-
Audit of annual and consolidated financial statements
We place particular emphasis on customized solutions and international service and adapt our services to your needs.
-
Assurance related advisory services
Assurance related advisory services are based on the knowledge and expertise that are the staff of life of our auditors.
-
Global audit technology
We apply our global audit methodology through an integrated set of software tools known as the Voyager suite.
-
Accounting related consulting
Accounting in accordance with UGB, US-GAAP or IFRS is in constant motion. The integration of new regulations into their own accounting systems poses special challenges for companies.
-
Corporate Tax
We are your problem solvers for corporate tax issues
-
Restructuring, Mergers & Acquisition
Expertise and creativity for the perfect structure
-
International Tax
We are here, whenever our clients require our assistance
-
Transfer pricing
We are your experts for an optimal transfer pricing structure
-
Indirect Tax & Customs
We take care of your indirect taxes so you can take care of your business
-
Private Wealth
We are your competent partner in the field of Private Wealth Tax Services
-
Real Estate Tax
We are a valuable partner at every stage of your property's life
-
Global Mobility Services
Local roots and global networking as a secret for successful assignment management
-
Advisor for Advisor
As advisors for advisors, we support in complex situations
-
Accounting & Tax Compliance Services
Grant Thornton Austria - Your Partner for Experts for Accounting & Tax Compliance Services. In an evolving regulatory landscape, efficient accounting, tax compliance, and financial statement preparation processes are crucial for maintaining an accurate and up-to-date view of your company’s financial position while ensuring compliance with all legal requirements. We provide tailored solutions that not only save your time and resources but also ensure compliance with complex regulations. Our experts are here to support you, allowing you to focus on your core business.
-
Payroll & People Advisory Services
Ensuring Compliance, Efficiency, and Strategic HR Solutions In an evolving legal landscape, it is crucial for companies of all sizes to have efficient and legally compliant payroll accounting systems. The ever-changing regulations and increasing complexity make this an ongoing challenge. At Grant Thornton Austria, we provide comprehensive, precise payroll processing as part of our Payroll & People Advisory Services. Additionally, we offer customized advisory services to help clients optimise their HR strategy, improve operational efficiency, and minimize potential risks.
-
Tax Controversy Services
Your Partner when it matters most! In increasingly complex environment and considering frequent changes in tax regulations, businesses are facing intensified scrutiny from tax authorities. This has resulted in a significant rise of complex tax audits, investigations and potential disputes. Our Tax Controversy Services are tailored to help you navigate these challenges proactively and effectively. Our experts will guide you through all stages of tax proceedings, ensuring robust defence of your position and advising you on preventive measures to minimize the risk of future tax disputes.
-
Tax Technology Services
Your digital partner for an efficient future! In an increasingly digitalised business world, companies must constantly look for optimisations and adjustments to ensure their long-term success. In order to best prepare for the future and to achieve efficiency increases and process optimisations in the digital area, the experts at Grant Thornton Austria are at your side as a reliable partner as part of our Tax Technology Services.
-
Valuation
Valuations are a core competence of Grant Thornton Austria. As auditors and tax advisors we combine profound know-how with our practical experience to offer you customized solutions for your valuation assignment. Our industry expertise is based on years of services to our clients, including listed companies as well as owner-managed companies with an international focus. We advise on valuation matters related to arbitration and provide expert opinions.
-
Forensic Services
When it comes to risks in business, our experts are on hand. We support you not only in suspicious cases or in disputes, but also develop suitable strategies in the area of prevention to avoid serious cases as far as possible. Our Cyber Security team helps you to keep your networks and applications secure and is quickly on hand in the event of a security leak.
-
Cyber Security
Cyber incidents, IT system failures, the resulting business interruptions and the loss of critical data are one of the greatest business risks for companies. Recent cases underline the need for strategic protection and awareness of the issue and require a holistic approach and technical expertise that takes into account all legislative, regulatory and technical aspects of cyber security to protect companies against the daily increase in cybercrime incidents.
-
Sustainability Services
Sustainability is no longer a trend, but the only way to create a future worth living. Our experts will support you in successfully developing your sustainability strategy and preparing your sustainability reporting in compliance with regulations.
-
Transaction Support
We can support you throughout the transaction process – helping achieve the best possible outcome at the point of the transaction and in the longer term.
-
Merger & Acquisition
Companies start new activities and separate from old ones, cooperate and merge. Markets and competitive conditions are subject to constant and increasingly rapid change. As a result, existing business models are changing. Some companies have to restructure and reorganize. But new business opportunities also open up.
