Why Accounting Firms Are Attractive Targets for Cyber Attacks
Not too long ago, a local accounting firm that we won’t name (they are not a client; this story was told to us by one of their workers) got hacked and their computers locked up by a blackmailer. Their IT guy eventually got their machines unlocked, and they hid the hack from their clients because they did not want anyone to know their clients' information had been hacked.
This kind of “let’s not spend money on cybersecurity and try to sweep it under the rug if something happens” attitude, along with the sensitive information they have access to, is exactly why accounting firms are major targets for bad actors.
Here are the main reasons accounting firms need to start taking cybersecurity seriously.
1. Accounting Firms Hold a High Concentration of Valuable Data
Most businesses only hold detailed financial information about themselves. Accounting firms hold it for many businesses and individuals. That creates concentration risk. A compromised email account, laptop, file server, cloud storage system, or client portal may provide access to:
- Tax returns.
- Payroll information.
- Banking details.
- Financial statements.
- Corporate ownership information.
- Personal identification documents.
- Estate and trust records.
- Client correspondence.
From an attacker's perspective, compromising one accounting firm can potentially provide access to the financial information of many organizations at once. That makes the firm itself an attractive target.
2. Attackers Can Exploit the Firm's Trusted Relationships
Accounting firms regularly communicate with clients about highly sensitive financial matters. They may also interact with banks, payroll providers, government agencies, lawyers, and other financial institutions. That trust creates another attack opportunity. If an attacker gains access to an accountant's email account, they do not necessarily need to steal files immediately. They may simply watch the mailbox. They can learn how the accountant communicates, who approves payments, which clients are expecting transactions, and what normal requests look like. The attacker can then send a message that appears completely legitimate as part of a long con.
This is why email security is so important in accounting firms. The value of the account is not just the information inside it, but the trust associated with the person sending the message.
3. Many Firms Have Small-Business Security With Enterprise-Level Data
This is one of the biggest mismatches in the industry. Many accounting practices are relatively small organizations, with 10, 20, or 50 employees and limited internal IT resources.
However, the data they manage may belong to companies that are much larger than they are. That means a relatively small accounting firm can hold extremely sensitive information while operating with the technology infrastructure and cybersecurity budget of a small business.
Attackers understand this and use it for leverage. They know that they do not always need to attack the largest company directly if they can gain access through one of its trusted advisers instead.
That is why accounting firms should think about security based on the sensitivity of the information they hold, not simply the size of their own organization.
4. Tax Season Creates an Ideal Environment for Social Engineering
Cyber attacks often succeed because someone is busy, distracted, or under pressure, and accounting firms have predictable periods when all three conditions exist during tax season. During tax season, employees are dealing with large volumes of emails, documents, deadlines, client questions, and filing requirements.
That creates a perfect environment for phishing and social engineering. A message referencing a tax filing, government portal, client document, payroll issue, or financial software platform may not look unusual when employees are already processing hundreds of similar requests.
The more pressure employees are under, the easier it becomes to click the wrong link, open the wrong attachment, or respond to a request without verifying it properly. Security procedures therefore become even more important during the periods when the firm is busiest.
Understand the Most Common Ways an Attack Can Happen
Here are a few ways malicious actors may attack accounting firms:
a) Business Email Compromise: An attacker gains access to an employee's email account and uses it to impersonate the employee, request sensitive information, or redirect payments. This can be especially dangerous because the fraudulent message comes from a legitimate email account.
b) Phishing: Employees receive messages designed specifically for accounting professionals. These may reference tax deadlines, CRA services, payroll issues, accounting software, document sharing, invoices, or client requests. The more relevant the message appears, the more likely someone is to interact with it.
c) Ransomware: Attackers encrypt or otherwise disrupt access to systems containing client files and demand payment. For an accounting firm, losing access to client records during a critical filing period can create enormous operational pressure.
d) Credential Theft: Passwords may be stolen through phishing, malware, password reuse, or compromised third-party services. Once an attacker has valid credentials, their activity can be much harder to distinguish from legitimate access.
e) Client Portal and File-Sharing:
Accounting firms regularly exchange sensitive documents with clients. If those documents are being transferred through poorly secured portals, email attachments, consumer file-sharing systems, or improperly configured cloud storage, the document exchange process itself can become a vulnerability.
6. Establish a Minimum Security Baseline
Cybersecurity does not need to start with an enormous enterprise security program. However, every accounting firm handling sensitive client information should have a strong baseline. Here is a quick list:
a) Require MFA Everywhere It Matters
Multi-factor authentication should be required on systems such as:
- Email.
- Practice management software.
- Cloud storage.
- Accounting platforms.
- Administrative accounts.
- Government portals.
- Banking and financial systems.
A stolen password should not be enough to give someone access to the firm's most sensitive systems.
b) Protect Every Device
Every computer that accesses client information should be centrally managed and protected.
That includes current security updates, endpoint protection, device encryption, appropriate user permissions, and the ability to respond quickly if a device is lost or compromised.
c) Maintain Reliable Backups
Critical data should be backed up somewhere that cannot easily be destroyed by the same attack that compromises the production environment.
The firm should also test restoration.
Having a backup is not the same thing as knowing you can recover from it.
d) Verify Financial Changes Outside Email
Any request to change banking or payment information should be independently verified. If a client emails new banking instructions, call the client using a known phone number before making the change. Do not use the phone number included in the suspicious email. A simple verification procedure can prevent a surprisingly expensive mistake.
e) Train Staff for the Attacks They Will Actually See
Generic cybersecurity training is better than nothing, but accounting employees should also be trained on scenarios that are specific to their work. That includes fake tax notices, document-sharing requests, payroll messages, invoice changes, executive impersonation, and fraudulent client instructions. People are more likely to recognize an attack when the training looks like the situations they encounter every day.
f) Review Cyber Insurance
Cyber insurance should also be reviewed as part of the firm's overall risk strategy. Management should understand what is covered, what is excluded, and what security controls the insurer expects the firm to maintain. Insurance is not a replacement for cybersecurity, but it can be an important part of the response if something does go wrong.
7. Prepare for the Possibility That Something Will Still Go Wrong
No security program reduces risk to zero. That means accounting firms also need to think about what happens after an incident. For example:
- Who gets called if an employee believes their account has been compromised?
- Can access be disabled quickly?
- Can the firm determine what information the attacker accessed?
- Can systems be restored from backup?
- Who communicates with affected clients?
- Who handles legal, insurance, and regulatory requirements?
The middle of an incident is a bad time to start answering those questions. And you definitely don’t want to do what that accounting firm did and just sweep things under the rug. A basic incident response plan can make the difference between a contained security event and a much larger operational problem.
The Real Risk Is Larger Than IT
A cybersecurity incident at an accounting firm can affect client relationships, professional liability, operations, reputation, insurance, and regulatory obligations. That is why the level of security should reflect the sensitivity of the information the firm holds. A 20-person accounting firm may be a small business, but it may still be responsible for protecting the financial information of hundreds of people and companies.
Smartt can help you build cybersecurity and IT environments appropriate for the data you manage. That includes identity and access security, endpoint protection, backups, cybersecurity policies, employee training, cloud security, monitoring, incident planning, and the underlying IT infrastructure that supports your firm. This way, we can make your firm significantly harder to compromise, reduce the likelihood that a single mistake becomes a major incident, and make sure the business can recover when something does go wrong. Get in touch for an initial assessment!