Cyber security for accountancy firms is not a technology problem that happens to land in a practice. It is a client-confidentiality problem, an anti-money-laundering problem, a professional-indemnity problem and a filing-deadline problem, all of which happen to be solved with technology. That distinction matters, because a generic twenty-point security checklist written for “UK SMEs” will tell you to patch your firewalls and say nothing about who can log into your agent services account in the last week of January.
This cyber security for accountancy checklist is written the other way round. Every one of the twenty controls below starts from something a practice actually holds or does — a client’s UTR, a bank feed, a portal invitation, a subcontracted bookkeeping file, a laptop that goes home in January — and then names the control that protects it, the person who owns it and the single artefact you would hand to a client, an insurer or the Information Commissioner’s Office to prove it exists. If you have already read our guide to IT support for accountancy firms, this is the control set that guide assumes underneath it.
Two of our other pieces cover adjacent ground and are worth reading alongside this one: the Microsoft 365 security checklist for accountancy firms covers one platform in depth, and Cyber Essentials for accountancy firms covers one certificate in depth. This guide to cyber security for accountancy is deliberately vendor-neutral and certificate-neutral: it is the twenty things that have to be true regardless of whose software you bought, and regardless of whether you certify.
Table of contents
- Cyber Security for Accountancy Starts With What a Practice Holds
- The 2026 Threat Picture Behind Cyber Security for Accountancy
- How to Score This Cyber Security for Accountancy Checklist
- Cyber Security for Accountancy, Domain 1: Identity and Access
- Cyber Security for Accountancy, Domain 2: Devices and the Practice Estate
- Cyber Security for Accountancy, Domain 3: Client Data, Portals and Email
- Cyber Security for Accountancy, Domain 4: Suppliers and Outsourced Work
- Cyber Security for Accountancy, Domain 5: People, Response and Assurance
- How the January Peak Bends Cyber Security for Accountancy Firms
- HMRC Agent Multi-Factor Authentication: The 2026 Timetable
- Companies House Duties Inside Cyber Security for Accountancy
- What Cyber Security for Accountancy Costs
- Cyber Security for Accountancy: A 42-Person Worked Example
- Mapping Cyber Security for Accountancy to Cyber Essentials, MLR 2017 and UK GDPR
- A 90-Day Plan for Cyber Security for Accountancy Firms
- Six Cyber Security for Accountancy Mistakes Practices Make
- Frequently Asked Questions About Cyber Security for Accountancy
- References
Cyber Security for Accountancy Starts With What a Practice Holds
Before any cyber security for accountancy checklist makes sense, it helps to write down the inventory honestly. Most partners underestimate it, because the data arrived gradually and none of it looks dramatic on its own.
The client data set is unusually complete
An accountancy practice holds a more complete picture of a business than almost any other supplier that business uses. Statutory accounts show what it owns. Management accounts show what it earns each month. Payroll shows who works there and what they are paid. VAT returns show the trading rhythm. The bank feed shows who it pays and when.
Add personal tax and you also hold directors’ home addresses, dates of birth, National Insurance numbers, dividend income, rental income and, frequently, the same details for their spouses and adult children. That combination is why cyber security for accountancy matters more than headcount suggests: financially motivated attackers treat a practice as a shortcut rather than a target of last resort.
The identity data set is a regulated set in its own right
Since identity verification became a legal requirement at Companies House on 18 November 2025, with the twelve-month transition for existing directors, people with significant control and LLP members closing on 18 November 2026, practices acting as Companies House authorised agents hold verified identity evidence too. An authorised corporate service provider must keep those identity-check records for seven years and must notify Companies House within fourteen days of any change, including loss of supervision.
Separately, regulation 40 of the Money Laundering Regulations 2017 requires customer due diligence and transaction records to be kept for five years. So cyber security for accountancy is not merely a question of client data. A practice holds a regulated evidence archive that it is legally obliged to be able to produce.
The credential set is the part nobody inventories
The third category never appears on an asset register, and it is where cyber security for accountancy is usually weakest: credentials. An agent services account. An HMRC online services for agents account. Companies House filing credentials. Bank feed authorisations for dozens of clients. Portal administrator rights. Payroll bureau logins. Every one of those is a key to somebody else’s money or filings, and most practices have never written down how many exist or who holds them.
| What the practice holds | Why an attacker wants it | Where it usually lives |
|---|---|---|
| Statutory and management accounts | Shows which clients hold cash and when | Accounts production software, document management |
| Payroll records | Bank details of every employee of every client | Payroll software, email attachments |
| Personal tax data | Identity theft and refund fraud | Tax software, portal, mailboxes |
| Supplier and customer ledgers | Target list for payment redirection | Bookkeeping ledger, bank feeds |
| Identity verification evidence | High-quality documents for impersonation | Practice management, secure storage |
| Agent and filing credentials | Direct access to client tax positions | Browsers, password managers, sticky notes |
| Engagement letters and fee data | Convincing pretext for invoice fraud | Practice management, mailboxes |
The estate is smaller than you think and messier than you hope
Most UK practices under fifty people run a genuinely small estate, which is why cyber security for accountancy is a scoping exercise rather than an engineering one: laptops, phones, a couple of shared desktops, perhaps one surviving on-premises server, and then ten to fifteen cloud services. The messiness that defeats cyber security for accountancy is not scale. It is that the cloud services were bought at different times by different partners, each has its own login model, and only some of them were ever configured deliberately.
The 2026 Threat Picture Behind Cyber Security for Accountancy
The numbers below are the ones worth quoting to a partner group that has never budgeted for cyber security for accountancy, because they come from government and insurer research rather than from vendor marketing.
