For most accounting practices, the months either side of the October tax deadlines are a blur. The phones run hot, the lodgements stack up, and anything that is not directly billable gets pushed to “later”. Cyber security almost always lives in “later”.
Then the deadlines pass and the practice exhales. That quieter window, before the next compliance cycle builds, is the single best time of the year to do the thing you never get to: look honestly at the state of your IT and fix what needs fixing. Not as a panic project, but as a calm, staged baseline you can finish before the busy season returns.
This is a 90-day plan to get there. It is built around the gaps we see most often in accounting practices, because the firms that handle client data, tax file numbers, and bank details all day are exactly the ones attackers find worth their time. If you want the broader picture for your sector first, our guide to IT for accounting firms sets the scene.
Why the Post-Season Window Matters
An accounting practice is a high-value target for a simple reason: you hold the data that makes fraud easy. Tax file numbers, dates of birth, bank account details, payroll, and the email trail that controls password resets for everything else. To an attacker chasing a payment or an identity, that is a rich seam.
The post-season window matters because security work done in a rush is security work done badly. Trying to tighten controls in the middle of lodgement season means staff resist anything that slows them down, and changes get half-finished. Doing it now means you can test properly, train people calmly, and have a documented baseline in place before the pressure returns.
The goal over the next 90 days is not perfection. It is a clear picture of where you stand and the biggest gaps closed in order.

The First 30 Days: See Where You Stand
You cannot fix what you have not measured. The first month is about getting an honest picture rather than buying anything.
Start with an inventory. List every system that holds client data or touches money: Microsoft 365, your practice management and ledger software, your document store, the portal clients use to send you files, and any remote access tools. For each one, answer a plain question: is multi-factor authentication actually enforced on it, or are you assuming?
This is where most practices find their first surprise. Multi-factor authentication is usually on for email and missing from the systems that matter most, the ledger, the portal, an old admin login nobody thinks about. Map it now, before you decide what to fix.
Days 30 to 60: Close the Accounting-Specific Gaps
With a clear picture, the second month is about closing the gaps that hit accounting practices hardest.
Client data and confidentiality. Not everyone in the practice needs access to every client. Review who can see what, restrict access to the matters and clients people actually work on, and make sure a departing staff member or a finished contractor loses access the day they leave. For a practice that handles sensitive financial records, loose access is a quiet liability.
Business email compromise. This is the pattern that does the most damage in your sector. An attacker gets into one mailbox, watches the invoices and remittances go back and forth, then sends a convincing email asking a client or supplier to update bank details before the next payment. Because it comes from a real account, it passes the usual checks. Multi-factor authentication on every mailbox makes the break-in much harder, and a simple rule that any bank-detail change is confirmed by a phone call to a known number, never a reply to the email, catches most of what slips through. Our guide to business email compromise covers how this plays out.
Tested backups. A backup nobody has restored from is a guess, not a safety net. Confirm your client files and ledger data are backed up, that the backups are tested on a schedule, and that at least one copy is protected so ransomware cannot encrypt or delete it along with everything else.
Days 60 to 90: Make It Stick and Map It to a Standard
The final month is about turning a one-off cleanup into something that stays fixed.
Security drifts. Controls get set up once, then a new account appears without multi-factor authentication, patching falls behind, or a backup quietly stops running. The difference between a practice that stays secure and one that slips back is ongoing monitoring and reporting, so you can see the state of your controls rather than hoping they held.
Everything in this plan lines up with Essential Eight, the baseline set of controls published by the Australian Cyber Security Centre. Multi-factor authentication, patching, tested backups, restricting access. You do not need to memorise the framework. You need the controls behind it working in your practice, which is what these 90 days deliver.
Where to Start
If you are not confident where your practice stands, the worst move is to guess, and the second worst is to wait for the next busy season to bury the question again. Use the quiet window while you have it.
A practical first step is to map where you stand. Our IT maturity assessment gives you a plain-English read on your current security in a few minutes and shows what needs attention first. From there you can decide what to handle internally and what to hand over.
We are a Sydney-based team in Bella Vista, and we work with accounting practices across the metro area. We understand the compliance rhythm your firm runs on and we secure it without getting in the way of the work. Talk to our team when you are ready.