All insights
Cyber compliance

AI has made your practice worth attacking properly. Here is how to check where you stand.

Australia's signals directorate has published guidance on how AI is changing cyber attacks, written jointly with the Australian Institute of Company Directors. It is addressed to board directors and senior leaders.

Nathan James
Founder, Worktopia
5 August 20267 min read
ASD with the AICD, August 2026
What changed is the price of attacking you.

Most of what they recommend is not new, which is the part almost nobody will report. Below there are two things you can check yourself, one to ask, and the questions to put to whoever runs your IT.

Start with the attack that actually costs firms money

It is not exotic. It is a compromised mailbox leading to a redirected payment. Someone watches the email traffic long enough to learn how your firm talks about invoices and trust disbursements, then sends a message at exactly the right moment, in exactly the right voice, with different bank details.

Every step of that is something frontier AI does well. Reading a mailbox and summarising who pays whom, when. Matching a writing style closely enough that a partner does not blink. Choosing the moment.

A practice holds tax file numbers, bank details, financials and a direct line into client money movements. That has always made you a high-consequence target. What changes is the economics. Attacking a small practice properly used to require skill that was better spent on bigger targets, and frontier AI sharply lowers that barrier.

What the ASD says, and what it means for you

The ASD says frontier AI has the potential to cut vulnerability discovery and exploitation timelines “from days to hours”. The part that should land hardest for a small firm is who gets to do it: this capability now reaches “malicious actors that previously lacked the knowledge or skills to perform such activities”.

Their answer is less dramatic than the threat. The immediate priorities are patching, and keeping systems configured the way they are supposed to be. Everything else they want in the short term is just as familiar: who can sign in to what, who has more access than they need, systems too old to be secured properly, and a plan that has actually been tested.

That is broadly the ground the Essential Eight already covers, the ASD's own baseline set of eight mitigation strategies. Their own threshold question points the same way: “Do we have control over our cyber security fundamentals, such as adherence with a recognised cyber security framework?”

Which is a smaller claim than it sounds, and a more useful one. Nothing about the near-term defence has been reinvented. Further out they do want something genuinely new, AI used for your own cyber defence, but that is the next conversation rather than this one. What has changed is the price of attacking you, and when attacks get cheaper the unglamorous basics start carrying weight they did not have to carry before.

Two things you can check yourself, and one to ask

You do not need us for this, and you should not have to take anyone's word for where you stand.

1
Is your practice software login shared?
Does more than one person use the same credentials for your practice management system, and is that password written down anywhere a staff member can read it? If your staff can see and copy it, that is the first weakness anyone finds.
2
How do you sign in to Microsoft 365 or Google Workspace?
If your second factor is a code you read off an app or a text message, or a notification you tap to approve, that is not phishing-resistant. A passkey, Windows Hello for Business, or a physical security key is. Every account with access to client information should be on one.
3
Would you know if a mailbox was taken over?
Ask whoever runs your IT one question: if a staff mailbox were compromised tomorrow, what would tell us, and how quickly. If the answer is that someone would probably notice something odd, you have your finding.

There is usually nothing to buy. A passkey uses the phone or laptop your staff already carry, so the cost is the afternoon of enrolment, not hardware. Physical security keys, if you want them for partner or administrator accounts, start from about fifty dollars. The one thing that can cost you is your licence tier. On Microsoft 365, enforcing phishing-resistant sign-in across the firm needs Business Premium rather than Business Standard. Check which one you are on before you tell the partners it is free.

If all three are fine, you are in better shape than most practices. If one is not, that is the thing to fix before anything else.

The aftermath, which is the expensive part

The attack is not the thing that costs you. The aftermath is.

If client information is exposed and the breach is likely to cause serious harm, you have notification obligations, to the affected clients and to the Office of the Australian Information Commissioner.

A practice that has ever turned over more than three million dollars is covered for everything it holds. Below that, the small business exemption still applies to most information, but not to tax file numbers, which sit outside it regardless of turnover. A compromised mailbox at an accounting practice almost always has TFNs in it. And since 1 July 2026, practices providing designated services under the AML/CTF tranche 2 reforms are reporting entities, which brings the Australian Privacy Principles to that part of the business as well.

