Cyber security for accountancy firms is not a technology problem that happens to land in a practice. It is a client-confidentiality problem, an anti-money-laundering problem, a professional-indemnity problem and a filing-deadline problem, all of which happen to be solved with technology. That distinction matters, because a generic twenty-point security checklist written for “UK SMEs” will tell you to patch your firewalls and say nothing about who can log into your agent services account in the last week of January.

This cyber security for accountancy checklist is written the other way round. Every one of the twenty controls below starts from something a practice actually holds or does — a client’s UTR, a bank feed, a portal invitation, a subcontracted bookkeeping file, a laptop that goes home in January — and then names the control that protects it, the person who owns it and the single artefact you would hand to a client, an insurer or the Information Commissioner’s Office to prove it exists. If you have already read our guide to IT support for accountancy firms, this is the control set that guide assumes underneath it.

Two of our other pieces cover adjacent ground and are worth reading alongside this one: the Microsoft 365 security checklist for accountancy firms covers one platform in depth, and Cyber Essentials for accountancy firms covers one certificate in depth. This guide to cyber security for accountancy is deliberately vendor-neutral and certificate-neutral: it is the twenty things that have to be true regardless of whose software you bought, and regardless of whether you certify.

Cyber Security for Accountancy Starts With What a Practice Holds

cyber security for accountancy firms 20 controls b3 monitor neck foot

Before any cyber security for accountancy checklist makes sense, it helps to write down the inventory honestly. Most partners underestimate it, because the data arrived gradually and none of it looks dramatic on its own.

The client data set is unusually complete

An accountancy practice holds a more complete picture of a business than almost any other supplier that business uses. Statutory accounts show what it owns. Management accounts show what it earns each month. Payroll shows who works there and what they are paid. VAT returns show the trading rhythm. The bank feed shows who it pays and when.

Add personal tax and you also hold directors’ home addresses, dates of birth, National Insurance numbers, dividend income, rental income and, frequently, the same details for their spouses and adult children. That combination is why cyber security for accountancy matters more than headcount suggests: financially motivated attackers treat a practice as a shortcut rather than a target of last resort.

The identity data set is a regulated set in its own right

Since identity verification became a legal requirement at Companies House on 18 November 2025, with the twelve-month transition for existing directors, people with significant control and LLP members closing on 18 November 2026, practices acting as Companies House authorised agents hold verified identity evidence too. An authorised corporate service provider must keep those identity-check records for seven years and must notify Companies House within fourteen days of any change, including loss of supervision.

Separately, regulation 40 of the Money Laundering Regulations 2017 requires customer due diligence and transaction records to be kept for five years. So cyber security for accountancy is not merely a question of client data. A practice holds a regulated evidence archive that it is legally obliged to be able to produce.

The credential set is the part nobody inventories

The third category never appears on an asset register, and it is where cyber security for accountancy is usually weakest: credentials. An agent services account. An HMRC online services for agents account. Companies House filing credentials. Bank feed authorisations for dozens of clients. Portal administrator rights. Payroll bureau logins. Every one of those is a key to somebody else’s money or filings, and most practices have never written down how many exist or who holds them.

What the practice holdsWhy an attacker wants itWhere it usually lives
Statutory and management accountsShows which clients hold cash and whenAccounts production software, document management
Payroll recordsBank details of every employee of every clientPayroll software, email attachments
Personal tax dataIdentity theft and refund fraudTax software, portal, mailboxes
Supplier and customer ledgersTarget list for payment redirectionBookkeeping ledger, bank feeds
Identity verification evidenceHigh-quality documents for impersonationPractice management, secure storage
Agent and filing credentialsDirect access to client tax positionsBrowsers, password managers, sticky notes
Engagement letters and fee dataConvincing pretext for invoice fraudPractice management, mailboxes

The estate is smaller than you think and messier than you hope

Most UK practices under fifty people run a genuinely small estate, which is why cyber security for accountancy is a scoping exercise rather than an engineering one: laptops, phones, a couple of shared desktops, perhaps one surviving on-premises server, and then ten to fifteen cloud services. The messiness that defeats cyber security for accountancy is not scale. It is that the cloud services were bought at different times by different partners, each has its own login model, and only some of them were ever configured deliberately.

The 2026 Threat Picture Behind Cyber Security for Accountancy

cyber security for accountancy firms 20 controls c2 pencil hexagonal shaft

The numbers below are the ones worth quoting to a partner group that has never budgeted for cyber security for accountancy, because they come from government and insurer research rather than from vendor marketing.

Why cyber security for accountancy scales with headcount

The Cyber Security Breaches Survey 2025/2026, published by the Department for Science, Innovation and Technology on 30 April 2026, found that 43% of UK businesses experienced a cyber breach or attack in the previous twelve months. Broken down by size, the figure was 42% for micro businesses, 46% for small businesses, 65% for medium businesses and 69% for large businesses.

That gradient is the single most useful planning fact in cyber security for accountancy. A four-partner practice and a sixty-person firm are not facing the same probability, and the control set below is deliberately sequenced so that a small practice can complete the first nine controls without a project.

Businesses reporting a breach or attack in the previous 12 months, by size (Cyber Security Breaches Survey 2025/2026)
Micro (1-9 staff) 42%
Small (10-49 staff) 46%
Medium (50-249 staff) 65%
Large (250+ staff) 69%

Phishing is the whole story, not part of it

The same survey put phishing at 38% of businesses, far ahead of every other attack type, while ransomware was reported by only 1%. Ransomware gets the headlines and the board papers; phishing is what actually arrives. A cyber security for accountancy checklist that spends nineteen controls on ransomware and one on email has the weighting backwards.

