EY and Information Security: Governance, Trust and Regulatory Alignment

When observing the Big Four through the lens of information security, it quickly becomes clear that the real differences between the firms are not found in their service portfolios but in how they position security within organizations. On paper, all of them offer cyber advisory, risk, compliance, and security services. In practice, however, the way security is approached, discussed, and embedded into companies feels very different. This is where EY becomes particularly interesting, because information security here is very consistently viewed through the perspective of governance, trust, and regulatory alignment.

EY has built a strong global reputation over many years in risk advisory, governance structures, internal control systems, and in translating regulatory requirements into organizational models. This DNA strongly influences how information security engagements are approached. While other firms often begin with architecture, transformation, or technical depth, EY frequently starts from a very different angle. The starting questions are often about structure rather than technology. How is security organizationally anchored. Where do responsibilities sit. How do risk, compliance, internal audit, and information security interact. And how can these structures be explained and justified to boards, audit committees, and regulators.A chief risk officer from a regulated environment once summarized this perception very clearly in a discussion. When we talk to EY about security, they immediately think in terms of governance and risk structures, not tools or architecture. This viewpoint is characteristic. Information security is not treated as an isolated IT topic, but as a component of corporate governance and enterprise risk management.

In times of increasing regulation, this perspective becomes even more relevant. Frameworks such as DORA, NIS2, industry-specific regulations, and growing scrutiny from supervisory authorities require organizations not only to be secure but to demonstrate why they are secure. They must show how security is embedded into risk frameworks, how responsibilities are defined, and how control mechanisms are structured. EY is widely recognized for its ability to build this bridge. Translating regulatory requirements into governance models, policies, control systems, and clear accountability structures is one of the firm’s core strengths.In many engagements, the work therefore does not start with architecture but with structure. Who is responsible for which aspect of security. How do the lines of defense operate. How is information security integrated into the overall risk framework. How are risks assessed, documented, and communicated. Only after this foundation is established do technical and operational measures follow. A risk manager once described it in a very fitting way. At EY, technology follows governance, not the other way around.

This approach may appear less spectacular than red teaming, SOC build-ups, or advanced detection engineering, but for many organizations it is the decisive factor. Without clear structures, without defined responsibilities, and without a strong governance model, technical measures often remain isolated and short-lived. EY focuses exactly on this point. Security is structured in a way that makes it sustainable and independent from individual people or temporary projects.From our perspective at Darkgate, this nuance is particularly noticeable. We are in daily conversations with CISOs, risk officers, audit professionals, and decision makers within audit and advisory firms. In these discussions, EY is repeatedly associated with this strength. When organizations need to structure security in a way that is regulatorily sound and organizationally robust, EY is very often mentioned.

A head of information security from a global company once put it into very simple words. EY forces us to think about security from the perspective of our board rather than from the perspective of IT. This statement captures the role very well. Information security becomes a matter of corporate governance and trust. Trust towards investors, towards supervisory bodies, and towards regulators.This strong connection between governance, risk, and information security leads to EY frequently being involved in projects that are closely linked to boards, audit committees, and regulatory institutions. The focus is not only on whether security measures exist, but on whether they are structurally understandable, documented, and embedded into formal control systems. Policies, accountability structures, reporting lines, and control mechanisms play a central role.

For information security professionals, this creates an environment that is highly strategic. They work closely with leadership levels, help design governance models, define risk structures, and ensure that security is integrated into the overall management of the organization. It is less about purely technical depth and more about positioning security as a stable, structured, and sustainable element of corporate operations.Ultimately, information security at EY is closely linked to trust. Trust in structures, trust in processes, and trust in control mechanisms. Security is not treated as an isolated discipline but as part of a broader governance and risk model. Anyone who wants to understand how information security is discussed and positioned at board level, and how regulatory requirements are translated into durable organizational structures, will find a very clear example of this approach at EY.

Darkgate is an independent magazine.
Our content is free and will always remain editorially independent.
If this article helped you, consider supporting our work with a small contribution.

Picture of Darkgate Editorial Team
Darkgate Editorial Team