or trader does not think of itself as a technology company. Its bank, its ERP and its email provider disagree. What internal audit should test when the IT team is three people.
1. The company that was not a target.
Consider a composite case, with details altered. A mid-sized auto-component manufacturer in Gujarat. Turnover of a few hundred crores, one ERP, a three-person IT team, and a promoter who described cyber risk as "something for the banks to worry about".
The first incident was not a sophisticated attack. An accounts executive received an email from what looked like a regular vendor's address asking that future payments go to a new bank account. The email had the vendor's signature block, referred to a genuine open invoice, and arrived on a Friday afternoon. The change was made. Two payments totalling about Rs 38 lakh went out before the real vendor called to ask about the delay.
Nothing in the ERP was breached. Nothing was encrypted or held to ransom. The control that failed was a payment control, and it failed because nobody had told the accounts team that a vendor bank account change needs a phone call to a known number.
This is what cyber risk looks like in most companies outside the technology sector. It is a business-process risk that happens to arrive by email.
2. Why the "not in IT" view is out of date.
Every company now depends on systems it does not own. The ERP is hosted by a vendor. Email lives with Microsoft or Google. Payroll runs on a portal. GST returns, e-invoices and e-way bills are generated through an ASP or GSP. Bank payments are made through a corporate net-banking portal with tokens that sit in someone's drawer.
The regulatory perimeter has moved as well. The Digital Personal Data Protection Act, 2023 applies to any company holding personal data of employees or customers, with obligations on security safeguards and breach notification. CERT-In's 2022 directions require reporting of specified cyber incidents within six hours. Listed companies are subject to SEBI's cybersecurity and cyber resilience framework and to disclosure requirements for material incidents under the LODR Regulations. Lenders increasingly ask for a cyber-insurance policy or an IT controls certificate as a loan covenant.
None of that requires a company to be "in IT". It only requires a company to have data, a bank account and email.
Cyber risk in a manufacturing company is not about firewalls. It is about who can move money, who can change a master record, and whether anyone would notice.
3. What internal audit should test.
Internal audit does not need to become a penetration-testing firm. It needs to test the handful of controls that stand between an ordinary phishing email and a loss. In our experience these are the ones that matter.
Payment and master-data changes. Every change to a vendor or employee bank account should require independent call-back verification to a number already on file, not the number in the email. Test a sample of changes in the last twelve months and ask for the evidence of the call-back. This is the single highest-value test on the list.
User access to the ERP and banking portals. Pull the full list of active users. Match it against the current employee list. Look for leavers who still have access, shared logins, and users with both maker and checker rights. In smaller companies the finance head often has every right in the system because "it was easier during implementation". That is a finding.
Multi-factor authentication. Check that it is switched on for email, the ERP, the banking portal and the GST and tax portals. Check who holds the physical tokens or registered mobile numbers, and what happens when that person is on leave.
Backups and recovery. Ask when the backup was last actually restored, not just taken. A backup that has never been tested is a hope, not a control. Ask where it is kept and whether the same credentials that could encrypt the live system could also reach the backup.
Patching and end-of-life systems. Ask for the list of servers and machines and their operating system versions. Factories often run critical machines on operating systems that stopped receiving security updates years ago because the machine vendor's software will not run on anything newer. That may be unavoidable, but it should be known, isolated from the main network, and on the risk register.
Vendor and cloud dependencies. For each hosted system, ask what the contract says about data location, security certification, breach notification and exit. Ask whether anyone has read the vendor's SOC 2 or ISO 27001 report, if one exists.
Incident response. Ask a simple question: if the ERP stopped working at 9 a.m. on a Monday, who would be called, in what order, and how long could the plant run on paper? If there is no written answer, the recovery plan is in someone's head, and that person may be the one who is unreachable.
Awareness. Ask whether staff have been told, in plain language, about payment fraud, fake vendor emails and password hygiene. A short session twice a year does more than an expensive tool that nobody configures.
4. Fitting this into the audit plan.
Cyber does not need a separate 40-page audit. Most of these tests belong inside audits internal audit already performs. Bank-account change verification sits in the procure-to-pay audit. User access review sits in the ERP general controls audit. Backup testing sits in the IT general controls review that supports Internal Financial Controls reporting.
What changes is the emphasis. The tests above should be run every year, not on a three-year rotation, and the results should reach the audit committee in a form it can act on: a one-page dashboard showing each control as tested, not tested, or failed.
5. What to tell the board.
Boards respond to consequences, not to acronyms. The message that works is short. Here is the money that could leave the company through a fake email. Here is the data whose loss would trigger a regulatory notification. Here is how long the plant would stop if the ERP went down. Here are the eight controls that protect against those three things, and here is how many of them are working.
This article is general in nature and does not constitute professional advice. Readers should seek specific advice before acting on any matter described here.
This website is meant for information purposes only. The contents are made available on a pull basis and are not intended to solicit work or advertise.
Frequently asked
Does a private company need to comply with any cyber regulation?
Yes, in several respects. The DPDP Act, 2023 applies to personal data held by any company. CERT-In directions on incident reporting and log retention apply broadly. Sector regulators such as RBI, IRDAI and SEBI impose additional requirements on the entities they regulate. Even where no specific rule applies, the board's duty to maintain adequate internal financial controls under section 134(5)(e) of the Companies Act, 2013 extends to the systems that produce the financial records.
Should internal audit or IT own the cyber review?
IT owns the controls. Internal audit tests them independently and reports to the audit committee. Where the IT team is small, the internal auditor may bring in a specialist for technical testing such as vulnerability scanning, but the control questions above can be answered by a finance-trained auditor with a clear checklist.
How much does cyber insurance help?
It helps with the cost of an incident, not with preventing one. Insurers typically require evidence of basic controls such as multi-factor authentication and tested backups before they will pay. An internal audit that confirms these controls exist is often a precondition for a claim being honoured.