Accounting and financial services
IT support for accountants and financial advisers
We look after IT for Perth accounting practices, tax agents, bookkeepers, financial advisers and mortgage brokers. Client data and ATO access locked down, practice software that stays fast at tax time and the evidence the TPB, ASIC and your insurer ask for.

- $2.5mPenalty ordered against FIIG Securities in 2026 over cyber security failures, after action by ASIC
- 157Data breach notifications from financial services providers to the OAIC in 2025
- 24/7Monitoring and response on SecureShield plans
- WAHosted practice servers and primary backups stay in Perth datacentres
01The risks
Where practices are exposed
Accounting and advice firms hold tax file numbers, bank details and ATO access for hundreds of clients. Attackers know that one compromised practice opens every client file inside it.
- 01
Someone opens a fake job application
In August 2026 the ATO warned that a small number of tax practices had their systems compromised through malicious links, starting with fake CVs. Once inside, attackers go after client records and ATO access.
FixEmail security that checks links and attachments before they arrive, 24/7 detection and response and MFA on every login.
- 02
ATO access is shared
Online services for agents needs each person's own myID at Standard strength, linked to the practice in RAM. The ATO asks practices to put MFA on email and myID and never share credentials.
FixIndividual identities and MFA on email and myID, with a joiner and leaver process that removes ATO access on the day someone leaves.
- 03
Tax time grinds to a halt
An ageing server or overloaded hosted desktop slows practice and tax software exactly when lodgements peak.
FixPractice and document servers hosted in our Perth private cloud, sized for peak season and monitored.
- 04
Nobody can show the controls
The TPB Code requires controls that protect the security and confidentiality of client records, and ASIC expects licensees to back cyber governance with evidence, not assurances.
FixDocumented controls, a quarterly Essential Eight score and a report you can table with partners or the board.
02What we look after
IT that holds up in peak season
One Perth team for hosted systems, security, email and devices, so the practice keeps moving when every client wants their return at once.
Fast support
A Perth service desk that answers in about 25 seconds and fixes most issues remotely, with engineers onsite across the metro area.
Service desk / onsite / after hours optionsHosted practice servers
Practice management, tax and document software on servers in our Perth private cloud, with secure remote desktop access for staff.
AustinCloud / hosted desktops / remote accessEmail and payment fraud protection
Email security, impersonation detection and identity threat monitoring, so a fake invoice or changed bank detail is caught early.
Email security / identity threat detection / MFAMicrosoft 365 and client files
Email, Teams and SharePoint set up by client, with sharing controls and a secure way to exchange documents with clients.
Microsoft 365 / SharePoint / sharing controlsSecurity and compliance
SecureShield plans with 24/7 monitoring, Essential Eight controls and evidence for the TPB, ASIC and your insurer.
SecureShield / Essential Eight / evidenceBackup and retention
Microsoft 365, server and document backups kept for as long as your records obligations require, in immutable storage.
Immutable backup / retention / restore tests03What ASIC looks for
The gaps ASIC took to court
In February 2026 the Federal Court ordered FIIG Securities to pay a $2.5 million penalty over cyber security failures. These were the gaps, and they are the same basics we put in place for every client.
- 01No MFA on remote access
Every remote login uses MFA, phishing resistant for administrators and anyone who can move money.
- 02Weak control of admin accounts
Separate admin accounts, granted only when needed and reviewed every quarter.
- 03No plan for patching
Operating systems and applications patched on a schedule, with the results reported.
- 04No penetration testing
Vulnerability scanning all year, with an annual external penetration test on our Gold plan.
- 05No staff training
Security awareness training for every staff member, included in every SecureShield plan.
- 06An untested incident response plan
A written plan with named roles, walked through with your leadership team.
ASIC's May 2026 open letter asked boards to see evidence of cyber controls, not just assurances.
SecureShield plans04Your obligations
What your regulators expect of your IT
Accountants, tax agents and advisers answer to different regulators, but the IT expectations overlap: protect client data, control access and be able to prove it.
| Obligation | What it asks of you | How we help |
|---|---|---|
| Tax Practitioners Board | The Code Determination requires a quality management system with controls that protect the security and confidentiality of client records. It has applied to firms of 100 or fewer employees since 1 July 2025 | Documented controls, access reviews and evidence for your quality system |
| ATO online services | Each person uses their own myID at Standard strength, linked in RAM, with MFA on email and myID and no shared credentials | Identity setup, MFA and access removed the day someone leaves |
| Tax file number breaches | The Notifiable Data Breaches scheme applies to breaches involving tax file numbers, whatever your turnover | Logging and an incident response plan to assess and report a breach |
| ASIC licensees | AFS and credit licensees must manage cyber risk as part of their licence obligations, as the RI Advice and FIIG Securities cases showed | Controls mapped to the Essential Eight, with evidence your board can see |
| Records of advice | Financial advisers must keep records of advice for at least seven years | Retention settings and immutable backups for the full period |
| AML/CTF | Since 1 July 2026, accountants providing designated services are reporting entities, and small firms must follow the Privacy Act for that work | Secure storage and access controls for identification and due diligence records |
We handle the technical controls and evidence. For regulatory interpretation we work alongside your compliance adviser or licensee.
05Proof
Practices that run on our cloud
Perth accounting firms already run their practice systems on our private cloud, backed by an audited security system.
Hosted practice servers
We host practice and tax software servers for Perth accounting firms in AustinCloud, with remote desktop access for staff and immutable backups.
Hosted cloud serversCertified and onshore
We are ISO 27001 certified, and hosted data and primary backups stay in Perth, under Australian law.
Security and governanceSecurity that won the work
Palisades, a professional services firm, met a prospective client's security requirements after we aligned them with the Essential Eight and won the work.
Read the case studyRelated industries
06Questions
Accounting and finance IT questions
What principals, practice managers and licensees ask us most. Anything else, call 1300 787 429.
01Can you host our practice software?
Yes. We host practice management, tax and document servers in our Perth private cloud, with secure remote desktop access for staff and immutable backups. If you run cloud platforms such as Xero Practice Manager or FYI, there is no server to host, and we look after the Microsoft 365, devices and access around them.
02What does the TPB expect from our IT?
The Code Determination requires a documented quality management system, including controls that protect the security and confidentiality of client records. We give you the documented controls, access reviews and reports that show those controls are working.
03How should myID and RAM be set up for our staff?
Each person needs their own myID at Standard strength or higher, linked to the practice in RAM with only the access their role needs. Protect email and myID with MFA, never share credentials and remove access the day someone leaves.
04We hold an AFS licence. What does ASIC expect?
That you manage cyber risk as part of your licence obligations and can show it. In May 2026 ASIC called for urgent cyber uplift and asked boards to see evidence rather than assurances. We map your controls to the Essential Eight and give you a report to table.
05What should we do if client tax file numbers may have been exposed?
Call us to contain it, then assess it quickly. The Notifiable Data Breaches scheme applies to tax file number breaches whatever your turnover, and the ATO asks practices to call its Client Identity Support Centre on 1800 467 033 if client identities may be compromised.
06What does IT support cost for a practice our size?
A monthly fee per user covers support, monitoring and security, with hosting and projects quoted separately. Agreements run month to month, and a free IT audit gives you a fixed quote.
07Accounting and financial services
Keep client data safe
through every tax time.
Start with a free IT audit. You get a plain English view of your security, ATO access, hosting and costs.