Back to All Events

San Diego Event In-Person and Online: The Unique Role of the IT Audit-Savvy Internal Auditors in Solving a Major Unmanaged Risk

  • XiFin, Inc. 12225 El Camino Real San Diego, CA, 92130 United States (map)

Third Parties can bring a large systemic risk that is not being addressed through traditional Third-Party Risk Management (TPRM). This risk becomes substantial and will likely become the largest risk for organizations as the number of third parties that can expose very large amounts of sensitive data increases beyond 15. Simple math can now allow internal auditors to measure this heretofore unknown and hence unowned risk to the extent that auditors can provide management with high-confidence assurance that a large third-party data breach is highly unlikely—once the systemic risk is properly managed.

This creates a unique opportunity for Internal Auditors who have a solid grasp of IT audit or who also hold a CISA certification. They possess both the technical grounding to understand the systemic nature of the exposure and the organizational authority to escalate unrecognized material risks across the various silos which exist in many organizations. In many cases, Internal Audit may be the only function positioned to surface this issue.

This session is the first in a multi-part series designed to equip IT- audit savvy or CISA-certified Internal Auditors with the conceptual, mathematical, and practical tools needed to address this unmanaged risk. In this session, we will explain the derivation of a simple formula that any organization can use to quantify systemic third-party breach risk in real-world units, demonstrate the random nature of third-party data breaches and show why they cannot be looked at as a weakest link problem. We will also provide a supporting white paper which includes the full mathematical derivation and illustrative examples used to evaluate the risk.

SPEAKERS:

Timothy Smith, Treasurer ISACA San Diego

Tim is a major contributor to ISACA audit standards and the treasurer of ISACA San Diego. Tim has had a 20-year career with KPMG, in the U.S. and International firms, specializing in data and analytics for IT and financial audit. In the later years of his tenure, he led the design, testing, implementation, documentation, and training of the data-analytics modules within KPMG’s proprietary audit platform, CLARA.

Before that role, Tim headed the IT audit practice in KPMG’s San Diego office and also served as IT Audit Manager at LPL Financial—the nation’s largest independent broker-dealer.

Tim is a California CPA and a CISA. He is an active member of AICPA, the California Society of CPAs, and ISACA San Diego. He assisted in editing ISACA’s “Information Technology Assurance Framework 3rd edition” and most recently provided guidance to ISCA Global on restructuring the requirements for chapter annual financial reporting requirements. He is coauthor of the white paper Thomas Lee and Timothy Smith (2025). How to Calculate the Probability of a Third-Party Data Breach. Tim can be reached at Tim@CPA4it.com.

Visit Tim on LinkedIn: https://www.linkedin.com/in/timothyksmith/

Dr Thomas Lee, CEO of VivoSecurity

Dr. Thomas Lee is the CEO of VivoSecurity, a Silicon Valley company specializing in data collection and regression modeling to quantify the inherent randomness of cybersecurity incidents. He has developed predictive models for online banking fraud, PII breach probability, and post-breach litigation exposure, and has presented across ISACA, ISC2, ISSA and IIA chapters, as well as at major conferences including SecTor 2024, ISC2 Security Congress 2025, the ISACA Los Angeles GRC Spring Conference and upcoming SecTor 2026 in Toronto, the National Conference of Internal Auditors 2026 in Mexico City and the joint IIA–ISACA GRC 2026 event in San Diego.

He is a member of the San Jose State University (SJSU) CAIC Advisory Board, a co-investigator in the SJSU Information Risk Management Laboratory, holds multiple patents, has published extensively in peer-reviewed journals, and earned dual BS degrees in Physics and Electrical Engineering from the University of Washington and a PhD in Biophysics from the University of Chicago. Tom can be reached at ThomasL@vivosecurity.com

Visit Thomas on LinkedIn: https://www.linkedin.com/in/thomas-lee-phd-b7766b10/

DETAILS:
Date: Thursday, November 19
Time: 12:00 - 1:15 p.m.
Location: In-Person and Online via Zoom
CPE: 1

ON PREMISES
XiFin, Inc.
12225 El Camino Real
San Diego, CA 92130

Attendance capacity is limited to 50

ONLINE
Online access is available via the chapter’s Zoom account (registration below).
Attendance capacity is 500