Ask what the Tax Practitioners Board requires of your firm's cyber security and you get a surprising answer: no specific technology, ever. What it does require is sharper, and it starts counting in days.
There is no TPB rule that says “have cyber security”. Not one technical control, from antivirus to multi-factor authentication, is mandatory under the Code of Professional Conduct. What binds you sits around the technology instead. The law says you must not disclose client information without permission. The TPB requires you to verify who your clients are and keep records proving it. And from 1 July 2024, you must notify the TPB in writing within 30 days of having reasonable grounds to believe a significant breach of the Code has occurred. A cyber incident can trip every one of those at once. That is the real shape of the obligation, and it is easy to get wrong in both directions.
Confidentiality. Code item 6 is statutory and blunt: “Unless you have a legal duty to do so, you must not disclose any information relating to a client's affairs to a third party without your client's permission.” A third party includes cloud storage providers and software vendors, so where your data sits and who can reach it is a compliance question, not just an IT one. We have written separately about how this plays out with AI tools.
Proof of identity. The TPB requires identity checks before you provide tax agent or BAS services, with set minimums for what you sight. It also requires something most firms find counterintuitive: you keep a record of the check, not the documents. Its proof-of-identity guidance, TPB(GS) 42/2022, says the TPB does not require or recommend retaining copies of client IDs, because holding them makes your firm a better target for identity theft. The contemporaneous record of each check must be kept for at least five years after the engagement ends.
Breach notification, with a clock. Since 1 July 2024, a registered practitioner must notify the TPB in writing within 30 days of the day they first have, or ought to have, reasonable grounds to believe they have breached the Code and the breach is significant. A parallel duty covers significant breaches you believe another registered practitioner has committed. Two details matter. The clock starts at reasonable grounds, not at the incident, and not at certainty. The TPB has no power to extend it. There is no standalone duty to report cyber attacks to the TPB, but an incident that exposes client information can be exactly the kind of significant Code breach the duty covers. The TPB's own guidance gives the example of a disclosure that later leads to client identity theft, and a case study of shared login credentials reported within 30 days.
Records and systems. The 2024 Code Determination adds statutory duties to keep proper client records for at least five years and to establish, document and enforce a quality management system. The word cyber appears nowhere in it. Protecting confidentiality shows up in the explanatory note on quality management, which is exactly the level the TPB works at: it regulates outcomes, not tools.
The TPB's technical advice is genuinely modest. Its cyber guidance page offers a six-item list it frames as minimum “best practice”: antivirus, firewalls, current security patches, encryption where possible, regular password changes, and considering a second form of authentication. Recommendations, all of them. The same is true of the fuller ICT lists in its guidance statements, of cyber insurance (explicitly not a requirement), and of the strong recommendation to move sensitive documents through secure channels rather than plain email, which is discouraged but not banned.
If your firm measures itself against the ACSC's Essential Eight or is working toward SMB1001 certification, you are already operating well above the TPB's stated floor. The TPB itself mentions the Essential Eight only in passing, in a webinar.
“It's only recommended” is cold comfort, and the reason sits on the TPB's own data breach page. When an incident happens, the questions the TPB says it will ask are: did the practitioner take reasonable steps to have sufficient IT controls in place, and was the practitioner reckless in their approach to cyber security? A practitioner found “incompetent or reckless regarding IT controls” whose lapse breached confidentiality can face Code sanctions, which in past identity-related cases have run as far as termination of registration.
So the best-practice list is not really optional. Before an incident, the six controls are recommendations. After one, they become the reference point for the reasonable steps you did or did not take, and the TPB judges each situation case by case. The Notifiable Data Breaches scheme runs in parallel and belongs to the OAIC, not the TPB. Eligible breaches are notified to the OAIC and affected individuals, while the TPB separately considers whether the same event breached the Code.
The breach notification duty applies to conduct from 1 July 2024. The 2024 Code Determination's obligations applied from 1 January 2025 for larger practices and 1 July 2025 for practices with 100 or fewer employees as at 31 July 2024. In April 2026 the TPB renamed its practice notes and information sheets to guidance statements; the documents behind this article are TPB(GS) 42/2022 (proof of identity), TPB(GS) 26/2014 (confidentiality) and TPB(GS) 48/2024 (breach reporting). If advice you are reading still calls these documents practice notes or information sheets, it was written before April 2026.
In our experience the firms that struggle here spend plenty on security. What they lack is the connective tissue the actual obligations describe: knowing where client information lives, who can reach it, what would count as a disclosure, and who starts the 30-day clock when something looks wrong. That is a systems-and-ownership problem before it is a technology problem, and it is why we run cyber security for accounting and advisory firms as the whole job rather than a product list.