Why Password Managers Aren’t Enough for Australian Accounting Firms — And What the Difference Actually Costs You
Blog Understanding Cybersecurity
8 min read | Practice Management | Cyber Security | Compliance | Access Control
Tools like 1Password, LastPass, and Dashlane were built to solve a credential problem. Australian accounting firms in 2026 have a compliance problem — and the two are not the same thing. The TPB Code, Privacy Act, and ATO now require specific security controls from every registered tax agent. This is what those controls look like, why standard password management doesn’t deliver them, and what a platform built specifically for your profession does instead.
If your firm is currently using a password manager — whether that’s 1Password, LastPass, Dashlane, or a similar tool — these four questions are worth sitting with before you read further.
If a regulator asked for your firm’s documented security system today, could you produce it — or would that require starting from scratch?
When someone leaves your firm, does access get removed across every connected system immediately — or does someone work through a manual checklist that may or may not be complete?
When a staff member changes roles, does their access update to reflect that — or do permissions quietly accumulate over time?
If you had a question about how a specific cyber security or access control requirement applies to your firm’s technology setup, is there someone you could call who actually knows your environment?
If any answer is unclear, it is worth understanding why — and what a different answer would look like.
The gap most accounting firms don’t realise they have
Password managers are useful tools. They organise credentials, reduce the friction of logging in across multiple platforms, and discourage the worst habit in any professional services environment: reusing the same password across every system.
But for accounting firms in 2026, credential storage is the starting point — not the solution.
The average accounting firm now operates across nine to fifteen cloud applications. Xero. MYOB. Karbon. Dext. FuseSign. Microsoft 365. Each one holds sensitive client data. Each one is a potential access pathway. And each one requires its own credentials — creating a sprawling access surface that grows with every new tool added to the stack.
A password manager manages passwords. It cannot enforce who has access to which application and under what conditions. It cannot remove a departing staff member’s access across every connected system in a single action. And it cannot produce a Data Breach Response Plan, which the OAIC recommends organisations maintain to support compliance with the Notifiable Data Breaches (NDB) Scheme, nor can it provide an up-to-date Privacy Policy aligned with the Privacy Act 1988 and the privacy reforms commencing between 2024 and 2026.
These are not edge cases. They are the regular operational realities of running a modern accounting firm — and they sit entirely outside what any password manager was designed to address.
What password managers are — and what they were built for
Tools like 1Password, LastPass, Dashlane, Keeper, and NordPass are well-regarded products. They do what they were designed to do: store login credentials securely, generate strong passwords, and reduce the friction of accessing multiple accounts. For a business whose primary security concern is weak or reused passwords, they provide genuine value.
The question for an Australian accounting firm is not whether these tools are good at what they do. The question is whether what they do is sufficient for the environment you operate in — and in 2026, for firms registered with the TPB and holding client tax data, financial statements, TFNs, and SMSF records, the answer is that the regulatory environment has moved well past what credential storage alone can address.
Here is what every standard password manager has in common when deployed in an accounting practice:
They manage passwords. They don’t govern identity.
A password manager tells you what the login is. It doesn’t tell you whether the person using that login still works for your firm, or whether their access level is appropriate for their current role. Password management and identity governance are different capabilities — and accounting firms in 2026 need both.
They don’t manage who has access – only what the credentials are.
A standard password manager tells a staff member how to log in. Its core function — credential storage, autofill, and password generation — does not extend to governing which staff members should have access to which systems based on their current role, or with one-click revoke access when they leave. Some vendors offer more advanced access governance features at higher enterprise tiers, but these are separate products requiring dedicated IT configuration — not what a small accounting firm with no IT staff deploys when they sign up for a password manager. And when a staff member leaves, some have an offboarding multi-step manual checklist: revoke access system by system, change shared passwords, transfer shared folder ownership, then audit the logs to confirm nothing was missed. That is not a single action. For accounting firms carrying Privacy Act and TPB obligations, the gap between a manual checklist and a one-click, timestamped, audit-ready lockout is the gap between a compliance position and a compliance exposure.
They produce no compliance documentation.
Since 1 July 2025, the TPB Code of Professional Conduct requires every registered tax agent to maintain a Quality Management System that includes documented security procedures. A password vault is not a documented security system. A shared credentials folder is not a Written Information Security Plan. A Data Breach Response Plan cannot be generated from a password manager export. None of these tools produce the documentation that the TPB, the OAIC, or a professional indemnity insurer will ask to see.
