All insights
Cyber

Cyber security for accounting firms: the Australian guide

What Australian law requires of an accounting firm, what the regulators recommend, what insurers ask, what is actually hitting practices, and what a defensible posture looks like.

Nathan James
Founder, Worktopia
22 August 202615 min read
The Australian guide
Australian law does not hand accounting firms a cyber security checklist. It gives them two duties and a deadline.

The short answer

Australian law does not hand accounting firms a cyber security checklist. It gives them two duties and a deadline. The Privacy Act's Australian Privacy Principles apply to an accounting firm only if its annual turnover exceeds $3 million, but the Tax File Number Rule and the breach-notification scheme for TFN information apply to every firm that holds a client's TFN, whatever its size. Firms the Principles cover must take "such steps as are reasonable in the circumstances" to protect personal information. Every firm holding TFNs must do the same for TFN information and restrict who can see it. When a breach is likely to cause serious harm, the firm must assess it within 30 days and notify the Information Commissioner and the people affected. Registered tax agents carry a parallel set from the Tax Practitioners Board: keep client information confidential, and report a significant breach of the Code within 30 days. Every named control you have read about, from multi-factor authentication to the Essential Eight, is a recommendation on top of that, and the recommendations are where a firm's posture is actually decided.

What the law requires: two tiers and a deadline

Tier one: the Privacy Act, for firms above $3 million. The Australian Privacy Principles bind "APP entities", and a business is only an organisation under the Act if it is not a small business operator. A small business is one with annual turnover of "$3,000,000 or less". So a suburban practice turning over less than that is outside the Principles, unless a carve-out catches it. The carve-outs are disclosing personal information for a benefit, providing a health service, contracting to the Commonwealth, or being related to a larger entity. Above the line, APP 11 applies. The entity "must take such steps as are reasonable in the circumstances to protect the information" from misuse, interference, loss, and unauthorised access, modification or disclosure. The 2024 amendments added one sentence to that principle, that such steps "include technical and organisational measures". They named no control.

Tier two: the TFN Rule, for every tax practice. Anyone "in possession or control of a record that contains tax file number information" is a file number recipient under the Act, and the Privacy (Tax File Number) Rule 2015, which describes itself as "legally binding", has no turnover test. It covers the TFNs of individuals, which is most of what a practice holds. It says TFN recipients "must take reasonable steps" to protect TFN information from misuse, loss and unauthorised access, to restrict access "to individuals who need to handle that information" for tax, personal assistance or superannuation purposes, to securely destroy it when it is no longer needed, and to make sure staff are trained on handling it. A breach of the Rule is an interference with privacy. For an accounting firm this is the duty that matters, because every client file has a TFN in it.

The deadline: notifiable data breaches. The breach scheme covers APP entities for personal information and file number recipients for TFN information, so a firm below the turnover line is still inside it for the TFNs it holds. It applies to an "eligible data breach": unauthorised access, disclosure or loss where "a reasonable person would conclude that the access or disclosure would be likely to result in serious harm" to someone. A firm that suspects one must assess it, and "take all reasonable steps to ensure that the assessment is completed within 30 days". Once it has reasonable grounds to believe a breach is eligible, it prepares a statement for the Commissioner "as soon as practicable" and notifies the individuals. The 30 days is the assessment ceiling, not a notification window.

The parallel set: the TPB. A registered tax or BAS agent is also bound by the Code of Professional Conduct. Item 6 is statutory and blunt: "Unless you have a legal duty to do so, you must not disclose any information relating to a client's affairs to a third party without your client's permission." Since 1 July 2024, a significant breach of the Code must be reported to the TPB in writing within 30 days of reasonable grounds to believe it has occurred, and a cyber incident that exposes client information can be exactly that. The data breach scheme itself is the OAIC's, not the TPB's. The TPB's full position, including what it does not require, is in what the TPB actually requires on cyber security.

