What clients now ask accountancy practices about security

The questions used to travel in one direction. Now a client forwards their customer’s supplier questionnaire and a two-partner practice is being asked about incident response.

For years an accountancy practice has been the party asking for documents. Identity evidence, bank statements, proof of address, the missing invoice. Over the past couple of years the questions have started arriving in the other direction, and they are about the practice’s own security rather than a client’s affairs. Most practices we speak to can answer them. What they cannot do is evidence the answers, a different and much cheaper problem.

The supply chain reached one step further than it used to

The route a questionnaire takes is worth tracing, because it explains the tone of the thing. A client wins work with a large customer, or renews with one. That customer sends across a supplier assurance questionnaire, because it has a security function and a policy saying it must. Your client works through it, reaches the section asking who else touches their financial and payroll data, and forwards that part to their accountant. Nobody in the chain has decided the practice is a weak link.

Large buyers have asked their direct suppliers these questions for well over a decade. What changed is that they now require those suppliers to ask their own providers, and professional services firms tend to be the ones asked.

Insurers arrive at the same place by another road. Where a renewal proposal form once asked whether you had antivirus, it now asks which systems multi-factor authentication covers, whether backups have been restored from, and who holds administrative rights. A client’s broker may separately ask what that client’s outsourced providers do, producing a second form from a different direction.

One concession, because it shapes how you should respond. A fair proportion of these questionnaires are badly targeted. A forty-page document written to assess a cloud hosting provider, asking about data centre access control and secure development practices, does not fit a firm whose technology is laptops and a practice management system. Mark those sections not applicable and say in one line why. A questionnaire is the opening of a conversation, not an exam paper.

Why the questions land on a practice rather than somewhere else

The usual explanation is that accountants hold sensitive data. So do dentists and recruitment agencies, and none of them receives this volume of questions.

The specific feature of an accountancy practice is concentration of authority. A practice does not only hold copies of client information, it holds delegated permission to act. It is recognised as an agent and files on clients’ behalf. It commonly knows how a client pays its people and its suppliers. Its emails are trusted on sight by client finance staff, because that trust is the substance of the relationship rather than an oversight.

Hold that in view and the structural point is clear. Where an ordinary supplier compromise is one organisation’s problem, a practice compromise is potentially several dozen organisations’ problem at the same moment, with nothing further having to happen. That is an observation about where consequence concentrates, not a prediction about any firm, and it is why a security team reading a supplier list stops at the accountant’s name.

Two qualifications, both genuine. Concentration works in your favour too, since a practice that gets a few things right protects many organisations at once, which is a better return on a modest budget than most organisations achieve. And being a sensible thing to ask about does not make an incident likely for any given firm. The questionnaire is asking about consequence rather than probability.

What is actually on the form

Strip away the formatting and the same items appear again and again. None of them is exotic.

The commonplace questionnaire items, and what satisfies each
What is askedWhat a good answer looks like
Multi-factor authentication on email and the practice management systemEnforced on every account including partners, with no standing exemptions
Who holds administrative access, and is it reviewedA short named list, separate from everyday accounts, reviewed on a stated interval
What happens to a leaver’s accessA checklist covering every system rather than just email, completed on the day and filed
Are devices managed and encryptedEncryption on every laptop and phone touching client data, and a way to wipe a lost one
Patching and supported softwareUpdates applied within a stated window, nothing the vendor no longer supports
BackupsA backup you have restored from, with the date of the last test
Incident responseA named contact, an out-of-hours route to them, and a written first hour
Staff trainingDated evidence that it happened, rather than a policy saying it should
Recognised certificationA current certificate number the other side can verify

The honest observation is how much of that a well-run practice already satisfies. Multi-factor authentication is often on because the vendor turned it on. Laptops are encrypted by default. Machines patch themselves. Someone does remove leavers.

Doing it and evidencing it are two different jobs

The second job is the one left undone. Take the administrative access question. If the partner who looks after IT glances at the user list from time to time and removes anyone obviously gone, the control genuinely exists and there is nothing to show for it. The gap is documentation rather than security, and a bare “yes” with no record behind it is what makes the follow-up conversation awkward.

What converts existing practice into evidence is unglamorous and cheap:

  • A one-page list of the systems that hold client data, who administers each and what it is for. Everything else hangs off this, and compiling it usually surfaces a system nobody had thought about.
  • A dated record of the last access review. A spreadsheet, a date, some initials and a note of what changed. The date is the part that carries weight.
  • A leaver checklist that is actually ticked and kept with the personnel record, listing every system rather than the two obvious ones.
  • A restore that was performed rather than assumed, with the date and what was restored. A backup nobody has restored from is a hypothesis with a monthly cost.
  • One named incident contact with an out-of-hours route, and a note of who gets told in the first hour. Usually answered with a shrug, and the cheapest of these to fix.
  • A training record with a date, attendees and the subject. Half an hour that happened beats an hour scheduled indefinitely.

None of that requires buying software. It requires one person to own it and half a day a quarter. Where it is missing the reason is rarely negligence. It is that nobody had ever asked to see it.

