Skip to content
Review Open access

Building public sector cyber-resilience through performance audit: responses to cybersecurity risks

Jul 2026 · Accounting, Auditing & Accountability Journal · 0 citations · 35 references

Abstract

This study asks which Performance Audit (PA) practices Supreme Audit Institutions (SAIs) prioritize to address cybersecurity risks and how these contribute to public sector cyber-resilience. Drawing on semi-structured interviews with sector participants across several jurisdictions, complemented by documentary analysis and international training materials, our exploratory qualitative design analyses the reconfiguration of PA practices to respond to public sector cyber-resilience imperatives. We show that public sector cyber-resilience goals re-temporalize and re-scale PA. Rather than focusing primarily on retrospective compliance, high-functioning SAIs increasingly orient PA towards anticipatory, system-level and future-facing forms of governance. Empirically, this shift is expressed through new audit objects, new audit practices and new audit products. Combined, these changes reposition PA as a catalytic and infrastructural governance device for building public sector cyber-resilience. PA contributes most strongly to cyber-resilience planning and anticipatory preparedness and increasingly to absorptive capacity, while recovery and adaptation remain uneven and often constrained by mandates, capabilities and institutional boundaries. Thus, PA has potential for, and limitations in, governing cybersecurity risk. The imperative of cyber-resilience underscores emerging tensions between independence, collaboration, transparency and security in cyber-related audits. What is new here is not “audit adapts to cybersecurity risk”, but that public sector cyber-resilience forces a reconfiguration of what counts as auditable, when audit intervenes (ex-ante or ex-post) and what the audit product is (including guidance, simulations, readiness reviews and cross-system coordination). Thus, PA moves beyond retrospective evaluation towards anticipatory and system-oriented governance.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.