Cyber Security for Accountancy Practices

Your agent credentials reach dozens or hundreds of client tax accounts. That concentration makes a practice a far more valuable target than its size suggests.

Primary risk
Agent access compromise
Peak exposure
December–January
Drivers
ICAEW/ACCA, clients, insurers
Usual start
Cyber Essentials

The concentration problem

An accountancy practice is an aggregation point. Agent services access to client tax accounts, payroll data for multiple employers, bank details for client payments, and complete financial pictures of every business you act for. Compromise one practice and an attacker reaches all of it.

That is why practices are targeted disproportionately to their size, and why "we're only a six-person firm" is not the protection it feels like.

What we consistently find

  • Agent credentials shared between staff, with no way to attribute an action to a person.
  • Multi-factor authentication absent on practice management software or on the email account that can reset it.
  • Client data on personal devices, particularly during self-assessment season when everyone is working late from home.
  • Payroll data emailed unencrypted — bank details and National Insurance numbers for hundreds of individuals in a mailbox attachment.
  • Long-departed staff still holding access to portals nobody remembered to revoke.

Seasonality is a real risk factor

December and January concentrate deadline pressure, temporary staff, long hours and unusual working patterns. Attackers know this. Phishing that would be spotted in June succeeds in January, and unusual access looks normal when everyone is working at odd hours. If you are going to tighten anything, tighten it in October.

Who is asking you for evidence

Professional bodies expect appropriate safeguards over client information. Corporate clients increasingly send security questionnaires before appointing. Insurers ask at renewal. And if you provide payroll bureau services, you are a data processor with your own UK GDPR obligations distinct from your clients'.

Where to start

Cyber Essentials, then a Microsoft 365 and identity review. The controls that matter most are unglamorous: individual named accounts for agent access, MFA everywhere including on practice software, encrypted transfer for payroll data, and a genuine offboarding process. A penetration test of a client portal is worthwhile if you run one, but rarely the first thing to buy.

Common questions

Is Cyber Essentials required for accountants?

Not by statute. But it is increasingly requested by corporate clients, some professional body schemes reference it, and it answers most of a client security questionnaire in one document. It is usually the cheapest way to satisfy the people asking.

We use cloud accounting software. Is that our responsibility?

The provider secures the platform. You are responsible for who has access, whether MFA is enforced, what happens when staff leave, and what lands in your email. Nearly every incident we see in this sector originates in one of those, not in the software.

Do you work around our busy season?

Yes, and we would encourage testing outside December to March. Remediation needs attention you will not have in January. Autumn is the sensible window.

We hold client bank details for payments. What is the biggest risk?

A compromised mailbox leading to altered payment instructions, and the same verified-callback discipline applies as in conveyancing. Technically it's mailbox security and MFA; procedurally it's never accepting a bank change by email alone.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.