7 Cyber Security Features Every Australian Accounting Firm Should Look For — And What Happens When One Is Missing
6 min read | Practice Management | Cyber Security | Compliance | Access Control
Every cyber security provider can say “we do MFA” or “we do access control.” Few can show you the audit trail, the compliance documentation, or a support team that already understands the accounting-specific stakes when something goes wrong. This is what separates a feature on a sales page from a control you can rely on — and the seven questions worth asking before you sign with any provider.
If your firm is currently comparing cyber security options — or already has something in place — these four questions are worth sitting with before you read further.
If a former staff member left your firm six months ago, could you say with certainty which systems they can still access?
If a regulator asked for your data breach response plan today, could you produce it — or would that require starting from scratch?
Is multi-factor authentication actually turned on across every application your firm uses, or only the ones someone remembered to configure?
If you had a question about how a specific access control requirement applies to your firm’s technology setup, is there someone you could call who actually knows Xero, Karbon, and the ATO portal — not just IT in general?
If any answer is unclear, it’s worth understanding why — and what a different answer would look like.
The gap many accounting firms don’t realise they have
Across 60 recent conversations with Australian accounting and bookkeeping firms, one gap came up in 58 of them: passwords stored in a spreadsheet, a shared document, a browser save function, or a notebook on someone’s desk. In several cases, the firm using the spreadsheet method had it saved inside the same document management system that held their client files — so anyone who got into one had the other too.
That’s not a rare finding. It’s the default state for most small accounting and bookkeeping practices, and it’s the single biggest reason firms start looking at cyber security seriously — not a hypothetical threat, but a concrete, everyday gap they can already see.
2025 saw 1,205 notifiable data breaches reported to the Office of the Australian Information Commissioner — an 8% increase on 2024’s total of 1,112, and the highest annual figure since mandatory reporting began in 2018. Malicious or criminal attacks remained the leading cause, accounting for 716 of those notifications — around 59%. Separately, the Australian Signals Directorate’s 2024–2025 Annual Cyber Threat Report put the average self-reported cost of a cybercrime incident for a small business at $56,600, up 14% on the year before.
Takeaway: The gap isn’t hypothetical, and it isn’t rare. It’s the starting position for most firms — which is exactly why a feature checklist matters more than a sales pitch.
What to look for before you choose a provider
Most providers can claim the same handful of features. What matters for a TPB-registered practice is whether those features are built around the app ecosystem accounting firms actually run on — Xero, MYOB, Karbon, Dext, SuiteFiles, Microsoft 365 — rather than adapted from generic small-business IT.
-
One secure access point across the apps you actually use, not just Microsoft 365
Most small-business security tools stop at Microsoft 365. That secures email. It doesn’t touch the systems holding your clients’ financial data. A typical 10-staff firm now runs 9–15 connected cloud applications, each with its own login. Single sign-on — built specifically for accounting, and applied wherever an app supports it — brings that stack onto one secure screen, with a tile through to ATO Online Services alongside it, rather than leaving your team to manage a separate password for every application.
The payoff: your team reaches the apps that support it from one login. The cost of the gap: every separate login is a separate credential to steal — and a separate account someone has to remember to close when a staff member leaves.
-
Multi-factor authentication enforced consistently, not left to individual choice
MFA only works as a control when it’s enforced firm-wide, with no exemptions for individual apps or team members — and when it’s actually turned on, wherever the application supports it, for every application your firm has connected. Ask specifically which applications are covered: coverage depends on whether each third-party app’s MFA has been configured within the platform, not on a blanket promise that “every app” is covered automatically. Left to individual choice, MFA becomes the setting a busy staff member switches off — and one unprotected login is all a phishing attempt needs. Cyber hacking is the leading cause of Australian data breaches, and stolen credentials are the way in.
-
Something that stops staff reusing the same password everywhere
This is the gap that shows up more than any other in real conversations with firm owners — the spreadsheet, the shared notebook, the browser-saved password used across five different systems. One password reused everywhere means one breach anywhere becomes a breach everywhere. Password cloaking (sometimes described as credential vaulting) lets staff use the tools they need without ever seeing or reusing the underlying password — removing that single point of failure at the source, rather than relying on people remembering not to reuse one.
-
Access restricted to the locations your firm actually operates from
This has become a live issue as more firms bring on offshore or remote team members — talent shortages are pushing accounting and bookkeeping practices toward offshore hiring, commonly in the Philippines and Vietnam, a pattern tracked by outsourcing-industry researchers and specialist providers now serving hundreds of Australian firms. Firms are understandably reluctant to hand over shared logins to a worker whose device and network they don’t control. Geo and IP-based access controls restrict credential-based apps to expected locations, so a new hire — or a stolen password — can’t reach client systems from an unexpected location without it being flagged.
