What Is a Human Firewall? How Accounting Firms Stop a Click Becoming a Breach
3 min read | Practice Management | Cyber Security | Email Security | Security Awareness
Quick answer: A human firewall is your team acting as an active layer of defence — trained to recognise current attack methods, verify payment and access requests before acting, and call immediately when something looks wrong. It does not replace technical controls. Phishing contributes to roughly one third of Australian data breaches, and AI-generated emails now replicate a firm’s own language and clients’ names closely enough that awareness alone cannot stop them. A security-first culture reduces how often a mistake happens. Multi-factor authentication, role-based access, and email filtering limit the damage when it does. Australian accounting firms need both.
Key Takeaways
- Credential theft through phishing contributes to roughly one third of Australian data breaches — making your people, not your systems, the most common way attackers gain access.
- AI-generated phishing now uses your firm’s language, your clients’ names, and real billing details. Default Microsoft 365 protection was not built to catch it.
- Some attacks can be filtered out by technology. Others — such as a fraudulent notice arriving in the post — rely entirely on a person knowing what to look for.
- The most valuable habit you can build is a team that calls before they are certain something is wrong. Early contact separates a contained incident from a notifiable breach.
- Under the TPB Code and the Privacy Act, documented and enforced policies covering how staff handle sensitive requests are now part of demonstrating adequate controls.
Most security awareness campaigns start from the same premise: your people are the problem. For Australian accounting firms in 2026, that framing gets it backwards. Your team is also your first line of defence — and the firms that handle incidents well are not the ones with infallible staff. They are the ones who built an environment where a human mistake doesn’t become a breach.
Think about your team right now. If a staff member received a convincing phishing email this afternoon — one that arrived from a client’s real address — what would they do?
Would they report it straight away, or delete it and move on?
For most firms, the honest answer is closer to “I’m not sure.” That answer matters more than any single control you have in place, because attackers go after people rather than systems for one reason: people are harder to patch.
Why are accounting firms targeted through their people?
Credential theft through phishing contributes to roughly one third of Australian data breaches, making it one of the most common ways attackers gain access to an organisation.
What has changed is the quality of the attempt. AI has made targeted phishing almost indistinguishable from legitimate correspondence — using your firm’s language, your clients’ names, and details like billing history. These are not mass spam campaigns. They are built from publicly available information about your practice.
The timing is deliberate too. Tax season, lodgement deadlines, and overflowing inboxes create exactly the conditions attackers look for, which is why campaigns are scheduled around them.
What does a genuinely convincing phishing attack look like?
In a recent case, an accounting firm received an email from one of their clients. Not a spoofed address. Not a lookalike domain. The client’s genuine email address — because the client’s own account had been compromised.
There was nothing suspicious about the sender. No awareness training fully prepares a team for that.
A second case involved no technology at all: an official-looking compliance notice that arrived in the post, complete with reference numbers and payment instructions. It was not from the regulator it appeared to come from.
One of these attacks was stopped by technical controls. The other could only ever have been stopped by a person recognising the warning signs. We walk through both in full — including what happened next and the specific signals staff can be trained to catch — in our on-demand webinar.
If culture can’t prevent every mistake, what does?
Even the best-trained team will occasionally click the wrong thing — particularly when a phishing email uses a client’s exact name and references their most recent lodgement.
A security-first culture reduces the likelihood of a mistake. Your team is still human. This is where technical controls add a layer of protection that culture alone cannot provide:
- Multi-factor authentication makes it much harder for a clicked link to turn into a credential compromise.
- Role-based access limits how far an attacker can move if credentials are compromised.
- Email filtering reduces how many of these emails reach a person in the first place.
What are the three layers that work together?
Protecting a firm properly means three layers doing different jobs at the same time.
The human layer is everyday behaviour — awareness, verification habits, documented policies, and knowing who to call when something doesn’t look right.
The access and device layer is the technical foundation — access protection enforced across every application, role-based access so people only reach what they need, one-click offboarding when someone leaves, and securing the company-managed devices your team works on.