They have no concept of your regulatory environment.
These tools serve millions of users across thousands of industries. Their support teams, configurations, and product roadmaps reflect that breadth. They are not updated when the TPB Code changes. They do not have accounting-specific threat intelligence. Their helpdesks do not know what a BAS deadline is or what the NDB scheme’s 30-day notification window means in practice.
What about enterprise identity platforms like Okta or JumpCloud?
These are a step above password managers — genuine identity platforms with SSO, MFA, and directory management. But they are built for enterprise IT environments with dedicated IT teams to configure and manage them. In a standard deployment for a small accounting firm with no IT staff, they require significant configuration to connect to accounting-specific applications, and they do not produce the TPB-aligned compliance documentation that registered practitioners are required to maintain. For accounting firms, a powerful tool that isn’t configured for your environment and doesn’t come with accounting-specific support produces a similar outcome to an underpowered one: a security gap that feels addressed but isn’t.
Practice Protect was built for one profession. Every integration covers the apps accounting and bookkeeping firms actually use. Every support interaction is handled by people who work exclusively with accounting practices. And the compliance documentation — the Written Information Security Plan (WISP) and Data Breach Response Plan — is built specifically for the TPB, Privacy Act, and ATO frameworks that registered tax agents answer to.
What standard password managers cover — and where accounting firms need more

What identity and access management actually means
The distinction that matters is not between a good password manager and a bad one. It is between credential storage and identity governance.
Credential storage answers one question: what are the login details for this system?
Identity governance answers a different set of questions: who in your firm has access to which systems, under what conditions, from where, and with what evidence trail behind every change?
For an accounting firm, the practical difference shows up in moments that credential storage cannot handle.
When a staff member leaves.
A password change in a standard password manager revokes that one credential. It does not remove the staff member’s access across the other applications connected to your firm — each of which may require a separate manual revocation step that someone has to remember, find, and action. In a firm managing that many cloud applications, that is nine to fifteen individual access points that need to be closed at the moment of departure. Under the Privacy Act as amended in December 2024, residual access to personal information after departure is not a potential future risk. It is an ongoing breach event.
There is a compounding problem most firms don’t consider. In a standard password manager, staff can see the credentials they use. Which means when someone leaves, the firm doesn’t just need to remove their access — it needs to change every password that person ever saw, across every application they touched, because that person now has those credentials stored in their own memory, their own notes, or their own devices. That is not a departure process. That is a credential reset project.
Practice Protect uses password cloaking — staff log in to applications through the platform, but the underlying credentials are encrypted and never visible to them. A staff member who leaves Practice Protect-managed firm has never seen the passwords in the first place. That means when access is removed, the firm does not need to chase down and reset every credential that person may have memorised or written down. In most cases, removing their access to Practice Protect is sufficient — and the timestamped audit record confirms the moment that access was closed. The time saving across a typical firm offboarding is significant. More importantly, so is the compliance position.
Practice Protect’s one-click lockout removes the staff member’s access to the portal and therefore to all connected applications simultaneously and generates a timestamped audit record automatically. This is the single action that replaces the manual checklist and supports the Privacy Act’s requirement for documented account deactivation on departure.
When a team member changes roles.
A password manager stores credentials. It does not track whether the access those credentials provide is still appropriate for the person’s current responsibilities. Permissions accumulate quietly over time unless someone is actively governing them — and in practice, even firms with IT support or an external MSP find that role-based access reviews are among the first tasks to slip when everyone is busy. Without a system that surfaces role changes as access review triggers automatically, the default outcome is accumulated permissions that no one intended and no one is monitoring.
When a regulator asks for evidence.
A password manager produces nothing relevant to a TPB review, a Privacy Act investigation, or an OAIC inquiry. The Written Information Security Plan, AI Policy, and Data Breach Response Plan that regulators expect to see require a different layer entirely — one that sits above credential storage and produces compliance evidence as part of its normal operation.
When someone needs help with an accounting-specific configuration.
A generic tool’s support team does not know what an ATO portal credential is, why a BAS deadline matters, or what the regulatory implications are of getting an access decision wrong. That knowledge gap is not a product feature — it is a service model problem.
The regulatory context that makes this urgent
This is not a cybersecurity best-practice argument. It is a legal compliance argument.