For a practice, the phishing pretexts that defeat cyber security for accountancy write themselves. An HMRC refund notice in the week the tax return went in. A Companies House filing reminder in the month before the accounts are due. A client asking you to look at an attached invoice. Our companion piece on invoice fraud in accountancy firms covers the payment-redirection variant in detail.

The profession already knows, which is the encouraging part

The survey also found that 85% of businesses in the professional, scientific or technical sector rated cyber security as a high priority — comfortably above the all-business average — and that 54% had sought external information or guidance. Board-level ownership in that sector, the one that contains cyber security for accountancy, ran at 41% against 31% across all businesses.

An insurer survey published on 24 April 2026 found professional firms ranking cyber attacks as their leading risk at 65%, ahead of economic pressures at 18%, professional negligence claims at 9% and regulatory change at 8%. The awareness gap in cyber security for accountancy has closed. The evidence gap has not.

Leading risk named by UK professional firms, April 2026 insurer survey
Cyber attacks 65%
Economic pressures 18%
Professional negligence claims 9%
Regulatory change 8%

Two-factor adoption is still under half

Across all UK businesses, the survey found two-factor authentication in use at 47%, cloud backups at 74%, a formal incident response plan at 25%, and immediate supplier risk review at 15%. Cyber Essentials certification stood at 5%, up from 3%.

Read those four numbers together and the shape of a realistic cyber security for accountancy programme appears: most practices have backups, about half have some multi-factor authentication, very few have written down what happens next, and almost none have looked at their suppliers.

How to Score This Cyber Security for Accountancy Checklist

cyber security for accountancy firms 20 controls d desk lamp domed shade

Most security checklists are scored on whether a control is “in place”. That wording is useless in a practice, because everyone believes their cyber security for accountancy controls are in place until somebody asks for the evidence.

Score the artefact, not the intention

This cyber security for accountancy checklist is therefore scored on evidence. For each of the twenty controls you record one of three states, and the only thing that decides the state is whether a named artefact exists and is current.

Current means the artefact exists, someone owns it, and it carries a date inside its review period. Stale means the artefact exists but the date has passed — a policy last reviewed in 2023, an access list built before two people left, a restore test from the year before last. Absent means there is no artefact, whatever the practice believes about the underlying control.

StateTestWhat it means commercially
CurrentNamed artefact exists and is dated inside its review periodAnswerable in a client questionnaire without a project
StaleArtefact exists but the review date has passedAnswerable, but a determined reviewer will find the gap
AbsentNo artefact, regardless of what the practice believesNot answerable; assume the honest answer is no

Why cyber security for accountancy fits how a practice already works

Every practice already runs an evidence model like the one cyber security for accountancy needs. A file review does not ask whether the work was done well in principle; it asks to see the working papers. Anti-money-laundering supervision does not ask whether you know your clients; it asks for the customer due diligence records. Cyber security for accountancy is the same discipline pointed at a different subject.

The practical benefit is that the cyber security for accountancy score is not a matter of opinion. Twenty controls, three states, one number: how many of the twenty are Current. A practice that scores eleven has a specific list of nine things to do, each with a named artefact at the end of it.

Set the review periods once and then leave them alone

Three review periods cover all twenty cyber security for accountancy controls. Quarterly, for anything that drifts with joiners and leavers. Annually, for policies, training and supplier reviews. Per engagement, for the handful of controls that attach to a client rather than to the practice.

Give every control an owner who is a person, not a department

“IT” is not an owner of cyber security for accountancy. In a practice of forty, the realistic owners are a named partner, the practice manager, the person who runs payroll, and whoever holds the relationship with your external IT provider. If a cyber security for accountancy control cannot be given a human owner, it will be Absent at the next review.

#ControlTypical ownerEvidence artefactReview
1Multi-factor authentication on every cloud servicePractice managerSign-in report showing zero exempt accountsQuarterly
2Named accounts only, with shared logins retiredPractice managerIdentity register listing every shared account and its planQuarterly
3Separate administrator accountsIT providerList of privileged accounts and their ownersQuarterly
4Joiners, movers and leavers processPractice managerCompleted checklist per person, last four eventsQuarterly
5Every device known and enrolledIT providerDevice inventory with owner and last check-inQuarterly
6Disk encryption on every laptop and phoneIT providerEncryption compliance reportQuarterly
7Operating system and application updates inside 14 daysIT providerPatch compliance report with exceptions namedQuarterly
8Supported software only, with a retirement planIT providerSoftware list with end-of-support datesAnnually
9Client data moved by portal, never by attachmentNamed partnerPortal usage report plus the client-facing wordingAnnually
10Email authentication published and enforcedIT providerDomain record screenshot and enforcement reportAnnually
11Backups that have actually been restoredIT providerDated restore test note naming what was recoveredQuarterly
12Retention and deletion applied to client filesNamed partnerRetention schedule mapped to each data categoryAnnually
13Supplier list with what each one can reachPractice managerSupplier register with data categoriesAnnually
14Security wording in every supplier contractNamed partnerSigned clause set or data processing termsPer engagement
15Subcontractors and offshore teams under the same rulesNamed partnerAccess list per subcontractor, datedQuarterly
16Bank detail changes verified out of bandPayroll and cashierCall-back log for the last twelve changesQuarterly
17Annual training that names the practice’s own pretextsPractice managerAttendance record and the material usedAnnually
18A one-page response plan with real phone numbersNamed partnerThe plan, dated, plus the last tabletop noteAnnually
19Logging kept long enough to investigateIT providerRetention setting screenshot per platformAnnually
20Independent assurance, renewed on a dateNamed partnerCertificate, report or audit letter with expiryAnnually

Cyber Security for Accountancy, Domain 1: Identity and Access

cyber security for accountancy firms 20 controls e4 strongroom safe lever

Four controls, and the foundation of cyber security for accountancy. If a practice does nothing else this year, it should do these, because every significant incident in professional services in the last three years started with a credential rather than an exploit.

