Does an accounting firm need the Essential Eight?
Not as a legal requirement, and increasingly as a commercial expectation. More usefully, the eight controls happen to line up almost exactly with what actually goes wrong in accounting practices, which is a better argument than any compliance one.
The two realistic incidents are a compromised mailbox leading to payment fraud, and ransomware encrypting the file store. Multi-factor authentication addresses the first, tested and protected backups address the second, and restricting administrative privileges limits how far either travels. Those three controls are not a framework exercise; they are a direct response to the two ways firms lose money and clients.
The commercial pressure is real and worth engaging with rather than resenting. Cyber insurers now ask specific questions about these controls at renewal, and answering inaccurately is a problem in its own right. Corporate clients conducting supplier due diligence ask. Government-connected work assumes it. There is no Essential Eight certificate, so what you need is a dated maturity report with evidence behind each score, which is what an assessment produces.
For most practices Maturity Level 1 is the right target and it is a project rather than a transformation. AFM Services reached it alongside migrating MYOB to Xero, decommissioning their server and deploying ThreatLocker. If you want to know where your firm sits today rather than guess, the Cyber Security Scorecard measures it free and reports control by control, or call 1800 456 567.
Find out where your firm sits
The free Cyber Security Scorecard measures your practice against all eight controls and reports in writing, with the evidence behind each score.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business