Phishing, then ransomware — and the clients’ names, birthdates and SINs were gone.
Missing control: Two-step authentication on servers — bought immediately afterwards
Source: Decision P2021-ND-342
You hold SINs, financial statements, payroll and tax filings for every client on your books — and attackers know exactly what that is worth.
A small Alberta accounting practice could not log into its servers one morning. A phishing campaign had led to ransomware, and the attackers left with 1,570 clients' names, dates of birth and social insurance numbers. The week after, the firm implemented two-step authentication on every server and brought in an outside firm to run regular security assessments.
Read the decision, and what the firm bought afterwards →
Missing control: Two-step authentication on servers — bought immediately afterwards
Source: Decision P2021-ND-342
Anyone on the internet can send a payment request that looks exactly like it came from you — 72% of Canadian accounting practices with a website publish nothing that tells a receiving mail server to refuse it.
It is one of the first things the free Snapshot checks — from the outside, nothing to install.
See what we’d find on your domain — get the free Security Snapshot →
The rulebook below says what you owe. It does not say what to have. Your insurer does — in writing, on the form you fill in before it will quote you. These four come up on every one of them, and putting them in and keeping them there is most of what the retainer is.
Not offered — enforced, and separately on each of email, remote access and privileged accounts. It is the first control on the Canadian questionnaire and the one an insurer is most likely to check after a claim.
An Ontario organisation had about $5 million of claims refused on exactly this ground, after spending $18.3 million recovering. The rollout had started; it had not finished.
At least weekly, covering all sensitive or business-critical data, and held where an intruder inside your network cannot reach them. A backup nobody has restored from is an assumption, not a control.
Anything reachable from outside — the mail service, the remote-access gateway, the portal — carries known, published weaknesses within days of their disclosure. Insurers ask whether you actively manage and install critical patches across those systems.
Who is called, in what order, with what authority to disconnect something. Written down and rehearsed before the morning you need it, not drafted during it.
And the one no form asks about: knowing it happened at all. Most of the duties below start running when you find out — and in almost every case we document, no system caught the intruder; the firm learned of it from someone else, weeks or months later. Cases →
Canada Revenue Agency · CPA Ontario
If the CRA suspends your EFILE authorization, the consequence is not a penalty but a practice that cannot file.
| The rule | Who it binds | If you don’t | Source |
|---|---|---|---|
| The privilege can be suspended | Any electronic filer | Loss of EFILE privileges — consider the timing in April | Canada Revenue Agency — EFILE eligibility and responsibilities |
| Suspension for failing to produce records | Any electronic filer | Suspension within a specified timeframe | Canada Revenue Agency — EFILE eligibility and responsibilities |
| What the CRA does when credentials are compromised | Account holders | Access is revoked as a preventative measure | Canada Revenue Agency — security of taxpayer information |
| Your own Code requires you to protect client information | Every CPA Ontario member and firm | A professional-conduct obligation, not merely good practice The Code binds you to the outcome but does not name controls; CPA Ontario’s guidance on passwords, firewalls and backups says they “may” be required. | CPA Ontario — CPA Code of Professional Conduct, Rule 208.3 |
| Representing a client carries a security undertaking | Any authorized representative (RepID) | Privileges can be revoked or suspended | Canada Revenue Agency — responsibilities of authorized representatives |
| Report a breach that could seriously harm someone | Every organisation subject to PIPEDA | Knowingly failing to report is an offence under PIPEDA s.28 — a fine of up to $10,000 on summary conviction, or up to $100,000 as an indictable offence. The same section covers the record duty below. | PIPEDA s.10.1(1) — report to Commissioner |
| Notify the people affected | Every organisation subject to PIPEDA | The duty is separate from reporting to the regulator, and it applies whether one person is affected or a thousand. | Privacy Commissioner of Canada |
| Keep a record of EVERY breach for two years | Every organisation subject to PIPEDA | Most firms keep none. It applies whether or not anything was ever reportable, so a regulator’s request finds a gap that cannot be filled retroactively — and knowingly contravening it is the same s.28 offence. | Breach of Security Safeguards Regulations, s. 6(1) |
| Make those records good enough to audit | Every organisation subject to PIPEDA | A record that does not show how you assessed the risk does not discharge the duty — the regulator has to be able to check your reasoning, not just see a log entry. | Privacy Commissioner of Canada |
| Satisfy your insurer before you need to claim | Any firm that wants cyber cover | A condition you have not met is a claim your policy may refuse — an Ontario organisation had about $5 million of claims refused on exactly this ground, after spending $18.3 million recovering. | Coalition Insurance Solutions Canada — cyber questionnaire |
| Answer your client’s regulator, not just your own | Any firm holding a federally regulated client’s data | A firm that cannot answer a third-party risk assessment is a firm its regulated clients now have to explain — which is a procurement problem long before it is a security problem. | OSFI — Guideline B-10, Third-Party Risk Management (in force 1 May 2024) |
If an electronic filer does not comply with these requirements during the program, we will issue warning letters as required and can suspend EFILE privileges
Canada Revenue Agency — EFILE eligibility and responsibilities
Most of these start running the moment you find out — which is the whole reason the date you notice matters as much as the breach itself. The rest are conditions you meet beforehand: what your insurer asks before it will quote you, and what your regulated clients are now required to verify about you.
CPA Ontario's Code binds you to protect client information, but it does not name the controls — the guidance on passwords, firewalls and backups says they "may" be required, not that they are. The specific, enforceable lever is still the CRA's. And we do not claim a breach automatically causes suspension: the grounds are failing to protect information and to produce records.
No cost, no obligation — you keep the findings either way.
One short form. No access to your systems, no software to install.
Passive, publicly observable checks only — the same view an attacker gets.
Your top findings in plain English — one page, no meeting required.