Accounting firms do not need a giant security program for the sake of it. They do need to be confident that the systems holding client information, tax records, financial data and email are being managed properly.
The difficult part is that the biggest gaps are often fairly ordinary. An old account that was never removed. MFA that is enabled for some users but not others. Backups that exist but have never been tested. Team members working around a recurring issue because nobody has reviewed the underlying problem.

Why accounting firms need to look a little closer
Accounting businesses depend heavily on online systems and hold information that is useful to an attacker. That can include identity details, tax information, financial records, client correspondence and access to cloud accounting platforms.
There is also a lot of email, document sharing and time-sensitive work. During busy periods, a believable phishing email or payment change request can arrive at exactly the wrong moment.

Photo by Scott Graham via Unsplash.
The gaps we would check first
1. Is MFA actually covering the important accounts?
MFA should be protecting email, document storage, cloud applications and administration access wherever possible. It is one of the most useful controls available if a password is stolen.
The useful question is not just, “do we have MFA?” It is whether it is applied consistently, whether old authentication methods are still available, and whether the important accounts are covered.
2. Who still has access to what?
Access tends to build up over time. Team members change roles, temporary access becomes permanent, shared accounts hang around, and former employees are not always removed from every system.
For an accounting firm, it is worth checking who can access client files, mailboxes, cloud accounting systems, document stores and administration portals. Most users should only have the access they genuinely need for their role.
3. Can the firm actually recover its data?
Having a backup product on an invoice is not the same as knowing the business can recover. The backup scope needs to cover the data the firm depends on, and restores should be tested rather than assumed.
That can include Microsoft 365 data, shared files, servers and line-of-business systems. It is also worth checking whether backups are separated enough from the live environment that an incident cannot simply take out both copies at once.
4. Is email being treated as a security system?
Email is where a lot of risk turns into a real business problem. A compromised mailbox can be used to read existing conversations, impersonate team members, reset other accounts or change payment details inside a legitimate thread.
Email protection should include more than spam filtering. Account security, authentication, suspicious sign-in visibility and sensible payment verification processes all matter.
5. Are devices actually managed and kept up to date?
Computers and applications need a proper patching process. Relying on team members to notice an update prompt and deal with it when they have time is not much of a process.
Older devices and unsupported software deserve particular attention. If a product no longer receives security updates, it should not quietly stay in service because replacing it is inconvenient.
6. Is anybody looking at the security alerts?
A lot of businesses have security products generating alerts. Fewer have a clear answer for who reviews those alerts, what gets investigated and what happens outside normal business hours.
The point of monitoring is not to collect more dashboards. It is to make sure suspicious activity gets in front of somebody who can decide whether it matters and act on it.

Photo by Jakub Żerdzicki via Unsplash.
Do not ignore the people and process side
Some of the highest-risk situations do not require a technical exploit at all. A fake supplier bank-detail change, a convincing login page or a phone call pretending to be a client can be enough.
Team members should know how to report something suspicious, and important financial changes should have a verification step that does not rely on replying to the same email that requested the change.
What should a cybersecurity risk assessment actually tell you?
A useful assessment should not end with a 40-page report and a list of products to buy. It should answer a few practical questions.
Where are the gaps?
Which controls are missing, inconsistent or only assumed to be working?
What matters first?
Which issues create meaningful business risk and should be fixed before lower-priority items?
Who owns the fix?
Is it something the internal team, IT provider, software vendor or management needs to address?
A sensible baseline for Australian firms
For smaller firms, the Australian Cyber Security Centre recommends starting with multi-factor authentication, software updates and backups, then working towards Maturity Level One of the Essential Eight.
That does not mean every accounting practice needs to implement every possible security control at once. It gives the firm a sensible baseline, and the assessment can then focus on the controls that matter most to the way the business actually operates.
If your IT provider handles it, ask for evidence
“Our IT provider handles security” is a perfectly reasonable answer, but it is not the same as knowing the control is in place and working.
Ask simple questions. Is MFA enforced across the important accounts? When was the last backup restore tested? How are old users removed? Who reviews security alerts? What happens if Microsoft 365 is compromised?
A good provider should be able to explain the answer in plain English and show enough evidence to give you confidence without drowning you in technical detail.
Start with the few things that would hurt most
For most accounting firms, the useful first step is not another generic security checklist. It is working out which systems and information the firm could least afford to lose, who can access them, how those accounts are protected, and whether recovery has actually been tested.
Q10 provides cybersecurity and IT support to help businesses reduce risk, improve security and keep their team supported. We can review the current environment, identify the higher-priority gaps and work through the improvements in sensible stages.