21.09.2026
Gabrielius Vinciunas

Cyber Security Audit vs Information Security Risk Assessment: What Is the Difference?

An information security risk assessment and a cyber security audit are distinct processes. A risk assessment helps an organisation understand the risks it faces and how to manage them, while an audit independently assesses compliance with applicable cyber security requirements. The two processes are related but differ in purpose, process and frequency.

With the NIS2 Directive requirements now in force in Lithuania, this distinction has become increasingly relevant. Organisations must not only implement the required measures but also continuously assess where their greatest risks lie and what to address first.

It is no surprise that this topic is also high on the business agenda. According to PwC, 60% of business and technology leaders rank investment in cyber risk management as a top strategic priority.

In this blog post, we look at how an information security risk assessment differs from a cyber security audit, what the two processes have in common, who they apply to and how they work together.

What Does the Lithuanian Law on Cyber Security Require for Risk Assessments and Audits?

Risk assessments and cyber security audits are two separate obligations for cyber security entities. The Lithuanian Law on Cyber Security (LCS) and the Cyber Security Requirements Description (CSRD) set out these requirements. The two processes follow different schedules:

  • Risk assessment – at least once a year.
  • Independent cyber security audit – at least once every three years.

These requirements apply to organisations included in the Register of Cyber Security Entities. The National Cyber Security Centre (NCSC) notifies organisations when they are included in the register, and that notification starts the deadlines for implementing the applicable requirements. Frequency differs between the two processes. A risk assessment may also need to be repeated more often than once a year – we look at the specific circumstances below.

This is not a choice between one process and the other. For cyber security entities, they are separate components of the same regulatory framework. Let us first look more closely at the risk assessment – the process organisations need to carry out more frequently.

What Is the Purpose and Outcome of an Information Security Risk Assessment?

An information security risk assessment aims to build a realistic picture of the risks an organisation faces. It considers what needs protecting, which threats and vulnerabilities are associated with those assets, and the consequences they could cause. The result is a clearer view of which areas need attention first and which measures can manage those risks.

The process begins with a simple question: what do we need to protect? For one organisation, a customer database may be critical; for another, it may be a production control system or a service whose disruption would immediately affect customers. CISA also treats risk assessment as more than an evaluation of technology assets, linking it to potential impacts on operations, critical services and reputation.

Next, it identifies threats and vulnerabilities, assesses potential impact, and determines the level of risk. Lithuanian cyber security requirements under the CSRD follow the same sequence: the risk assessment and management process must include identifying and classifying networks and information systems, analysing risks, and selecting risk treatment measures.

What Happens After Cyber Security Risks Have Been Assessed?

Once risks have been assessed, the organisation must decide which require immediate attention and how to manage them. One risk may need to be reduced immediately, another monitored, while in some cases the organisation may choose to accept it.

Not every weakness identified creates the same level of risk. A similar vulnerability in a rarely used internal system and in a system on which core operations depend can have very different consequences.

The key outcome of the assessment is therefore not the number of issues found. What matters more is identifying the most significant risks, where additional security controls are needed, and what to address first.

If remediable gaps are identified, the applicable Lithuanian cyber security requirements under CSRD require a risk treatment plan. The plan must set out:

  • measures for treating unacceptable risks,
  • the resources required,
  • responsible persons,
  • implementation deadlines.

Cyber risks are also increasingly being considered within the organisation’s broader risk landscape. In the FAIR Institute survey, 38% of respondents said cyber risks in their organisations are already managed alongside other business risks, while a further 61% said cyber risk information is fed into enterprise risk management.

When Does a Risk Assessment Need to Be Repeated?

A risk assessment must be conducted at least once a year, but it may need to be repeated sooner. Under the applicable Lithuanian cyber security requirements, reassessment is required in the following circumstances:

  • regularly – at least once a year,
  • following significant organisational or other material changes,
  • following a major cyber security incident.

The reasoning is straightforward: much more than the date on the calendar can change over the course of a year. New systems may be introduced, while suppliers, access rights, infrastructure or processes may change.

For example, an organisation may start using a new cloud service. This can change not only the technology itself but also where data is stored, who has access to it, and which provider the service depends on. The previous risk assessment will not reflect these new circumstances.