Control 1: multi-factor authentication on every cloud service, with no exemptions

The cyber security for accountancy requirement is not “on the main system”. It is on every service that holds or touches client data: the tenant, practice management, tax software, accounts production, payroll, the bookkeeping ledger, the client portal, e-signature, the bank feed aggregator, anti-money-laundering screening, the backup console and the password manager itself.

Two deadlines make this the non-negotiable starting point for cyber security for accountancy in 2026. Microsoft made multi-factor authentication mandatory for admin-centre sign-in from 9 February 2026. And the Cyber Essentials scheme treats missing multi-factor authentication on a cloud service as an automatic failure — including where it sits behind a paid licence tier you have not bought.

The evidence artefact is a sign-in or authentication report showing zero exempt accounts. “We turned it on” is not the cyber security for accountancy artefact. The report that shows nobody slipped through the net is.

Control 2: named accounts only, with every shared login on a retirement plan

Shared logins are the single most common cyber security for accountancy finding in professional services. The reception mailbox that four people open. The payroll login that two people use because the licence is expensive. The generic account that submits the VAT returns.

Each one destroys attribution: after an incident you cannot say who did what, which is exactly the question your insurer and the ICO will ask about your cyber security for accountancy controls. Some shared accounts genuinely cannot be removed this quarter, and that is fine — the control is not “zero shared accounts”, it is “every shared account is on a written register with an owner, a reason and a plan”.

Where a shared login has to survive, distribute the authenticator seed key rather than a password, and make sure at least two administrators exist for every account, because nobody can reset their own multi-factor authentication.

Control 3: separate administrator accounts, used only for administration

An administrator account that also reads email is a phishing target holding the keys to everything cyber security for accountancy protects. The control is that privileged work happens in a separate account with no mailbox and no day-to-day browsing.

The ICO fined DPP Law Ltd £60,000 after a brute-force attack on an infrequently used administrator account that had no multi-factor authentication, followed by lateral movement and the theft of 32GB of data — discovered only when the National Crime Agency reported client information on the dark web. The infringements cited were Articles 5(1)(f), 32(1), 32(2) and 33(1). Read that case as a cyber security for accountancy warning about a small professional firm rather than a large corporate, because that is what it is.

Control 4: a joiners, movers and leavers process that actually completes

In a practice, leaving is rarely clean, and that is where cyber security for accountancy quietly fails. People go part-time, move between offices, come back for the January season, or stay on the payroll for a month after their last client meeting. The control is a single checklist per event, covering the tenant, every cloud service, the portal, the phone, the device, and the agent credentials.

The cyber security for accountancy artefact is the last four completed checklists. If they exist and are dated, the control is Current. If the practice manager describes the process from memory, it is Absent.

Cyber Security for Accountancy, Domain 2: Devices and the Practice Estate

cyber security for accountancy firms 20 controls f ink bottle flat cap

Four controls covering the hardware, and the part of cyber security for accountancy an IT provider can usually deliver quickly. This domain is where practices with a surviving on-premises server and a January contractor cohort tend to lose points.

Control 5: every device known, owned and enrolled

Cyber security for accountancy cannot protect an estate nobody has counted. The inventory needs a line per device with a named owner and a last-check-in date, and it needs to include the awkward categories: the partner’s personal laptop used at home, the practice mobiles, the reception desktop nobody has logged into since March, and any contractor machine that touches client data.

Personal devices are a cyber security for accountancy policy decision, not a technical one. Either they are in scope and enrolled, or they are excluded and genuinely cannot reach client data. The failure mode is the middle position, where personal devices are informally tolerated and formally invisible.

Control 6: disk encryption on every laptop and phone

A laptop left on a train is a notifiable personal data breach if the disk is readable and a non-event if it is not. Modern operating systems make this close to free, so the only real cyber security for accountancy work is proving it — a compliance report listing every device and its encryption state, not a policy that says devices should be encrypted.

Include phones. A practice mobile with a mailbox on it holds the same client correspondence as the laptop, and the recovery key or passcode policy is the whole control.

Control 7: operating system and application updates applied inside fourteen days

Fourteen days is the number to write down in any cyber security for accountancy plan, because it is the number external assessors and questionnaires use. The clock starts when the vendor publishes the update, not when your provider notices it. Both the operating system and router or firewall firmware, and the applications, browsers and their extensions, are in scope.

The realistic difficulty for cyber security for accountancy is tax and accounts production software, which is often certified against a specific operating system build and updated on the vendor’s own timetable. Name those exceptions explicitly in the artefact with a compensating control beside each one. In cyber security for accountancy, an honest exception list is a stronger position than a patch report with a silent gap in it.

Control 8: supported software only, with a written retirement plan

Every practice has one thing running on something out of support, and it is always an early cyber security for accountancy question: a payroll module tied to an old Windows build, a document scanner with a driver that never got updated, a legacy tax product kept alive for one client’s historic returns.

The control is a software list with end-of-support dates against every entry and a plan for anything already past. Where retirement genuinely cannot happen this year, the compensating control is isolation: no internet access, no email, no shared credentials, and a documented reason. Our IT security page covers the segregation options for exactly this case.

Cyber Security for Accountancy, Domain 3: Client Data, Portals and Email

Four controls covering the data itself and the two channels it travels down. This is the part of cyber security for accountancy that clients actually notice, because it changes how they interact with the practice.