-
Restructuring & Going Concern Forecast
Restructuring & Going Concern Forecast: Bundled services for your strategic, operational and financial decisions offer the right answers for companies, banks, shareholders and investors.
-
Internal Audit
Internal Audit helps companies and organisations to achieve their goals by analysing and evaluating the effectiveness of risk management, controls and management and monitoring processes. Internal Audit focuses on independent and objective audit (assurance) and consulting services that improve the value creation and business activities of your company.
-
Expert dispute resolution & advisory
Grant Thornton Austria offers comprehensive services in the field of business-oriented expert services with a broad range of competencies from banking to communication. The core activity of experts is the objective recording of findings and the preparation of expert opinions - regardless of all external circumstances. Our experts Gottwald Kranebitter and Georg H. Jeitler, as sworn and court-certified experts, ensure that the highest professional standards and the principle of objectivity are observed.
-
Blockchain and Crypto-Asset
Blockchain as a carrier technology for crypto currencies and smart contracts, among other things, is becoming increasingly important. Grant Thornton Austria offers comprehensive audit and confirmation services for block chain technologies and business models.
-
Corporate & Brand Strategy
We support you in developing growth strategies for a sustainably successful future and in maximizing the potential of your brand.
-
International Project Coordination
Our International Engagement Management team is your central point of contact for international projects in all our service lines. We take care of operational project management for you and act as a central point of contact and coordination for your projects. We support companies that start international projects from Austria as well as companies from abroad that want to gain a foothold in Austria or use Austria as a hub for their international projects, especially in the DACH (Germany, Austria and Switzerland) and CEE region.
-
International Desks
As a member of the Grant Thornton network, we guarantee direct access to resources from our worldwide circle of partners. This global connection enables us to seamlessly integrate highly qualified specialists and industry experts from different countries around the world into our teams. Through our broad perspective and diverse expertise, we ensure that we can optimally meet the individual requirements of our clients in an increasingly globalised economy.
Businesses have ploughed billions of dollars into technology that promises to keep cyber threats at bay. Gartner claims that end-user spending for the information security market is estimated to grow at a CAGR of 8.5% between 2017 and 2022, reaching $170bn.
While technology undoubtedly plays a major role in combating digital threats, other areas have been neglected. Tellingly, mid-market business leaders surveyed in Grant Thornton’s International Business Report (IBR) say that over-reliance on software is their weakest point in managing cyber and privacy-related threats.
It’s encouraging that business leaders acknowledge this. But now they must act, by improving their employees’ awareness and specialist skills in cyber security.
This doesn’t necessarily mean spending more money. In many cases, companies will be able to taper technology spending as they strengthen and invest in their business acumen, processes and in-house skills.
Customer trust is built on more than technology
“It is essential that businesses understand that investing in technology alone is not the only answer to reducing digital risk, and it will not protect them from losing customer trust should the worst happen” says Mike Harris, cyber security services, Grant Thornton Ireland. “A key starting point for companies is understanding the type of business they’re in, and the value they deliver to the customer”.
Once this is understood, companies will have a clearer idea of the potential impact a breach would have on that relationship, and can better work out how to mitigate this, through a range of measures. Internal governance, processes and people are the other crucial ingredients here.
Take a casino chain as an example. Many casino customers are high-net-worth individuals, who take the security of their financial data – such as transaction history and payment information – extremely seriously. The casino can have the best technology systems in place to protect this data, but it is not enough in isolation.
The company must have robust governance procedures, customer relationship managers and trust policies in place to complement the technology and to protect the company’s reputation in the event of a breach. In this example, the value the casino provides to its customer revolves around customer service, trust and entertainment – with technology acting simply as an enabler to make this happen. Therefore, the company’s approach to digital risk must mirror this – with robust trust procedures around in place, complemented by top-class technologies.
Boosting awareness of human risk management
Understanding that there is more to managing digital risk than relying on technology is just the first step. Companies must then take a number of non-tech measures to protect themselves.
New ways to raise awareness
Companies might be investing in sophisticated cyber security technology, but that won’t necessarily prevent the human error that’s behind many cyber breaches. After all, it’s the human workforce that responds to phishing emails and installs unauthorised software.
Managers can address this by increasing awareness of cyber security issues across the business. But how to do this effectively? Businesses have been running cyber security webinars and mandatory training programmes for many years, yet human error continues to open them up to cyber attack. A new form of education is necessary.