The same applies after a major cyber security incident. It may reveal previously unidentified vulnerabilities or show that the measures in place work differently in practice than expected.

What Requirements Apply to the Risk Assessment Methodology?

A risk assessment must cover the elements required by Lithuanian cyber security regulation, but this does not mean every organisation has to follow one specific methodology. The NCSC has developed a risk assessment methodology (in Lithuanian) that can help structure the process, drawing on international practices including ISO/IEC 27005, NIST, BSI and NATO risk management principles.

Among these, ISO/IEC 27005 is an international standard focused on information security risk management. It covers risk identification, analysis, evaluation and treatment, but the Lithuanian requirements do not require organisations to conduct their risk assessment specifically in accordance with ISO/IEC 27005.

The standard also does not mean that every organisation’s risk assessment should look the same. Organisations adapt the process to their activities, systems, information assets, and risk environment. A manufacturing company and a financial institution will naturally have different risk profiles.

Importantly, organisations that were already systematically assessing risks before the current LCS and CSRD requirements took effect do not necessarily need to start from scratch. Instead, they should ensure their existing process covers all required elements and is carried out at the required frequency.

What Is Assessed During a Cyber Security Audit?

A cyber security audit assesses an organisation’s compliance with the cyber security requirements applicable to it. The audit follows the methodology approved by the NCSC and examines both organisational and technical cyber security measures, as well as their practical implementation.

The audit goes beyond reviewing documentation. It examines the processes operating within the organisation, the measures in place, and the evidence demonstrating that the applicable requirements have been implemented.

The results are documented in an audit report, including conclusions, identified non-conformities and other information required by the methodology. The report is prepared to ensure the audit results are properly documented and can be submitted to the NCSC where required.

What Does the Cyber Security Audit Process Look Like, Step by Step?

A cyber security audit, like a risk assessment, typically follows several stages:

1. Defining the audit scope

The first step is to agree the audit scope – which systems, processes, business units or areas of activity will be assessed.

2. Collecting information and evidence

The auditor then gathers and analyses audit-related information and evidence. This may include organisational policies and procedures, technical configurations, system logs, and other relevant documentation. Where necessary, the auditor may conduct interviews with responsible employees, system administrators, or other representatives, and carry out on-site checks.

3. Assessing compliance

Once the auditor has collected and analysed the information, they assess whether the cyber security measures implemented in practice meet applicable Lithuanian legal requirements and the organisation’s internal policies. If the organisation is ISO/IEC 27001 certified, the assessment may also consider the standard’s requirements. This does not remove the obligation to comply with Lithuanian cyber security requirements, but it can enable more effective use of existing documentation and processes.

4. Preparing audit conclusions and the report

Once the assessment is complete, the auditor prepares an audit report that sets out the audit conclusions, identified non-conformities, and, where applicable, remediation recommendations.

5. Submitting documents to the Cyber Security Information System

Where required, the audit report together with documents confirming the auditor’s qualifications must be submitted to the Lithuanian Cyber Security Information System (KSIS).

Who Can Conduct a Cyber Security Audit?

A cyber security audit may be conducted only by an auditor who meets the applicable requirements. Under the LCS, these requirements are as follows:

  • appropriate qualifications,
  • independence,
  • impartiality,
  • good professional standing.

When selecting cyber security audit services, it is therefore important to consider not only the company providing the service but also the competence and experience of the individual specialists who will conduct the audit.

Auditors assess both organisational and technical cyber security measures, which requires appropriate knowledge and qualifications. The law sets out how an auditor’s competence can be demonstrated, so it is worth checking this before selecting a specialist.

In practice, auditors often demonstrate their qualifications through international certifications such as ISACA CISA, CISM, or CRISC; (ISC)² CISSP; GIAC GSNA; or ISO/IEC 27001 Lead Auditor (LA). The exact list of accepted certifications and other qualification requirements is set out in the methodology approved by the NCSC.

Another important requirement is that the auditor must be independent of the activity under assessment.

An independent assessor cannot be responsible for the decisions or processes being assessed and also confirm their compliance. This helps preserve an impartial view of how the organisation actually implements cyber security requirements.

What Happens If Non-Conformities Are Identified During the Audit?

Non-conformities identified during an audit must not only be recorded in the audit report; the organisation must also take concrete steps to address them. As with a risk assessment, this will generally involve preparing a remediation plan that sets out priorities, responsible individuals, and implementation deadlines.