Why cyber security for accountancy scales with headcount
The Cyber Security Breaches Survey 2025/2026, published by the Department for Science, Innovation and Technology on 30 April 2026, found that 43% of UK businesses experienced a cyber breach or attack in the previous twelve months. Broken down by size, the figure was 42% for micro businesses, 46% for small businesses, 65% for medium businesses and 69% for large businesses.
That gradient is the single most useful planning fact in cyber security for accountancy. A four-partner practice and a sixty-person firm are not facing the same probability, and the control set below is deliberately sequenced so that a small practice can complete the first nine controls without a project.
Phishing is the whole story, not part of it
The same survey put phishing at 38% of businesses, far ahead of every other attack type, while ransomware was reported by only 1%. Ransomware gets the headlines and the board papers; phishing is what actually arrives. A cyber security for accountancy checklist that spends nineteen controls on ransomware and one on email has the weighting backwards.
For a practice, the phishing pretexts that defeat cyber security for accountancy write themselves. An HMRC refund notice in the week the tax return went in. A Companies House filing reminder in the month before the accounts are due. A client asking you to look at an attached invoice. Our companion piece on invoice fraud in accountancy firms covers the payment-redirection variant in detail.
The profession already knows, which is the encouraging part
The survey also found that 85% of businesses in the professional, scientific or technical sector rated cyber security as a high priority — comfortably above the all-business average — and that 54% had sought external information or guidance. Board-level ownership in that sector, the one that contains cyber security for accountancy, ran at 41% against 31% across all businesses.
An insurer survey published on 24 April 2026 found professional firms ranking cyber attacks as their leading risk at 65%, ahead of economic pressures at 18%, professional negligence claims at 9% and regulatory change at 8%. The awareness gap in cyber security for accountancy has closed. The evidence gap has not.
Two-factor adoption is still under half
Across all UK businesses, the survey found two-factor authentication in use at 47%, cloud backups at 74%, a formal incident response plan at 25%, and immediate supplier risk review at 15%. Cyber Essentials certification stood at 5%, up from 3%.
Read those four numbers together and the shape of a realistic cyber security for accountancy programme appears: most practices have backups, about half have some multi-factor authentication, very few have written down what happens next, and almost none have looked at their suppliers.
How to Score This Cyber Security for Accountancy Checklist
Most security checklists are scored on whether a control is “in place”. That wording is useless in a practice, because everyone believes their cyber security for accountancy controls are in place until somebody asks for the evidence.
Score the artefact, not the intention
This cyber security for accountancy checklist is therefore scored on evidence. For each of the twenty controls you record one of three states, and the only thing that decides the state is whether a named artefact exists and is current.
Current means the artefact exists, someone owns it, and it carries a date inside its review period. Stale means the artefact exists but the date has passed — a policy last reviewed in 2023, an access list built before two people left, a restore test from the year before last. Absent means there is no artefact, whatever the practice believes about the underlying control.
| State | Test | What it means commercially |
|---|---|---|
| Current | Named artefact exists and is dated inside its review period | Answerable in a client questionnaire without a project |
| Stale | Artefact exists but the review date has passed | Answerable, but a determined reviewer will find the gap |
| Absent | No artefact, regardless of what the practice believes | Not answerable; assume the honest answer is no |
Why cyber security for accountancy fits how a practice already works
Every practice already runs an evidence model like the one cyber security for accountancy needs. A file review does not ask whether the work was done well in principle; it asks to see the working papers. Anti-money-laundering supervision does not ask whether you know your clients; it asks for the customer due diligence records. Cyber security for accountancy is the same discipline pointed at a different subject.
The practical benefit is that the cyber security for accountancy score is not a matter of opinion. Twenty controls, three states, one number: how many of the twenty are Current. A practice that scores eleven has a specific list of nine things to do, each with a named artefact at the end of it.
Set the review periods once and then leave them alone
Three review periods cover all twenty cyber security for accountancy controls. Quarterly, for anything that drifts with joiners and leavers. Annually, for policies, training and supplier reviews. Per engagement, for the handful of controls that attach to a client rather than to the practice.
Give every control an owner who is a person, not a department
“IT” is not an owner of cyber security for accountancy. In a practice of forty, the realistic owners are a named partner, the practice manager, the person who runs payroll, and whoever holds the relationship with your external IT provider. If a cyber security for accountancy control cannot be given a human owner, it will be Absent at the next review.
| # | Control | Typical owner | Evidence artefact | Review |
|---|---|---|---|---|
| 1 | Multi-factor authentication on every cloud service | Practice manager | Sign-in report showing zero exempt accounts | Quarterly |
| 2 | Named accounts only, with shared logins retired | Practice manager | Identity register listing every shared account and its plan | Quarterly |
| 3 | Separate administrator accounts | IT provider | List of privileged accounts and their owners | Quarterly |
| 4 | Joiners, movers and leavers process | Practice manager | Completed checklist per person, last four events | Quarterly |
| 5 | Every device known and enrolled | IT provider | Device inventory with owner and last check-in | Quarterly |
| 6 | Disk encryption on every laptop and phone | IT provider | Encryption compliance report | Quarterly |
| 7 | Operating system and application updates inside 14 days | IT provider | Patch compliance report with exceptions named | Quarterly |
| 8 | Supported software only, with a retirement plan | IT provider | Software list with end-of-support dates | Annually |
| 9 | Client data moved by portal, never by attachment | Named partner | Portal usage report plus the client-facing wording | Annually |
| 10 | Email authentication published and enforced | IT provider | Domain record screenshot and enforcement report | Annually |
| 11 | Backups that have actually been restored | IT provider | Dated restore test note naming what was recovered | Quarterly |
| 12 | Retention and deletion applied to client files | Named partner | Retention schedule mapped to each data category | Annually |
| 13 | Supplier list with what each one can reach | Practice manager | Supplier register with data categories | Annually |
| 14 | Security wording in every supplier contract | Named partner | Signed clause set or data processing terms | Per engagement |
| 15 | Subcontractors and offshore teams under the same rules | Named partner | Access list per subcontractor, dated | Quarterly |
| 16 | Bank detail changes verified out of band | Payroll and cashier | Call-back log for the last twelve changes | Quarterly |
| 17 | Annual training that names the practice’s own pretexts | Practice manager | Attendance record and the material used | Annually |
| 18 | A one-page response plan with real phone numbers | Named partner | The plan, dated, plus the last tabletop note | Annually |
| 19 | Logging kept long enough to investigate | IT provider | Retention setting screenshot per platform | Annually |
| 20 | Independent assurance, renewed on a date | Named partner | Certificate, report or audit letter with expiry | Annually |
Cyber Security for Accountancy, Domain 1: Identity and Access
Four controls, and the foundation of cyber security for accountancy. If a practice does nothing else this year, it should do these, because every significant incident in professional services in the last three years started with a credential rather than an exploit.