Christos Makedonas, technology risk leader at Grant Thornton Cyprus, says that shorter training formats would help. “No one has time to watch hour-long training videos,” he says. “They should be shortened to a maximum of two minutes. You also need visual reminders – such as banners around the office and messages on screens – to remind people of best practice.
“Businesses should then simulate phishing attempts, and the employees that respond to them can then be given further training. We’ve found these sorts of training programmes to be much more successful than conventional webinars.”
Identify vulnerabilities first, invest later
Businesses need to understand where they are vulnerable to cyber attacks and data-protection breaches before investing in preventive software. This requires specialised skills that most cyber security functions don’t have.
“Businesses need cyber security and privacy-related skillsets to help map out their data and understand their regulatory requirements – particularly in a cloud environment,” says Mike Harris, partner, cyber security services, Grant Thornton Ireland. “They also need cyber technology skills around the technologies they are using.
“For example, if you are using cloud services provided by Amazon or Azure, you need to have the security skills in house to work out what they will and will not do regarding cyber security. That skills component is often overlooked.”
Advanced analytical tech needs advanced analytical minds
Many businesses have invested heavily in advanced analytical cyber security technologies that help identify new threats and vulnerabilities. But these are only as good as the workforce that can interpret the results and implement corresponding changes.
“Lots of people look to technology as a silver bullet, but it isn’t,” says James Arthur, partner, head of cyber consulting, Grant Thornton. “Many companies spend a lot of money on AI-driven, behavioural analytics cyber security software, which can be really useful in some circumstances. However, you normally need to spend an awful lot of human time training it to ensure it delivers useful insights. Then, you need a human at the end of that chain who can look at the output and make/approve changes.”
Insure against the inevitable
“There are only two types of companies: those that have been hacked and those that will be. And even they are converging into one category: companies that have been hacked and will be hacked again.”
These are the words of former FBI director Robert Mueller back in 2012.His message is clear – and just as relevant today as it was seven years ago: a breach is inevitable. It makes a strong case for investing in insurance as another way to manage digital risk.
“Any reasonable cyber security programme has to have an element of detection, response and insurance, because cyber events will happen,” says Harris. “We see increased adoption of insurance that covers both cyber attacks and data privacy regulatory breaches. But while it’s imperative and its use is increasing, the majority of businesses still don’t have this type of insurance or aren’t protecting the right data assets.”
Understand your most valuable data assets and protect accordingly
Businesses should undertake a structured programme to assess and understand their data assets, using a categorisation and classification process. Then, they can identify their ‘crown jewels’ and invest in appropriate insurance cover.
But how do you do this? One way to identify your most critical data is to think like a hacker and then consider the maximum damage they could cause. “The current data security environment is consistently evolving with new threats and vulnerabilities,” says Harris. “Leaders have to be willing to step into the shoes of cyber criminals, understand the threats these groups pose and come up with proactive strategies to protect their business’ interests.”
Which email threads could a former employee leak to embarrass their former managers? What intellectual property and trade secrets would be of interest to a foreign power? And how might a cyber criminal use your data to try to extort money from your business? These are just some of the questions you need to ask before purchasing insurance as part of your digital risk management plan.
Five recommendations for balanced cyber risk management
- Companies must understand that the increasing amount of data that customers share with brands means that trust is more important than ever. It’s essential that businesses understand the necessity of trust management, and that digital risk policies and procedures go a long way to ensuring this.
- Traditional approaches to cyber training are not working. Businesses should develop shorter, more frequently distributed training videos and simulate phishing attempts to better educate their workforces.
- Businesses need to identify and map out their digital vulnerabilities. They need to recruit staff with specialised cyber skills that complement cyber security technical skills. This will ensure that their investment in preventive software is focused on the right areas.
- All businesses will suffer a cyber attack – no matter how much they invest in preventive software. Investing in insurance can bolster your risk management but it is crucial to insure your most valuable data assets and explore specific insurance that covers both cyber attacks and data-privacy breaches.
- Once insurance is secured, businesses must be vigilant about adhering to the terms and conditions. If they fail to install updates, it could nullify the insurance.
These recommendations must be implemented in the context of businesses’ specific digital risk environments. The first step for business leaders is to understand their specific vulnerabilities and threats. Only then can they implement the most relevant technologies, training initiatives and insurance coverage.
If you would like to discuss any of the areas raised in this article, please contact our Business Risk expert Georg H. Jeitler