A twelve-person accounting practice holds something almost no other business of that size holds: several hundred complete identity sets. Full name, date of birth, residential address, tax file number, bank account details, driver licence or passport scans collected at onboarding, and years of financial history, all of it in one practice management system, one document portal and one email account.
That concentration is the point. A criminal who wants three hundred Australians’ identity records can attempt three hundred separate break-ins, or one. Accounting and bookkeeping practices sit at the second option, and they are being treated accordingly.
The Essential Eight is a set of eight mitigation strategies published by the Australian Signals Directorate (ASD). It was not written for accounting practices, which is why so much of it reads as though it belongs in someone else’s business. This article translates it into practice terms, sets out the obligations that genuinely apply to a small Australian practice, and suggests a starting order. If you want the framework itself explained first, start with our guide to what the Essential Eight is. Translating controls into the language of a specific profession is what CyberSmart360 does, but nothing below requires you to sign up.
Why an accounting practice is a high-value target
Two attack shapes account for most of the damage done to practices, and neither of them is exotic.
The first is identity and refund fraud. A tax file number sitting alongside a date of birth, an address and a scanned identity document is directly monetisable. The attacker does not need to touch your systems again once they have the export.
The second is payment redirection, usually through business email compromise. Somebody gets into a mailbox — a principal’s, or an administrator’s — watches the correspondence for a fortnight, then sends a client a perfectly ordinary-looking email saying the practice has changed banks. Or, more damaging, sends the practice an email that appears to come from a client, asking to update the bank account a refund is paid into. Nothing is encrypted, nothing looks broken, and the loss is discovered weeks later.
Ransomware adds a third dimension that is specific to your profession: timing. An encryption event that would be a bad fortnight for most businesses lands differently when it falls in the week before a lodgement deadline and your working papers are the thing encrypted.
Which obligations actually apply to your practice
This is where most practice principals get an unhelpful answer, because the honest answer is “it depends on what services you provide”. Here is the picture at a level that is accurate. It is general information, not legal advice — the scoping questions below are worth putting to your own solicitor or professional body.
First, the direct answer: the Essential Eight is not legally required of accounting practices. It is mandatory for Australian non-corporate Commonwealth entities under the Protective Security Policy Framework, which requires them to implement Essential Eight Maturity Level Two mitigations. For your practice it is a baseline that clients, insurers and tender processes increasingly ask about.
What does apply is a set of obligations that all point in the same direction: protect the client information you hold.
| Obligation | How it applies to a small practice |
|---|---|
| Privacy Act 1988 — Australian Privacy Principles | The OAIC states that most small businesses (annual turnover of $3 million or less) are not covered by the Privacy Act, but some are. Regardless of turnover, the Act covers a business that is, among other things, a reporting entity under the AML/CTF Act, a contractor providing services under a Commonwealth contract, related to a business the Act covers, or one that has opted in. |
| Privacy (Tax File Number) Rule 2015 | The OAIC lists this separately from the APPs as an obligation some small businesses may be required to comply with. It regulates the handling of individuals’ tax file number information. A practice holding client TFNs should treat this as directly relevant regardless of turnover. |
| Notifiable Data Breaches scheme | The OAIC states that entities with existing obligations under the Privacy Act to secure personal information must comply with the NDB scheme, and lists tax file number recipients among them. In practice this means having a way to detect a breach, assess whether serious harm is likely, and notify — decided in advance, not during the incident. |
| AML/CTF Act — Tranche 2 | From 1 July 2026, accountants providing designated services under the AML/CTF Act are reporting entities. CPA Australia notes that routine accounting and tax compliance activities — preparing tax returns and financial statements, and providing tax advice — are not designated services. Company and trust formation, registered office services, nominee roles and certain client-money services generally are. If you are in scope, the OAIC states that reporting entities must comply with the Privacy Act when handling personal information for, or in connection with, their AML/CTF obligations, including small businesses with turnover under $3 million. |
| Tax Agent Services Act 2009 — Code of Professional Conduct | Code item 6 requires that you do not disclose information relating to a client’s affairs to a third party without permission, unless there is a legal duty to do so. The TPB states that it is important to have sufficient IT controls in place to protect the security and confidentiality of client records, and that doing so assists in meeting Code obligations. Its stated minimum best practice includes keeping operating systems and programs patched, using anti-virus software and firewalls, encrypting client files where possible, and considering a second form of authentication on online accounts. |
| Professional body requirements | Members of CPA Australia, Chartered Accountants ANZ and the Institute of Public Accountants are bound by the APES 110 Code of Ethics for Professional Accountants, which includes confidentiality as a fundamental principle. None of these bodies requires Essential Eight compliance as such; all of them expect client information to be protected. |
The pattern worth noticing: every one of those obligations tells you to protect client data, and none of them tells you how. The Essential Eight is a credible answer to the “how”, which is precisely why it keeps appearing in client questionnaires and insurance forms even though no law names it.