Control 1: multi-factor authentication on every cloud service, with no exemptions
The cyber security for accountancy requirement is not “on the main system”. It is on every service that holds or touches client data: the tenant, practice management, tax software, accounts production, payroll, the bookkeeping ledger, the client portal, e-signature, the bank feed aggregator, anti-money-laundering screening, the backup console and the password manager itself.
Two deadlines make this the non-negotiable starting point for cyber security for accountancy in 2026. Microsoft made multi-factor authentication mandatory for admin-centre sign-in from 9 February 2026. And the Cyber Essentials scheme treats missing multi-factor authentication on a cloud service as an automatic failure — including where it sits behind a paid licence tier you have not bought.
The evidence artefact is a sign-in or authentication report showing zero exempt accounts. “We turned it on” is not the cyber security for accountancy artefact. The report that shows nobody slipped through the net is.
Control 2: named accounts only, with every shared login on a retirement plan
Shared logins are the single most common cyber security for accountancy finding in professional services. The reception mailbox that four people open. The payroll login that two people use because the licence is expensive. The generic account that submits the VAT returns.
Each one destroys attribution: after an incident you cannot say who did what, which is exactly the question your insurer and the ICO will ask about your cyber security for accountancy controls. Some shared accounts genuinely cannot be removed this quarter, and that is fine — the control is not “zero shared accounts”, it is “every shared account is on a written register with an owner, a reason and a plan”.
Where a shared login has to survive, distribute the authenticator seed key rather than a password, and make sure at least two administrators exist for every account, because nobody can reset their own multi-factor authentication.
Control 3: separate administrator accounts, used only for administration
An administrator account that also reads email is a phishing target holding the keys to everything cyber security for accountancy protects. The control is that privileged work happens in a separate account with no mailbox and no day-to-day browsing.
The ICO fined DPP Law Ltd £60,000 after a brute-force attack on an infrequently used administrator account that had no multi-factor authentication, followed by lateral movement and the theft of 32GB of data — discovered only when the National Crime Agency reported client information on the dark web. The infringements cited were Articles 5(1)(f), 32(1), 32(2) and 33(1). Read that case as a cyber security for accountancy warning about a small professional firm rather than a large corporate, because that is what it is.
Control 4: a joiners, movers and leavers process that actually completes
In a practice, leaving is rarely clean, and that is where cyber security for accountancy quietly fails. People go part-time, move between offices, come back for the January season, or stay on the payroll for a month after their last client meeting. The control is a single checklist per event, covering the tenant, every cloud service, the portal, the phone, the device, and the agent credentials.
The cyber security for accountancy artefact is the last four completed checklists. If they exist and are dated, the control is Current. If the practice manager describes the process from memory, it is Absent.
Cyber Security for Accountancy, Domain 2: Devices and the Practice Estate
Four controls covering the hardware, and the part of cyber security for accountancy an IT provider can usually deliver quickly. This domain is where practices with a surviving on-premises server and a January contractor cohort tend to lose points.
Control 5: every device known, owned and enrolled
Cyber security for accountancy cannot protect an estate nobody has counted. The inventory needs a line per device with a named owner and a last-check-in date, and it needs to include the awkward categories: the partner’s personal laptop used at home, the practice mobiles, the reception desktop nobody has logged into since March, and any contractor machine that touches client data.
Personal devices are a cyber security for accountancy policy decision, not a technical one. Either they are in scope and enrolled, or they are excluded and genuinely cannot reach client data. The failure mode is the middle position, where personal devices are informally tolerated and formally invisible.
Control 6: disk encryption on every laptop and phone
A laptop left on a train is a notifiable personal data breach if the disk is readable and a non-event if it is not. Modern operating systems make this close to free, so the only real cyber security for accountancy work is proving it — a compliance report listing every device and its encryption state, not a policy that says devices should be encrypted.
Include phones. A practice mobile with a mailbox on it holds the same client correspondence as the laptop, and the recovery key or passcode policy is the whole control.
Control 7: operating system and application updates applied inside fourteen days
Fourteen days is the number to write down in any cyber security for accountancy plan, because it is the number external assessors and questionnaires use. The clock starts when the vendor publishes the update, not when your provider notices it. Both the operating system and router or firewall firmware, and the applications, browsers and their extensions, are in scope.
The realistic difficulty for cyber security for accountancy is tax and accounts production software, which is often certified against a specific operating system build and updated on the vendor’s own timetable. Name those exceptions explicitly in the artefact with a compensating control beside each one. In cyber security for accountancy, an honest exception list is a stronger position than a patch report with a silent gap in it.
Control 8: supported software only, with a written retirement plan
Every practice has one thing running on something out of support, and it is always an early cyber security for accountancy question: a payroll module tied to an old Windows build, a document scanner with a driver that never got updated, a legacy tax product kept alive for one client’s historic returns.
