IT audit, explained through what actually went wrong
MarcoWeb is a practical resource for IT auditors, security teams and the people who have to answer to them. Every control is explained through a real, publicly documented breach, what failed, what good looks like, and exactly how it gets tested.
What MarcoWeb publishes
The ITGC series
Every IT general control across the framework, each one paired with the breach that proves why it matters, from Colonial Pipeline to Maersk, Wirecard to Knight Capital.
Threat reports by industry
Breach analyses filtered by sector, FinTech, healthcare, telecom, mining, energy, gaming and critical infrastructure, mapped to the controls that failed.
Free IT audit trainingfree
Short lessons with knowledge checks covering the reasoning behind IT general controls, design versus operating effectiveness, sampling, and evidence that holds up under review.
The ITGC Audit Tool ↗
A browser-based platform for running IT general controls assessments, risk and control matrices, workpaper generation, and evidence tracking.
How the analysis is produced
Everything published here is based on publicly documented incidents, regulatory findings, court records, official post-incident reviews and vendor disclosures. Nothing identifies undisclosed weaknesses in any named organisation.
Sources are cited where used, drawing on material from CISA, the FBI, the ACSC, NIST, ENISA and national regulators. Where a control maps to a recognised framework, COBIT, ISO 27001, NIST, that mapping is made explicit rather than implied.
Corrections are welcome and applied openly. See theeditorial policy for sourcing standards and how content is reviewed.
Who writes it

Marco Cavani
Information Security Consultant · IT Governance
MarcoWeb is written and reviewed by Marco Cavani, who works in information security and IT governance and built the ITGC Audit Tool. Based in Australia.
Get in touch
Questions, corrections, collaboration enquiries or report requests, all welcome.
Contact MarcoWeb