Accounting and financial services

IT support for accountants and financial advisers

We look after IT for Perth accounting practices, tax agents, bookkeepers, financial advisers and mortgage brokers. Client data and ATO access locked down, practice software that stays fast at tax time and the evidence the TPB, ASIC and your insurer ask for.

Accountant working through client spreadsheets on a laptop
Practice servers in PerthHosted in AustinCloud
  • $2.5mPenalty ordered against FIIG Securities in 2026 over cyber security failures, after action by ASIC
  • 157Data breach notifications from financial services providers to the OAIC in 2025
  • 24/7Monitoring and response on SecureShield plans
  • WAHosted practice servers and primary backups stay in Perth datacentres

01The risks

Where practices are exposed

Accounting and advice firms hold tax file numbers, bank details and ATO access for hundreds of clients. Attackers know that one compromised practice opens every client file inside it.

  1. Someone opens a fake job application

    In August 2026 the ATO warned that a small number of tax practices had their systems compromised through malicious links, starting with fake CVs. Once inside, attackers go after client records and ATO access.

    FixEmail security that checks links and attachments before they arrive, 24/7 detection and response and MFA on every login.

  2. ATO access is shared

    Online services for agents needs each person's own myID at Standard strength, linked to the practice in RAM. The ATO asks practices to put MFA on email and myID and never share credentials.

    FixIndividual identities and MFA on email and myID, with a joiner and leaver process that removes ATO access on the day someone leaves.

  3. Tax time grinds to a halt

    An ageing server or overloaded hosted desktop slows practice and tax software exactly when lodgements peak.

    FixPractice and document servers hosted in our Perth private cloud, sized for peak season and monitored.

  4. Nobody can show the controls

    The TPB Code requires controls that protect the security and confidentiality of client records, and ASIC expects licensees to back cyber governance with evidence, not assurances.

    FixDocumented controls, a quarterly Essential Eight score and a report you can table with partners or the board.

03What ASIC looks for

The gaps ASIC took to court

In February 2026 the Federal Court ordered FIIG Securities to pay a $2.5 million penalty over cyber security failures. These were the gaps, and they are the same basics we put in place for every client.

  1. 01
    No MFA on remote access

    Every remote login uses MFA, phishing resistant for administrators and anyone who can move money.

  2. 02
    Weak control of admin accounts

    Separate admin accounts, granted only when needed and reviewed every quarter.

  3. 03
    No plan for patching

    Operating systems and applications patched on a schedule, with the results reported.

  4. 04
    No penetration testing

    Vulnerability scanning all year, with an annual external penetration test on our Gold plan.

  5. 05
    No staff training

    Security awareness training for every staff member, included in every SecureShield plan.

  6. 06
    An untested incident response plan

    A written plan with named roles, walked through with your leadership team.

ASIC's May 2026 open letter asked boards to see evidence of cyber controls, not just assurances.

SecureShield plans

04Your obligations

What your regulators expect of your IT

Accountants, tax agents and advisers answer to different regulators, but the IT expectations overlap: protect client data, control access and be able to prove it.

IT related obligations for accounting and financial services firms and how Austin Technology helps
ObligationWhat it asks of youHow we help
Tax Practitioners BoardThe Code Determination requires a quality management system with controls that protect the security and confidentiality of client records. It has applied to firms of 100 or fewer employees since 1 July 2025Documented controls, access reviews and evidence for your quality system
ATO online servicesEach person uses their own myID at Standard strength, linked in RAM, with MFA on email and myID and no shared credentialsIdentity setup, MFA and access removed the day someone leaves
Tax file number breachesThe Notifiable Data Breaches scheme applies to breaches involving tax file numbers, whatever your turnoverLogging and an incident response plan to assess and report a breach
ASIC licenseesAFS and credit licensees must manage cyber risk as part of their licence obligations, as the RI Advice and FIIG Securities cases showedControls mapped to the Essential Eight, with evidence your board can see
Records of adviceFinancial advisers must keep records of advice for at least seven yearsRetention settings and immutable backups for the full period
AML/CTFSince 1 July 2026, accountants providing designated services are reporting entities, and small firms must follow the Privacy Act for that workSecure storage and access controls for identification and due diligence records

We handle the technical controls and evidence. For regulatory interpretation we work alongside your compliance adviser or licensee.

05Proof

Practices that run on our cloud

Perth accounting firms already run their practice systems on our private cloud, backed by an audited security system.

/01

Hosted practice servers

We host practice and tax software servers for Perth accounting firms in AustinCloud, with remote desktop access for staff and immutable backups.

Hosted cloud servers
/02

Certified and onshore

We are ISO 27001 certified, and hosted data and primary backups stay in Perth, under Australian law.

Security and governance
/03

Security that won the work

Palisades, a professional services firm, met a prospective client's security requirements after we aligned them with the Essential Eight and won the work.

Read the case study

Related industries

06Questions

Accounting and finance IT questions

What principals, practice managers and licensees ask us most. Anything else, call 1300 787 429.

01

Can you host our practice software?

Yes. We host practice management, tax and document servers in our Perth private cloud, with secure remote desktop access for staff and immutable backups. If you run cloud platforms such as Xero Practice Manager or FYI, there is no server to host, and we look after the Microsoft 365, devices and access around them.

02

What does the TPB expect from our IT?

The Code Determination requires a documented quality management system, including controls that protect the security and confidentiality of client records. We give you the documented controls, access reviews and reports that show those controls are working.

03

How should myID and RAM be set up for our staff?

Each person needs their own myID at Standard strength or higher, linked to the practice in RAM with only the access their role needs. Protect email and myID with MFA, never share credentials and remove access the day someone leaves.

04

We hold an AFS licence. What does ASIC expect?

That you manage cyber risk as part of your licence obligations and can show it. In May 2026 ASIC called for urgent cyber uplift and asked boards to see evidence rather than assurances. We map your controls to the Essential Eight and give you a report to table.

05

What should we do if client tax file numbers may have been exposed?

Call us to contain it, then assess it quickly. The Notifiable Data Breaches scheme applies to tax file number breaches whatever your turnover, and the ATO asks practices to call its Client Identity Support Centre on 1800 467 033 if client identities may be compromised.

06

What does IT support cost for a practice our size?

A monthly fee per user covers support, monitoring and security, with hosting and projects quoted separately. Agreements run month to month, and a free IT audit gives you a fixed quote.

07Accounting and financial services

Keep client data safe
through every tax time.

Start with a free IT audit. You get a plain English view of your security, ATO access, hosting and costs.

Level 2, 541 Hay Street, Subiaco WA 6008 Onsite across the Perth metro area. Remote support across regional WA and Australia.
Scroll to Top