Since July 2025, the TPB Code of Professional Conduct requires every registered tax agent to maintain a Quality Management System — including documented procedures for protecting client data. The standard for what constitutes adequate documentation has shifted from aspirational to auditable.
The Privacy Act, as amended in December 2024, now explicitly names multi-factor authentication, access privilege management, and account deactivation on departure as technical and organisational measures firms must demonstrate as part of their ‘reasonable steps’ obligation under APP 11. A statutory tort effective June 2025 means individual clients can now sue their accounting firm directly for privacy breaches — creating class action exposure for firms holding TFNs and financial data across hundreds of clients.
The ATO’s Digital Service Provider Operational Security Framework mandates MFA for all software accessing ATO services. ATO agent credentials are formally identified by the ATO as high-value targets for fraud — compromised credentials can enable fraudulent lodgments and refund redirection across an agent’s entire client portfolio.
AML/CTF Tranche 2, effective 1 July 2026, brings accounting firms providing designated services into the AUSTRAC reporting framework — with access control, data integrity, and seven-year recordkeeping obligations that require demonstrable governance, not just credential management.
None of these obligations are met by a password manager. And while a good IT provider can contribute meaningfully to a firm’s security posture, the documentation layer — the TPB-compliant Quality Management System, the Data Breach Response Plan — requires controls and frameworks built specifically for the regulatory environment accounting firms operate in.
These obligations map directly to what Practice Protect delivers: compliance you can prove, not just claim; protection built for the specific apps your firm runs on, not a generic product adapted for a different market; and a done-for-you model that includes a Cyber Security Compliance Hub. These are not abstract aspirations. They are the three things that separate a firm with a defensible compliance position from one that is exposed.
The consequences are not theoretical. A Brisbane-based accounting firm — a registered tax agent with 21 staff, offering tax, advisory, bookkeeping, and SMSF services — was listed by the Qilin ransomware operation after suffering unauthorised access to its IT environment. Client financial and banking data was subsequently published on the dark web. The firm notified impacted individuals, engaged cyber security specialists, and informed both the ACSC and the OAIC. Every obligation that followed — notification, evidence of response, regulatory reporting — required the firm to have controls and documentation in place before the incident occurred. The firms that were prepared had a defensible position. The firms that weren’t had to build one under pressure.
What purpose-built access governance looks like
An identity and access management platform built for accounting firms covers a different scope to a password manager — in both the technical controls it provides and the compliance infrastructure it generates alongside them.
On the access side: single sign-on across the full accounting app stack — Xero, MYOB, Karbon, Dext, SuiteFiles, FuseSign, and 6,000+ accounting-specific integrations — with MFA enforced firm-wide. Password cloaking means staff can use credentials without ever seeing them, eliminating the reuse that exposes entire client portfolios through a single compromised login. Geo and IP access controls restrict credential-based application access to expected locations, so a login attempted from an unexpected location triggers a block rather than a breach.
Practice Protect comes in two tiers. Core™ covers Access & Identity — SSO, MFA, password cloaking, geo/IP access controls, one-click lockout, and the Cyber Security Compliance Hub. Complete™ builds on Core™ with three additional layers: Email Security (BEC filtering, domain spoofing controls, and AI-enhanced phishing interception), Device Security (device management, MDM, patch enforcement, and remote wipe), and deeper data breach investigation capabilities, as well as more holistic reporting across your environment. For most firms, Core™ is the foundation that supports access governance and compliance documentation obligations. Complete™ closes the remaining gaps across email threats, device security, and holistic technology stack management.
When a staff member leaves.
A single action removes the staff member’s access across all 6,000+ connected applications — every app connected to Practice Protect via SSO — simultaneously. Not a checklist to work through manually. One action, one outcome, one timestamped audit record that satisfies the Privacy Act’s requirement for documented account deactivation on departure.
The AI threat has changed the landscape.
In 2026, phishing emails targeting accounting firms are increasingly generated using AI — crafted to replicate your firm’s communication style, reference your clients by name, and mimic your billing cycles. These are not mass spam campaigns. They are targeted attacks built from publicly available information about your practice. Standard email security — including the default Microsoft 365 filtering most accounting firms rely on — was designed to catch generic malicious content, not a contextually accurate, AI-written email that appears to come from your own firm. This is one of the reasons Practice Protect’s Email Security layer exists as a distinct capability: because the threats targeting accounting firms in 2026 are specific to the profession, and defending against them requires intelligence that is specific to the profession.
