IT security for accountancy practices: protecting client data and keeping deadlines on track

A practical guide for small accountancy and bookkeeping practices: protecting client data, stopping payment-detail fraud, backing up the right systems and keeping IT running through the busy season.

The short answer: most small accountancy and bookkeeping practices don’t need an elaborate security programme. They need a handful of habits done consistently: multi-factor authentication (MFA) on every account, access to client files matched to each person’s role, a fixed rule for checking any change to bank details, a secure way to exchange documents with clients, and backups that cover every place your data lives, with tested restores. Put those in place before the autumn rush and both client data and deadlines are on firmer ground.

This guide to IT security for accountancy practices is for partners and practice managers in firms of 5 to 50 people, whether you’re in Meath, elsewhere in the North East or in Dublin.

Why accountancy practices need to take particular care

A typical practice holds PPS numbers, payslips, bank statements and tax returns for hundreds of people and businesses. It also sits close to money: refunds, payroll runs and supplier payments. Add hard filing dates and a busy team, and an urgent-sounding request is more likely to be acted on without a second look. That calls for a few clear rules everyone follows, partners included.

Protecting confidential tax, payroll and client files

Start by writing down where client data lives. For most firms that’s Microsoft 365, one or more accounting and payroll applications, a practice management system, and often folders on a local server or individual PCs.

Permissions and MFA

  • Turn on MFA for every mailbox, every accounting or payroll login that supports it, and every administrator account.
  • Give people access to the client folders and payroll files their role requires, not the whole practice drive.
  • Keep administrator rights to a small number of named people, using separate admin accounts.

Joiners, leavers and role changes

Many access problems start with a missed step when someone joins, leaves or changes role. Use a short checklist each time: create or remove the Microsoft 365 account, update access in each accounting app, recover devices, and change any shared passwords the person knew.

Phishing, impersonation and fraudulent payment changes

Accountancy staff receive official-looking messages every day, so impersonation is the risk to plan for. Revenue says it does not correspond with customers through traditional email or SMS and uses MyEnquiries for secure correspondence. A message claiming to be from Revenue and asking for personal information is a scam.

The costlier version is a request to change bank details for a refund, a supplier invoice or a salary. Ireland’s National Cyber Security Centre lists supplier fraud and payroll diversion among the common forms of business email compromise.

Hypothetical example

A week before a payroll run, a bookkeeper gets an email apparently from a long-standing client, asking that an employee’s wages go to a new account. The address is one letter off. Because the practice confirms every bank-detail change by phone on a number already on file, the bookkeeper calls the client, the request is exposed, and nothing is paid.

Make that rule formal: no change to bank details without a call to a number you already hold, and a second person signing off. Pair it with short, regular phishing awareness sessions. We cover more warning signs in our article on AI-assisted phishing.

If client personal data is exposed, the Data Protection Commission expects a notifiable breach to be reported without undue delay and, where feasible, within 72 hours of becoming aware of it. Know in advance who in the practice makes that call.

Requesting, receiving and sharing client documents securely

Email attachments are hard to control once sent. Revenue’s own guidance warns against sending personal or confidential information by standard email. Better options:

  • A client portal, or the upload feature in your practice software, for incoming documents.
  • SharePoint or OneDrive links limited to named people, with an expiry date, for outgoing documents.
  • A note in engagement letters telling clients how you will, and won’t, ask for documents.

Keeping PCs and accounting apps available in busy periods

For the 2025 Form 11, the pay and file date is 31 October 2026, extended to 18 November 2026 for those who both pay and file through ROS, according to Revenue. That’s not the week to discover a laptop won’t start.

  • Schedule Windows and application updates well before your busiest weeks, then keep changes to a minimum.
  • Replace or repair ageing PCs over the summer, not in October.
  • Check accounting software licences won’t lapse mid-season.
  • Keep a spare, set-up laptop so one fault doesn’t stop someone for days.

Backup and tested recovery: start with where your data lives

Your backup needs depend on where your data is stored. A Microsoft 365 backup covers Microsoft 365 data such as email, OneDrive and SharePoint. It does not automatically cover desktop accounting databases on a server or PC, files saved locally, or every cloud platform you use. Cloud accounting providers have their own arrangements, so check what they keep and what you can export.

For each system, ask: is it backed up, where is the copy, and when was something last restored from it? The Data Protection Commission’s data security guidance refers to restoring access to personal data in a timely way, which only testing can show. Read more about our backup and recovery service.

Secure remote working

Use practice-managed laptops with disk encryption and automatic updates, require MFA for remote access, and keep client files in Microsoft 365 or your practice software rather than on USB keys or personal devices. Our guide to security practices for remote workers goes into more detail.

Working with your accounting-software vendors

Your software vendors know their products best; your IT provider looks after the PCs, network, Microsoft 365 accounts and security those products depend on. Agree who does what, keep vendor contacts and licence details in one place, and plan major upgrades together so they don’t land in a busy month.

A practical checklist for practice managers

  • List every system that holds client data and who has access to each.
  • Confirm MFA is on for all email, accounting, payroll and admin accounts.
  • Adopt a written call-back and two-person rule for bank-detail changes.
  • Choose one secure method for receiving and sharing client documents, and tell clients.
  • Use a joiner/leaver checklist and review access twice a year.
  • Check what each backup covers, including accounting data and local files.
  • Carry out a test restore and record the result.
  • Finish updates and hardware replacements before the autumn deadlines.
  • Keep a contact list for your IT provider and software vendors.
  • Agree who decides whether a data breach must be reported to the DPC.

How Sweeney Computer Services can help

Founded in 1985 and based in Hurdlestown, Co. Meath, we support more than 50 businesses and over 10 schools. Silver starts from €45 and Gold from €70 per user per month, excluding VAT; Microsoft 365 licences are charged separately. Both include Microsoft 365 backup of email, OneDrive and SharePoint, with restores tested every two weeks and records available on request. Device and server backup is scoped in each proposal. Gold adds email security, phishing training and 24/7 security monitoring through our partner, separate from our Monday to Friday, 9am to 5:30pm helpdesk. See our cyber security services for more.

more insights