The control is a software list with end-of-support dates against every entry and a plan for anything already past. Where retirement genuinely cannot happen this year, the compensating control is isolation: no internet access, no email, no shared credentials, and a documented reason. Our IT security page covers the segregation options for exactly this case.
Cyber Security for Accountancy, Domain 3: Client Data, Portals and Email
Four controls covering the data itself and the two channels it travels down. This is the part of cyber security for accountancy that clients actually notice, because it changes how they interact with the practice.
Control 9: client data moves by portal, never by email attachment
Emailing a set of accounts as a password-protected attachment, with the password sent in the next message, is still normal practice in parts of the profession, and it is the most visible cyber security for accountancy failure a client will ever see. It should not be. The attachment survives in two mailboxes indefinitely, the password protection on most office formats is weak, and the whole exchange is the exact pattern attackers imitate.
For cyber security for accountancy the portal is not just more secure; it is more defensible. It produces an access log, it expires, and it lets you revoke. The artefact for this control is a portal usage report plus the client-facing wording that explains the change, because the control fails the moment one partner keeps emailing files to a client who prefers it.
Control 10: email authentication published and set to enforce
Publish the three domain records that let recipients reject forged mail from your domain, and move the policy from monitoring to enforcement. Half-configured email authentication is the most common cyber security for accountancy oversight: the records exist but the policy is set to take no action, which means a spoofed message claiming to be from your senior partner still lands.
The cyber security for accountancy artefact here is genuinely quick to produce — a screenshot of the published records plus a report showing what was rejected last month. Fifteen minutes of work, and it removes an entire class of impersonation aimed at your clients rather than at you.
Control 11: backups that somebody has actually restored
The Cyber Security Breaches Survey figure of 74% for cloud backups is encouraging until you ask the follow-up question, which is when the practice last restored something. A backup nobody has tested is a belief, not a cyber security for accountancy control.
The requirement is a dated restore test note naming what was recovered, how long it took, and who did it. The National Cyber Security Centre’s guidance on offline backups is worth reading here: at least one copy needs to be beyond the reach of an attacker who has your administrator credentials, which for most practices means immutable retention rather than a second copy in the same tenant.
Do not forget the cloud-hosted practice systems. Many practices assume their software vendor handles this part of cyber security for accountancy. Some do, some do not, and some retain for thirty days. That answer belongs in the supplier register from Control 13.
Control 12: retention and deletion actually applied to client files
A practice that keeps everything forever has quietly increased the size of every future breach. A practice that deletes on instinct breaks its statutory record-keeping duties. The cyber security for accountancy control is a written retention schedule mapped to each data category, and a technical mechanism that applies it.
There are three separate clocks in a UK practice and they do not align, which is exactly why the schedule has to be written down rather than remembered. Our data protection page covers the lawful-basis side of this; the table below covers the periods.
| Record category | Retention period | Source of the obligation |
|---|---|---|
| Customer due diligence and transaction records | 5 years | Money Laundering Regulations 2017, regulation 40 |
| Identity-check records held as an authorised agent | 7 years | Companies House authorised agent requirements |
| Tax correspondence and working papers | Practice policy, commonly 6 to 7 years | Professional body guidance and engagement terms |
| Personal data with no statutory clock | No longer than necessary | UK GDPR storage limitation principle |
| Ex-employee HR and payroll records | Practice policy against statutory minimums | Employment and payroll legislation |
The three-clock problem is the reason this cyber security for accountancy control is Absent in most practices. Somebody has to decide, in writing, that a departed client’s file is kept for the longest applicable clock and then deleted, and somebody has to configure the retention policy that makes it happen without a human remembering.
Cyber Security for Accountancy, Domain 4: Suppliers and Outsourced Work
Four controls covering everyone who is not on your payroll but can reach your client data. Only 15% of UK businesses reviewed the risks posed by their immediate suppliers, which makes supplier work the weakest domain in cyber security for accountancy and across the whole economy.
Control 13: a supplier register that names what each one can reach
The cyber security for accountancy register needs one row per supplier with the data categories they can see, the access mechanism, the contract owner and the review date. For a typical practice that is ten to fifteen rows: the software vendors, the IT provider, the outsourced bookkeeping team, the payroll bureau, the archive and shredding company, and the accountant’s accountant.
The revealing column is “can they see client data”. Practices routinely discover that a niche add-on bought for one workflow has read access to the entire document store, because that is how the integration was configured on day one.
Control 14: security wording in every supplier contract
The cyber security for accountancy wording does not need to be elaborate. Four things carry most of the weight: notify us of a breach affecting our data within a defined period, do not subcontract without telling us, delete or return our data at the end of the contract, and maintain a named baseline of controls.
The artefact is a signed clause set or set of data processing terms per supplier. Note that this control is scored per engagement rather than annually, because a supplier added in June with no wording is a gap regardless of what the register said in January.
Control 15: subcontractors and offshore teams under the same rules
Outsourced bookkeeping and offshore accounts preparation are now normal in UK practices, and they are the highest-risk access in cyber security for accountancy: real people, doing real work, inside your systems, on devices you do not manage.
The control is a dated access list per subcontractor, reviewed quarterly, plus a decision about how they connect. The two defensible models are a managed device you supply, or a virtual desktop with no local download. What is not defensible is a personal machine with a copy of your document store synchronised onto it.
Control 16: bank detail changes verified out of band, every time
This is the cyber security for accountancy control that most often prevents a genuine loss. Any change to bank details — a client’s, a supplier’s, an employee’s on the payroll — is verified by calling a number you already held, never a number in the message requesting the change.
