Earlier quoted context omitted.
The subject of security consultants, security departments, and whistleblowing seems to me to be of particular concern. I mean, if an auditor publicly reports an audit finding that is ignored by the company and his ethics demand its reporting, is he branded a "whistleblower"? I do not think so, instead it is an "auditor finding". Why does that not apply here? It kind of dovetails with how pathetically organized IT in…
That's not really how auditors work. Auditors either give the client a letter saying what the client wants it to say[0] or decline to provide the client with that letter. They do not go public with their reasons. [0] Companies want the letter to say whatever their regulators and/or contractual obligations demand that it say.
Twitter is a publicly held company.
I'm sure there are conflicts of interest and some degree of confidentiality for auditors and clients, but there is a fundamental public interest of disclosure, at a minimum to the government, in the event of irregularities.
From the SEC:
"In addition, we will continue to focus on auditors. As the Supreme Court noted nearly 30 years ago in U.S. v. Arthur Young & Co., 465 U.S. 805 (1984), auditors play a crucial role in the financial reporting process by serving as the “public watchdog.” So, it is important that we carefully monitor their work and ensure that they fully comply with their professional obligations. If there is a significant restatement or if we learn about improper accounting from a whistleblower, our proactive efforts, or the media, then you can expect that we will scrutinize not only the CEO, CFO and Controller, but also the engagement partner, engagement quality reviewer, and the auditing firm as a whole. We are going to probe the quality of the audit and determine whether the auditors missed or ignored red flags, whether they have proper documentation, and whether they followed professional standards.
And it is important to remember that our ability to bring Rule 102(e) bars against auditors extends beyond instances where there are accounting irregularities at a public company. Our Rule 102(e) program is remedial in nature and meant to protect the integrity of the Commission’s processes. As a result, we can and have investigated auditors when their audits fail to meet the most basic standards, regardless of whether there was an actual problem with the auditing client. By pursuing actions over these bad audits, we can fully leverage the Division’s resources and close off access to those who shirk their responsibilities as gatekeepers to the securities markets."
-------From there you can see legal and institutional gravitas, ethics, and expectations of accountants and auditors of public companies. That's kind of what I'm getting at re: elevating security and certain IT roles to higher responsibility and codification.
Now, is this a smear attempt by Jack Dorsey in relation to the Elon Musk lawsuit? Eh, maybe.