Australia’s financial sector regulator has made its position clear. ASIC has warned that AI tools are materially expanding the threat landscape — creating the ability to expose vulnerabilities far faster than most organisations realise — and has told financial services firms that cyber resilience is not just an IT issue, but a core obligation. “The clock is at a minute to midnight,” ASIC Commissioner Simone Constant said. “If you aren’t on top of your cyber resilience already, the time to act and prepare is right now.” Accounting firms sit squarely within the financial services sector this warning is directed at.
The network intelligence advantage.
There is one capability that no password manager and no generic identity platform can offer: the intelligence that comes from 28,000 accounting professionals on a single platform. Every accounting firm on Practice Protect is using the same applications, facing the same threats, and operating under the same regulatory obligations. When a new phishing campaign targets accounting firm credentials, or a new attack pattern appears targeting Xero or M365 integrations, it is visible across the network — and that intelligence feeds into the platform’s protection for every firm on it. Your firm benefits from the collective security posture of the Australian accounting profession. A password manager protects your vault. Practice Protect protects your profession.
When something goes wrong, the support model matters.
A less than 15-minute average response time from a team that only works with accounting and bookkeeping firms — who understand Xero, the ATO portal, what tax season means operationally, and what the NDB scheme’s 30-day notification window requires — is a materially different resource than a general IT helpdesk that serves every industry. Accounting-specific support, every time.
“Practice Protect has helped with security. I used to wake up in the middle of the night worried about our client data. I don’t do that anymore. It’s all securely protected — single sign-on, auto-generated passwords. I just don’t have to worry about it.”
That is what peace of mind sounds like for a practice owner who has actually fixed the problem — not outsourced the worry, but removed it.
The Cyber Security Compliance Hub: documentation the profession needs
Any platform can enforce MFA. The Cyber Security Compliance Hub is what separates access governance from compliance confidence.
It provides a suite of structured compliance documents — an updated privacy policy in line with the 2024 reforms still coming into effect, AI Acceptable Use Policy, and Data Breach Response Plan — each designed to support the obligations Australian accounting firms face under the TPB Code, Privacy Act APP 11, and AML/CTF Tranche 2. These are templates your firm applies its own details to, so the documentation reflects your practice, your systems, and your risk profile — not a generic placeholder that a regulator would see through immediately.
The result: when the TPB, OAIC, or a professional indemnity insurer asks what steps your firm has taken to protect client data, the answer is not a scramble. It is a documentation suite that was built for exactly that question.
No general-purpose password manager provides this. No generic IT provider has built it for the accounting profession specifically. It is the capability gap that matters most in a compliance environment that has shifted from guidance to enforcement.
Moving past a password manager isn’t just a security decision. It’s a positioning decision.
When a TPB renewal comes around, when the OAIC opens an inquiry, when a staff member leaves unexpectedly, or when a client asks what your firm is doing to protect their TFN — the firms that have implemented identity governance rather than credential storage have a straightforward answer. They can produce the documentation. They can show the audit trail. They can demonstrate that credential-based access across their connected app stack was revoked at the moment of departure, with a timestamped record to prove it.
Practice Protect delivers three things no password manager delivers: compliance you can prove to the TPB, Privacy Act, and ATO; protection built specifically for the apps your firm runs on — not a generic product adapted from a different market; and a done-for-you model that removes the operational burden of security from your firm entirely, saving time and money in the process.
It is not a more expensive version of 1Password. It is a different category of solution — one built exclusively for the profession where client trust, regulatory standing, and the financial security of hundreds of clients depend on getting access governance right.
→ Download the 2026 Accounting Regulatory Compliance Map
→ Book a Free Access Consultation to see what your firm’s access infrastructure should look like today.
Frequently Asked Questions
What is the difference between a password manager and an identity and access management platform?
Tools like 1Password, LastPass, and Dashlane are password managers — they store and organise login credentials. Practice Protect is an identity governance platform built exclusively for accounting firms — it controls who has access to which systems, under what conditions, and removes that access across all 6,000+ connected applications in a single action when someone leaves, with a timestamped audit record produced automatically.
Why isn’t a password manager enough for an accounting firm in 2026?
The Privacy Act as amended in December 2024 now explicitly requires multi-factor authentication, access privilege management, and account deactivation on departure as demonstrable ‘reasonable steps’ under APP 11. The TPB Code requires a documented Quality Management System covering security procedures. AML/CTF Tranche 2, effective 1 July 2026, requires access governance for in-scope firms. None of these obligations are met by credential storage alone. They require documented controls, audit trails, and compliance documentation that a password manager was never designed to produce.
