Cyber Security: Practical Steps to Build a More Resilient Firm

Cover Image for Cyber Security: Practical Steps to Build a More Resilient Firm

| Courtney Price

Accountancy firms hold valuable financial data and occupy trusted positions in client networks. Strong cyber resilience therefore depends on people, technology and recovery planning working together.

Cyber security is not only an IT issue for accountancy firms. It is a business continuity issue.

Accountants and bookkeepers handle financial records, payroll information, tax data and payment details. They also communicate regularly with clients about sensitive financial matters.

That combination creates opportunities for criminals. As Richard Morrison Butcher explained during a webinar on cyber resilience, attackers can exploit both technical weaknesses and everyday human decisions.

For smaller practices, the practical response is not to eliminate every possible threat. It is to reduce common vulnerabilities, make attacks harder and prepare the firm to recover when something goes wrong.

1. Treat people as part of your cyber controls

One case study discussed during the webinar involved a manufacturing business whose employee used a work laptop to stream a boxing match.

Software downloaded to watch the event contained ransomware. When the laptop returned to the workplace, the ransomware activated and caused extensive damage to the company's infrastructure.

The wider lesson applies directly to accountancy practices.

Remote and hybrid working can blur the boundary between business and personal technology. A secure device can become vulnerable through an apparently ordinary decision.

That makes cyber awareness training an operational control rather than a compliance exercise.

Your team should understand how to recognise suspicious messages, handle unexpected downloads and respond to requests for sensitive information.

Policies covering personal use of work devices, remote working and bring-your-own-device arrangements should also reflect how people actually work.

2. Make phishing harder to succeed

Phishing remains a central theme in cyber attacks because criminals can target people directly.

Artificial intelligence is making impersonation more convincing. The webinar highlighted voice cloning and increasingly sophisticated social engineering as emerging concerns.

Traditional warning signs may therefore become less reliable.

One practical principle remains useful: verify an unusual or sensitive request through another trusted channel.

If an email asks you to change bank details, for example, do not rely solely on the email thread. Contact the person using previously verified contact details.

The same principle applies to unexpected requests for credentials, confidential documents or payments.

Pressure matters too. Accountancy firms have predictable periods when teams work quickly and at volume. Criminals can exploit that environment because people have less time to question apparently routine instructions.

3. Use layers of protection rather than relying on passwords

Strong, unique passwords remain useful, but passwords should not stand alone.

The webinar highlighted multi-factor authentication (MFA), software updates, endpoint protection, network monitoring and access controls as important layers of defence.

MFA is particularly relevant when an attacker obtains or tricks somebody into revealing a password. Requiring another authentication factor creates an additional obstacle.

Practices should also identify outdated technology and keep operating systems, browsers and other software updated.

The principle is straightforward: a criminal should not be able to move freely through your systems because one control has failed.

4. Protect your most important data

The British Library ransomware attack provided another case study during the session.

The discussion highlighted the importance of network segmentation, access controls and additional protection around particularly sensitive information.

Accountancy firms can apply the same principle without becoming cyber-security specialists.

Start by identifying the systems and information that would cause the greatest damage if they became unavailable, altered or stolen.

That could include client financial information, payroll records, practice-management systems or credentials giving access to other platforms.

Then consider who genuinely needs access and what additional controls protect those assets.

This approach shifts the question from simply asking, "Are we secure?" to a more useful question: "What information matters most, and how well are we protecting it?"

5. Plan for recovery as well as prevention

No security control can make a business immune to attack.

That means cyber resilience must include recovery.

Your business continuity plan should explain what happens when important systems become unavailable. It should identify responsibilities, critical systems and the information needed to continue essential work.

The webinar also raised an important practical test: can the plan actually be used during an incident?

A document that looks comprehensive on paper may provide little help if staff cannot access it when systems are unavailable.

Review and test your recovery arrangements periodically. Consider how the practice would communicate, access essential information and continue priority work during disruption.

6. Consider Cyber Essentials and the Cyber Action Toolkit

The webinar encouraged smaller businesses to consider Cyber Essentials, the UK government-backed cyber-security scheme covering fundamental technical controls.

For businesses that are not ready to pursue Cyber Essentials, the session also highlighted the National Cyber Security Centre's Cyber Action Toolkit as a way to assess and improve cyber practices progressively.

The important point is to choose a practical starting point.

A sole practitioner may have different resources from a 100-person firm. Both can still review their vulnerabilities, improve authentication, train people and strengthen recovery arrangements.

Cyber resilience should develop alongside the business rather than waiting until an incident forces the issue.

What should an accountancy firm do first?

Start with the controls most closely connected to everyday risk.

Review how staff recognise and verify suspicious requests. Check where MFA is enabled. Make sure software and devices are being updated. Identify your most important data and systems.

Then look at recovery. Ask what would happen tomorrow if a critical platform suddenly became unavailable.

For accountancy practices, cyber security is ultimately about maintaining trust and keeping the firm operational. The strongest approach combines trained people, sensible technical controls and a recovery plan that works when you need it.

Frequently asked questions about cyber security for accountants

Why are accountancy firms attractive targets for cyber criminals?

Accountancy firms hold sensitive financial information and often have trusted access to client systems and communications. They may handle payroll, tax records, bookkeeping data and financial transactions. Compromising an accountancy practice can therefore expose valuable information or potentially create opportunities for further attacks. Smaller firms should not assume their size makes them unattractive to criminals.

What is the most important cyber-security control for a small accountancy practice?

There is no single control that removes cyber risk. The webinar emphasised a combination of staff awareness, multi-factor authentication, software updates, access controls and recovery planning. A useful starting point is to examine how easily an attacker could exploit a staff member, compromised password or outdated device, then strengthen the weakest areas.

How can accountants protect themselves against AI-enabled phishing?

Treat unusual requests as something to verify rather than something to trust automatically. AI can make emails, messages and even cloned voices more convincing. When somebody requests sensitive information, changed payment details or another unusual action, confirm the request through a separate trusted channel. Staff also need current awareness training as attack methods change.

What is multi-factor authentication and why does it matter?

Multi-factor authentication requires another form of verification in addition to a password. This creates an extra barrier if a criminal obtains login credentials. Accountancy practices should review important systems and accounts to understand where MFA or other stronger authentication methods are available and whether they have been enabled appropriately.

What should a cyber incident recovery plan cover?

A useful recovery plan identifies critical systems, responsibilities and the actions required to continue essential work during disruption. It should also consider how staff communicate and access necessary information if normal systems are unavailable. The webinar stressed that recovery planning deserves attention alongside prevention. Practices should test whether their plans can be followed under realistic conditions.

What is Cyber Essentials?

Cyber Essentials is a UK government-backed scheme designed around fundamental technical controls that help organisations protect themselves against common cyber attacks. The webinar encouraged SMEs to consider it as a baseline for improving cyber security. Firms that are not yet ready for Cyber Essentials can also investigate the National Cyber Security Centre's Cyber Action Toolkit as a structured starting point.

The contents of this article are meant as a guide only and are not a substitute for professional advice. The author/s accept no responsibility for any action taken, or refrained from, as a result of the material contained in this document. Specific advice should be obtained before acting or refraining from acting, in connection with the matters dealt with in this article. The information at the time of publishing was accurate and could be subject to final changes.

Image of Courtney Price

About the Author

Courtney Price is a content creator for CPDStore UK. Courtney joined us during the COVID-19 pandemic and has been involved in the ever-evolving world of accounting ever since. Her passion for reading and writing, coupled with her degree in copywriting from Vega School has allowed her to channel her creativity and expertise into crafting engaging and informative content.