Then there is your professional indemnity insurer, who will want to know what controls you had, and your own clients, several hundred of whom will receive a letter with your name at the top. Worth knowing which policy does what: professional indemnity covers a claim made against you. The cost of the notification exercise itself, the forensics and the legal advice, is cyber cover, which is usually a separate policy or a separate section of your PI policy, and cyber is not mandatory the way PI is.

That is the real reason the boring controls matter. Not because an attacker is clever, but because “we had shared passwords and no way to tell a mailbox had been taken over” is a bad sentence to have to write several hundred times.

Questions worth putting to whoever runs your IT

The ASD gives directors sixteen threshold questions. Four of the five below come from that list. The first one does not, and is the question we would start with. Each has a note on what a good answer sounds like, because a confident technical answer is not the same as a good one.

What is our weakest point if someone gets into a mailbox?
A good answer names specific systems, not categories. If you hear “the network”, ask which server, which mailbox, and what is on it.
Where could minor weaknesses in our systems and cyber supply chain be combined into a major incident?
A good answer describes a chain, not a list. Someone who has thought about this can walk you from a small gap to a bad day.
Are we relying on vendors without enough oversight, including an understanding of their foreign ownership, control or influence?
A good answer includes a list of every app and tool connected to your Microsoft or Google account, and when it was last reviewed.
If attacks moved from taking days to hours, could we still detect and respond?
A good answer gives you a time and says how it is measured. For a practice your size, detection inside an hour and a response the same day is a reasonable bar. Days is not.
Have our incident response and continuity plans been tested against this?
A good answer names a date and what broke on the day. Plans that have never been tested have never failed, which is not the same as working.

If your provider answers those well, you are in good shape on the things the ASD is pointing at, and you do not need to do anything else about this. That is a real outcome and it is the one we would expect from a practice that has been well looked after.

If the answers are thin, the gap is usually not competence. It is that nobody has asked them to look at this yet. So ask, in writing, for three things: a detection and response time you can hold them to, a passkey rollout scheduled for a week that is not in lodgement season, and a list of what is connected to your Microsoft or Google account with a date against when it was last reviewed. A good provider will be glad of the prompt. You do not need to change anyone to get this done.

Read next
Do accounting firms need client consent to use AI?
Read it →

Common questions

How is AI changing cyber attacks?
According to ASD guidance published in August 2026, frontier AI has the potential to cut vulnerability discovery and exploitation timelines from days to hours, to chain multiple low severity weaknesses into high-impact compromises, and to run malicious activity with little to no human oversight. It also puts that capability in the hands of attackers who previously lacked the knowledge or skills.
Are small accounting firms actually at risk from AI-enabled attacks?
The risk changes in economics rather than in kind. A practice already holds the data attackers want. What frontier AI lowers is the cost and skill barrier that made sophisticated attacks uneconomic against smaller targets, so a small firm becomes worth attacking properly.
What should a firm do about AI-enabled cyber threats?
The ASD's immediate priorities are secure configuration baselines and timely patching. Its short-term priorities are legacy systems, identity and access management, least privilege, and tested incident response. Over the medium term it also asks organisations to adopt AI for their own cyber defence. Most of the near-term work is the security fundamentals a practice should already recognise.
What is phishing-resistant multi-factor authentication?
MFA that cannot be defeated by tricking a user into handing over a code or approving a prompt, so passkeys or security keys rather than SMS codes or push notifications. The ASD calls for it for users authenticating to systems, including from untrusted, external or high-risk locations, and it is also the bar the Essential Eight sets above its first maturity level.
Does this guidance apply to AI tools my own firm uses?
Yes, in two ways. The guidance asks that privileges be restricted for personnel and services including AI agents, treating them as identities to be governed. It also asks directors about reliance on vendors, including an understanding of their foreign ownership, control or influence. So your firm's own AI adoption sits inside the same governance conversation as the threat.
Nathan James
Founder, Worktopia
Nathan started Worktopia after years inside a Brisbane accounting firm, moving it off legacy systems and into the cloud. He writes about the practical side of security and IT for practices that would rather be doing the work.
Kip, the Worktopia mascot, holding a shield
See where you stand

Start with what you can actually measure

If those checks turned something up, or you would rather not guess, our free Cyber Compliance Health Check scores your firm against the fundamentals the ASD is pointing at and shows you the gaps in plain English. Read-only. Nothing in your systems changes. You approve access, and revoke it any time.

Book your free Health Check or call 1300 856 912