What "reasonable steps" means. The Act never says. The OAIC's Guide to securing personal information is, in its own words, "not legally binding", but the OAIC says it will refer to its own guide when "investigating whether an entity has complied" with its security obligations. Its test is practical: cost and inconvenience count, "however, you are not excused from taking specific steps to protect information just because it would be inconvenient, time-consuming or costly to do so". Every control in the guide is phrased as "should", "consider", "it is expected", or a question. Are patches installed as they become available? Are backups tested? Is multi-factor authentication used for higher-risk access? How quickly are accounts removed when someone leaves? None of it is a rule. All of it is what the regulator will measure a firm against after an incident.

What insurers ask

Cyber insurance is worth having, and the proposal form is worth reading even before you buy, because it is the closest thing an accounting firm gets to a written test of its posture. Nobody requires it. The TPB says cover "is not a requirement under the Code of Professional Conduct". SMB1001 does expect a Gold-tier firm to hold it, and the questions on the form are the ones a regulator would ask after an incident anyway. Three current Australian SME forms ask, in yes-or-no terms:

  • Do you require multi-factor authentication for remote access, privileged accounts, backups and web email?
  • Do you run next-generation antivirus or endpoint detection and response on every endpoint?
  • How quickly are critical patches applied? One form offers 24, 48 or 72 hours. Another asks "within 30 days of release".
  • How often do you back up, are backups offline or isolated, and are they tested at least annually?
  • Do you have a tested incident response plan?
  • Do staff receive social engineering training, with phishing simulations?
  • Are system accesses removed promptly when someone leaves?

Every answer on that list goes to the underwriter, and each one has to be an answer the firm can evidence. Read the list against SMB1001, the Australian small-business standard, and it is close to the Gold tier: patching, backups and awareness training sit at Bronze, multi-factor authentication for every user at Silver, and endpoint detection, MFA on business apps, a tested incident response plan and ongoing awareness work at Gold. A firm that can answer yes to the form, with the evidence behind it, has done most of what the OAIC, the ACSC and the certifier ask for.

What is recommended, and by whom

The recommendations come from three places, and it helps to keep them separate.

The TPB publishes a short best-practice list: antivirus, firewalls, current patches, encryption where possible, regular password changes, and considering a second form of authentication. All six are recommendations.

The ACSC tells small businesses to start with three measures, "turn on multi-factor authentication; update your software; back up your information", and then "we recommend small businesses implement Maturity Level One of the Essential Eight". The Essential Eight is eight mitigation strategies drawn from ASD's Strategies to mitigate cyber security incidents, with its controls mapped to the Information Security Manual. Cyber.gov.au says "organisations are recommended to implement" it and that there is "no requirement" to have an implementation certified. The one place it uses the word mandatory is for non-corporate Commonwealth entities under the Protective Security Policy Framework, where Maturity Level Two "is considered a mandatory baseline". It is not mandatory for an accounting firm. We have written up both whether your firm needs it and where its replacement is up to. The short version of the latter: ASD consulted in June and July 2026 on evolving the Essential Eight into an "Essentials series", its first chapter being Essentials for enterprise IT, and ASD's notice promises "strong alignment" with existing controls. The November 2023 maturity model is still the published standard.

The professional bodies. CPA Australia's member checklist traffic-lights its measures and puts updates, antivirus, a password manager, multi-factor authentication, staff training, supplier checks and tested backups in red, the most important tier. Its legal section is carefully conditional: "if obligated under the Privacy Act", report breaches to the OAIC. CA ANZ's regulation for members in public practice requires "an acceptable professional standard of facilities" for confidentiality, which is a membership rule rather than law.

For a firm that wants a standard it can be certified against, SMB1001 is the Australian option built for small business. Its five tiers are cumulative, the first three are attested by a director rather than audited, and the controls are the ones above: support, firewalls, antivirus, patching, passwords, backups and training at Bronze, then MFA, individual accounts, least privilege and email anti-spoofing at Silver, then EDR, app MFA, policies and an incident plan at Gold. We have compared it with the Essential Eight and explained its tiers.

