What clients now ask accountancy practices about security
The questions used to travel in one direction. Now a client forwards their customer’s supplier questionnaire and a two-partner practice is being asked about incident response.
For years an accountancy practice has been the party asking for documents. Identity evidence, bank statements, proof of address, the missing invoice. Over the past couple of years the questions have started arriving in the other direction, and they are about the practice’s own security rather than a client’s affairs. Most practices we speak to can answer them. What they cannot do is evidence the answers, a different and much cheaper problem.
The supply chain reached one step further than it used to
The route a questionnaire takes is worth tracing, because it explains the tone of the thing. A client wins work with a large customer, or renews with one. That customer sends across a supplier assurance questionnaire, because it has a security function and a policy saying it must. Your client works through it, reaches the section asking who else touches their financial and payroll data, and forwards that part to their accountant. Nobody in the chain has decided the practice is a weak link.
Large buyers have asked their direct suppliers these questions for well over a decade. What changed is that they now require those suppliers to ask their own providers, and professional services firms tend to be the ones asked.
Insurers arrive at the same place by another road. Where a renewal proposal form once asked whether you had antivirus, it now asks which systems multi-factor authentication covers, whether backups have been restored from, and who holds administrative rights. A client’s broker may separately ask what that client’s outsourced providers do, producing a second form from a different direction.
One concession, because it shapes how you should respond. A fair proportion of these questionnaires are badly targeted. A forty-page document written to assess a cloud hosting provider, asking about data centre access control and secure development practices, does not fit a firm whose technology is laptops and a practice management system. Mark those sections not applicable and say in one line why. A questionnaire is the opening of a conversation, not an exam paper.
Why the questions land on a practice rather than somewhere else
The usual explanation is that accountants hold sensitive data. So do dentists and recruitment agencies, and none of them receives this volume of questions.
The specific feature of an accountancy practice is concentration of authority. A practice does not only hold copies of client information, it holds delegated permission to act. It is recognised as an agent and files on clients’ behalf. It commonly knows how a client pays its people and its suppliers. Its emails are trusted on sight by client finance staff, because that trust is the substance of the relationship rather than an oversight.
Hold that in view and the structural point is clear. Where an ordinary supplier compromise is one organisation’s problem, a practice compromise is potentially several dozen organisations’ problem at the same moment, with nothing further having to happen. That is an observation about where consequence concentrates, not a prediction about any firm, and it is why a security team reading a supplier list stops at the accountant’s name.
Two qualifications, both genuine. Concentration works in your favour too, since a practice that gets a few things right protects many organisations at once, which is a better return on a modest budget than most organisations achieve. And being a sensible thing to ask about does not make an incident likely for any given firm. The questionnaire is asking about consequence rather than probability.
What is actually on the form
Strip away the formatting and the same items appear again and again. None of them is exotic.
| What is asked | What a good answer looks like |
|---|---|
| Multi-factor authentication on email and the practice management system | Enforced on every account including partners, with no standing exemptions |
| Who holds administrative access, and is it reviewed | A short named list, separate from everyday accounts, reviewed on a stated interval |
| What happens to a leaver’s access | A checklist covering every system rather than just email, completed on the day and filed |
| Are devices managed and encrypted | Encryption on every laptop and phone touching client data, and a way to wipe a lost one |
| Patching and supported software | Updates applied within a stated window, nothing the vendor no longer supports |
| Backups | A backup you have restored from, with the date of the last test |
| Incident response | A named contact, an out-of-hours route to them, and a written first hour |
| Staff training | Dated evidence that it happened, rather than a policy saying it should |
| Recognised certification | A current certificate number the other side can verify |
The honest observation is how much of that a well-run practice already satisfies. Multi-factor authentication is often on because the vendor turned it on. Laptops are encrypted by default. Machines patch themselves. Someone does remove leavers.