UK Finance recorded invoice and mandate scams at £41.3 million across 2,305 cases in 2025, both the lowest figures ever recorded and down from 4,721 cases in 2020. The average loss was £17,918. But only 48% of those losses were returned to victims, thirteen points below the 61% average across all authorised push payment fraud. The frequency is falling and the recovery rate is poor, which is precisely the risk profile that justifies a call-back rule.
The artefact is a call-back log covering the last twelve changes, showing who called, which number was used, and who confirmed.
Cyber Security for Accountancy, Domain 5: People, Response and Assurance
The final four controls. This is where cyber security for accountancy stops being technical work and becomes practice management.
Control 17: annual training that uses the practice’s own pretexts
Generic awareness training does very little for cyber security for accountancy. Training that shows the actual messages your practice receives does a great deal. Build the material from three things: the HMRC refund pretext, the Companies House filing reminder pretext, and the “please look at the attached invoice” pretext.
Add one accountancy-specific scenario that generic training never covers: the help-desk reset. The National Cyber Security Centre’s guidance following the 2025 retail incidents told organisations to review how their help desk authenticates a caller before resetting a password, especially for privileged accounts. In a practice, the caller who says they are locked out at eleven at night in January is very plausible, and the person answering wants to help.
Control 18: a one-page response plan with real phone numbers
Twenty-five per cent of UK businesses have a formal incident response plan. In cyber security for accountancy, the plan can genuinely be one page: who decides, who calls the insurer, who calls the clients, who calls the regulator, and the phone numbers for all of them. Store it somewhere reachable when the tenant is not.
Two clocks belong on that page. A personal data breach that meets the threshold must be reported to the Information Commissioner’s Office within 72 hours. And from 19 June 2026, section 164A of the Data Protection Act 2018 requires a data protection complaint to be acknowledged within 30 days. Our incident response page covers the retainer options if the practice would rather not hold that capability itself.
Test it once a year around a table for an hour. The artefact is the plan plus a dated note from the last walkthrough.
Control 19: logging kept long enough to investigate
After an incident the first question is always “what did they access, and when”. Answering it requires sign-in and audit logs from the tenant, the practice management system and the portal, retained long enough that the answer still exists.
Default retention on many platforms is thirty or ninety days, and the median time between compromise and discovery is frequently longer than that. The cyber security for accountancy artefact is a screenshot of the retention setting for each platform that matters, which usually reveals at least one system logging nothing at all.
Control 20: independent assurance, renewed on a date
The final control converts nineteen internal cyber security for accountancy beliefs into an external statement. For most practices that means Cyber Essentials, sometimes Cyber Essentials Plus, occasionally an independent penetration test or an ISO certification where a large client demands it.
Certification adoption across UK businesses is only 5%, up from 3%. That means a certificate is still a differentiator in a tender rather than a hygiene factor. The artefact is the certificate, report or audit letter with an expiry date on it, held by a named partner who has a diary reminder ninety days before.
Assurance is also where a good external provider earns their cyber security for accountancy fee. If the practice buys managed IT services, the contract should say which of these twenty artefacts the provider produces and on what cadence, because an unowned control is the same as an absent one.
How the January Peak Bends Cyber Security for Accountancy Firms
Every practice has one month in which its own rules bend, and any cyber security for accountancy checklist that ignores it is describing a firm that does not exist.
The volume is real and it is documented
HM Revenue and Customs received 11,489,825 Self Assessment returns by the 31 January 2026 deadline, against 12,029,168 expected. Of those, 11,173,825 were filed online — 97.25% — and 316,000 on paper. Around one million taxpayers missed the deadline entirely, and 475,772 returns were filed on the final day.
That last figure is the cyber security for accountancy story. Nearly half a million returns went in on one day, which means several hundred thousand client interactions, password resets, file transfers and last-minute queries compressed into twenty-four hours across the profession.
Seasonal staff arrive faster than the joiner process
January contractors, returning part-timers and temporary bookkeepers all need access on day one, which is exactly when the joiners checklist gets skipped. Two practical cyber security for accountancy fixes: pre-build the seasonal accounts in December with an expiry date already set, and give them a distinct naming convention so a quarterly review can spot any that survived into February.
The expiry date is the important half. An account that switches itself off on 15 February needs nobody to remember it.
Out-of-hours work weakens the strongest controls
Work moves home, onto personal networks and sometimes onto personal machines. Multi-factor prompts get approved reflexively at eleven at night. A locked-out colleague is more likely to be helped than verified.
Write the January cyber security for accountancy exceptions down in advance rather than improvising them: what a seasonal account may access, who may authorise a reset out of hours, and which categories of request always wait until the morning regardless of the deadline.
The pretexts get better in January
Attackers read the same calendar you do. A refund notice, a filing-failure warning or an urgent client request all land with far more credibility in the last fortnight of January than in the first week of July. Run the annual training in November or early December, not in the spring, so it is fresh when it matters.
HMRC Agent Multi-Factor Authentication: The 2026 Timetable
This section is the one to put in front of the partner group, because it is the part of cyber security for accountancy with fixed dates attached, and it changes how the practice logs in rather than what it believes.
What is changing and what is not
From 2026, HMRC is applying multi-factor authentication to web sign-in on GOV.UK for both the agent services account and HMRC online services for agents. It does not affect Making Tax Digital for VAT or PAYE submissions made through software, which continue to work as they do now.
The three phases
Agents were given a phased path, set out in Agent Update 141 published on 19 March 2026.
| If the request was made by | Multi-factor authentication switched on | What the practice should do |
|---|---|---|
| 30 June 2026 | 15 July 2026 | Early movers; test the shared-login problem first |
| 31 July 2026 | 19 August 2026 | Second window; complete before the autumn workload |
| No request made | 28 September to 15 October 2026 | Switched on automatically; do not be surprised in January |
How the codes arrive
Codes come by authenticator app, which is HMRC’s preferred method, by text message from 60551, or by automated voice call from 01749 608007. Text and voice codes are six digits and valid for fifteen minutes.