The business outcome: you can bring on offshore or remote staff — the way firms are solving the talent shortage — without handing over logins to a device and network you don’t control.
-
A single action that locks down access the moment someone leaves
Under the Privacy Act, ongoing access after a staff member’s departure is treated as a live exposure, not a future risk. A centralised lockout — covering Xero, Karbon, Microsoft 365, and every connected application from one screen — cuts access immediately, rather than requiring someone to remember, find, and revoke each login one by one. From there, full offboarding of each connected system is completed methodically rather than under pressure — the immediate lockout is what stops a missed login staying open while you work through the list.
-
A record you can actually produce, not just describe
Ask a provider to show you the audit trail, not just describe it. A centralised access dashboard, maintained and monitored on your behalf, that can produce timestamped access and offboarding records is a materially different proposition to a generic claim of “compliance.”
It’s also worth asking exactly what documentation a provider produces: a current privacy policy and a data breach response plan are concrete, TPB- and OAIC-relevant artefacts; a marketing badge or a client-facing brochure is not evidence a regulator will accept.
The same access records also support your firm’s data retention and disposal obligations — showing who could reach a record and confirming access was closed off — even though the retention and deletion decision itself remains the firm’s to make. Clients also receive a Data Retention and Disposal Policy Template as part of the Cyber Security Compliance Hub™, to document how those decisions are actually made.
-
Support that’s already seen this exact scenario
A breach response call with a generalist IT helpdesk often starts with them learning what Xero is and what the Notifiable Data Breaches scheme requires — while the clock on your obligations is already running. Support built exclusively around accounting and bookkeeping firms starts several steps ahead, because the scenario isn’t new to them — and because every call is backed by patterns already seen across a 28,000+ strong network of accounting and bookkeeping firms, not just one support agent’s individual experience.
Takeaway: Any provider can claim these seven things exist. Fewer can show you they work the way an accounting firm needs them to — covering the actual app stack, producing an actual audit trail, and answering the phone with actual accounting knowledge.
Where this shows up in practice, not in a sales conversation
The difference between a feature on a page and a control you can rely on becomes visible at specific moments — not in the everyday running of the firm.
When someone leaves.
A password reset in a standalone tool revokes one credential. It doesn’t remove a departing staff member’s access across the other 8–14 applications connected to your firm — each of which may need a separate manual step someone has to remember, find, and action. Under the Privacy Act as amended in December 2024, residual access to personal information after departure is not a potential future risk. It’s an ongoing exposure. Clients also receive a monthly, plain-English security report — a dated point of reference between reviews, not a substitute for the access and offboarding records held in the platform itself.
When a regulator asks for evidence.
A generic tool rarely produces documentation mapped to a TPB review or an OAIC inquiry. The Privacy Policy, AI Usage Policy, and Data Breach Response Plan that regulators expect to see require a purpose-built compliance layer — one that produces this documentation as part of its normal operation, not as an afterthought.
When someone needs help with an accounting-specific configuration.
A generic support team doesn’t know what an ATO portal credential is, why a BAS deadline matters, or what the regulatory implications are of getting an access decision wrong. That gap isn’t a product feature missing — it’s a service model built for a different market.
Takeaway: These moments are where a checklist item either holds up or doesn’t. Ask a provider to walk you through exactly what happens in each of these three scenarios before you sign anything.
The regulatory context that makes this non-negotiable
This isn’t a best-practice argument. It’s a compliance one.
Since 1 July 2025, the TPB Code of Professional Conduct has required every registered tax agent to maintain a Quality Management System, including documented procedures for protecting client data. From 11 December 2024, the Privacy Act 1988 (Cth) — as amended by the Privacy and Other Legislation Amendment Act 2024 — requires firms to take steps that are reasonable in the circumstances to protect personal information, and the new APP 11.3 confirms those steps include technical and organisational measures. The OAIC’s guidance identifies controls such as multi-factor authentication, limiting access to what staff need for their role, and promptly deactivating accounts when staff leave as examples of the reasonable steps firms are expected to take. A statutory tort effective June 2025 means individual clients can sue their accounting firm directly for a privacy breach.
The ATO’s Digital Service Provider Operational Security Framework mandates MFA for software that integrates directly with ATO services — separate from the myGovID authentication individual practitioners use for parts of the ATO portal — and the ATO has repeatedly warned tax professionals that the sensitive client data they hold makes them a target for identity thieves and cybercriminals.
AML/CTF Tranche 2, effective 1 July 2026, brings accounting firms providing designated services into the AUSTRAC reporting framework, with access control and recordkeeping obligations of its own.