Doing it and evidencing it are two different jobs
The second job is the one left undone. Take the administrative access question. If the partner who looks after IT glances at the user list from time to time and removes anyone obviously gone, the control genuinely exists and there is nothing to show for it. The gap is documentation rather than security, and a bare “yes” with no record behind it is what makes the follow-up conversation awkward.
What converts existing practice into evidence is unglamorous and cheap:
- A one-page list of the systems that hold client data, who administers each and what it is for. Everything else hangs off this, and compiling it usually surfaces a system nobody had thought about.
- A dated record of the last access review. A spreadsheet, a date, some initials and a note of what changed. The date is the part that carries weight.
- A leaver checklist that is actually ticked and kept with the personnel record, listing every system rather than the two obvious ones.
- A restore that was performed rather than assumed, with the date and what was restored. A backup nobody has restored from is a hypothesis with a monthly cost.
- One named incident contact with an out-of-hours route, and a note of who gets told in the first hour. Usually answered with a shrug, and the cheapest of these to fix.
- A training record with a date, attendees and the subject. Half an hour that happened beats an hour scheduled indefinitely.
None of that requires buying software. It requires one person to own it and half a day a quarter. Where it is missing the reason is rarely negligence. It is that nobody had ever asked to see it.
What is worth certifying, and what is not
Cyber Essentials is the cheap, recognised answer to the middle of almost any questionnaire. It was designed for organisations of exactly this size, its five control areas map closely onto the table above, and its value here is conversion: a dozen assertions become one certificate number a client’s procurement team already knows how to read. Where it stops short is worth saying plainly. It covers technical controls, so a form weighted towards policy, supplier due diligence and governance will still leave you writing prose in the gaps.
IASME Cyber Assurance is the step up for that situation, where a client wants something closer to an information security management system than a technical baseline. It covers risk management, policy, people, incident response and data protection obligations as well as technical controls, at Level 1 as a verified self-assessment and Level 2 as an independent audit. It earns its place when questionnaires keep asking for documented processes, or when a practice is compared against larger firms holding ISO 27001. It does not earn its place when one client sent one form that Cyber Essentials would have answered.
Solusec is an appointed IASME Certification Body for Cyber Essentials and is licensed for IASME Cyber Assurance Levels 1 and 2, so we assess and issue both ourselves rather than passing the work on.
A penetration test answers a different question altogether: whether a particular system can be broken into. For a practice whose technology is laptops and services bought from vendors, there is little for a tester to examine that the practice could then fix, since the findings would belong to those vendors. It is usually the wrong first purchase, and a questionnaire demanding one from such a firm has been copied from a template. It becomes genuinely relevant the moment a practice runs something of its own facing the internet: a client portal, an upload site, a remote access gateway, anything stood up in a hurry and never withdrawn. Then it is not optional, and what a test costs is the next thing to read.
When the honest answer to something is no
Say no, and give a date. A useful answer has three parts: where you are now, what you are doing in the meantime, and the date by which the answer becomes yes. A dated remediation plan is routinely accepted, because a plan with an owner and a date reads as evidence of management rather than an admission of failure.
What is not accepted, eventually, is a yes that was not true. It never surfaces at a convenient moment. It surfaces after an incident, when the contract and the insurance policy are both being read closely by people looking for a reason, and it turns a security problem into a contractual one as well.
The short version. The questionnaire is not an accusation, it is a form that travelled one hop further than it used to, and you probably already do most of what it asks. Write down the few things that make your existing practice visible, certify at the level the questions require rather than the level that sounds impressive, and answer the rest truthfully with dates against it.
Common questions
Why have we suddenly started receiving these questionnaires?
Can we decline to fill one in?
Is Cyber Essentials enough to answer a client questionnaire?
A client is asking for ISO 27001. We are a four-person practice.
The questionnaire asks about multi-factor authentication on a system that does not support it.
Do we need a penetration test if everything we use is a cloud service?
Related
Solusec
Typically replies within one business day
Had an incident, or need a penetration test or Cyber Essentials at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day
Not sure which you need? Ask us.
Direct from the Certification Body, with one accountable team.