Accountants are attractive targets for cybercriminals for obvious reasons: they have access to client bank details, payroll records, tax credentials, and Companies House filing permissions. A breach doesn’t just expose the practice — it exposes every client the practice serves.
Yet many small accounting practices operate with the same security posture as a general small business, without recognising that the nature of the data they hold warrants additional measures. This guide is for sole-trader accountants, small partnerships, and bookkeepers who want to get this right.
Why Accountants Are Specifically Targeted
HMRC portal credentials give access to file returns, view PAYE records, and in some cases authorise repayments. If an attacker compromises an agent login, they can redirect client tax refunds or access years of financial history. HMRC fraud is a significant and growing problem.
Cloud accounting platforms — Xero, QuickBooks, Sage, FreeAgent — aggregate client financials in one place. A single set of compromised credentials can expose dozens of clients. Attackers who compromise an accountant’s login to Xero can see bank feeds, supplier details, payroll data, and cash balances across every client in that subscription.
Email is the primary attack vector. Accountants send and receive sensitive attachments constantly — bank statements, payroll files, accounts drafts. Attackers impersonate clients to intercept documents, or impersonate the accountant to redirect payments.
Invoice fraud (also called mandate fraud) particularly affects accounting practices. An attacker compromises email or spoofs a supplier, then sends a plausible “updated bank details” message at the moment when a payment is expected. Because accountants regularly handle payment instructions, the social context makes these attacks highly effective.
GDPR and ICO Obligations
Under GDPR, accountants are data controllers for the personal data of their clients and often joint controllers or processors for client employee data (payroll). This creates legal obligations:
- You must implement appropriate technical and organisational security measures
- A personal data breach that is likely to result in a risk to individuals must be reported to the ICO within 72 hours
- You must maintain records of processing activities
- You must register with the ICO and pay the data protection fee (£40–60/year for most small practices)
The ICO has enforcement powers and has issued fines to professional services firms for inadequate data protection. The monetary penalties are significant, but the reputational damage from a notifiable breach is often worse for a small practice that depends on client trust.
Your professional body — ICAEW, ACCA, CIMA, AAT, or the Institute of Certified Bookkeepers — will have sector-specific guidance on GDPR compliance for accounting practices. This is worth reading alongside generic ICO guidance.
Securing HMRC Agent Credentials
HMRC’s agent services are protected by Government Gateway credentials. These should be treated as some of the most sensitive credentials your practice holds.
- Use a dedicated email address for HMRC agent registrations that is separate from general practice email. This reduces exposure if your main email is compromised.
- Enable two-step verification (HMRC’s term for two-factor authentication) on your Government Gateway account. It’s available and should be mandatory.
- Never share Government Gateway credentials with staff via email or messaging apps. Use a password manager with granular sharing, and revoke access immediately when staff leave.
- Review the authorisations on your agent account regularly. Remove authorisations for clients you no longer act for.
- Be aware that HMRC will never call or email asking for your Government Gateway password or One Time Password. Any such request is a phishing attack.
Cloud Accounting Security
For Xero, QuickBooks, Sage, and similar platforms:
Multi-factor authentication is non-negotiable. Every platform supports it; all staff must use it. This alone prevents the majority of credential-stuffing attacks.
Role-based access control: staff should only have access to the clients they work on and the functions they need. A junior bookkeeper does not need admin access to your entire subscription.
Audit logs: Xero, QuickBooks Online, and Sage all maintain audit logs showing who accessed which records and when. Review these logs monthly. If you see access at unusual times or from unusual locations, investigate immediately.
OAuth app permissions: if you connect third-party apps to your accounting platforms (payroll integrations, bank feeds, receipt scanners), review what permissions they have. Remove connections to apps you no longer use. A compromised third-party app with access to your Xero account is as dangerous as a compromised password.
Client data segregation: where your platform allows it, confirm that staff members working on one client cannot accidentally access another client’s records.
Email Security
Given that email is both your primary business tool and your primary attack surface, email security deserves specific attention.
Enforce DMARC on your domain. If your practice domain doesn’t have a DMARC policy set to p=reject, attackers can send emails that appear to come from your domain. Your registrar or email provider can help with this; several will do it automatically if you’re using Microsoft 365 or Google Workspace with their domain management tools.
Train staff to verify bank detail changes. Mandate a callback to a previously known number before acting on any email requesting changes to supplier bank details or client payment instructions. This applies even when the email looks completely legitimate.
Treat unexpected attachments with suspicion. If a client sends an unexpected password-protected ZIP or an Office document you weren’t expecting, verify via a separate channel before opening. Malware delivery via email attachment remains the most common entry point for practice breaches.
Microsoft 365 or Google Workspace security settings: if you use either platform, review the security centre. Enable Safe Links and Safe Attachments in Microsoft Defender for Office 365 (included in M365 Business Premium). Enable Google Workspace’s advanced phishing and malware protection in the Admin console.
Secure Document Handling
Accountants send and receive sensitive documents constantly. Attaching payroll spreadsheets unencrypted to standard emails is common practice but represents real risk.
Consider:
- Secure client portals: Xero, QuickBooks, and dedicated client portal software (TaxCalc, CCH, Iris) allow clients to upload and download documents securely without sending them as email attachments. This is standard in larger practices and increasingly expected.
- Password-protected files for any sensitive document sent by email. The password should be communicated via a separate channel (SMS or phone), not in the same email.
- Secure file sharing via OneDrive (with access limited to the specific client) or a dedicated secure sharing service, rather than general email attachments.
Physical Security
Accounting documents — paper bank statements, signed accounts, payroll printouts — contain sensitive personal and financial data.
- Cross-cut shred (never strip-cut) all paper documents before disposal.
- Lock cabinets containing client files when the office is unattended.
- If you work from home, consider a locked filing cabinet and ensure your screen is not visible to others during video calls where financial data is displayed.
- Clear desk policy: don’t leave client documents visible on your desk between sessions.
Practical Starting Points
If you’re not sure where to start, work through these in order:
- Turn on MFA on all accounts — HMRC, Xero, QuickBooks, email, ICO portal
- Use a password manager for all practice credentials (Bitwarden is free and reliable for small practices)
- Enable DMARC on your domain
- Run NCSC’s free Cyber Essentials self-assessment — it’s a good baseline and the certification is recognised by clients and insurers
- Review your ICO registration and make sure your privacy notice is up to date
- Brief any staff or subcontractors on recognising phishing, particularly HMRC-spoofing phishing
The ICAEW’s Technology Faculty publishes cybersecurity guidance specifically for accounting practices and updates it regularly. ACCA and AAT have equivalent resources. These are worth bookmarking alongside the generic NCSC Small Business Guide.
Client trust is the core asset of an accounting practice. Protecting it means protecting the data they’ve entrusted you with.