All insights
Cyber

What the TPB actually requires on cyber security

Ask what the Tax Practitioners Board requires of your firm's cyber security and you get a surprising answer: no specific technology, ever. What it does require is sharper, and it starts counting in days.

Nathan James
Founder, Worktopia
21 August 20266 min read
Tax Practitioners Board
The clock starts at reasonable grounds, not at the incident, and not at certainty.

The short answer

There is no TPB rule that says “have cyber security”. Not one technical control, from antivirus to multi-factor authentication, is mandatory under the Code of Professional Conduct. What binds you sits around the technology instead. The law says you must not disclose client information without permission. The TPB requires you to verify who your clients are and keep records proving it. And from 1 July 2024, you must notify the TPB in writing within 30 days of having reasonable grounds to believe a significant breach of the Code has occurred. A cyber incident can trip every one of those at once. That is the real shape of the obligation, and it is easy to get wrong in both directions.

What is actually mandatory

Confidentiality. Code item 6 is statutory and blunt: “Unless you have a legal duty to do so, you must not disclose any information relating to a client's affairs to a third party without your client's permission.” A third party includes cloud storage providers and software vendors, so where your data sits and who can reach it is a compliance question, not just an IT one. We have written separately about how this plays out with AI tools.

Proof of identity. The TPB requires identity checks before you provide tax agent or BAS services, with set minimums for what you sight. It also requires something most firms find counterintuitive: you keep a record of the check, not the documents. Its proof-of-identity guidance, TPB(GS) 42/2022, says the TPB does not require or recommend retaining copies of client IDs, because holding them makes your firm a better target for identity theft. The contemporaneous record of each check must be kept for at least five years after the engagement ends.

Breach notification, with a clock. Since 1 July 2024, a registered practitioner must notify the TPB in writing within 30 days of the day they first have, or ought to have, reasonable grounds to believe they have breached the Code and the breach is significant. A parallel duty covers significant breaches you believe another registered practitioner has committed. Two details matter. The clock starts at reasonable grounds, not at the incident, and not at certainty. The TPB has no power to extend it. There is no standalone duty to report cyber attacks to the TPB, but an incident that exposes client information can be exactly the kind of significant Code breach the duty covers. The TPB's own guidance gives the example of a disclosure that later leads to client identity theft, and a case study of shared login credentials reported within 30 days.

Records and systems. The 2024 Code Determination adds statutory duties to keep proper client records for at least five years and to establish, document and enforce a quality management system. The word cyber appears nowhere in it. Protecting confidentiality shows up in the explanatory note on quality management, which is exactly the level the TPB works at: it regulates outcomes, not tools.

What is recommended but not required

The TPB's technical advice is genuinely modest. Its cyber guidance page offers a six-item list it frames as minimum “best practice”: antivirus, firewalls, current security patches, encryption where possible, regular password changes, and considering a second form of authentication. Recommendations, all of them. The same is true of the fuller ICT lists in its guidance statements, of cyber insurance (explicitly not a requirement), and of the strong recommendation to move sensitive documents through secure channels rather than plain email, which is discouraged but not banned.

If your firm measures itself against the ACSC's Essential Eight or is working toward SMB1001 certification, you are already operating well above the TPB's stated floor. The TPB itself mentions the Essential Eight only in passing, in a webinar.

How best practice turns enforceable after an incident

“It's only recommended” is cold comfort, and the reason sits on the TPB's own data breach page. When an incident happens, the questions the TPB says it will ask are: did the practitioner take reasonable steps to have sufficient IT controls in place, and was the practitioner reckless in their approach to cyber security? A practitioner found “incompetent or reckless regarding IT controls” whose lapse breached confidentiality can face Code sanctions, which in past identity-related cases have run as far as termination of registration.

So the best-practice list is not really optional. Before an incident, the six controls are recommendations. After one, they become the reference point for the reasonable steps you did or did not take, and the TPB judges each situation case by case. The Notifiable Data Breaches scheme runs in parallel and belongs to the OAIC, not the TPB. Eligible breaches are notified to the OAIC and affected individuals, while the TPB separately considers whether the same event breached the Code.

Dates worth knowing

The breach notification duty applies to conduct from 1 July 2024. The 2024 Code Determination's obligations applied from 1 January 2025 for larger practices and 1 July 2025 for practices with 100 or fewer employees as at 31 July 2024. In April 2026 the TPB renamed its practice notes and information sheets to guidance statements; the documents behind this article are TPB(GS) 42/2022 (proof of identity), TPB(GS) 26/2014 (confidentiality) and TPB(GS) 48/2024 (breach reporting). If advice you are reading still calls these documents practice notes or information sheets, it was written before April 2026.

Where this leaves a firm

In our experience the firms that struggle here spend plenty on security. What they lack is the connective tissue the actual obligations describe: knowing where client information lives, who can reach it, what would count as a disclosure, and who starts the 30-day clock when something looks wrong. That is a systems-and-ownership problem before it is a technology problem, and it is why we run cyber security for accounting and advisory firms as the whole job rather than a product list.

Related reading: Your engagement letter probably doesn't mention AI. After the TPB's new guidance, that's a problem.
Related reading: SMB1001 vs the Essential Eight: why your firm needs both

Common questions

Does the TPB require cyber security?
Not as a specific technical standard. No TPB rule mandates antivirus, firewalls, MFA or any named control. The TPB's six-item list is described as best practice. The binding obligations are confidentiality of client information (Code item 6), proof of identity checks with five-year records, proper client records, a documented quality management system, and notifying significant Code breaches within 30 days.
Do I have to report a cyber attack to the TPB?
Not automatically. There is no standalone duty to report cyber incidents to the TPB. The duty is to notify a significant breach of the Code within 30 days of having reasonable grounds to believe one occurred, and a cyber incident that exposes client information can qualify. Eligible data breaches are separately notifiable to the OAIC under the Notifiable Data Breaches scheme, which the TPB does not administer.
When does the 30-day notification period start?
The 30-day period runs from the day the practitioner first has, or ought to have, reasonable grounds to believe a significant breach of the Code has occurred. It does not run from the date of the incident, and the TPB has no power to extend it.
Does the TPB require the Essential Eight or MFA?
No. The TPB mentions the Essential Eight only as an ACSC reference in webinar material, and describes a second form of authentication as something to consider. In practice, firms treat the TPB's list as a floor, because cybersecurity that stops at antivirus and passwords would not answer the questions the TPB asks after an incident.
Should we keep copies of client identity documents?
No. The TPB does not require or recommend retaining copies or originals of identity documents, because holding them increases identity theft risk. It requires a contemporaneous record of each check, kept for at least five years after the engagement ceases.
Nathan James
Founder, Worktopia
Nathan started Worktopia after years inside a Brisbane accounting firm, moving it off legacy systems and into the cloud. He writes about the practical side of security and IT for practices that would rather be doing the work.
Kip, the Worktopia mascot, holding a shield

Know where your obligations meet your systems.

The TPB's questions after an incident are about your controls, your records and your response. Our Cyber Compliance Health Check shows where your firm stands before anyone else asks.

Start a Health Check or call 1300 856 912