What is worth certifying, and what is not

Cyber Essentials is the cheap, recognised answer to the middle of almost any questionnaire. It was designed for organisations of exactly this size, its five control areas map closely onto the table above, and its value here is conversion: a dozen assertions become one certificate number a client’s procurement team already knows how to read. Where it stops short is worth saying plainly. It covers technical controls, so a form weighted towards policy, supplier due diligence and governance will still leave you writing prose in the gaps.

IASME Cyber Assurance is the step up for that situation, where a client wants something closer to an information security management system than a technical baseline. It covers risk management, policy, people, incident response and data protection obligations as well as technical controls, at Level 1 as a verified self-assessment and Level 2 as an independent audit. It earns its place when questionnaires keep asking for documented processes, or when a practice is compared against larger firms holding ISO 27001. It does not earn its place when one client sent one form that Cyber Essentials would have answered.

Solusec is an appointed IASME Certification Body for Cyber Essentials and is licensed for IASME Cyber Assurance Levels 1 and 2, so we assess and issue both ourselves rather than passing the work on.

A penetration test answers a different question altogether: whether a particular system can be broken into. For a practice whose technology is laptops and services bought from vendors, there is little for a tester to examine that the practice could then fix, since the findings would belong to those vendors. It is usually the wrong first purchase, and a questionnaire demanding one from such a firm has been copied from a template. It becomes genuinely relevant the moment a practice runs something of its own facing the internet: a client portal, an upload site, a remote access gateway, anything stood up in a hurry and never withdrawn. Then it is not optional, and what a test costs is the next thing to read.

When the honest answer to something is no

Say no, and give a date. A useful answer has three parts: where you are now, what you are doing in the meantime, and the date by which the answer becomes yes. A dated remediation plan is routinely accepted, because a plan with an owner and a date reads as evidence of management rather than an admission of failure.

What is not accepted, eventually, is a yes that was not true. It never surfaces at a convenient moment. It surfaces after an incident, when the contract and the insurance policy are both being read closely by people looking for a reason, and it turns a security problem into a contractual one as well.

The short version. The questionnaire is not an accusation, it is a form that travelled one hop further than it used to, and you probably already do most of what it asks. Write down the few things that make your existing practice visible, certify at the level the questions require rather than the level that sounds impressive, and answer the rest truthfully with dates against it.

Common questions

Why have we suddenly started receiving these questionnaires?
Because supplier assurance has extended by one link. Large organisations have asked their direct suppliers these questions for years, and they now require those suppliers to ask their own providers. Your client is passing down a section of a form they were sent. Insurers have moved the same way, with renewal proposal forms asking specifically about multi-factor authentication coverage, backup testing and administrative access where they once asked only whether you had antivirus.
Can we decline to fill one in?
You can, and occasionally that is the right call for a form wildly mismatched to your firm. It is generally a worse outcome than answering, because the client has an obligation of their own to satisfy and a refusal makes you the reason they cannot satisfy it. A better route is to answer what applies, mark what genuinely does not apply as not applicable with a one-line reason, and offer a short call about anything needing context. Blank fields read as evasion, whereas a reasoned not applicable reads as competence.
Is Cyber Essentials enough to answer a client questionnaire?
For the technical bulk of a typical questionnaire, usually yes, and it has the advantage of being one verifiable certificate rather than a dozen assertions. It will not cover everything. Questions about policies, risk assessment, supplier due diligence, training records and incident handling sit outside its five control areas, so expect to write some prose alongside the certificate. If those governance questions dominate the form, that is the signal to look at IASME Cyber Assurance rather than to keep answering them one at a time.
A client is asking for ISO 27001. We are a four-person practice.
Ask whether an alternative is acceptable before assuming it is not, because the requirement has frequently been copied from a template written for a much larger supplier. IASME Cyber Assurance is aligned to ISO 27001 and independently assessed, and it is often accepted where the underlying concern is whether you manage security in a structured way. If the requirement turns out to be genuinely fixed, that becomes a commercial decision about the value of the client, and it is better established early than at contract stage.
The questionnaire asks about multi-factor authentication on a system that does not support it.
Write what is true, name the system, and say what compensates in the meantime: a long unique password held in a password manager, access restricted to a named handful of people, sign-in monitoring if the system offers it. Then give the date by which you will either have the control or have moved off the system. That answer is credible. A yes that a later conversation contradicts is not, and legacy systems without modern authentication are common enough that assessors are used to reading exactly this response.
Do we need a penetration test if everything we use is a cloud service?
Usually not as a first purchase. If your estate is laptops plus services you buy from vendors, a test would mostly produce findings that belong to those vendors and that you have no ability to remediate. The answer changes if you run anything internet-facing yourself, such as a client portal or a remote access gateway, in which case testing it is proportionate and a questionnaire asking about it is asking the right question. If you are unsure which category you are in, listing the systems that hold client data usually settles it in an afternoon.

Related

Not sure which you need? Ask us.

Direct from the Certification Body, with one accountable team.