← Back to list

Cyber Security “Consulting” at PwC: A Simulation Write-Up

With four semesters of a Georgia Tech Online Master in Science in Cybersecurity Policy under my belt and an early career background in…

Tarunika Kapoor · 2026-04-11 20:19 · 0 claps · 4.2 min read
#consulting #cybersecurity #upskilling #pwc
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity 🔧 · Data Engineering 🔬 · Science · General

Cyber Security “Consulting” at PwC: A Simulation Write-Up

With four semesters of a Georgia Tech Online Master in Science in Cybersecurity Policy under my belt and an early career background in cybersecurity consulting, I’m always looking for ways to practice my cybersecurity and governance, risk, and compliance (GRC) skills. Recently, I completed the Cyber Security Consulting simulation from PwC on Forage to build hands-on experience in risk assessment, controls evaluation, and audit-style communication.

Task 1: Risk Assessment

According to the simulation description, you, the user, are given “the opportunity to step into the shoes of a PwC team member working with a cybersecurity group within the platform, the Enterprise Risk and Control Solutions group, and complete tasks that replicate the work that this team does.” This task focuses on a risk assessment of the client MedTech Industries’ procure-to-pay (P2P) process based on SOX regulations as they look to go public.

You’re provided with their P2P SOP and some other resources such as a document on IT general controls but are also encouraged to conduct your own independent research, summarizing your findings in an email to a senior associate.

As this was my first simulation, I started by reviewing the SOP and the reference resources suggested to build a baseline of the client’s applicable P2P process and IT system controls. I then analyzed their process and summarized business process and system control gaps (such as flawed approval processes or shared department passwords) into the email deliverable, recommending improvements where possible.

This task strengthened my ability to:

  • Analyze business processes through a controls lens
  • Map observed gaps to risk and compliance implications
  • Communicate findings in a concise, audit-style format

A key gap in my approach was the lack of rigor. I relied on my general knowledge of IT concepts rather than systematically reviewing SOX regulations, which limited the depth of my analysis. My lack of structured notes also reduced the precision and organization of my assessment. Both of these issues are areas of improvement that I will focus on in future assessments.

Task 2: SDLC Walkthrough Questions

The next task involves a simulated meeting (conducted as a multiple-choice quiz) with an IT manager from MedTech Industries in relation to the Software Development Life Cycle (SDLC) program for the implementation of a payroll system.

It’s a fairly effective way to provide the feeling of “being in the room” with the client and your colleague, and understanding what these interactions can look like and the (time or effort) demands that come with them. It provided light practice in evaluating SDLC processes and identifying control-relevant signals during a walkthrough.

Still, the responses provided for each meeting “scenario” are limited in complexity, thus reducing the need to apply deeper judgement and critical thinking. Because the correct responses were quite self-evident, this task did not challenge my ability to navigate ambiguous client interactions or competing interpretations, which I know from personal experience are skills critical in real consulting environments.

Task 3: IT General Controls Test of Design and Operating Effectiveness

After the last successful meeting, you are tasked with evaluating change management controls through a Test of Design and Operating Effectiveness for the client. To do so, you’re provided with several artifacts — walkthrough notes, instructions for the task, a template, a few change management examples — to assess whether controls were appropriately designed and consistently executed. I aligned evidence with various controls and organized my analysis into the template provided.

This task highlighted several areas for improvement:

  • Interpreting testing templates and expectations more carefully upfront
  • Distinguishing clearly between design adequacy and operating effectiveness
  • Maintaining consistency and granularity in documenting control evaluations

My misinterpretation of part of the task led to me reworking a significant portion of it, which serves as a handy reminder to fully understand the criteria before you begin analysis. Once again, my lack of granularity was my weak point in this task and provided a learning curve and a future area of improvement.

Task 4: Controls Testing Summary Presentation

For this final task, you are tasked with summarizing the control failures, process gaps, and recommendations on a single-slide presentation for a compliance stakeholder of MedTech Industries.

This task involved reviewing past artifacts such as the email summary from the second task and your analysis from the previous. I synthesized this prior analysis into the provided format and proposed remediation steps, though fine-tuning the clarity and conciseness required for high-level communication took longer. The true challenge of this task was ensuring accuracy and completeness given the earlier gaps in my analysis. This was helped by revisiting my past work and refining my conclusions.

In Conclusion: Takeaways

This simulation provided targeted practice in:

  • Control gap identification and risk assessment
  • IT general controls evaluation (design vs. operating effectiveness)
  • Structuring findings for audit and stakeholder communication

The PwC simulation served as a good introduction to cybersecurity consulting and provided the useful reminder to approach concepts through a more rigorous and granular framework. Nevertheless, it lacked the ambiguity, complexity, and indirect feedback that would lead to the maturation in GRC skills and judgement that I was seeking. This simulation didn’t entirely hit the mark for me, but it is mostly straightforward and well-guided and highlights the importance of precision, structured analysis, and alignment to formal control frameworks.


메타데이터
post_id
1aefbec442d4
slug
cyber-security-consulting-at-pwc-a-simulation-write-up-1aefbec442d4
url
https://medium.com/@tarunikakapoor/cyber-security-consulting-at-pwc-a-simulation-write-up-1aefbec442d4
canonical_url
https://medium.com/@tarunikakapoor/cyber-security-consulting-at-pwc-a-simulation-write-up-1aefbec442d4
author_url
https://medium.com/@tarunikakapoor
status
ok
fetched_at
2026-06-13 07:35:29