The eight strategies, translated to a practice
These are the eight mitigation strategies as ASD names them, described for a practice running practice management software, a client document portal, cloud ledgers and email.
| Strategy | What it means in an accounting practice |
|---|---|
| Multi-factor authentication | A second factor on every system holding client data: the client portal, the cloud ledger, practice management, email, and the credentials used for lodgement. At Maturity Level One ASD requires multi-factor authentication for online services holding your organisation’s sensitive data, including third-party services, and for online customer services holding sensitive customer data. The client portal is a customer-facing service — the question is not only whether staff use a second factor, but whether clients can. |
| Restrict administrative privileges | Who can change things, as distinct from who can do the work. At Maturity Level One, privileged access is validated when first requested, anyone doing administrative work has a separate dedicated account used only for that, and those accounts are kept off email and web browsing. In practice terms this is also the control that governs who can add a user to the ledger, change a bank account on a client record, or export the client list. |
| Patch applications | Practice management software, the ledger desktop components, browsers and their extensions, email clients, PDF software and security products. ASD requires those categories to be patched within two weeks of release, and within 48 hours where the vendor rates the vulnerability critical or a working exploit exists. Anything of yours facing the internet — a self-hosted portal, a document server — sits on the tighter clock. Software the vendor no longer supports gets removed. |
| Patch operating systems | Windows and macOS on desktops and laptops, and iOS and Android on the phones staff read client email on. Workstation operating systems within one month; internet-facing systems within 48 hours where critical. Operating systems the vendor no longer supports are replaced — which is usually the argument that finally retires the machine in the back office running the old scanning software. |
| Regular backups | Working papers, the practice management database, and anything not already held by a cloud vendor on your behalf. ASD requires backups to be performed and retained in line with business criticality, held securely and resiliently, synchronised so everything restores to a common point in time, and tested by actually restoring as part of a disaster recovery exercise. Everyday user accounts must not be able to modify or delete backups. |
| Application control | Only approved software runs on practice machines. At Maturity Level One this applies to workstations and covers the folders where downloads and email attachments land — which is exactly where a malicious attachment from a “client” tries to execute. |
| Restrict Microsoft Office macros | Practices run on spreadsheets, and some of those spreadsheets have macros in them. At Maturity Level One, macros are disabled for users without a demonstrated business requirement, macros in files that arrived from the internet are blocked, macro antivirus scanning is on, and staff cannot change the setting themselves. A macro-enabled workbook emailed in by a client is a common delivery route. |
| User application hardening | Turning off risky features in everyday software. At Maturity Level One: Internet Explorer 11 disabled or removed, web browsers not processing Java from the internet, web browsers not processing web advertisements from the internet, and users unable to change browser security settings. |
This is the specific problem CyberSmart360 was built to solve. The platform holds 186 controls across the Essential Eight and the ACSC Security Principles, with every control rewritten for 44 industries — 8,184 published translations. Working through the accounting translation set, you are asked about your practice management system, your client portal and your ledger software, not about executables, software libraries and control panel applets. It also produces a costed 12-month remediation plan, which for most practices is the genuinely useful output: the gaps ranked, with an indicative cost against each, so the work can be budgeted across a financial year rather than landing as one unbudgeted quote in March.
The two controls that stop the two most common losses
If you do nothing else this quarter, do these two.
Multi-factor authentication on every system holding client data. Email first, because email is the pivot point for almost every payment-redirection loss. Then the ledger, the portal, practice management and lodgement credentials. This is also the single control most often assumed to be on when it is not: enforcement across all users is a different setting from availability.
A change-of-bank-details procedure that does not rely on email. Any request to change a bank account — a client’s refund account, or a supplier’s — is verified by phoning a number already on file, never a number contained in the request itself, and a second person approves the change. Log who requested it, who verified it and who approved it. This sits under restrict administrative privileges in the framework, but in a practice it is as much a process control as a technical one, and it is the cheapest control in this article.
Backups, working papers and lodgement deadlines
Two assumptions cause most of the trouble here. The first is that because the ledger is in the cloud, the practice is backed up. The ledger vendor holds the ledger; they do not hold your working papers, your correspondence, your practice management database or the schedules sitting in a folder on the server. The second is that file synchronisation is a backup. It is not. A deletion syncs, and so does an encryption.
What matters for a practice is not just whether a backup exists but how long a restore takes, because the cost of ransomware in a practice is measured in lodgement days lost, not in gigabytes. Time one. Restore a single client folder, note how long it took, and write the number down. That number is what you are actually buying when you spend money on backup.
