Accounting firms in Australia handle some of the most sensitive personal and financial information of any small business sector. Tax returns, bank account details, superannuation records, and ATO credentials — all in one place, all under your responsibility.
This checklist is written for principals, practice managers, and partners at Australian accounting firms who want a clear picture of where their security stands. It is not a technical document — it is a decision-maker’s guide.
1. Multi-Factor Authentication (MFA)
MFA requires a second form of verification in addition to a password. Without it, a stolen password gives an attacker full access to your systems.
- MFA enabled on Microsoft 365 for all users (not just admins)
- MFA enabled on your ATO portal and ATO Online services
- MFA enabled on MYOB, Xero, and any cloud-based accounting platforms
- MFA enforced on remote access (VPN or remote desktop)
ACSC Essential Eight context: The Australian Cyber Security Centre rates MFA as one of the most effective controls for preventing account compromise. For accounting firms with access to ATO systems, it is non-negotiable.
2. Patching and Software Updates
Unpatched software is one of the most common entry points for attackers. This applies to operating systems, accounting software, and browsers.
- Windows devices are patched within 48 hours of critical security updates
- MYOB, Xero, and practice management software kept current
- Browsers and plugins (particularly Adobe Reader, used for client documents) are updated
- End-of-life operating systems (Windows 7, Windows 8) removed from use
3. Email Security and BEC Protection
Business email compromise (BEC) targeting accounting firms typically involves impersonating clients or suppliers to redirect payments or obtain sensitive data. It is one of the most common cyber threats facing Australian accounting practices.
- DMARC, DKIM, and SPF configured on your email domain
- Email filtering in place to catch impersonation attempts
- Staff trained to verify payment change requests via a second channel (phone call, not reply email)
- External email warnings displayed on all inbound messages from outside your domain
4. Backup and Recovery
Ransomware on accounting data can shut down a practice entirely. The ability to recover quickly depends on having a tested, recent backup — not just a backup that exists.
- Daily backup of practice management data and client files
- Backup stored separately from the primary system (offsite or air-gapped)
- Backup tested with a documented restore procedure (not assumed to work)
- Recovery time objective (RTO) defined and aligned with your ATO lodgement calendar
5. Access Control
Not every staff member needs access to every client’s data. Restricting access reduces the impact of a breach or insider incident.
- Staff access provisioned on a need-to-know basis
- Admin accounts separated from everyday user accounts
- Departing staff accounts disabled promptly (same day, not weeks later)
- Shared credentials (team logins) replaced with individual accounts
6. Privacy Act and NDB Compliance
Under the Privacy Act 1988 and the Notifiable Data Breaches (NDB) scheme, accounting firms handling personal information of clients must take reasonable steps to protect that information and notify the OAIC if a breach is likely to cause serious harm.
- Privacy policy reviewed and current
- Data retention and disposal procedures documented
- Incident response procedure in place — who to call, what to log, when to notify the OAIC
- Third-party data processors (cloud software vendors) reviewed for privacy compliance
Note: The Privacy Act 1988 is currently under reform. The Australian Government has proposed significant changes to strengthen privacy obligations. Check the OAIC website for current guidance.
7. Staff Awareness
Most successful attacks start with a human — a phishing email clicked, a password shared, a payment request not verified. Training staff is one of the highest-return investments in cyber security.
- Staff receive phishing awareness training at least annually
- Staff know what to do if they suspect a phishing email or security incident
- New staff included in security induction before access is provisioned
What To Do Next
If you have identified gaps in the above checklist, the next step is to prioritise. Start with MFA — it is the highest-impact, lowest-cost control you can implement. Then work through patching, email security, and backup.
If you are unsure where to start or want an independent assessment of your firm’s current security posture, SouthCore provides free IT assessments for Melbourne accounting firms.
RELATED READING
Related Resources
Related
IT Support for Accounting Firms in Melbourne
How SouthCore supports Melbourne accounting practices with managed IT and cyber security.
Related
Does Microsoft 365 Need Backup for Accounting Firms?
What Australian accounting firms need to know about protecting client data and ATO records.