Control 9: client data moves by portal, never by email attachment

Emailing a set of accounts as a password-protected attachment, with the password sent in the next message, is still normal practice in parts of the profession, and it is the most visible cyber security for accountancy failure a client will ever see. It should not be. The attachment survives in two mailboxes indefinitely, the password protection on most office formats is weak, and the whole exchange is the exact pattern attackers imitate.

For cyber security for accountancy the portal is not just more secure; it is more defensible. It produces an access log, it expires, and it lets you revoke. The artefact for this control is a portal usage report plus the client-facing wording that explains the change, because the control fails the moment one partner keeps emailing files to a client who prefers it.

Control 10: email authentication published and set to enforce

Publish the three domain records that let recipients reject forged mail from your domain, and move the policy from monitoring to enforcement. Half-configured email authentication is the most common cyber security for accountancy oversight: the records exist but the policy is set to take no action, which means a spoofed message claiming to be from your senior partner still lands.

The cyber security for accountancy artefact here is genuinely quick to produce — a screenshot of the published records plus a report showing what was rejected last month. Fifteen minutes of work, and it removes an entire class of impersonation aimed at your clients rather than at you.

Control 11: backups that somebody has actually restored

The Cyber Security Breaches Survey figure of 74% for cloud backups is encouraging until you ask the follow-up question, which is when the practice last restored something. A backup nobody has tested is a belief, not a cyber security for accountancy control.

The requirement is a dated restore test note naming what was recovered, how long it took, and who did it. The National Cyber Security Centre’s guidance on offline backups is worth reading here: at least one copy needs to be beyond the reach of an attacker who has your administrator credentials, which for most practices means immutable retention rather than a second copy in the same tenant.

Do not forget the cloud-hosted practice systems. Many practices assume their software vendor handles this part of cyber security for accountancy. Some do, some do not, and some retain for thirty days. That answer belongs in the supplier register from Control 13.

Control 12: retention and deletion actually applied to client files

A practice that keeps everything forever has quietly increased the size of every future breach. A practice that deletes on instinct breaks its statutory record-keeping duties. The cyber security for accountancy control is a written retention schedule mapped to each data category, and a technical mechanism that applies it.

There are three separate clocks in a UK practice and they do not align, which is exactly why the schedule has to be written down rather than remembered. Our data protection page covers the lawful-basis side of this; the table below covers the periods.

Record categoryRetention periodSource of the obligation
Customer due diligence and transaction records5 yearsMoney Laundering Regulations 2017, regulation 40
Identity-check records held as an authorised agent7 yearsCompanies House authorised agent requirements
Tax correspondence and working papersPractice policy, commonly 6 to 7 yearsProfessional body guidance and engagement terms
Personal data with no statutory clockNo longer than necessaryUK GDPR storage limitation principle
Ex-employee HR and payroll recordsPractice policy against statutory minimumsEmployment and payroll legislation

The three-clock problem is the reason this cyber security for accountancy control is Absent in most practices. Somebody has to decide, in writing, that a departed client’s file is kept for the longest applicable clock and then deleted, and somebody has to configure the retention policy that makes it happen without a human remembering.

Cyber Security for Accountancy, Domain 4: Suppliers and Outsourced Work

Four controls covering everyone who is not on your payroll but can reach your client data. Only 15% of UK businesses reviewed the risks posed by their immediate suppliers, which makes supplier work the weakest domain in cyber security for accountancy and across the whole economy.

Control 13: a supplier register that names what each one can reach

The cyber security for accountancy register needs one row per supplier with the data categories they can see, the access mechanism, the contract owner and the review date. For a typical practice that is ten to fifteen rows: the software vendors, the IT provider, the outsourced bookkeeping team, the payroll bureau, the archive and shredding company, and the accountant’s accountant.

The revealing column is “can they see client data”. Practices routinely discover that a niche add-on bought for one workflow has read access to the entire document store, because that is how the integration was configured on day one.

Control 14: security wording in every supplier contract

The cyber security for accountancy wording does not need to be elaborate. Four things carry most of the weight: notify us of a breach affecting our data within a defined period, do not subcontract without telling us, delete or return our data at the end of the contract, and maintain a named baseline of controls.

The artefact is a signed clause set or set of data processing terms per supplier. Note that this control is scored per engagement rather than annually, because a supplier added in June with no wording is a gap regardless of what the register said in January.

Control 15: subcontractors and offshore teams under the same rules

Outsourced bookkeeping and offshore accounts preparation are now normal in UK practices, and they are the highest-risk access in cyber security for accountancy: real people, doing real work, inside your systems, on devices you do not manage.

The control is a dated access list per subcontractor, reviewed quarterly, plus a decision about how they connect. The two defensible models are a managed device you supply, or a virtual desktop with no local download. What is not defensible is a personal machine with a copy of your document store synchronised onto it.

Control 16: bank detail changes verified out of band, every time

This is the cyber security for accountancy control that most often prevents a genuine loss. Any change to bank details — a client’s, a supplier’s, an employee’s on the payroll — is verified by calling a number you already held, never a number in the message requesting the change.

UK Finance recorded invoice and mandate scams at £41.3 million across 2,305 cases in 2025, both the lowest figures ever recorded and down from 4,721 cases in 2020. The average loss was £17,918. But only 48% of those losses were returned to victims, thirteen points below the 61% average across all authorised push payment fraud. The frequency is falling and the recovery rate is poor, which is precisely the risk profile that justifies a call-back rule.

The artefact is a call-back log covering the last twelve changes, showing who called, which number was used, and who confirmed.

Model wording for a payment change
We will never change your bank details on the basis of an email alone. If you ask us to change where we send money, or if you receive a request that appears to come from us asking you to change where you send money, we will telephone the number held on your engagement record before anything moves. If we cannot reach you on that number, the payment waits.

