| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Obvladovanje kibernetskih tveganj v računovodstvu: vloga notranjih kontrol
Authors:ID Hancman, Mojca (Author)
ID Zdolšek, Daniel (Mentor) More about this mentor... New window
Files:.pdf VS_Hancman_Mojca_2025.pdf (804,27 KB)
MD5: 374678897119CE886A46153BE9726E63
 
Language:Slovenian
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:EPF - Faculty of Business and Economics
Abstract:V diplomskem delu je raziskana vloga notranjih kontrol pri obvladovanju kibernetskih tveganj v računovodskih informacijskih sistemih. Namen diplomskega dela je bil raziskati, kako notranje kontrole prispevajo k večji varnosti računovodskih informacijskih sistemov in zmanjšujejo tveganja za kibernetske napade. V delu so najprej predstavljeni osnovni pojmi in vrste notranjih kontrol, nato pa je sledi pregled domače in tuje strokovne literature, ki obravnava pomen teh kontrol pri zaščiti informacijskih sistemov. Poudarili smo ranljivost računovodskih informacijskih sistemov v digitalnem okolju, kjer grožnje, kot so phishing napadi, kraja identitete in malware napadi, predstavljajo resno nevarnost za organizacije. Predstavljene so glavne vrste notranjih kontrol (preventivne, detektivne in korektivne) ter njihova implementacija preko sodobnih računovodskih informacijskih sistemov, ki omogočajo omejevanje dostopa, ustvarjanje revizijskih sledi ter sprotno spremljanje transakcij. Obravnavali smo tudi možne napredne varnostne ukrepe, kot so blockchain tehnologija, pametne pogodbe in neprekinjena revizija. Diplomsko delo zaključuje, da učinkovita zaščita računovodskih informacijskih sistemov temelji na celostnem pristopu, ki vključuje napredno tehnologijo, usposabljanje zaposlenih in stalno posodabljanje varnostnih politik. Rezultati potrjujejo, da notranje kontrole pomembno prispevajo k zmanjšanju kibernetskih tveganj in ohranjanju stabilnega in zanesljivega finančnega poročanja podjetij. Preverjene so tri hipoteze. Hipoteza H1 se nanašala na povezavo med rednimi pregledi notranjih kontrol in zmanjšano pojavnostjo nepooblaščenih dostopov ter finančnih prevar. Hipoteza H3 obravnava vpliv celovitih strategij obvladovanja tveganj v računovodskih informacijskih sistemih na preprečevanje finančnih izgub in kibernetskih incidentov. Obe hipotezi sta bili podprti z ugotovitvami iz strokovne literature. Hipoteze H2, ki predvidevala, da so podjetja z močnimi preventivnimi kontrolami redkeje tarča kibernetskih napadov, pa ni bilo mogoče potrditi ali ovreči, saj v pregledanih virih ni bilo dovolj empiričnih podatkov za primerjavo pogostosti napadov glede na vrsto uporabljenih notranjih kontrol. Raziskava ima določene omejitve, ki jih je treba upoštevati pri interpretaciji ugotovitev. Osredotoča se zgolj na najpogostejše oblike kibernetskih groženj in ne zajema vseh možnih vrst napadov. Prav tako obravnava predvsem osnovne vrste notranjih kontrol in izbrane avtomatizirane varnostne ukrepe, pri čemer niso vključeni vsi varnostni mehanizmi, ki jih uporabljajo sodobni računovodskih informacijski sistemi. Diplomsko delo temelji izključno na pregledu obstoječe literature v slovenskem in angleškem jeziku. Poleg tega se raziskava ne ukvarja s podrobno primerjavo posameznih programskih rešitev računovodskih informacijskih sistemov (npr. SAP, Oracle, Microsoft Dynamics), temveč ostaja na ravni splošnih značilnosti notranjih kontrol v digitalnem okolju.
Keywords:kibernetska tveganja, kibernetska varnost, računovodstvo, upravljanje kibernetskih tveganj, notranje kontroliranje, notranje kontrole
Place of publishing:Maribor
Publisher:M. Hancman
Year of publishing:2025
PID:20.500.12556/DKUM-93694 New window
UDC:004.056:657
COBISS.SI-ID:247371523 New window
Publication date in DKUM:02.09.2025
Views:220
Downloads:59
Metadata:XML DC-XML DC-RDF
Categories:EPF
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:14.07.2025

Secondary language

Language:English
Title:Managing cybersecurity risks in accounting: the role of internal controls
Abstract:In our bachelor’s degree thesis we explore the role of internal controls in managing cybersecurity risks within accounting information systems (AIS). The purpose of the thesis is to examine how internal controls enhance the security of accounting information systems and reduce exposure to cyber threats. The thesis first introduces the key concepts and types of internal controls, followed by an analysis of Slovenian and international literature addressing their role in safeguarding AIS. It highlights the vulnerability of such systems in the digital environment, where threats like phishing attacks, identity theft, and malware represent serious risks to organizations. The main types of internal controls—preventive, detective, and corrective—are presented, along with their implementation through modern AIS, which enable access restrictions, audit trails, and real-time transaction monitoring. Possible advanced security mechanisms such as blockchain technology, smart contracts, and continuous auditing are also discussed. The thesis concludes that effective protection of AIS requires a comprehensive approach that combines advanced technologies, employee training, and regular updates to security policies. The findings confirm that internal controls contribute significantly to reducing cybersecurity risks and to maintaining stable and reliable financial reporting. Three hypotheses were evaluated. Hypothesis H1 examined the relationship between regular reviews of internal controls and a lower occurrence of unauthorized access and financial fraud. Hypothesis H3 considered whether organisations applying enterprise risk management strategies in AIS are more effective at preventing financial losses and cyber incidents. Both were supported by findings from the reviewed literature. In contrast, Hypothesis H2, which states that organizations with strong preventive controls are less frequently targeted by cyberattacks, could neither be confirmed nor rejected due to a lack of empirical data comparing attack frequency across different internal control settings. The research has certain limitations that should be acknowledged. It focuses on the most common types of cyber threats and does not cover the full range of possible attack methods. Moreover, it addresses only basic categories of internal controls and selected automated security activities, without covering all technical solutions used in contemporary AIS. The analysis in our thesis is based solely on literature in Slovenian and English. Furthermore, the thesis does not include a detailed comparison of specific AIS software solutions (such as SAP, Oracle, or Microsoft Dynamics) but remains at the level of general internal control characteristics in the digital environment.
Keywords:cyber risk, cyber security, accounting, cybersecurity risk management, internal control, internal controls


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica