Field Notes / Compliance
The threat your auditor cannot see
A clean audit does not mean you are secure. The audit and the cyber attack surface are two different territories on the same map. Here is which risks each layer covers, and the one gap only a red team closes.
01 What your financial audit checks
he audit is one of the few external pressures a Filipino SMB owner takes seriously. It is calendared, paid for and closely watched. The auditor signs off, the report goes into the file, and the business moves on confident the controls are working. That confidence is earned on one set of risks and misapplied to another.
A financial audit in the Philippines, run under PFRS or PSA standards by SGV, P&A, a Big Four affiliate or a smaller local practice, checks the integrity of your financial statements. The auditor confirms revenue matches the supporting documents, expenses are categorised correctly, assets and liabilities reconcile, and the statements present a true and fair view. Within that scope the auditor tests controls too: whether the person who initiates a payment is separate from the one who approves it, whether journal entries carry documented authorisation, whether bank reconciliations are signed off each month.
This is good work. It is also a narrow slice. The auditor will not log into your Microsoft 365 tenant to check whether MFA is enabled. They will not review the access list on your accounting software, test whether your firewall exposes remote desktop to the open internet, or run a phishing campaign against your staff. None of that is in scope for a financial audit, and none of it was ever meant to be.
So when an owner says "we just had our audit," they usually mean a clean financial audit that confirms the books are in order. The cyber attack surface was not examined. It was, structurally, invisible to the work that was done.
02 What SOC 2 and ISO 27001 catch
For SMBs that must prove security to customers, usually B2B BPOs, fintechs or healthcare data processors, the next step up is a SOC 2 Type II or ISO 27001 audit. These are security-focused. They verify that documented information-security controls exist and operate consistently over a period of time. SOC 2 organises this around five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality and Privacy AICPA SOC 2 . ISO 27001 organises it around an Information Security Management System ISO/IEC 27001:2022 . Both hand you a report a customer can trust as evidence you manage security at the process level.
On the security dimension this is far more rigorous than a financial audit. The auditor examines your access-management policy, samples evidence that quarterly access reviews happen, checks that backups are documented and tested, and confirms incident-response runbooks exist. You get a defensible answer to the question customers are asking.
What SOC 2 and ISO 27001 do not do is test whether the controls hold against a real attacker. The auditor reads your policy that says MFA is enabled for every administrative account. They sample evidence the policy was followed. They confirm the control operates as designed. They do not try to bypass it. That distinction is the whole point of this article.
03 The territory the audit cannot reach
Here is what a real attacker exploits that no audit reliably catches. Auditors do not Google your company. Attackers do. They pull your staff from LinkedIn, your mail records from public DNS, your subdomains from certificate transparency logs, and your leaked passwords from old breaches. By the time they write the phishing email they know more about how your business runs than your auditor ever asked. Stolen and reused credentials remain the single largest action in confirmed breaches, and that share has climbed every year for half a decade Verizon DBIR 2024 .
The audit confirms MFA is enabled. The attacker confirms one employee has it switched off. The audit confirms phishing training was delivered. The attacker writes a mail that mimics your CEO's real writing style, references a meeting that actually happened, and uses internal jargon learned from nine days of reconnaissance. The audit examines your cloud configuration at one moment. Six months of change requests drift it, and the next sample is half a year away. None of these are auditor failures. They are scope failures. The gaps live in the territory between disciplines.
Coverage by audit type
Strength of each engagement across four areas of risk. Read horizontally: what does this layer actually catch?
| Audit type | Ledger accuracy | Financial controls | Security controls | Real attack paths |
|---|---|---|---|---|
| Financial audit Annual, by an audit firm. Calendar-driven. | ●●●●● Full | ●●●●○ Strong | ●○○○○ Weak | ○○○○○ None |
| SOC 2 / ISO 27001 When customers require it. Process-focused. | ●○○○○ Weak | ●●●○○ Some | ●●●●● Full | ●○○○○ Weak |
| Red team Risk-driven. Tests reality, not paper. | ○○○○○ None | ●○○○○ Weak | ●●○○○ Some | ●●●●● Full |
Red Team Partners synthesis of AICPA SOC 2 Trust Services Criteria, ISO/IEC 27001:2022, and CREST penetration testing standards. Strength reflects what each engagement is designed to verify, not what it could reach with extra scope.
Read that table down the last column. On real attack paths, the thing an intruder actually walks, both audits score near zero. That column is what a red team is built to fill, using the same reconnaissance and standards-based method a professional attacker would CREST .
04 The three-layer stack that works
The owners who handle this well do not treat security as one line item. They run it as a stack of three layers, each answering a question the others cannot. The financial audit confirms the books. The compliance audit confirms the process. The red team confirms reality. The red team is the smallest of the three by cost, typically PHP 280,000 to PHP 850,000 against PHP 600,000 to PHP 4 million for a compliance audit, and it delivers the highest reduction in real risk per peso.
The relationship is sequential, not competitive. The audit verifies your controls are in place. The red team checks whether they hold, and hands you the exact paths that succeeded. Some are paths the audit thought were closed. Some it never considered. Those findings feed the next audit cycle, so the controls you strengthen get verified as operating consistently. Run annually, that loop produces security you can defend to a customer or a regulator, not compliance theatre that decays the day the report is filed. Enforcement under the Data Privacy Act is becoming more active, and insurers are starting to require evidence of security testing before they write a cyber policy NPC Philippines .
If you already have an auditor, ask them straight whether their work has covered the ground a red team would. A good one will tell you it is outside their scope and that you would benefit from both. If you have no security testing yet, run the red team first. Its findings tell you where the control gaps are, then you build the policy layer and audit it once it is mature enough to test.
- Keep the annual financial audit; it confirms the books, nothing more.
- Add SOC 2 or ISO 27001 only where a customer or regulator requires it.
- Run a red team every 12 to 18 months to test whether the controls hold.
- Feed every red team finding into the next audit cycle so fixes get verified.
- Start with a free first-look scan to see which services are exposed today.
If you run a Filipino SMB above PHP 50 million in revenue, the real question is which of the three layers you already have and which you are missing. For most owners the financial audit is in place, the compliance audit may or may not apply, and the red team has never been done. That last gap is the one your auditor cannot close, and the one we exist to fill. Book a free first-look scan and we will tell you, for your specific setup, exactly what ground a red team would cover.
References
Sources
- AICPA. SOC 2 Trust Services Criteria. American Institute of Certified Public Accountants, 2022. aicpa-cima.com
- ISO/IEC. ISO/IEC 27001:2022 Information Security Management Systems. International Organization for Standardization, 2022. iso.org
- CREST International. Penetration Testing Standard. CREST, 2024. crest-approved.org
- Verizon. 2024 Data Breach Investigations Report (DBIR). Verizon Business, 2024. verizon.com
- National Privacy Commission. Data Privacy Act Enforcement. National Privacy Commission of the Philippines, 2024. privacy.gov.ph