Cyber Security for Accountancy, Domain 5: People, Response and Assurance

The final four controls. This is where cyber security for accountancy stops being technical work and becomes practice management.

Control 17: annual training that uses the practice’s own pretexts

Generic awareness training does very little for cyber security for accountancy. Training that shows the actual messages your practice receives does a great deal. Build the material from three things: the HMRC refund pretext, the Companies House filing reminder pretext, and the “please look at the attached invoice” pretext.

Add one accountancy-specific scenario that generic training never covers: the help-desk reset. The National Cyber Security Centre’s guidance following the 2025 retail incidents told organisations to review how their help desk authenticates a caller before resetting a password, especially for privileged accounts. In a practice, the caller who says they are locked out at eleven at night in January is very plausible, and the person answering wants to help.

Control 18: a one-page response plan with real phone numbers

Twenty-five per cent of UK businesses have a formal incident response plan. In cyber security for accountancy, the plan can genuinely be one page: who decides, who calls the insurer, who calls the clients, who calls the regulator, and the phone numbers for all of them. Store it somewhere reachable when the tenant is not.

Two clocks belong on that page. A personal data breach that meets the threshold must be reported to the Information Commissioner’s Office within 72 hours. And from 19 June 2026, section 164A of the Data Protection Act 2018 requires a data protection complaint to be acknowledged within 30 days. Our incident response page covers the retainer options if the practice would rather not hold that capability itself.

Test it once a year around a table for an hour. The artefact is the plan plus a dated note from the last walkthrough.

Control 19: logging kept long enough to investigate

After an incident the first question is always “what did they access, and when”. Answering it requires sign-in and audit logs from the tenant, the practice management system and the portal, retained long enough that the answer still exists.

Default retention on many platforms is thirty or ninety days, and the median time between compromise and discovery is frequently longer than that. The cyber security for accountancy artefact is a screenshot of the retention setting for each platform that matters, which usually reveals at least one system logging nothing at all.

Control 20: independent assurance, renewed on a date

The final control converts nineteen internal cyber security for accountancy beliefs into an external statement. For most practices that means Cyber Essentials, sometimes Cyber Essentials Plus, occasionally an independent penetration test or an ISO certification where a large client demands it.

Certification adoption across UK businesses is only 5%, up from 3%. That means a certificate is still a differentiator in a tender rather than a hygiene factor. The artefact is the certificate, report or audit letter with an expiry date on it, held by a named partner who has a diary reminder ninety days before.

Assurance is also where a good external provider earns their cyber security for accountancy fee. If the practice buys managed IT services, the contract should say which of these twenty artefacts the provider produces and on what cadence, because an unowned control is the same as an absent one.

How the January Peak Bends Cyber Security for Accountancy Firms

Every practice has one month in which its own rules bend, and any cyber security for accountancy checklist that ignores it is describing a firm that does not exist.

The volume is real and it is documented

HM Revenue and Customs received 11,489,825 Self Assessment returns by the 31 January 2026 deadline, against 12,029,168 expected. Of those, 11,173,825 were filed online — 97.25% — and 316,000 on paper. Around one million taxpayers missed the deadline entirely, and 475,772 returns were filed on the final day.

That last figure is the cyber security for accountancy story. Nearly half a million returns went in on one day, which means several hundred thousand client interactions, password resets, file transfers and last-minute queries compressed into twenty-four hours across the profession.

Seasonal staff arrive faster than the joiner process

January contractors, returning part-timers and temporary bookkeepers all need access on day one, which is exactly when the joiners checklist gets skipped. Two practical cyber security for accountancy fixes: pre-build the seasonal accounts in December with an expiry date already set, and give them a distinct naming convention so a quarterly review can spot any that survived into February.

The expiry date is the important half. An account that switches itself off on 15 February needs nobody to remember it.

Out-of-hours work weakens the strongest controls

Work moves home, onto personal networks and sometimes onto personal machines. Multi-factor prompts get approved reflexively at eleven at night. A locked-out colleague is more likely to be helped than verified.

Write the January cyber security for accountancy exceptions down in advance rather than improvising them: what a seasonal account may access, who may authorise a reset out of hours, and which categories of request always wait until the morning regardless of the deadline.

The pretexts get better in January

Attackers read the same calendar you do. A refund notice, a filing-failure warning or an urgent client request all land with far more credibility in the last fortnight of January than in the first week of July. Run the annual training in November or early December, not in the spring, so it is fresh when it matters.

HMRC Agent Multi-Factor Authentication: The 2026 Timetable

This section is the one to put in front of the partner group, because it is the part of cyber security for accountancy with fixed dates attached, and it changes how the practice logs in rather than what it believes.

What is changing and what is not

From 2026, HMRC is applying multi-factor authentication to web sign-in on GOV.UK for both the agent services account and HMRC online services for agents. It does not affect Making Tax Digital for VAT or PAYE submissions made through software, which continue to work as they do now.

The three phases

Agents were given a phased path, set out in Agent Update 141 published on 19 March 2026.

If the request was made byMulti-factor authentication switched onWhat the practice should do
30 June 202615 July 2026Early movers; test the shared-login problem first
31 July 202619 August 2026Second window; complete before the autumn workload
No request made28 September to 15 October 2026Switched on automatically; do not be surprised in January

How the codes arrive

Codes come by authenticator app, which is HMRC’s preferred method, by text message from 60551, or by automated voice call from 01749 608007. Text and voice codes are six digits and valid for fifteen minutes.

For a practice, the authenticator app is the only sensible answer, because it works without signal in a basement office and it survives a lost phone if the seed key was recorded.

The shared-login problem, and the two-administrator rule

A practice where three people use one agent login has to distribute the authenticator seed key so all three can generate the same codes. That works, but it is a stopgap rather than a durable cyber security for accountancy control, and it is a good prompt to move to named agent access.