For a practice, the authenticator app is the only sensible answer, because it works without signal in a basement office and it survives a lost phone if the seed key was recorded.
The shared-login problem, and the two-administrator rule
A practice where three people use one agent login has to distribute the authenticator seed key so all three can generate the same codes. That works, but it is a stopgap rather than a durable cyber security for accountancy control, and it is a good prompt to move to named agent access.
The rule to write down now: every account needs at least two administrators, because nobody can reset their own multi-factor authentication. A single-administrator account whose holder loses their phone in January is a genuinely serious operational problem.
Companies House Duties Inside Cyber Security for Accountancy
The Economic Crime and Corporate Transparency Act 2023 turned Companies House from a filing cabinet into a verifying registrar, and it created a new category of regulated data inside accountancy practices.
The identity verification timetable
Identity verification became a legal requirement on 18 November 2025, with a twelve-month transition for existing directors, people with significant control and LLP members that closes on 18 November 2026. Registration for authorised corporate service providers opened on 18 March 2025 at a fee of £55, and verification through an authorised agent or GOV.UK One Login has been available since 8 April 2025.
Agents filing on behalf of clients will need authorised agent registration from no earlier than November 2026, and identity verification for filers from no earlier than November 2027.
What authorised agent status obliges you to hold
An authorised corporate service provider must be supervised by one of the twenty-five UK anti-money-laundering supervisory bodies, must keep identity-check records for seven years, and must notify Companies House within fourteen days of any change — including the loss of that supervision.
Read that as a cyber security for accountancy requirement rather than a filing requirement. Seven years of identity evidence, held in a practice, is a high-value archive. It belongs in the retention schedule at Control 12, in the supplier register at Control 13 if a third party stores it, and in the logging scope at Control 19.
The credential is now worth more than it was
An agent credential that can verify an identity or change a company’s registered details is worth considerably more to a fraudster than one that can only file accounts. That is the argument for pulling the first four cyber security for accountancy controls forward rather than treating them as a project for next year.
The professional bodies still do not mandate certification
Neither ICAEW, ACCA nor AAT mandates Cyber Essentials. Any blog that tells you otherwise is repeating provider marketing. What they do require is competence, confidentiality and adequate professional indemnity cover — ICAEW’s regulations, effective from 1 September 2024, set a minimum limit of indemnity of £2 million with a participating insurer. Certification is a commercial choice that makes those obligations easier to evidence, not a regulatory one.
What Cyber Security for Accountancy Costs
The honest answer is that cyber security for accountancy is mostly configuration rather than purchase. The spending is concentrated in three places: assurance, cover and time.
What cyber security for accountancy certification costs
IASME publishes its Cyber Essentials self-assessment fees by size band. They are annual, and they are per legal entity, so a practice with a separate corporate finance company or payroll bureau pays for each.
| Size band | Headcount | Fee (ex VAT, 12 months) | Cost per head at the top of the band |
|---|---|---|---|
| Micro | 1 to 9 | £320 | £35.56 |
| Small | 10 to 49 | £440 | £8.98 |
| Medium | 50 to 249 | £500 | £2.01 |
| Large | 250 and above | £600 | £2.40 at 250 |
The audited version, Cyber Essentials Plus, starts from around £1,400 ex VAT and must be taken within three months of the self-assessment certificate.
Insurance is where cyber security for accountancy pays for itself
Cyber liability cover is the second line item, and the underwriting questions map almost exactly onto this control set — most cybersecurity proposal forms ask about multi-factor authentication, backups, patching and training before they ask about anything else. A practice that can answer those four from evidence rather than memory usually gets a faster decision.
Certification also carries £25,000 of cyber liability cover for UK businesses with turnover under £20 million, which covers a large share of the profession by firm count.
Time is the real cost of cyber security for accountancy
Realistically, a practice of forty spends the equivalent of a fortnight of one competent person’s time moving its cyber security for accountancy score from typical to good, most of it in Domain 1 and Domain 4. After that the ongoing cost of cyber security for accountancy is the quarterly review, which is an hour with the practice manager and the IT provider.
| Cost area | Usually already paid for? | Where the money actually goes |
|---|---|---|
| Multi-factor authentication | Yes, in most business licences | Configuration time, not licence spend |
| Disk encryption | Yes, built into modern operating systems | Proving it centrally across every device |
| Device enrolment | Sometimes; depends on the licence tier | Per-user licence plus a one-off enrolment project |
| Immutable backup | Rarely for cloud practice systems | A dedicated backup product and its storage |
| Training | No | A platform subscription or a facilitated session |
| Certification | No | The published IASME fee, plus preparation time |
Cyber Security for Accountancy: A 42-Person Worked Example
Abstract control sets are easy to agree with and hard to act on. Here is what cyber security for accountancy looks like against a specific firm, using only arithmetic on the counts stated.
The estate, counted honestly
The practice has 42 staff across three offices: 31 fee earners and 11 support. Counting devices gives 42 staff laptops, 5 shared meeting-room and reception PCs, 1 surviving on-premises file and print server, 9 practice mobiles and 7 contractor laptops brought in for January. That is 64 in-scope devices.
As proportions of those 64: staff laptops 65.6%, practice mobiles 14.1%, January contractor laptops 10.9%, shared PCs 7.8% and the server 1.6%. The cyber security for accountancy remediation concentrates in the 5 shared PCs and the 7 contractor laptops — 12 of 64, or 18.8% — because those are the devices with no single owner.
