Skip to main content

Seven Cyber Gaps in Sydney Accounting Practices

11 August 2026 | By Birender Chahal

Most accounting practices we meet believe their IT is in reasonable shape. There is antivirus on the machines, the practice software is in the cloud, and someone set things up a few years back. On paper, it looks handled.

Then we look properly, and the same gaps appear again and again. Not because anyone was careless, but because a practice holds exactly what attackers want: client tax file numbers, bank details, financial statements, and the email account that approves payments. The pressure points cluster around BAS and tax deadlines, when staff are busy, churn is high, and a fraudulent invoice is easiest to slip through. If you have read our guide to IT for accounting firms, this is the practical list of where firms actually fall short.

Gap 1: Client TFN and Financial Data Sitting in the Open

A practice holds tax file numbers, ABNs, bank details, and full financial histories for every client. That data is often spread across a file server, a few cloud folders, and individual mailboxes, with far broader access than anyone intended.

Under the Privacy Act, a breach of this data is a notifiable event, and the reputational cost in a referral-driven profession is severe. The fix is to know where client financial data actually lives, restrict access by role so a bookkeeper cannot see partner-level files they do not need, and stop treating shared drives as a free-for-all.

Gap 2: Invoice and Payment Fraud Around Deadlines

The single most damaging attack on an accounting practice is not data theft. It is payment redirection. An attacker who gets into one mailbox watches the flow of invoices and supplier payments, then strikes at the right moment with an email that looks genuine, asking to update bank details before the next transfer.

This spikes around BAS and tax deadlines, when volume is high and staff are rushing. The defence is part technical and part process: MFA on every mailbox to make the initial break-in harder, plus a hard rule that any change to bank details is confirmed by a phone call to a known number, never by replying to the email. This pattern, business email compromise, does more damage in this sector than anything else.

Accountant working at desk with calculator and laptop
In accounting, the payment chain and the client data are both the prize.

Gap 3: Practice and Portal Software Without MFA

Your practice management system, your ledger software, and the ATO and client portals you log into hold the most sensitive data in the business. We routinely find multi-factor authentication switched on for Microsoft 365 email but missing from the very systems that matter most.

An attacker looks for the one login protected by a password alone. The fix is to inventory every system that holds client data or connects to the ATO, and confirm MFA is enforced on all of them, with no “just this one” exceptions for a senior partner who finds it inconvenient.

Gap 4: Ex-Staff Access During Busy-Season Churn

Accounting practices take on seasonal staff and contractors around tax time, and people move on once the rush ends. Each arrival and departure is a small security event, and in the busiest weeks it is the one most likely to be missed.

The common gap is access that never gets removed. A departed accountant or a finished contractor keeps a login to the practice software or a shared drive long after they should. Months later, that forgotten account is a quiet way in. The fix is unglamorous: access granted by role, reviewed regularly, and revoked on someone’s last day, not whenever IT next gets around to it.

Gap 5: Client Files Living in Email Instead of Proper Systems

In a busy practice, client documents end up as email attachments. Tax returns, statements, and signed authorities sit in inboxes and sent folders because that was the quickest way to move them at the time.

Email is the front door for most incidents, and a mailbox full of client financial documents is a serious prize. If that account is compromised, the attacker gets the data and the trust that comes with sending from your address. The fix is to move client documents into a proper system with controlled access, and use a secure portal for exchanging sensitive files rather than plain email.

Gap 6: Backups That Have Never Been Restored

Backups are “running”, the dashboard is green, and everyone assumes the client ledger and working papers are safe. Then an incident hits, someone tries to restore, and the files are incomplete, corrupted, or, in a ransomware case, encrypted along with everything else.

For a practice, losing years of working papers and client records mid-season is close to fatal. A backup you have never restored from is a guess, not a safety net. The fix is to test restores on a schedule and keep at least one copy an attacker cannot alter or delete. You can read more in our guide to immutable backup.

Gap 7: No Alerting on Email Forwarding Rules

This is the gap that quietly undoes the others. When an attacker gets into a mailbox, the first thing they often do is set up a hidden forwarding rule, so every invoice and payment conversation is copied to them without anyone noticing. The account looks normal. Nobody is watching.

Without monitoring, that rule can sit there for weeks while the attacker waits for the right invoice. The fix is alerting on new mailbox forwarding rules and unusual sign-ins, so a compromise is caught early rather than discovered after the money has gone.

Closing the Gaps

None of these are exotic. They are the everyday shortfalls that turn a preventable incident into a real one, and most of them map straight to Essential Eight, the baseline published by the Australian Cyber Security Centre. The hard part is knowing which ones apply to you, because they stay invisible until someone looks.

Where to Start

If you recognised your practice in more than one of these, you are normal, and you are in a good position, because every gap on this list has a clear fix.

Start by getting a clear picture of where you stand. Our IT maturity assessment takes a few minutes and shows you which controls need attention first.

We are a Sydney-based team in Bella Vista, and we work with accounting practices across the metro area. We understand the rhythm of the financial year and secure your practice without getting in the way of the work. No jargon, no scare tactics, just the basics done properly.

Birender Chahal
Founder, CIO Tech

Birender founded CIO Tech and holds an IT degree from the University of Technology Sydney. He has delivered IT projects across hotels and serviced offices, covering property management systems, guest networks, and Essential Eight hardening. More about CIO Tech.

Stop putting off IT that works

Book an IT Audit

$990 one-off. 90-day deep dive into your IT environment with a prioritised action plan.

Book IT Audit

Free IT Health Check

Takes 3 minutes. See where your IT stands and what to fix first.

Free IT Health Check

Cyber Posture Snapshot

Your details 1 / 10

How exposed is your business?

Six quick questions, two short ones to tailor the result, and you'll see where your business stands. About two minutes. Plain English, no jargon.

We'll use your email to send a copy of your result. No spam, no pushy sales calls.

Question 1 of 9

When your team logs in to email and business apps, do they need a code from their phone as well as a password?

Question 2 of 9

If a ransomware attack locked all your files tomorrow, could you restore them from a backup?

Question 3 of 9

When Microsoft or Apple release a critical security update, how fast does it land on your computers?

Question 4 of 9

How many people in your business can install software or change system settings on any work computer?

Question 5 of 9

If a staff member got a fake invoice or "urgent" email pretending to be from you right now, what would happen?

Question 6 of 9

When a staff member leaves, when does their access to email, files, and apps actually get cut off?

Question 7 of 9

How many people work in your business?

Question 8 of 9

Who looks after your IT today?

Question 9 of 9

What sort of business are you?

Tailoring your result...

Hi there, here's where your business stands.

Your Cyber Posture
Critical gaps Critical
Notable exposure Notable
Mixed picture Mixed
On the right track On track

Notable exposure

Your two biggest gaps

  1. 1
  2. 2

Where this leaves you on Essential Eight

  • MFA Multi-factor authentication
  • Backups Regular backups
  • Patching Covers 2 of 8: Patch applications + Patch operating systems
  • Admin access Restrict administrative privileges

This snapshot covers 5 of the 8 Essential Eight controls. The full IT Maturity Assessment covers all 8, plus Microsoft 365 hardening, device management, and staff training.