The consequences aren’t theoretical. Earlier this year, a Brisbane accounting firm was named by a ransomware operation after unauthorised access to its systems, with client financial and banking data subsequently published online. The firm had to notify affected clients, engage specialists, and report to both the ACSC and the OAIC — and every step of that response depended on controls and documentation the firm either had in place already, or had to build under pressure.
Takeaway: The TPB, Privacy Act, and AML/CTF Tranche 2 each require specific, demonstrable controls. A feature list satisfies none of them on its own — documentation and an audit trail are what turn a control into evidence.
What a generic tool covers, and where accounting firms need more

The network intelligence advantage
There’s a factor most checklists leave out entirely: scale within the profession. When you join our network, your firm gets access to Collective Industry Intelligence, where you can stay ahead of emerging threats with insights drawn from thousands of accounting firms.
Every threat one firm sees becomes protection every other firm already has. A generalist IT provider spread across fifty industries doesn’t have that same vantage point into what’s specifically targeting accounting firms right now.
Firms that move to single sign-on with credentials their team never sees often describe the same shift: no longer wondering whether client data is exposed.
That’s the practical difference between a feature list and a firm that’s actually addressed the problem.
The Cyber Security Compliance Hub™: documentation, not just controls
Any provider can claim to enforce MFA. Fewer produce the documentation a regulator actually asks for. The Cyber Security Compliance Hub™ provides a current Privacy Policy, AI Usage Policy, and Data Retention and Disposal Policy Template, plus a Data Breach Response Plan aligned to the Notifiable Data Breaches scheme — structured as templates your firm applies its own details to, alongside audit-ready access and offboarding records. Ready to produce for the TPB, OAIC, or a professional indemnity insurer when asked — not built from scratch under pressure.
Clients on both Core™ and Complete™ also receive a monthly security report — a plain-English summary of what’s covered across each protected area, alongside a handful of headline stats, giving the firm a dated record to point to between audits.
Takeaway: Controls that work are necessary. Documentation that proves they work is what a regulator, an auditor, insurer or your client actually asks for.
Where to start
You don’t need to work through all seven points from scratch. The fastest starting point is the one question at the centre of most of these conversations: who currently has access to your systems, and has every former staff member’s access actually been closed?
Want to know what other questions you should be asking about your cyber security set up → Download The Firm Owner’s Security Checklist
Practice Protect Core™ and Practice Protect Complete™ are built exclusively for Australian accounting and bookkeeping firms. Trusted by 28,000+ accounting professionals.
Disclaimer: This article does not constitute legal advice. For AML/CTF or other compliance obligations specific to your firm, consult your legal or compliance adviser.
Frequently Asked Questions
What cyber security features does a TPB-registered accounting firm actually need?
At minimum: single sign-on across accounting-specific apps, firm-wide multi-factor authentication, unique credentials per application, geo-restricted access, a centralised lockout covering every connected application the moment someone leaves, a timestamped access audit trail, and support that understands accounting-specific obligations like the TPB Code and the Notifiable Data Breaches scheme.
Does Microsoft 365’s built-in email security cover an accounting firm’s obligations?
Microsoft 365’s default protection, Exchange Online Protection, is a spam, malware, and phishing filter for email — nothing more. It doesn’t govern who can log into Xero, Karbon, Dext, or the other applications a firm’s client data actually lives in; that’s a separate layer, and each of those tools needs its own access governance. ATO Online Services is a partial exception: some ATO systems authenticate through the myGovID app on an individual’s own device, which sits outside any platform’s control. Practice Protect surfaces a single-login tile through to ATO Online Services alongside the rest of the stack, rather than replacing the ATO’s own identity requirements.
What happens to a former employee’s access if it isn’t manually revoked everywhere?
Under the Privacy Act, access that remains open after a staff member leaves is treated as an ongoing exposure. Manual, system-by-system offboarding is easy to leave incomplete — a login here, an integration there — which is why a centralised way to lock down access across every connected application at once matters.
How many data breaches were reported in Australia last year?
2025 recorded 1,205 notifiable data breaches to the Office of the Australian Information Commissioner — an 8% increase on 2024, and the highest annual total since the scheme began in 2018.
How much does a cyber security incident cost a small Australian business?
The Australian Signals Directorate’s 2024–25 Annual Cyber Threat Report put the average self-reported cost of a cybercrime incident for a small business at $56,600, a 14% increase on the prior year.
What does Practice Protect’s Cyber Security Compliance Hub™ actually include?
A current Privacy Policy, AI Usage Policy, and Data Retention and Disposal Policy Template, and a Data Breach Response Plan aligned to the Notifiable Data Breaches scheme — structured templates your firm applies its own details to, plus audit-ready access and offboarding records ready to produce for the TPB, OAIC, or a PI insurer.