The identities, counted the same way
Identities are 42 named staff accounts, 14 shared or generic mailboxes across the three offices, and 5 administrator accounts: 61 identities in total. Of those, 19 — the 14 shared plus the 5 administrator accounts — are shared or privileged. That is 31.1% of all identities, and it is where Controls 2 and 3 do their work.
The cloud services, counted before anyone argues about them
Thirteen services hold or touch client data: the tenant, practice management, tax software, accounts production, payroll, the bookkeeping ledger, the client portal, e-signature, the bank feed aggregator, anti-money-laundering screening, time and fees, backup, and the password manager. All thirteen need multi-factor authentication under Control 1, and all thirteen belong in the supplier register under Control 13.
The starting cyber security for accountancy score, and where it lands
A practice of this shape typically opens its cyber security for accountancy score at eight or nine Current out of twenty. Multi-factor authentication is on the tenant but not on three of the smaller services. Backups exist but the last restore test is undated. The supplier register does not exist at all.
At 42 staff the practice sits in the small band, so certification costs £440 ex VAT, and with an audited Cyber Essentials Plus assessment at around £1,400 the assurance line is £1,840, or £43.81 per head. That is the whole external cyber security for accountancy spend for Control 20.
Mapping Cyber Security for Accountancy to Cyber Essentials, MLR 2017 and UK GDPR
Partners reasonably ask why cyber security for accountancy needs a bespoke list when three external frameworks already exist. The answer is that none of the three covers a practice completely, and this list is the intersection plus the bits only accountancy has.
| Domain | Cyber Essentials | MLR 2017 and agent duties | UK GDPR |
|---|---|---|---|
| 1. Identity and access | Covered; missing multi-factor authentication is an auto-fail | Indirect, via record integrity | Article 32 security of processing |
| 2. Devices and estate | Covered in full | Not addressed | Article 32 security of processing |
| 3. Client data and channels | Partly; retention is out of scope | Regulation 40 five-year records | Storage limitation and Article 5(1)(f) |
| 4. Suppliers and outsourcing | Not addressed directly | Reliance and outsourcing provisions | Article 28 processor obligations |
| 5. People, response, assurance | Partly; training is not tested | Training and internal controls duties | Article 33 breach notification in 72 hours |
Where Cyber Essentials stops
The scheme is a technical baseline. It says nothing about retention schedules, supplier registers, subcontractor access lists or bank-detail call-backs, all of which are the cyber security for accountancy controls that stop the losses a practice actually suffers.
Where the money-laundering regulations stop
Regulation 40 tells you how long to keep records. It does not tell you to encrypt the laptop they sit on, or to log who opened them.
Where UK GDPR stops
Article 32 requires appropriate technical and organisational measures, which is deliberately open-ended. It gives you the obligation and leaves you to invent the cyber security for accountancy control set. This list is one defensible answer to that question, expressed in artefacts you can actually produce.
The overlap is the case for one cyber security for accountancy programme
Fourteen of the twenty cyber security for accountancy controls satisfy more than one framework at once. That is the practical case for doing them in one programme rather than three: the certification project, the anti-money-laundering file review and the data protection audit are all asking for versions of the same twenty artefacts.
A 90-Day Plan for Cyber Security for Accountancy Firms
Twenty controls is a year of drift if nobody sequences them, which is how most cyber security for accountancy programmes stall. Ninety days is enough to make all twenty Current in a practice under fifty people, provided the order is right.
Days 1 to 30: the nine controls that need no budget
Start with everything that is configuration and paperwork rather than purchase. That is Controls 1, 2, 3, 4, 6, 10, 13, 16 and 18: multi-factor authentication everywhere, the identity register, separate administrator accounts, the joiners and leavers checklist, encryption evidence, email authentication, the supplier register, the bank-detail call-back rule and the one-page response plan.
Nine of twenty Current by day 30 is 45%, and it is achievable because none of it requires a procurement decision. It is also the half that removes the most risk, because it closes the credential path.
Days 31 to 60: the seven that need a supplier conversation
Controls 5, 7, 8, 11, 14, 15 and 19 all involve someone outside the partner group: the IT provider for device enrolment, patching, the software retirement list, the restore test and logging retention; the legal or contract owner for supplier wording; and each subcontractor for the access list.
That takes the running total to sixteen of twenty, or 80%. Expect this month to be the slow one, because it moves at the speed of other people’s diaries.
Days 61 to 90: the four that change how the practice works
Controls 9, 12, 17 and 20 are the ones clients and staff notice: the portal-only rule, the retention schedule, the training session and the assurance decision. They come last deliberately, because each needs a partner-level decision and a communication rather than a setting.
By day 90 all twenty should be Current: 100%, with a review date already in the calendar for each one.
Do not start cyber security for accountancy work in December
The single most common scheduling error is launching a cyber security for accountancy programme in the run-up to the January deadline. Nothing will happen, the momentum will be lost, and the practice will conclude that the checklist did not work. February to April, or June to September, are the windows where a partner group actually has attention to spare.
| Window | Controls | Who drives it | What blocks it |
|---|---|---|---|
| Days 1 to 30 | 1, 2, 3, 4, 6, 10, 13, 16, 18 | Practice manager | Shared logins nobody wants to give up |
| Days 31 to 60 | 5, 7, 8, 11, 14, 15, 19 | IT provider and contract owner | Supplier response times |
| Days 61 to 90 | 9, 12, 17, 20 | Named partner | Partner consensus and client communication |
| Quarterly thereafter | All controls marked quarterly | Practice manager | Nothing, if the review is diarised |
Six Cyber Security for Accountancy Mistakes Practices Make
These are the patterns that turn good cyber security for accountancy into a stale checklist, drawn from what actually goes wrong rather than from a threat model.
