How should an accounting firm protect client financial data?
Four things in order: multi-factor authentication on every mailbox, access control so people reach the clients they work on and not others, managed and encrypted devices, and an absolute rule that payment detail changes are verified by phone. Those four address the overwhelming majority of what actually happens to firms.
Accounting practices are concentrated targets and it is worth being clear about why. A single firm holds tax file numbers, bank details, financial statements and payment instructions for hundreds of businesses and individuals. That concentration is more valuable to an attacker than any one of those clients, which is why practices are targeted deliberately rather than incidentally, and why the security posture appropriate to a twenty-person firm is not the one appropriate to a twenty-person business selling widgets.
The mailbox comes first because it is where the attacks land. Multi-factor authentication on every account, without exceptions for partners who find it inconvenient, is the single highest-value control available. Beyond that, conditional access rules that consider the device and location of a sign-in turn a stolen password from an incident into a blocked attempt. The threat worth designing against is not someone reading one email; it is someone sitting in a mailbox for weeks learning how the firm discusses money.
Then payment verification, which is procedural rather than technical and prevents the loss that actually hurts. Any change to bank account details, whether it appears to come from a client, a supplier or a staff member, is verified by telephone to a number you already held, never a number supplied in the request. Make it a rule that cannot be waived for urgency, because manufactured urgency is precisely the pressure the fraud applies. Firms have lost very large sums to this and almost every case would have been stopped by one phone call.
Access control is third and is where most firms carry quiet exposure. Everyone being able to open every client file is common, convenient and hard to defend if something goes wrong. Structure storage so each area of work has its own permissions, restrict sensitive engagements, and pay particular attention to anything involving staff, partners or related entities, which is exactly the material that causes trouble when it is visible to the wrong colleague. Departures need a same-day process, since a former employee retaining access to client financials is both a real risk and an awkward conversation.
Devices are fourth and become urgent the first time a laptop is left somewhere. Every machine that opens client data should be encrypted, managed, patched and remotely wipeable, which is what device management delivers, and that includes phones carrying email. Firms increasingly run this through Intune with something like ThreatLocker controlling what can execute, which is the Zero Trust posture AFM Services and the not-for-profit accounting firm we work with both adopted alongside Essential Eight Maturity Level 1.
Underneath all four sits the Essential Eight, and it is worth treating as the organising framework rather than yet another initiative. Multi-factor authentication, restricted administrative privileges, patched systems, application control and tested backups map almost exactly onto the risks described above. Reaching Maturity Level 1 is a one-to-three-month project for most firms, and the reason to do it is that it produces evidence: a dated report you can show an insurer, a corporate client conducting due diligence, or a client asking a pointed question after reading about a breach elsewhere.
Backups deserve their own line because of retention. Accounting records must be kept for years, and the risk is not usually deletion but attrition during change: material lost in a platform migration, a provider changeover or a software replacement. Confirm that the systems holding long-retention records are actually covered, that a restore has been performed and logged recently, and that a copy exists beyond the reach of the network it protects, since ransomware that reaches the file store will look for the backups too.
There is a human layer that no control replaces. Staff should know how to report a suspicious email or a mistake, and the last person who did so should have been thanked rather than blamed, because a punished reporter is the last report you will receive. In a profession where the fraud arrives as a plausible email during the busiest week of the year, the person who says something feels wrong is your most effective control and the cheapest one to maintain.
The honest caveats. None of this is advice about your professional obligations, which come from your regulator and your professional body. Security that obstructs the work during tax season will be worked around, so controls must be built for how the firm actually operates under pressure. And no arrangement makes a breach impossible; the goal is to make it unlikely, contained, and something you can answer questions about afterwards. If you want yours reviewed properly, call 1800 456 567.
Protect the data clients trust you with
We put multi-factor authentication, access control, device management and monitoring around a practice's client data, with the evidence to show for it.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business