How is Practice Protect different from 1Password, LastPass, or Dashlane for an accounting firm?
The first question covers the technical difference. The practical difference for an Australian accounting firm is this: 1Password, LastPass, and Dashlane were built to solve password storage and sharing. They were not built to solve the broader compliance, access governance, and cyber security requirements that firms face today. Practice Protect was built for firms registered with the TPB, carrying obligations under the Privacy Act, and operating across the specific apps — Xero, MYOB, Karbon, Dext, FuseSign — that accountants actually use. The access controls needed to comply with the TPB’s Information Security requirements, the offboarding process your Privacy Act obligations demand, and the support from a team that understands your profession — none of that comes with a general-purpose password manager, regardless of how good it is at storing credentials.
How is Practice Protect different from enterprise identity platforms like Okta or JumpCloud?
Okta and JumpCloud are enterprise identity platforms built for IT-managed business environments. They are powerful, but they are not configured for the Australian accounting profession’s specific app stack — Xero, MYOB, Karbon, Dext, FuseSign. — and they don’t produce the TPB-aligned compliance documentation that registered tax agents are required to maintain. Practice Protect is the only identity governance platform built exclusively for accounting and bookkeeping firms, with support from a team that works only with this profession.
What is the Practice Protect Cyber Security Compliance Hub?
The Cyber Security Compliance Hub is a structured compliance documentation suite included with Practice Protect Core™. It provides an AI Policy, and Data Breach Response Plan — each aligned to Australian regulatory requirements for accounting firms. These are structured templates your firm applies its own details to, giving you documentation that reflects your practice specifically and is ready to produce to the TPB, OAIC, AUSTRAC, or a professional indemnity insurer when required. No equivalent exists in any general-purpose password manager or generic IT security product.
What does one-click offboarding actually cover?
A single offboarding action removes the departing staff member’s access across all 6,000+ applications connected to Practice Protect via SSO — simultaneously, not one system at a time. A timestamped audit record is produced automatically, documenting which access was removed, when, and by whom. This is the evidence the Privacy Act requires to demonstrate that account deactivation on departure was carried out as a formal, documented control — not a manual process someone may or may not have completed. For firms on Complete™, remote device wipe is also available — closing the physical access pathway alongside the application layer. Complete™ Device Security includes device management, Email Security includes BEC filtering and domain spoofing controls, and Accounting Technology Management with a fully managed, proactive technology solution for accounting & bookkeeping firms. M365 backup — covering email, SharePoint, and OneDrive — is available as a separate add-on.
What Australian compliance obligations does Practice Protect support?
Practice Protect supports obligations across the TPB Code of Professional Conduct (including the Quality Management System requirement effective 1 July 2025), Privacy Act APP 11 (as amended December 2024), the ATO Digital Service Provider Framework, the Cyber Security Act 2024, AML/CTF Tranche 2 (effective 1 July 2026), and the ACSC Essential Eight baseline access control practices. The Cyber Security Compliance Hub documentation suite is consistently updated in line with the evolving guidelines from these regulatory bodies, and the platform’s access management features — including single-action lockout and timestamped audit logs — are designed to produce the evidence these frameworks require.
What does Practice Protect support include?
Practice Protect support is provided by a team that works exclusively with accounting and bookkeeping firms. They understand the specific systems, seasonal pressures, and regulatory obligations that accounting practices operate under — including Xero, the ATO portal, and what the NDB scheme’s 30-day notification window means in practice. Average response time is under 15 minutes. It is not a general helpdesk. It is a support model built around the specific needs of accounting practices, and it underpins a 96%+ client satisfaction rating.
How quickly can Practice Protect be implemented?
Implementation timelines depend on firm size and the number of connected systems. Practice Protect provides structured onboarding support designed specifically for accounting environments — not a generic setup guide — with ongoing support available as your team and systems evolve.
Practice Protect is the only cyber security service built exclusively for Australian accounting and bookkeeping firms — giving every practice the compliance confidence, client protection, and operational simplicity that protecting client data now demands. Trusted by 28,000+ accounting professionals.
Disclaimer: This article does not constitute legal advice. For AML/CTF or other compliance obligations specific to your firm, consult your legal or compliance adviser.