Skip to content
Industry

Cyber Essentials for Accountants: Protecting Client Financial Data in 2026

Accountancy firms are data controllers under UK GDPR, handling sensitive financial records for thousands of clients. Here is why Cyber Essentials certification is becoming the expected benchmark for the profession.

a person sitting at a desk with a calculator

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

8 min read

Share

Section 01

Cyber Essentials for Accountants: Protecting Client Financial Data in 2026

Accountancy practices sit on a goldmine of data that cyber criminals want. Tax returns, payroll records, bank details, company accounts, personal financial statements - the breadth of sensitive information flowing through even a small practice is significant.

The regulatory bodies have taken notice. ICAEW publishes dedicated cyber security guidance for its members. ACCA publishes cybersecurity resources. Under UK GDPR, a practice must identify when it acts as controller or processor and apply appropriate technical and organisational measures for its processing risks.

Cyber Essentials certification provides a structured, verifiable way to demonstrate that those measures are in place.

Section 02

The Regulatory Landscape

Accountancy firms in the UK operate under several overlapping regulatory obligations:

UK GDPR and the Data Protection Act 2018 - Determine when the practice acts as controller or processor. Apply appropriate technical and organisational measures proportionate to the processing risks; encryption and access controls are relevant safeguards, but neither the law nor a Cyber Essentials certificate creates a universal product list or settles all obligations.

ICAEW guidance - the Institute of Chartered Accountants in England and Wales publishes cyber security resources and actively recommends that member firms adopt recognised certification standards. While ICAEW does not currently mandate Cyber Essentials, its guidance on "appropriate systems and controls" aligns closely with the five Cyber Essentials control themes.

ACCA resources - ACCA’s cybersecurity guidance can support preparation. Firms seeking best practice can use these resources; guidance and training do not establish a universal firm-certification requirement; check applicable membership, regulatory and client conditions.

Professional indemnity insurance - PI insurers for accountancy practices increasingly ask about cyber security controls during the renewal process. Holding Cyber Essentials provides a clear, third-party-verified answer.

Client expectations - enterprise clients and public sector organisations increasingly require their professional advisers to hold Cyber Essentials. If your practice advises government departments, NHS trusts, or large corporates, expect to be asked for your certificate.

Section 03

Why Accountancy Firms Are Targeted

Accounting practices are targeted because of what they hold and how they operate:

Volume of sensitive data. A mid-sized practice might hold tax records, bank details, and payroll data for hundreds of clients. That data has direct financial value to criminals. Stolen tax records can be used to file fraudulent returns. Payroll data enables identity theft. Bank details enable direct financial fraud.

Seasonal pressure. Tax deadlines create periods of intense pressure where staff are working long hours and processing large volumes of data. These are exactly the conditions where phishing emails succeed - a well-crafted message impersonating HMRC or a client is more likely to be clicked when staff are under time pressure.

Client trust. The relationship between an accountant and their client is built on trust. Clients share their most sensitive financial information without hesitation. That trust is destroyed in the event of a breach, and for a profession built on relationships, the commercial damage extends far beyond the immediate incident.

Small firm vulnerability. Small practices can be exposed through compromised accounts, malicious attachments and unsupported software. Assess those risks even without a dedicated IT team; business size alone does not establish protection.

Section 04

What Cyber Essentials Covers

The five controls address the most common attack vectors that accountancy firms face:

Firewalls - protecting the boundary between your practice network and the internet. For cloud-first practices, this includes the configuration of your cloud services and the settings on your staff devices.

Secure configuration - removing default passwords, disabling unnecessary services, and hardening your systems. This applies to your accounting software (Xero, Sage, QuickBooks), your document management system, and your email platform.

Enable MFA for every user account accessing in-scope cloud services, including administrator and third-party accounts. Implement MFA where available on non-cloud systems and apply the separate administrative-access and password controls; do not assume v3.3 mandates MFA on every local account regardless of availability. Document non-interactive service identities separately rather than treating them as human logins.

Malware protection - Use an applicable supported scheme-permitted approach, such as anti-malware or application allow-listing on relevant computers, and the approved-app-store/application-signing approach where applicable to mobiles.

Apply vendor-approved vulnerability fixes within 14 days of release when the vendor rates the vulnerability critical or high, its CVSS v3 score is 7 or higher, or the vendor provides no severity details. This includes supported in-scope operating systems, applications, extensions and firmware; it is not a deadline for every routine update.

Section 05

Making Tax Digital and Cloud Accounting

The shift to Making Tax Digital and cloud-based accounting platforms (Xero, QuickBooks Online, FreeAgent) has changed the security landscape for practices. Data that was once stored on local servers is now in the cloud, accessible from anywhere.

This makes access control and MFA more important than ever. If your team can access client records from any device with an internet connection, the security of those access credentials is the primary barrier between a threat actor and your client data.

Cyber Essentials v3.3 addresses this directly by mandating MFA for all cloud services. If your practice uses cloud accounting software, cloud document storage, or cloud email, MFA must be enforced on every one of those services.

Section 06

The Certification Process

For accountancy practices, getting certified is straightforward:

1. Check your readiness - Use Fig Group's free readiness tool to assess your current position

2. Address common gaps - For accountancy firms, the most frequent issues are: MFA not enforced on cloud accounting platforms, shared user accounts between staff, and overdue Windows or macOS updates

3. Complete the assessment - The self-assessment questionnaire covers your actual technical configuration across the five control themes

Fig Group guarantees Basic assessment within six working hours for a complete, compliant submission received before midday on a UK Business Day, subject to the certification terms. Preparation, clarification and remediation are separate; certificate issuance requires a successful assessment.

For practices that want external verification (particularly useful when demonstrating compliance to enterprise clients), Cyber Essentials Plus adds an independent technical audit. Use a prepared-assessment target of 2–3 working days, subject to scheduling, device access and remediation; successful assessment is required for issuance.

Section 07

Timing It Right

If your practice handles government contracts, public sector advisory work, or enterprise clients, you may already need Cyber Essentials. Check your existing contracts and terms of engagement for cybersecurity requirements.

For all other practices, the direction of travel is clear. Certification is moving from "nice to have" to "expected standard." Getting certified now - before it becomes a contractual requirement from a key client - puts you in a stronger position than scrambling to comply under deadline pressure.

Certificates are valid for 12 months. Many practices align their renewal with their professional indemnity insurance renewal or their annual compliance review, keeping all their governance documentation on the same cycle.

Get your practice certified today

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Ready to get certified?

Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.