Most accounting practices we meet believe their IT is in reasonable shape. There is antivirus on the machines, the practice software is in the cloud, and someone set things up a few years back. On paper, it looks handled.
Then we look properly, and the same gaps appear again and again. Not because anyone was careless, but because a practice holds exactly what attackers want: client tax file numbers, bank details, financial statements, and the email account that approves payments. The pressure points cluster around BAS and tax deadlines, when staff are busy, churn is high, and a fraudulent invoice is easiest to slip through. If you have read our guide to IT for accounting firms, this is the practical list of where firms actually fall short.
Gap 1: Client TFN and Financial Data Sitting in the Open
A practice holds tax file numbers, ABNs, bank details, and full financial histories for every client. That data is often spread across a file server, a few cloud folders, and individual mailboxes, with far broader access than anyone intended.
Under the Privacy Act, a breach of this data is a notifiable event, and the reputational cost in a referral-driven profession is severe. The fix is to know where client financial data actually lives, restrict access by role so a bookkeeper cannot see partner-level files they do not need, and stop treating shared drives as a free-for-all.
Gap 2: Invoice and Payment Fraud Around Deadlines
The single most damaging attack on an accounting practice is not data theft. It is payment redirection. An attacker who gets into one mailbox watches the flow of invoices and supplier payments, then strikes at the right moment with an email that looks genuine, asking to update bank details before the next transfer.
This spikes around BAS and tax deadlines, when volume is high and staff are rushing. The defence is part technical and part process: MFA on every mailbox to make the initial break-in harder, plus a hard rule that any change to bank details is confirmed by a phone call to a known number, never by replying to the email. This pattern, business email compromise, does more damage in this sector than anything else.

Gap 3: Practice and Portal Software Without MFA
Your practice management system, your ledger software, and the ATO and client portals you log into hold the most sensitive data in the business. We routinely find multi-factor authentication switched on for Microsoft 365 email but missing from the very systems that matter most.
An attacker looks for the one login protected by a password alone. The fix is to inventory every system that holds client data or connects to the ATO, and confirm MFA is enforced on all of them, with no “just this one” exceptions for a senior partner who finds it inconvenient.
Gap 4: Ex-Staff Access During Busy-Season Churn
Accounting practices take on seasonal staff and contractors around tax time, and people move on once the rush ends. Each arrival and departure is a small security event, and in the busiest weeks it is the one most likely to be missed.
The common gap is access that never gets removed. A departed accountant or a finished contractor keeps a login to the practice software or a shared drive long after they should. Months later, that forgotten account is a quiet way in. The fix is unglamorous: access granted by role, reviewed regularly, and revoked on someone’s last day, not whenever IT next gets around to it.
Gap 5: Client Files Living in Email Instead of Proper Systems
In a busy practice, client documents end up as email attachments. Tax returns, statements, and signed authorities sit in inboxes and sent folders because that was the quickest way to move them at the time.
Email is the front door for most incidents, and a mailbox full of client financial documents is a serious prize. If that account is compromised, the attacker gets the data and the trust that comes with sending from your address. The fix is to move client documents into a proper system with controlled access, and use a secure portal for exchanging sensitive files rather than plain email.
Gap 6: Backups That Have Never Been Restored
Backups are “running”, the dashboard is green, and everyone assumes the client ledger and working papers are safe. Then an incident hits, someone tries to restore, and the files are incomplete, corrupted, or, in a ransomware case, encrypted along with everything else.
For a practice, losing years of working papers and client records mid-season is close to fatal. A backup you have never restored from is a guess, not a safety net. The fix is to test restores on a schedule and keep at least one copy an attacker cannot alter or delete. You can read more in our guide to immutable backup.
Gap 7: No Alerting on Email Forwarding Rules
This is the gap that quietly undoes the others. When an attacker gets into a mailbox, the first thing they often do is set up a hidden forwarding rule, so every invoice and payment conversation is copied to them without anyone noticing. The account looks normal. Nobody is watching.
Without monitoring, that rule can sit there for weeks while the attacker waits for the right invoice. The fix is alerting on new mailbox forwarding rules and unusual sign-ins, so a compromise is caught early rather than discovered after the money has gone.
Closing the Gaps
None of these are exotic. They are the everyday shortfalls that turn a preventable incident into a real one, and most of them map straight to Essential Eight, the baseline published by the Australian Cyber Security Centre. The hard part is knowing which ones apply to you, because they stay invisible until someone looks.
Where to Start
If you recognised your practice in more than one of these, you are normal, and you are in a good position, because every gap on this list has a clear fix.
Start by getting a clear picture of where you stand. Our IT maturity assessment takes a few minutes and shows you which controls need attention first.
We are a Sydney-based team in Bella Vista, and we work with accounting practices across the metro area. We understand the rhythm of the financial year and secure your practice without getting in the way of the work. No jargon, no scare tactics, just the basics done properly.