All insights

Does an accounting firm need the Essential Eight?

2 min readBy Brendon Whiting, Founder · 14 January 2026

Not as a legal requirement, and increasingly as a commercial expectation. More usefully, the eight controls happen to line up almost exactly with what actually goes wrong in accounting practices, which is a better argument than any compliance one.

The two realistic incidents are a compromised mailbox leading to payment fraud, and ransomware encrypting the file store. Multi-factor authentication addresses the first, tested and protected backups address the second, and restricting administrative privileges limits how far either travels. Those three controls are not a framework exercise; they are a direct response to the two ways firms lose money and clients.

The commercial pressure is real and worth engaging with rather than resenting. Cyber insurers now ask specific questions about these controls at renewal, and answering inaccurately is a problem in its own right. Corporate clients conducting supplier due diligence ask. Government-connected work assumes it. There is no Essential Eight certificate, so what you need is a dated maturity report with evidence behind each score, which is what an assessment produces.

For most practices Maturity Level 1 is the right target and it is a project rather than a transformation. AFM Services reached it alongside migrating MYOB to Xero, decommissioning their server and deploying ThreatLocker. If you want to know where your firm sits today rather than guess, the Cyber Security Scorecard measures it free and reports control by control, or call 1800 456 567.

Find out where your firm sits

The free Cyber Security Scorecard measures your practice against all eight controls and reports in writing, with the evidence behind each score.

Frequently asked questions

Not as a matter of law for private firms. It arrives through insurers asking about its controls at renewal, corporate clients embedding it in supplier due diligence, and any government-connected work assuming it. Voluntary in law and increasingly expected commercially, which is a distinction that keeps narrowing.

Multi-factor authentication and tested backups, then restricting administrative privileges. Those three address the two things that actually happen to practices: a compromised mailbox leading to payment fraud, and ransomware encrypting the file store. The remaining controls matter and these three do most of the work.

A one-to-three-month project for a typical firm, with the fastest wins in the first fortnight. Some evidence is inherently time-shaped, since a patching cadence cannot be shown until it has run several cycles. Plan it for a quiet period rather than the season, and start before a client deadline forces it.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.