What Maturity Level One looks like in a practice under 20 staff
ASD defines four maturity levels, Maturity Level Zero through to Maturity Level Three, and advises organisations to plan for the same maturity level across all eight strategies before moving to a higher one, because the eight are designed to complement each other. Level One is the sensible target for a small practice.
Realistically, over one financial year, that looks like: multi-factor authentication enforced across email, portal, ledger and practice management; automatic updates on every machine and phone; unsupported operating systems retired; separate administrator accounts created and everyday logins dropped to standard user; macros disabled except where a documented business need exists; browsers left on default security settings that staff cannot change; and a backup regime with a tested restore. Application control is normally the slowest of the eight, because it means maintaining a list of approved software rather than changing a setting.
Worth knowing before you spend money: ASD states there is no requirement for organisations to have their Essential Eight implementation certified by an independent party, although an implementation may need to be assessed by one where a government directive, a regulator or a contract requires it. For a small practice, a documented self-assessment with evidence behind it is usually what a client or insurer is asking for. If you are weighing that against engaging a consultant, we compare the options in what Essential Eight compliance costs.
What to tell clients who ask how you protect their data
More clients are asking, and the worst answer is a vague reassurance. Be specific, be honest about what is in progress, and put it in writing once so you are not composing it fresh each time. A short, accurate statement does the job. Name the framework you assess against and the level you are working to. State that multi-factor authentication is enforced on the systems holding client data, that client files are held in named cloud services rather than on individual laptops, and that backups are taken and restores tested. Describe the verification step for any change to bank details. Say when the practice last assessed itself and when it will next. Where something is not yet done, give the date it will be. A client who is told “multi-factor authentication is enforced on email and the portal now, and on practice management by the end of Q2” trusts you more than one who is told everything is fine.
Keep it to a page, put it on the website or in the engagement pack, and date it. It also answers the same question when it arrives from an insurer or a corporate client’s procurement team, and if that question turns up inside a formal tender schedule, our guide to answering Essential Eight questions in government tenders covers what evidence is expected.
Five things worth doing this month
- Enforce multi-factor authentication on email, then the client portal, then the ledger and practice management system. Check enforcement across all users, not just availability.
- Write down every system holding client data and who has a login to each — including former staff and the bookkeeper who left in March.
- Put the change-of-bank-details verification step in writing and tell the whole team, including whoever covers reception.
- Restore one client folder from backup and time it.
- Check whether any machine is running an operating system the vendor no longer supports, and schedule its replacement.
Frequently asked questions
Is the Essential Eight mandatory for accounting practices?
No. It is mandatory for non-corporate Commonwealth entities under the Protective Security Policy Framework. For an accounting practice it is a baseline that clients, insurers and tender processes increasingly ask about, and a practical way to demonstrate that you are meeting the confidentiality and security obligations that do apply to you.
Does the Privacy Act apply to my practice?
It depends. The OAIC states that most small businesses with annual turnover of $3 million or less are not covered, but that certain businesses are covered regardless of turnover — including reporting entities under the AML/CTF Act and Commonwealth contracted service providers. Separately, the Privacy (Tax File Number) Rule 2015 regulates the handling of tax file number information, and the OAIC lists tax file number recipients among the entities that must comply with the Notifiable Data Breaches scheme. Given what a practice holds, the safe working assumption is that you are in scope for something. Confirm your specific position with your solicitor or professional body.
Does using cloud accounting software mean we are already secure?
No. The vendor patches their platform and generally offers multi-factor authentication, audit logs and access controls. Turning those on, deciding who holds administrator access, patching your own devices, controlling what software runs on them, and backing up everything the vendor does not hold all remain yours.
What maturity level should a small practice aim for?
Maturity Level One across all eight strategies is the realistic first target, unless a specific client contract or regulator requires more. Read any questionnaire carefully. It usually states the level expected.
Do we need to be certified?
ASD states there is no requirement for organisations to have their Essential Eight implementation certified by an independent party. An independent assessment may be required by a government directive, a regulatory authority or a contract, so check what the specific requester is asking for.
Start with an assessment, then budget the work
The reason security frameworks stall in small practices is not unwillingness. It is that the framework arrives as a wall of technical language with no indication of what applies, what it costs or what order to do it in, and there is never a quiet week to work it out.
CyberSmart360 turns that into a plain-language assessment written in the language of accounting practice. You answer questions about your practice management system, your portal and your ledger; the platform produces a compliance score, a gap report ranked by priority, a costed 12-month remediation plan, evidence tracking and a downloadable PDF report you can hand to a client, an insurer or your professional indemnity broker. The free 7-day trial at cybersmart360.com needs no credit card and covers one user and one assessment. Detail is on the plans and pricing page.
This article is general information about a security framework and the obligations that commonly sit around it. It is not legal, tax or professional advice, and it does not replace advice specific to your .