What is hitting firms

ASD's ACSC received over 84,700 cybercrime reports in 2024-25, one every six minutes, and assesses that "the vast majority of cybercrime continues to go unreported". The average self-reported cost per report for a small business was $56,600, up 14 per cent. For businesses overall it was $80,850. The top three self-reported cybercrimes for business were email compromise with no financial loss (19 per cent), business email compromise fraud with a loss (15 per cent), and identity fraud (11 per cent). Ransomware featured in 11 per cent of the incidents ASD responded to. Professional services, the division accounting sits in, accounted for 6 per cent of incidents reported to the ACSC.

Put those numbers together and the most likely incident for an accounting firm is a compromised mailbox, a diverted payment or an identity stolen from the data the firm holds, well ahead of the headline ransomware event. That is why ASD's advice for small business is the basics: "use strong MFA wherever possible, use strong and unique passwords or passphrases, keep software on devices updated, be alert for phishing messages and scams, and regularly back up important data".

What AI changes

The same ASD report has a section on cybercriminal use of generative AI, and it is short on hype. AI "almost certainly enables malicious cyber actors to execute attacks on a larger scale and at a faster rate". Criminals use it to sift stolen data for "valuable credentials or extortion material", and to produce "high-quality videos, fake voices, websites, know-your-customer records and spearphishing emails" that pass as legitimate "with relatively minimal effort". Social engineering, ASD says, is "becoming easier for malicious cyber actors to use at scale, thanks in part to AI technologies", and phishing was recorded in 60 per cent of the incidents reported to it.

For an accounting firm that changes two things. The first is that the things a practice used to trust on sight, a client's voice on the phone, a video call, a scanned driver licence, an email that reads exactly like the client, no longer prove anything on their own. Payment changes, TFN requests and identity checks need a second channel the attacker does not control. The second is inside the firm: it needs to decide which AI tools staff may use, with what client data, under what login. SMB1001 expects a Gold-tier firm to have that policy written down, and ASD's own line is that businesses "must ensure" a "safe and secure approach is taken to the integration of AI technologies". What does not change is the control list. Multi-factor authentication, patched devices, tested backups and trained staff are the same answer to a faster attacker that they were to a slower one. ASD's board-level guidance on frontier AI says much the same, and we have set out what to check in our piece on frontier AI cyber threats.

What a defensible posture looks like

Put the law, the recommendations, the insurer questions and the threat data side by side and they describe the same firm.

Identity first: one Microsoft identity per person with multi-factor authentication enforced, conditional access, and the firm's app logins held behind it rather than in a spreadsheet. We have written up the problem in the Xero login problem and the answer in how we run passwords for accounting firms.

Devices the firm manages and patches, with security software that someone actually watches. Email filtered before it reaches an inbox, because email compromise is the top line in ASD's numbers. Backups that are tested, not assumed.

Access by role, with TFN records restricted to the people who need them, which is the TFN Rule's own wording. A documented program, because APP 1.2 asks for practices, the OAIC says document them, and the TPB's Determination requires a documented quality management system. A written plan for the 30-day assessment clock, with someone who owns it.

That is also why we run cyber security for accountants as the whole job rather than a list of products. The regulator's questions after an incident are about the firm's controls, records and response, and a firm answers them as a whole or not at all.

Where to start

If the firm has done nothing structured, SMB1001 Bronze is the right first target. It is the ACSC's three measures with a few things around them, it is reachable in weeks for a firm with its basics in order, and a director can attest it without an audit. From there the climb to Gold is the same list an insurer will put in front of you. The Essential Eight is the better-known name, but in our experience even Maturity Level One is a larger lift than it looks for a firm of ten or twenty people, because Maturity Level One already includes application control and macro restrictions on every workstation, which most practices have never run. Start with Bronze, keep the Essential Eight as the map for later, and the first step is the same either way: know what you run, who can reach it, and whether you could show a regulator or an insurer the evidence.

