Skip to content

Security for small accounting practices

You hold SINs, financial statements, payroll and tax filings for every client on your books — and attackers know exactly what that is worth.

What it actually looks like when it happens

A small Alberta accounting practice could not log into its servers one morning. A phishing campaign had led to ransomware, and the attackers left with 1,570 clients' names, dates of birth and social insurance numbers. The week after, the firm implemented two-step authentication on every server and brought in an outside firm to run regular security assessments.

Read the decision, and what the firm bought afterwards →

Documented cases at accounting practices

Cases →

Anyone on the internet can send a payment request that looks exactly like it came from you — 72% of Canadian accounting practices with a website publish nothing that tells a receiving mail server to refuse it.

It is one of the first things the free Snapshot checks — from the outside, nothing to install.

See what we’d find on your domain — get the free Security Snapshot →

The controls they check for

The rulebook below says what you owe. It does not say what to have. Your insurer does — in writing, on the form you fill in before it will quote you. These four come up on every one of them, and putting them in and keeping them there is most of what the retainer is.

Multi-factor authentication, enforced

Not offered — enforced, and separately on each of email, remote access and privileged accounts. It is the first control on the Canadian questionnaire and the one an insurer is most likely to check after a claim.

An Ontario organisation had about $5 million of claims refused on exactly this ground, after spending $18.3 million recovering. The rollout had started; it had not finished.

Backups you have restored from

At least weekly, covering all sensitive or business-critical data, and held where an intruder inside your network cannot reach them. A backup nobody has restored from is an assumption, not a control.

Patching what faces the internet

Anything reachable from outside — the mail service, the remote-access gateway, the portal — carries known, published weaknesses within days of their disclosure. Insurers ask whether you actively manage and install critical patches across those systems.

An incident-response plan you have tested

Who is called, in what order, with what authority to disconnect something. Written down and rehearsed before the morning you need it, not drafted during it.

And the one no form asks about: knowing it happened at all. Most of the duties below start running when you find out — and in almost every case we document, no system caught the intruder; the firm learned of it from someone else, weeks or months later. Cases →

Our Service →

What you are already required to do

Canada Revenue Agency · CPA Ontario

If the CRA suspends your EFILE authorization, the consequence is not a penalty but a practice that cannot file.

The rule Who it binds If you don’t Source
The privilege can be suspended Any electronic filer Loss of EFILE privileges — consider the timing in April Canada Revenue Agency — EFILE eligibility and responsibilities
Suspension for failing to produce records Any electronic filer Suspension within a specified timeframe Canada Revenue Agency — EFILE eligibility and responsibilities
What the CRA does when credentials are compromised Account holders Access is revoked as a preventative measure Canada Revenue Agency — security of taxpayer information
Your own Code requires you to protect client information Every CPA Ontario member and firm A professional-conduct obligation, not merely good practice
The Code binds you to the outcome but does not name controls; CPA Ontario’s guidance on passwords, firewalls and backups says they “may” be required.
CPA Ontario — CPA Code of Professional Conduct, Rule 208.3
Representing a client carries a security undertaking Any authorized representative (RepID) Privileges can be revoked or suspended Canada Revenue Agency — responsibilities of authorized representatives
Report a breach that could seriously harm someone Every organisation subject to PIPEDA Knowingly failing to report is an offence under PIPEDA s.28 — a fine of up to $10,000 on summary conviction, or up to $100,000 as an indictable offence. The same section covers the record duty below. PIPEDA s.10.1(1) — report to Commissioner
Notify the people affected Every organisation subject to PIPEDA The duty is separate from reporting to the regulator, and it applies whether one person is affected or a thousand. Privacy Commissioner of Canada
Keep a record of EVERY breach for two years Every organisation subject to PIPEDA Most firms keep none. It applies whether or not anything was ever reportable, so a regulator’s request finds a gap that cannot be filled retroactively — and knowingly contravening it is the same s.28 offence. Breach of Security Safeguards Regulations, s. 6(1)
Make those records good enough to audit Every organisation subject to PIPEDA A record that does not show how you assessed the risk does not discharge the duty — the regulator has to be able to check your reasoning, not just see a log entry. Privacy Commissioner of Canada
Satisfy your insurer before you need to claim Any firm that wants cyber cover A condition you have not met is a claim your policy may refuse — an Ontario organisation had about $5 million of claims refused on exactly this ground, after spending $18.3 million recovering. Coalition Insurance Solutions Canada — cyber questionnaire
Answer your client’s regulator, not just your own Any firm holding a federally regulated client’s data A firm that cannot answer a third-party risk assessment is a firm its regulated clients now have to explain — which is a procurement problem long before it is a security problem. OSFI — Guideline B-10, Third-Party Risk Management (in force 1 May 2024)
If an electronic filer does not comply with these requirements during the program, we will issue warning letters as required and can suspend EFILE privileges

Canada Revenue Agency — EFILE eligibility and responsibilities

Most of these start running the moment you find out — which is the whole reason the date you notice matters as much as the breach itself. The rest are conditions you meet beforehand: what your insurer asks before it will quote you, and what your regulated clients are now required to verify about you.

CPA Ontario's Code binds you to protect client information, but it does not name the controls — the guidance on passwords, firewalls and backups says they "may" be required, not that they are. The specific, enforceable lever is still the CRA's. And we do not claim a breach automatically causes suspension: the grounds are failing to protect information and to produce records.

Would you notice before the tax files left?

No cost, no obligation — you keep the findings either way.

  1. Tell us your domain

    One short form. No access to your systems, no software to install.

  2. We look from the outside

    Passive, publicly observable checks only — the same view an attacker gets.

  3. You get one page

    Your top findings in plain English — one page, no meeting required.