How should a small Irish accountancy practice set up secure remote working for busy season?

How small Irish accountancy and bookkeeping practices can set up secure remote and hybrid working for busy season, from ROS certificates to lost laptops.

The short answer: secure remote working in an accountancy practice comes down to five habits. First, staff reach practice software and client files through secure sign-ins, so nobody copies files home. Each person also has their own ROS sub-user certificate, kept only on a practice laptop. Multi-factor authentication (MFA) covers every account. Practice-managed, encrypted laptops replace shared home PCs. Finally, everyone knows exactly what to do when a laptop goes missing.

This guide is for accountancy and bookkeeping practices in Meath, Cavan, Westmeath, Louth and Dublin. It focuses on busy season, when more people work late from home. For wider practice security, such as phishing and payment fraud, see our guide to IT security for accountancy practices.

What secure remote working looks like in a busy practice

In busy season, a partner might finish returns at the kitchen table while a trainee works from a spare room. Meanwhile, a bookkeeper covers payroll from a client’s office. That flexibility helps. However, every extra location is another place where client data can leak.

The aim of secure remote work is simple. Staff should get the same tools at home as in the office, with the same protections. Client files should stay in the practice’s systems rather than on home PCs, USB keys or personal email.

Reach practice software and client files without copying them home

Start with where each system lives. Cloud accounting and payroll apps usually just need a secure sign-in. Desktop software on an office server is different, because staff need a secure route into the office. Usually that means a VPN or a remote desktop gateway, set up and monitored by your IT provider. Never leave remote desktop open directly to the internet.

For documents, keep client folders in SharePoint or OneDrive, with access limited to the people who work on each client. That way, secure remote work means opening files where they live, not downloading copies. The NCSC’s cyber security guidance for SMEs also recommends encrypting laptops and using a VPN on public Wi-Fi.

Protect ROS logins and digital certificates

ROS logins deserve special care, because ROS access can let someone file returns and see Revenue records. Revenue explains that a ROS digital certificate is an encrypted file saved on your device. You need both the file and its password to log in. Certificates are valid for up to two years.

Revenue also says certificates should never be emailed or shared between users. To use ROS on another device, set up a sub-user certificate instead. For secure remote working, that means:

  • One sub-user certificate per person, never a shared office login.
  • Certificates stored only on practice-managed laptops, not home PCs.
  • Permissions matched to each role, because the ROS administrator controls what sub-users can do.
  • Certificate passwords kept out of notebooks, emails and shared spreadsheets.

The ROS administrator can also revoke sub-user certificates, and Revenue’s guide covers suspending them. So when seasonal staff leave, remove their ROS access on the same day as their email.

Turn on MFA for secure remote working

A stolen password shouldn’t be enough to get into client data. That’s why MFA matters so much for secure remote work. Turn it on for Microsoft 365 and the VPN or remote desktop gateway. Add it to every accounting or payroll app that supports it. The NCSC advises enabling MFA on all systems and services.

Keep administrator accounts separate from day-to-day accounts, too. Then a phishing email aimed at one person can’t hand over the keys to the whole practice.

Use practice-managed laptops, not shared home PCs

Other people in the house often use home PCs, and your IT provider can’t check or update them. Instead, give remote staff a practice laptop that you manage centrally. The Data Protection Commission’s data security guidance says portable devices holding personal data should be encrypted.

A managed laptop should also get automatic updates, security software and a screen lock. Your IT provider should be able to lock or wipe it remotely. As a result, secure remote working gives a home worker the same protection as the office.

What happens when a laptop goes missing

Losing a laptop is stressful, so build these steps into your secure remote working plan:

  • Staff tell the practice manager and IT provider straight away, even late at night.
  • IT locks or wipes the device remotely and signs the user out of Microsoft 365.
  • Passwords change next, starting with email and remote access.
  • The ROS administrator revokes the sub-user certificate on that laptop and issues a new one.
  • Partners decide whether the loss counts as a personal data breach.

On that last point, the DPC explains the rule for any breach that presents a risk to individuals. Organisations must report it within 72 hours of becoming aware of it. Encryption and a quick remote wipe help when you assess that risk. Even so, write down what happened and what you decided.

Hypothetical example

A six-person practice in Mullingar takes on two seasonal staff for October. Before they start, IT gives each of them an encrypted practice laptop with MFA and a VPN. The ROS administrator then issues each a sub-user certificate with limited permissions. When someone leaves a laptop on a train, IT wipes it and the administrator revokes that certificate. Afterwards, the practice records its breach assessment and carries on filing, because it planned secure remote working in advance.

Plan secure remote working before busy season starts

Changes made in the middle of busy season tend to cause problems. So test remote access, MFA and the lost-laptop steps a few weeks before your busiest period. Issue laptops and ROS sub-user certificates to seasonal staff before their first day, rather than on it.

How Sweeney Computer Services can help

Oliver Sweeney founded the company in 1985. Today we support more than 50 businesses and more than 10 schools from Hurdlestown, Kells, Co. Meath. We set up managed laptops, MFA and secure remote working for practices, and we work alongside your accounting software vendors.

Silver starts from €45 and Gold from €70 per user per month, excluding VAT. Microsoft 365 licences are billed separately. Both packages include Microsoft 365 backup of email, OneDrive and SharePoint. However, that backup doesn’t automatically cover accounting data, local files or every cloud platform. So we scope device and server backup separately. Gold also adds 24/7 security monitoring through our partner. Our helpdesk runs Monday to Friday, 9am to 5:30pm.

See how we support accountants and bookkeepers, along with our managed IT support, cybersecurity and Microsoft 365 services.

more insights