Cyber security for professional services

Cyber Security for Professional Services: Accountants, Law Firms and Advisers

Last updated: July 2026

Professional firms run on two things attackers prize above almost anything: money in motion and confidential client information. A single convincing email can redirect a settlement or a tax refund, and a single compromised login can expose every client file at once. Vintaris secures Australian accounting and legal practices with controls built around how these firms actually work, and how they are actually attacked.

Invoice redirection: the fraud built for professional firms

The most damaging attack on Australian professional practices is not technical wizardry. It is a payment instruction that looks exactly right.

1

Mailbox compromised or spoofed

2

Real invoice intercepted, bank details changed

3

Client or firm pays the criminal

A call-back to a known number breaks the chain here.
4

Discovery, weeks later

The defence is procedural, and nearly free: a mandatory call-back to a known number before any bank-detail change is actioned, on client payments, supplier invoices, and your own firm’s details on outgoing invoices. Paired with mailbox protection and dual authorisation on payments, the chain breaks before money moves.

Business email compromise protection

Business email compromise (BEC) is the umbrella over invoice fraud, settlement redirection and executive impersonation, and email is where professional firms live. Protection is layered: enforced MFA on every mailbox, mail rules audited for silent forwarders, domain lockdown (SPF, DKIM, DMARC) so criminals cannot send as your firm, staff who recognise the pressure patterns, and the payment controls above as the final backstop. Our assessment verifies each layer, and where you want it managed, we deploy and oversee the tooling.

Two professions, two risk profiles

Accountants and accounting firms

  • Client TFNs and financials make you an identity-theft goldmine, and the Privacy Act’s TFN rules apply regardless of firm size.
  • Tax season concentrates payment flows, and criminals time their redirection attempts to match.
  • Practice suites (MYOB AE, APS, CCH, HandiSoft) are often self-managed, patching and backups are yours.
  • ATO and myGov impersonation targets your clients using details taken from you.

Law firms

  • Trust accounts are the single most attractive target in professional services, and dual authorisation is the control that protects them.
  • Legal professional privilege makes a breach a professional catastrophe, not just a privacy incident.
  • Settlement and conveyancing payments are the classic redirection target, verified callback is non-negotiable.
  • Matter-level access control means one phished login does not expose every client the firm has ever acted for.

Cyber security for accounting firms and legal practices is not generic IT hardening: it is these specific controls, verified against how your practice actually runs.

The professional firm’s checklist

  1. A mandatory call-back rule before any bank-detail change is actioned, no exceptions, including for the managing partner.
  2. Dual authorisation on trust, client and firm account payments above a threshold.
  3. MFA on every mailbox and every practice system login.
  4. Client file access restricted to the matters people work on.
  5. Confidential documents shared through a secure portal, not email attachments.
  6. Caller identity verified before client information is discussed or instructions changed.
  7. Practice system hosting understood: vendor-cloud, or self-managed with patching and backups assigned.
  8. Backups the ransomware cannot reach, restore-tested.
  9. Your professional body's and PI insurer's cyber obligations reviewed in the last year.

Want this scored against your actual firm instead of read as a list? That is what the free check does in two minutes.

Your obligations, and your insurer’s expectations

Professional bodies and PI insurers increasingly impose cyber expectations of their own, and cyber insurers verify controls before paying claims: the firms that can evidence MFA, payment verification and tested backups insure on better terms and recover faster. If insurance is what brought you here, our free briefing ‘When the Insurer Moves the Goalposts’ explains what insurers now require.

When you want more than a checklist

Expert help

Expert-led assessment and ongoing help

Verification, configuration review and a tailored roadmap, or ongoing consulting as the independent security layer alongside your IT provider. Sole practitioner? The small business stream may fit better, and we will say so.

Talk to us

Every Service, Sized for Professional Services

Everything in the Vintaris catalogue is available to professional firms, deployed and priced for your practice. Select any service to explore it.

// Click any node to view the full service page

FAQ

Frequently asked questions

What cyber security do accountants need?

The controls matched to how accounting firms are attacked: MFA on every mailbox and practice system, a call-back rule on bank-detail changes, dual authorisation on payments, a secure client portal instead of email attachments, restricted client-file access, and clarity on whether your practice suite's patching and backups are the vendor's job or yours.

What cyber security do law firms need?

Everything above, plus the law-specific layer: dual authorisation on trust account payments, matter-level access control so one compromised login cannot expose the whole client base, defined caller-verification steps before discussing matters or changing instructions, and settlement-payment verification as an absolute rule.

What is invoice redirection fraud?

A criminal intercepts or imitates a legitimate invoice and changes the bank details, so a real payment for a real service goes to the criminal's account. It is Australia's most costly email-enabled fraud against businesses, professional firms are targeted because they move client money, and a call-back to a known number before actioning any detail change defeats it.

How do we protect against business email compromise?

Layered controls: enforced MFA on all mailboxes, auditing for hidden forwarding rules, SPF/DKIM/DMARC so your domain cannot be spoofed, staff trained on the pressure patterns, and payment verification as the backstop that catches whatever gets through. BEC protection services can deploy and manage these layers; verification that they are actually working is what our assessment does.

Do law firms need cyber insurance?

Increasingly yes, and PI cover alone does not respond to most cyber events. The more important question is whether a policy would actually pay: insurers require evidence of controls like MFA and tested backups, and refuse claims where declared controls were not in place. See our guide to cyber insurance requirements.

Vintaris provides cybersecurity assessment and advisory services. General information on this page is not legal, financial or insurance advice.

See where your firm actually stands.

Start the free 2-minute check

Prepared and reviewed by the Vintaris security team.