The rule to write down now: every account needs at least two administrators, because nobody can reset their own multi-factor authentication. A single-administrator account whose holder loses their phone in January is a genuinely serious operational problem.

Companies House Duties Inside Cyber Security for Accountancy

The Economic Crime and Corporate Transparency Act 2023 turned Companies House from a filing cabinet into a verifying registrar, and it created a new category of regulated data inside accountancy practices.

The identity verification timetable

Identity verification became a legal requirement on 18 November 2025, with a twelve-month transition for existing directors, people with significant control and LLP members that closes on 18 November 2026. Registration for authorised corporate service providers opened on 18 March 2025 at a fee of £55, and verification through an authorised agent or GOV.UK One Login has been available since 8 April 2025.

Agents filing on behalf of clients will need authorised agent registration from no earlier than November 2026, and identity verification for filers from no earlier than November 2027.

What authorised agent status obliges you to hold

An authorised corporate service provider must be supervised by one of the twenty-five UK anti-money-laundering supervisory bodies, must keep identity-check records for seven years, and must notify Companies House within fourteen days of any change — including the loss of that supervision.

Read that as a cyber security for accountancy requirement rather than a filing requirement. Seven years of identity evidence, held in a practice, is a high-value archive. It belongs in the retention schedule at Control 12, in the supplier register at Control 13 if a third party stores it, and in the logging scope at Control 19.

The credential is now worth more than it was

An agent credential that can verify an identity or change a company’s registered details is worth considerably more to a fraudster than one that can only file accounts. That is the argument for pulling the first four cyber security for accountancy controls forward rather than treating them as a project for next year.

The professional bodies still do not mandate certification

Neither ICAEW, ACCA nor AAT mandates Cyber Essentials. Any blog that tells you otherwise is repeating provider marketing. What they do require is competence, confidentiality and adequate professional indemnity cover — ICAEW’s regulations, effective from 1 September 2024, set a minimum limit of indemnity of £2 million with a participating insurer. Certification is a commercial choice that makes those obligations easier to evidence, not a regulatory one.

What Cyber Security for Accountancy Costs

The honest answer is that cyber security for accountancy is mostly configuration rather than purchase. The spending is concentrated in three places: assurance, cover and time.

What cyber security for accountancy certification costs

IASME publishes its Cyber Essentials self-assessment fees by size band. They are annual, and they are per legal entity, so a practice with a separate corporate finance company or payroll bureau pays for each.

Size bandHeadcountFee (ex VAT, 12 months)Cost per head at the top of the band
Micro1 to 9£320£35.56
Small10 to 49£440£8.98
Medium50 to 249£500£2.01
Large250 and above£600£2.40 at 250

The audited version, Cyber Essentials Plus, starts from around £1,400 ex VAT and must be taken within three months of the self-assessment certificate.

Insurance is where cyber security for accountancy pays for itself

Cyber liability cover is the second line item, and the underwriting questions map almost exactly onto this control set — most cybersecurity proposal forms ask about multi-factor authentication, backups, patching and training before they ask about anything else. A practice that can answer those four from evidence rather than memory usually gets a faster decision.

Certification also carries £25,000 of cyber liability cover for UK businesses with turnover under £20 million, which covers a large share of the profession by firm count.

Time is the real cost of cyber security for accountancy

Realistically, a practice of forty spends the equivalent of a fortnight of one competent person’s time moving its cyber security for accountancy score from typical to good, most of it in Domain 1 and Domain 4. After that the ongoing cost of cyber security for accountancy is the quarterly review, which is an hour with the practice manager and the IT provider.

Cost areaUsually already paid for?Where the money actually goes
Multi-factor authenticationYes, in most business licencesConfiguration time, not licence spend
Disk encryptionYes, built into modern operating systemsProving it centrally across every device
Device enrolmentSometimes; depends on the licence tierPer-user licence plus a one-off enrolment project
Immutable backupRarely for cloud practice systemsA dedicated backup product and its storage
TrainingNoA platform subscription or a facilitated session
CertificationNoThe published IASME fee, plus preparation time

Cyber Security for Accountancy: A 42-Person Worked Example

Abstract control sets are easy to agree with and hard to act on. Here is what cyber security for accountancy looks like against a specific firm, using only arithmetic on the counts stated.

The estate, counted honestly

The practice has 42 staff across three offices: 31 fee earners and 11 support. Counting devices gives 42 staff laptops, 5 shared meeting-room and reception PCs, 1 surviving on-premises file and print server, 9 practice mobiles and 7 contractor laptops brought in for January. That is 64 in-scope devices.

As proportions of those 64: staff laptops 65.6%, practice mobiles 14.1%, January contractor laptops 10.9%, shared PCs 7.8% and the server 1.6%. The cyber security for accountancy remediation concentrates in the 5 shared PCs and the 7 contractor laptops — 12 of 64, or 18.8% — because those are the devices with no single owner.

The identities, counted the same way

Identities are 42 named staff accounts, 14 shared or generic mailboxes across the three offices, and 5 administrator accounts: 61 identities in total. Of those, 19 — the 14 shared plus the 5 administrator accounts — are shared or privileged. That is 31.1% of all identities, and it is where Controls 2 and 3 do their work.

Identity mix in the worked example (61 identities in total)
Named staff accounts (42) 68.9%
Shared or generic mailboxes (14) 23.0%
Administrator accounts (5) 8.2%

The cloud services, counted before anyone argues about them

Thirteen services hold or touch client data: the tenant, practice management, tax software, accounts production, payroll, the bookkeeping ledger, the client portal, e-signature, the bank feed aggregator, anti-money-laundering screening, time and fees, backup, and the password manager. All thirteen need multi-factor authentication under Control 1, and all thirteen belong in the supplier register under Control 13.