The email layer reduces what reaches your team in the first place. Default Microsoft 365 protection catches bulk spam, but it was not built to catch AI-generated emails written in your firm’s language and naming your clients. That takes BEC-specific filtering, domain spoofing controls, and accounting-aware threat detection.
We break down what each layer covers, and where most firms have gaps between them, in the full session.
What do the best-protected firms actually do?
01 · Unsure? Call.
Early contact is the difference between an incident that gets contained and one that becomes a notifiable breach. A security-first culture means your team knows that calling is always the right move — even before they’re sure something is wrong.
02 · Verify before you trust.
Any unusual request involving a payment, bank detail change, or access request gets verified by phone before action is taken. Not because the email looks suspicious — because the stakes are too high to assume. This is a process, not a product. Write it down, make it a firm policy, and review adherence regularly.
03 · Build security into the documented culture.
A security-first culture is not a video watched once per year. It is a set of documented expectations that staff are onboarded into and reminded of regularly. Under the TPB Code and the Privacy Act, having documented, enforced, and evidenced policies around how your team handles sensitive data is becoming an expectation, not a nice-to-have. This is what the Cyber Security Compliance Hub™, included with Practice Protect Core™, provides — structured templates your firm applies its own details to, ready to produce when the TPB, OAIC, or a professional indemnity insurer asks.
Frequently Asked Questions
What is a human firewall?
A human firewall describes your staff acting as an active layer of defence rather than a liability. It combines awareness of current attack methods, verification habits for payment and access requests, documented firm policies, and a clear understanding of who to contact when something looks wrong. It works alongside technical controls — not instead of them.
Is security awareness training enough on its own for an accounting firm?
No. Training reduces how often a mistake happens, but it cannot eliminate it — particularly when a phishing email arrives from a genuine, compromised client address with nothing suspicious about the sender. Training needs technical controls underneath it to limit the impact when a mistake happens. Equally, no technical control catches a fraudulent letter arriving in the post. Both layers are required.
Does Microsoft 365 email protection catch AI-generated phishing?
Default Microsoft 365 email protection is effective against bulk spam and generic malicious content. It was not designed to catch a contextually accurate, AI-written email that uses your firm’s language, names your clients, and references your billing patterns. Catching those requires BEC-specific filtering, domain spoofing controls, and accounting-aware threat detection.
What should a staff member do if they think they have clicked a phishing link?
Call immediately, before they are certain anything is wrong. Early contact is what separates a contained incident from a notifiable breach. A culture where staff hesitate to report — for fear of blame or of wasting someone’s time — is the single most expensive cultural gap a firm can have.
How do we document our security expectations for the TPB or a PI insurer?
You need documented, enforced policies rather than informal practice — typically a current Privacy Policy, AI Usage Policy, IT and Internet Usage Policy, Data Retention & Disposal Policy, and Data Breach Response Plan, supported by records showing who could access client data and when that access was removed. Under the TPB Code and the Privacy Act, the standard has shifted from claiming you take security seriously to demonstrating it with documentation a regulator will accept.
What can a firm with no IT staff do about this in the next week?
Three things. Run a five-minute team conversation and ask your team how they would handle a suspicious email from a client’s real address. Set a written verification rule requiring a phone call before any payment, bank detail change, or access update is actioned. And check what your current email and device security actually covers, rather than assuming.
Practice Protect is the only cyber security service built exclusively for Australian accounting and bookkeeping firms — giving every practice the compliance confidence, client protection, and operational simplicity that protecting client data now demands. Trusted by 28,000+ accounting professionals.
Disclaimer: This article does not constitute legal advice. For compliance obligations specific to your firm, consult your legal or compliance adviser.
Ready to see how your team would handle a suspicious email? Download the Email Phishing Checklist below.
Want to hear how these attacks actually unfolded?
Both cases in this article — and several others — are walked through in full in our session Building a Human Firewall: Creating a Security-First Culture, along with what each security layer actually covers and the warning signs your team can be trained to catch.
WATCH THE ON-DEMAND WEBINAR