Scott-Mahoney_Web

Scott Mahoney

CISA, CRISC Principal

Get to Know Me

Scott Mahoney is a Principal with more than 25 years of experience, focusing on information technology risk and control matters.

This includes SOC 1 and SOC 2 reporting, risk assessments, SOX 404 testing and internal audit co-sourcing. Scott is a member of Withum’s Risk Advisory and Assurance Services Team working primarily in the financial services, technology, insurance, professional services and manufacturing industries.

Industry Expertise

Service Expertise

Learn More About My Story

Learn more about my professional experience and how I spend my time outside the firm.

Education:

  • MBA, Concentration in Management, Bentley University – McCallum Graduate School of Business
  • BS, Accounting Information Systems, Bentley University

Professional Affiliations:

  • American Institute of Certified Public Accountants (AICPA)
  • Information Systems Audit and Control Association (ISACA)

Authored Insights

Read more
Healthcare Cyber Patient Data
Understanding and Evaluating Controls for Your Healthcare Organization

Have you ever heard the phrase, what keeps you up at night? If you’re a healthcare executive, there is an ever-growing list of challenges, including patient care, staffing, technology and equipment, facilities, and pandemics. And those are just the primary concerns. This leaves little room to be consistently overburdened with extra administrative oversight of internal…

Read more
1200-x-435-Vulnerability-Assessment
Vulnerability Assessment: What Does It Really Assess?

Vulnerability Assessments: Vulnerable: susceptible to physical or emotional attack or harm. Synonyms: defenseless, powerless, weak, susceptible. I’m sure your initial thoughts, like mine, personified the word. But today this term is used to describe an organization’s cybersecurity posture. Maintaining an awareness of your organization’s vulnerabilities is one way to protect yourself from a cybersecurity attack….

Read more
1200-x-435-penetration-test
What Does a Penetration Test Really Tell You?

Share Penetrationtesting is one of the essential elements neededto gain insight into your currentcybersecurityposture. Itenablesyouto identify how you may be susceptible to unknownweaknessesthat external parties may be able to exploit.Making the decision to have a penetration test done to your network is a great first step. Understanding what having the test done will show you,…