The starting cyber security for accountancy score, and where it lands

A practice of this shape typically opens its cyber security for accountancy score at eight or nine Current out of twenty. Multi-factor authentication is on the tenant but not on three of the smaller services. Backups exist but the last restore test is undated. The supplier register does not exist at all.

At 42 staff the practice sits in the small band, so certification costs £440 ex VAT, and with an audited Cyber Essentials Plus assessment at around £1,400 the assurance line is £1,840, or £43.81 per head. That is the whole external cyber security for accountancy spend for Control 20.

Mapping Cyber Security for Accountancy to Cyber Essentials, MLR 2017 and UK GDPR

Partners reasonably ask why cyber security for accountancy needs a bespoke list when three external frameworks already exist. The answer is that none of the three covers a practice completely, and this list is the intersection plus the bits only accountancy has.

DomainCyber EssentialsMLR 2017 and agent dutiesUK GDPR
1. Identity and accessCovered; missing multi-factor authentication is an auto-failIndirect, via record integrityArticle 32 security of processing
2. Devices and estateCovered in fullNot addressedArticle 32 security of processing
3. Client data and channelsPartly; retention is out of scopeRegulation 40 five-year recordsStorage limitation and Article 5(1)(f)
4. Suppliers and outsourcingNot addressed directlyReliance and outsourcing provisionsArticle 28 processor obligations
5. People, response, assurancePartly; training is not testedTraining and internal controls dutiesArticle 33 breach notification in 72 hours

Where Cyber Essentials stops

The scheme is a technical baseline. It says nothing about retention schedules, supplier registers, subcontractor access lists or bank-detail call-backs, all of which are the cyber security for accountancy controls that stop the losses a practice actually suffers.

Where the money-laundering regulations stop

Regulation 40 tells you how long to keep records. It does not tell you to encrypt the laptop they sit on, or to log who opened them.

Where UK GDPR stops

Article 32 requires appropriate technical and organisational measures, which is deliberately open-ended. It gives you the obligation and leaves you to invent the cyber security for accountancy control set. This list is one defensible answer to that question, expressed in artefacts you can actually produce.

The overlap is the case for one cyber security for accountancy programme

Fourteen of the twenty cyber security for accountancy controls satisfy more than one framework at once. That is the practical case for doing them in one programme rather than three: the certification project, the anti-money-laundering file review and the data protection audit are all asking for versions of the same twenty artefacts.

A 90-Day Plan for Cyber Security for Accountancy Firms

Twenty controls is a year of drift if nobody sequences them, which is how most cyber security for accountancy programmes stall. Ninety days is enough to make all twenty Current in a practice under fifty people, provided the order is right.

Days 1 to 30: the nine controls that need no budget

Start with everything that is configuration and paperwork rather than purchase. That is Controls 1, 2, 3, 4, 6, 10, 13, 16 and 18: multi-factor authentication everywhere, the identity register, separate administrator accounts, the joiners and leavers checklist, encryption evidence, email authentication, the supplier register, the bank-detail call-back rule and the one-page response plan.

Nine of twenty Current by day 30 is 45%, and it is achievable because none of it requires a procurement decision. It is also the half that removes the most risk, because it closes the credential path.

Days 31 to 60: the seven that need a supplier conversation

Controls 5, 7, 8, 11, 14, 15 and 19 all involve someone outside the partner group: the IT provider for device enrolment, patching, the software retirement list, the restore test and logging retention; the legal or contract owner for supplier wording; and each subcontractor for the access list.

That takes the running total to sixteen of twenty, or 80%. Expect this month to be the slow one, because it moves at the speed of other people’s diaries.

Days 61 to 90: the four that change how the practice works

Controls 9, 12, 17 and 20 are the ones clients and staff notice: the portal-only rule, the retention schedule, the training session and the assurance decision. They come last deliberately, because each needs a partner-level decision and a communication rather than a setting.

By day 90 all twenty should be Current: 100%, with a review date already in the calendar for each one.

Cumulative controls scored Current across the 90-day plan (out of 20)
By day 30 – 9 controls 45%
By day 60 – 16 controls 80%
By day 90 – 20 controls 100%

Do not start cyber security for accountancy work in December

The single most common scheduling error is launching a cyber security for accountancy programme in the run-up to the January deadline. Nothing will happen, the momentum will be lost, and the practice will conclude that the checklist did not work. February to April, or June to September, are the windows where a partner group actually has attention to spare.

WindowControlsWho drives itWhat blocks it
Days 1 to 301, 2, 3, 4, 6, 10, 13, 16, 18Practice managerShared logins nobody wants to give up
Days 31 to 605, 7, 8, 11, 14, 15, 19IT provider and contract ownerSupplier response times
Days 61 to 909, 12, 17, 20Named partnerPartner consensus and client communication
Quarterly thereafterAll controls marked quarterlyPractice managerNothing, if the review is diarised

Six Cyber Security for Accountancy Mistakes Practices Make

These are the patterns that turn good cyber security for accountancy into a stale checklist, drawn from what actually goes wrong rather than from a threat model.

Treating cyber security for accountancy as an IT deliverable

Half of cyber security for accountancy belongs to the practice manager or a named partner, not to a technician. Handing all twenty to the IT provider guarantees that the supplier register, the retention schedule, the call-back rule and the training never get done, because the provider has no authority over any of them.

Confusing a policy with an artefact

A document that says devices will be encrypted is not evidence that they are. The artefact is always the report, the list, the log or the dated note — the thing a sceptical reader could not have written from imagination.

Scoring on belief rather than on dates

“We do that” is the answer that keeps a cyber security for accountancy control Absent for years. Every artefact needs a date on it, and the date is what turns twenty opinions into a score anyone can audit.