The NCSC may request copies of the audit report, compliance assessment documents and the remediation plan. The organisation must provide these documents within five working days of receipt of the NCSC’s request.

If an organisation fails to comply with the applicable cyber security requirements, the LCS provides for a fine. In such cases, responsibility rests with the head of the cyber security entity, rather than with the auditor or a particular IT department.

When Might an Audit Be Required Earlier Than the Standard Deadline?

Although the general rule is that an independent cyber security audit must be conducted at least once every three years, certain sectors or specific circumstances may require more frequent audits. For example, some energy infrastructure may be subject to an audit requirement at least once every 12 months.  

According to the official guidance of Lithuanian distribution network operator ESO (in Lithuanian), owners of power plants above 100 kW, solar and wind power plants, and energy storage facilities must undergo cyber security audits periodically throughout the operating life of the equipment, but no less frequently than once every 12 months from the submission of the security declaration.

In addition, when inspecting an organisation, the NCSC may request its latest audit report. In practice, it is advisable to plan audit timelines in advance rather than leave the audit until the last possible day before the three-year deadline.

What Is the Difference Between a Risk Assessment and a Cyber Security Audit?

The five main differences between an information security risk assessment and a cyber security audit are summarised as follows:

  • Purpose. A risk assessment identifies and evaluates the risks relevant to the organisation and helps select appropriate risk treatment measures. An audit independently assesses compliance with applicable cyber security requirements.
  • Frequency. A risk assessment is conducted at least once a year and in additional circumstances specified by the applicable requirements. An independent cyber security audit is conducted at least once every three years.
  • Who conducts it? The organisation can conduct a risk assessment internally or with external specialists. Only independent auditors who meet the applicable requirements may conduct an audit.
  • Methodology. A risk assessment must cover the elements required by Lithuanian cyber security regulation and may use the NCSC methodology as a framework. A cyber security audit is conducted in accordance with the NCSC-approved audit methodology.
  • Outcome. A risk assessment identifies and evaluates risks and, where necessary, leads to a risk treatment plan. Audit findings and identified non-conformities are documented in the audit report.

How Do Risk Assessments and Cyber Security Audits Complement Each Other?

Although they serve different purposes, the results of one process can inform the other. Non-conformities identified during an audit provide additional insight into the organisation’s risks, while a risk assessment helps strengthen security controls in a targeted way ahead of the next audit.

This relationship is also reflected in Lithuanian cyber security requirements. When assessing the effectiveness of applicable cyber security measures, an entity must consider the results of risk assessments, incidents that have occurred, and the outcomes of incident management.

The practical benefit is straightforward: an issue identified during an audit can be incorporated into the next risk assessment, where its likelihood and potential impact can be evaluated. The risk assessment, in turn, helps determine which improvements to prioritise.

According to the FAIR Institute’s 2025 State of Cyber Risk Management survey, 76% of risk management professionals regularly use compliance audit findings to inform cyber risk decisions.

Together, the two processes therefore support a consistent cycle of cyber security management across the organisation.

Cyber Security Audit or Risk Assessment: Which Should Come First?

For cyber security entities included in the register, there is essentially no choice between the two processes: both the risk assessment and the independent cyber security audit are legal obligations with different deadlines. A risk assessment must be conducted at least once a year, while an independent audit must be conducted at least once every three years from the date of inclusion in the register.

In practice, the question of where to start usually arises when an organisation has only recently been notified by the NCSC that it has been included in the register, or when neither deadline has yet passed. In that situation, it generally makes sense to begin with a risk assessment, as its findings can help the organisation prepare more effectively for the subsequent independent audit.

For organisations not subject to these statutory obligations, the appropriate starting point depends on the circumstances. Significant technological or organisational changes, or the need to gain a clearer view of cyber security risks before planning further security measures, are common reasons to begin with a risk assessment.

Baltic Amadeus cyber security specialists conduct information security risk assessments and independent cyber security audits. First, assess your organisation's current needs and choose the next steps accordingly. Contact the Baltic Amadeus cyber security team.

Related Blogs

Let’s talk about your project

Starting something new or need support for an existing project? Reach out, and our experts will get back to you within one business day.

Start the conversation

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.