Treating cyber security for accountancy as an IT deliverable
Half of cyber security for accountancy belongs to the practice manager or a named partner, not to a technician. Handing all twenty to the IT provider guarantees that the supplier register, the retention schedule, the call-back rule and the training never get done, because the provider has no authority over any of them.
Confusing a policy with an artefact
A document that says devices will be encrypted is not evidence that they are. The artefact is always the report, the list, the log or the dated note — the thing a sceptical reader could not have written from imagination.
Scoring on belief rather than on dates
“We do that” is the answer that keeps a cyber security for accountancy control Absent for years. Every artefact needs a date on it, and the date is what turns twenty opinions into a score anyone can audit.
Buying a tool to fix a process problem
Shared logins, unverified bank changes and unmanaged subcontractor access are all process failures. No product fixes them. Conversely, patch compliance reporting and encryption evidence genuinely do need tooling, and trying to do those by hand is equally wasteful.
Ignoring the smallest suppliers
The niche add-on nobody thinks about is usually the one with the broadest permissions, because it was installed by a partner in a hurry and granted whatever it asked for. The supplier register exists to surface exactly that.
Assuming the sector siblings do not apply
A practice is not a hotel and not a property manager, but the failure modes rhyme. Our hotel cyber security checklist uses a different scoring model on a different estate, and reading it alongside this one is a quick way to see which of your controls are sector-specific and which are simply good practice. The same applies to our wider compliance work.
Frequently Asked Questions About Cyber Security for Accountancy
How many of the twenty controls does a small practice really need?
All twenty, but not at once. A four-person practice can make Controls 1 to 4, 6, 10, 16 and 18 Current in a fortnight, and those eight carry most of the risk reduction. The remaining twelve are still required; they simply take longer because they involve suppliers and partner decisions.
Is Cyber Essentials enough on its own?
No, and it does not claim to be. It is an excellent technical baseline and a useful commercial signal, but it says nothing about retention schedules, supplier registers, subcontractor access or bank-detail verification. Roughly the first two cyber security for accountancy domains and part of the third map onto it; Domains 4 and 5 largely do not.
Do ICAEW, ACCA or AAT require certification?
No. None of the three mandates Cyber Essentials. They require competence, confidentiality and adequate professional indemnity insurance, and certification is a convenient way to evidence part of that. Any claim that certification is mandatory traces back to marketing rather than to a rulebook.
What is the single most valuable cyber security for accountancy control?
Control 1, multi-factor authentication on every cloud service with no exemptions. Every other cyber security for accountancy control assumes that an attacker cannot simply log in as one of your people. Control 16, the bank-detail call-back, is the one most likely to prevent a direct cash loss.
How long should the quarterly review take?
An hour, once the artefacts exist. The practice manager and the IT provider walk the twenty rows, check the dates, and mark anything that has slipped to Stale. The first review is the long one because it doubles as the baseline.
Who should own the cyber security for accountancy score in a partnership?
One named partner, not a committee and not “the partners”. The practical model is that a named partner owns the score and reports it at a partners’ meeting once a quarter, while the practice manager owns the day-to-day evidence and the IT provider produces the technical reports.
What changes when we take on authorised agent status?
Three things. You start holding identity evidence, which needs a seven-year retention rule and its own access controls. Your agent credentials become more valuable to a fraudster. And you acquire a fourteen-day notification duty to Companies House, which belongs on the one-page response plan alongside the 72-hour reporting clock.
Does cyber security for accountancy help with cyber insurance?
Directly. Underwriters ask about multi-factor authentication, backups, patching and training first, which are Controls 1, 11, 7 and 17. Being able to answer from a dated artefact rather than from memory is usually the difference between a fast quote and a long questionnaire, and certification carries £25,000 of cyber liability cover for UK businesses under £20 million turnover.
References
Cyber Security Breaches Survey 2025/2026
Cyber Security Breaches Survey collection
NCSC: Small businesses to receive cyber security boost with new toolkit from experts
NCSC: Small Organisations Guide to Cyber Security
NCSC: Advice and guidance for small to medium sized organisations
NCSC Small Business Guide: Response and Recovery
NCSC: Incidents impacting retailers
NCSC: Offline backups in an online world
NCSC: It’s time for all small businesses to act
NCSC: 10 Steps to Cyber Security
NCSC: Password administration for system owners
NCSC: Multi-factor authentication for online services
NCSC: Device Security Guidance
NCSC: Managing deployed devices
NCSC: Vulnerability Management
NCSC: Phishing attacks – defending your organisation
NCSC: Supply chain security guidance
NCSC Cyber Security Board Toolkit
NCSC: Cyber insurance guidance
NCSC Cyber Essentials overview
Cyber Governance Code of Practice
ATT: Multi-factor authentication – how can agents prepare?
Companies House: Changes to UK company law
Economic Crime and Corporate Transparency Act 2023 factsheets
Economic Crime and Corporate Transparency Act 2023
Money Laundering Regulations 2017, regulation 40
GOV.UK: Money laundering regulations – your responsibilities
GOV.UK: Anti-money laundering registration
Data (Use and Access) Act 2025
ICO: Report a personal data breach
ICAEW: Cyber security resources
ICAEW: Professional indemnity insurance
ICAEW: Phishing most prevalent cyber attack, confirms UK survey
ICAEW: Accountancy practices face daily cyber threats
SecurityBrief UK: Cyber-attacks top risk for professional firms in 2026
House of Commons Library: Bank fraud and scams
FBI Internet Crime Report 2025
HMRC: Use Making Tax Digital for Income Tax
GOV.UK: Report suspicious emails, websites and phishing
Microsoft: Mandatory multifactor authentication for Microsoft Entra
Microsoft Entra Conditional Access overview
Microsoft: Passkeys and FIDO2 in Microsoft Entra ID
Microsoft Intune documentation
Microsoft Purview retention policies