Buying a tool to fix a process problem

Shared logins, unverified bank changes and unmanaged subcontractor access are all process failures. No product fixes them. Conversely, patch compliance reporting and encryption evidence genuinely do need tooling, and trying to do those by hand is equally wasteful.

Ignoring the smallest suppliers

The niche add-on nobody thinks about is usually the one with the broadest permissions, because it was installed by a partner in a hurry and granted whatever it asked for. The supplier register exists to surface exactly that.

Assuming the sector siblings do not apply

A practice is not a hotel and not a property manager, but the failure modes rhyme. Our hotel cyber security checklist uses a different scoring model on a different estate, and reading it alongside this one is a quick way to see which of your controls are sector-specific and which are simply good practice. The same applies to our wider compliance work.

Frequently Asked Questions About Cyber Security for Accountancy

How many of the twenty controls does a small practice really need?

All twenty, but not at once. A four-person practice can make Controls 1 to 4, 6, 10, 16 and 18 Current in a fortnight, and those eight carry most of the risk reduction. The remaining twelve are still required; they simply take longer because they involve suppliers and partner decisions.

Is Cyber Essentials enough on its own?

No, and it does not claim to be. It is an excellent technical baseline and a useful commercial signal, but it says nothing about retention schedules, supplier registers, subcontractor access or bank-detail verification. Roughly the first two cyber security for accountancy domains and part of the third map onto it; Domains 4 and 5 largely do not.

Do ICAEW, ACCA or AAT require certification?

No. None of the three mandates Cyber Essentials. They require competence, confidentiality and adequate professional indemnity insurance, and certification is a convenient way to evidence part of that. Any claim that certification is mandatory traces back to marketing rather than to a rulebook.

What is the single most valuable cyber security for accountancy control?

Control 1, multi-factor authentication on every cloud service with no exemptions. Every other cyber security for accountancy control assumes that an attacker cannot simply log in as one of your people. Control 16, the bank-detail call-back, is the one most likely to prevent a direct cash loss.

How long should the quarterly review take?

An hour, once the artefacts exist. The practice manager and the IT provider walk the twenty rows, check the dates, and mark anything that has slipped to Stale. The first review is the long one because it doubles as the baseline.

Who should own the cyber security for accountancy score in a partnership?

One named partner, not a committee and not “the partners”. The practical model is that a named partner owns the score and reports it at a partners’ meeting once a quarter, while the practice manager owns the day-to-day evidence and the IT provider produces the technical reports.

What changes when we take on authorised agent status?

Three things. You start holding identity evidence, which needs a seven-year retention rule and its own access controls. Your agent credentials become more valuable to a fraudster. And you acquire a fourteen-day notification duty to Companies House, which belongs on the one-page response plan alongside the 72-hour reporting clock.

Does cyber security for accountancy help with cyber insurance?

Directly. Underwriters ask about multi-factor authentication, backups, patching and training first, which are Controls 1, 11, 7 and 17. Being able to answer from a dated artefact rather than from memory is usually the difference between a fast quote and a long questionnaire, and certification carries £25,000 of cyber liability cover for UK businesses under £20 million turnover.

References

Cyber Security Breaches Survey 2025/2026

Cyber Security Breaches Survey collection

NCSC: Small businesses to receive cyber security boost with new toolkit from experts

NCSC: Small Organisations Guide to Cyber Security

NCSC: Advice and guidance for small to medium sized organisations

NCSC Small Business Guide: Response and Recovery

NCSC: Incidents impacting retailers

NCSC: Offline backups in an online world

NCSC: It’s time for all small businesses to act

NCSC: 10 Steps to Cyber Security

NCSC: Password administration for system owners

NCSC: Multi-factor authentication for online services

NCSC: Device Security Guidance

NCSC: Managing deployed devices

NCSC: Vulnerability Management

NCSC: Phishing attacks – defending your organisation

NCSC: Phishing guidance

NCSC: Supply chain security guidance

NCSC: Incident management

NCSC: Cloud security guidance

NCSC Cyber Security Board Toolkit

NCSC: Cyber insurance guidance

NCSC Early Warning service

NCSC Cyber Essentials overview

IASME Cyber Essentials

Cyber Governance Code of Practice

HMRC Agent Update: issue 141

ATT: Multi-factor authentication – how can agents prepare?

Companies House: Changes to UK company law

Economic Crime and Corporate Transparency Act 2023 factsheets

Economic Crime and Corporate Transparency Act 2023

Money Laundering Regulations 2017, regulation 40

GOV.UK: Money laundering regulations – your responsibilities

GOV.UK: Anti-money laundering registration

Data Protection Act 2018

Data (Use and Access) Act 2025

ICO: Report a personal data breach

ICO: A guide to data security

ICO: Enforcement action

ICAEW: Cyber security resources

ICAEW: Professional indemnity insurance

ICAEW: Practice Assurance

ICAEW: Phishing most prevalent cyber attack, confirms UK survey

ICAEW: Accountancy practices face daily cyber threats

SecurityBrief UK: Cyber-attacks top risk for professional firms in 2026

House of Commons Library: Bank fraud and scams

FBI Internet Crime Report 2025

HMRC: Use Making Tax Digital for Income Tax

GOV.UK: Report suspicious emails, websites and phishing

Microsoft: Mandatory multifactor authentication for Microsoft Entra

Microsoft Entra Conditional Access overview

Microsoft Entra ID Protection

Microsoft: Passkeys and FIDO2 in Microsoft Entra ID

Microsoft Intune documentation

Microsoft Purview retention policies

Microsoft Purview Data Loss Prevention

Microsoft Defender for Office 365