Common questions

Is cyber security mandatory for accounting firms in Australia?
No single law mandates specific cyber security controls for accounting firms. The Privacy Act, the Privacy (Tax File Number) Rule 2015 and the TPB's Code of Professional Conduct impose duties to take reasonable steps to protect client information, to restrict access to TFN information, and to assess and report eligible data breaches and significant Code breaches within 30 days. Named controls such as multi-factor authentication and the Essential Eight are recommended, not required.
Does the Privacy Act apply to my accounting firm?
The Privacy Act's Australian Privacy Principles apply to an accounting firm only if its annual turnover exceeds $3 million, but the Tax File Number Rule and the breach-notification scheme for TFN information apply to every firm that holds a client's TFN, whatever its size. Carve-outs can bring a smaller firm under the Principles too, such as disclosing personal information for a benefit or holding a Commonwealth contract. In practice, every tax practice has security and breach-notification duties for TFN information even if it is below the threshold.
Is the Essential Eight mandatory for accounting firms?
No. The ACSC says "organisations are recommended to implement" the Essential Eight and that there is "no requirement" to have it certified. The only mandatory baseline is Maturity Level Two for non-corporate Commonwealth entities under the Protective Security Policy Framework. The ACSC recommends small businesses implement Maturity Level One. ASD consulted in mid-2026 on an Essentials series to succeed the Essential Eight, and the November 2023 maturity model remains the published standard.
Do I have to report a cyber attack, and to whom?
If it is an eligible data breach under the Privacy Act, one likely to result in serious harm to an individual, the firm must assess it within 30 days and notify the Office of the Australian Information Commissioner and the affected individuals as soon as practicable. For a firm below the $3 million threshold, that duty applies to TFN information. The TPB does not administer that scheme, but a registered agent must separately notify the TPB within 30 days of having reasonable grounds to believe a significant breach of the Code of Professional Conduct has occurred, which a cyber incident exposing client information can be.
Does AI change what an accounting firm has to do about cyber security?
It changes the threat more than the controls. ASD's 2024-25 report says AI lets attackers work at larger scale and faster, and that criminals use generative AI for fake voices, videos, know-your-customer records and spearphishing emails. For a firm, that means voice, video and scanned documents no longer verify a client or a payment change on their own, and a second channel is needed. It also means the firm needs a written position on which AI tools staff may use with client data, which SMB1001 expects at its Gold tier. The underlying controls, multi-factor authentication, patching, backups and training, are unchanged.
What do cyber insurers ask accounting firms?
Current Australian SME proposal forms ask seven things. Is multi-factor authentication required for remote access, privileged accounts, backups and web email? Is endpoint detection or next-generation antivirus on every endpoint? How quickly are critical patches applied? How often do backups run, and are they offline and tested annually? Is there a tested incident response plan? Do staff get social engineering and phishing training? Is access removed promptly when someone leaves? They are rating questions, not conditions of cover, the list lines up closely with SMB1001's Gold tier, and the TPB says cyber insurance "is not a requirement under the Code of Professional Conduct".
What should a small accounting firm do first?
Aim for SMB1001 Bronze. It covers the ACSC's three measures, turn on multi-factor authentication, update your software and back up your information, plus antivirus, firewalls, password hygiene, staff training and someone responsible for IT, and a director attests it without an audit. Then climb toward Gold, which is close to what an insurer's form asks. Alongside that, restrict access to client records containing tax file numbers to the people who need them, document what you do, and decide who owns the 30-day assessment clock if something goes wrong.
Nathan James
Founder, Worktopia
Nathan started Worktopia after years inside a Brisbane accounting firm, moving it off legacy systems and into the cloud. He writes about the practical side of security and IT for practices that would rather be doing the work.
Kip, the Worktopia mascot, holding a shield

Find out where your firm actually stands.

The Cyber Compliance Health Check shows where your firm stands against everything on this page, the law, the recommendations and the insurer's form, in plain English, with the evidence to back it up.

Start a Health Check or call 1300 856 912