What Every Accounting Firm Should Have: the IT checklist

An accounting firm cybersecurity checklist for tax season

T4 and T5 slips at the end of February, most personal returns by April 30, and a client’s SIN and bank details in every file. Tax season is the worst time to find out what is missing. This accounting firm cybersecurity checklist is the IT we would want in place at a Canadian firm before a server dies or a fake CRA email gets a click, drawn as one small office.

Bring your insurer’s cyber questionnaire to the free IT consult. We will go through it with you.

What you can count on

  • Under 2 hrsto restore a failed server from local backups
  • 30 days lockedbackups no one can delete early, not even us
  • 3-2-1backup copies, one offsite in Vancouver, BC
  • 24/7a person answers (604) 813-7881

Why does a tax file need more protection than most?

Once a year, clients hand you their whole financial life. Keeping it private is part of the job, and part of why they come back.

SINs, slips and bank details in one place

One client file can hold a SIN, a date of birth, T4 and T5 slips, banking details and past returns. Together, that is what someone needs to attempt identity theft or a fake refund. Service Canada asks people to keep their SIN confidential, and your clients trust you with it.

Fake CRA messages look real

Scammers copy the CRA, and tax season gives them cover. The CRA says its emails will not include a link asking you to enter personal or financial information, and that it will never email or text you a link to a refund. Your staff see these messages too, often dressed up as a client.

Your EFILE access is a key

The CRA asks EFILE filers to keep their EFILE number and password confidential, and to tell the CRA right away about any loss, or suspected loss, of client information from electronic filing. One stolen staff login can put both at risk.

Privacy law expects real safeguards

Canadian privacy law asks firms to protect personal information with safeguards that match how sensitive it is, and financial information is generally treated as sensitive. In BC and Alberta, the provincial Personal Information Protection Act usually applies. PIPEDA applies when information crosses provincial or national borders, and under PIPEDA a breach that creates a real risk of significant harm must be reported to the Privacy Commissioner and the people affected told.

General information, not legal advice. Ask your lawyer or professional body what applies to your firm. Sources: CRA, recognize a scam, CRA, EFILE responsibilities, Service Canada, protect your SIN, Privacy Commissioner of Canada, safeguards and which privacy law applies.

A real case, seen as a client

An Alberta accounting firm, in the middle of tax season

In early April, an Alberta accounting firm found ransomware on its network. It locked their computers, and staff could not reach their data.

They wiped every computer, storage device and server, and rebuilt from backups the attack had not touched. They reported it to the police. To meet tax deadlines, they rebuilt quickly and did not investigate how the attackers got in.

They also had to send their clients a breach notice. It said the information that may have been involved included:

  • Names
  • SINs
  • Dates of birth
  • Driver’s licence information
  • Addresses
  • Banking and financial information
  • Tax data
  • Employee payroll and benefits data

We know this one from the other side. We were a client of this firm, and our own personal and business information was in that breach notice. We had raised security concerns with them before the attack. After the attack, from where we sat as a client, the firm could not work the way it used to, and we moved our accounting elsewhere. Your clients can do the same.

What changes the ending

  1. Backups locked for 30 days, with an offsite copy, and tested. A clean copy is there to restore, and you already know it works.
  2. Huntress on every computer. Watched 24/7 by our security operations team (SOC), with a text alert when something looks wrong.
  3. A written breach plan. Who to call, who decides, and how clients and regulators are told. We recommend one for every firm.
  4. Find how they got in before you rebuild. Otherwise the same door can still be open when the new systems go live.

See item 5: locked backups

The office, item by item

Green shields are the 6 security layers. Grey circles are the rest of a good build. The cards below explain each one.

Floor plan of a small accounting office, with its security layers highlightedA small accounting office inside a protected perimeter, with reception, two partner offices, a file and scan station, a boardroom, staff desks and a server closet. The internet comes in through a business firewall in the server closet. Green shields mark six security layers: the firewall, DNS filtering that also protects a work from home laptop, Huntress and BitLocker on every computer, multi-factor sign-in with number matching, backups locked for 30 days with an offsite copy in Vancouver, BC, and email anti-spoofing. Grey circles mark the Hyper-V server, RAID 10 storage, guest Wi-Fi kept separate, printers and scanners, and a battery backup. Each number is explained in the list below.PROTECTED PERIMETERPartner officePartner officeBoardroomFile and scan stationStaff desksReceptionServer closet30 DAYS LOCKEDInternetWork from home laptopOffsite copyVancouver, BC1234567891011Security layerEverything else in a good build
  1. A business firewall at the front door
  2. DNS filtering, in the office and at home
  3. Huntress and BitLocker on every computer
  4. Multi-factor sign-in with number matching
  5. Backups locked for 30 days, with an offsite copy
  6. Email that is hard to fake
  7. A Hyper-V server for your tax and accounting software
  8. RAID 10 storage
  9. Guest Wi-Fi kept separate
  10. Printers and scanners on their own network
  11. A UPS (battery backup)

The checklist

The 6 security layers

These are the layers that keep client SINs, slips and banking details private. See how our cybersecurity works.

Security layer

A business firewall at the front door

Why it matters. Everything that comes in from the internet passes through here first.

A Cisco Meraki MX firewall with Advanced Security, sized to your internet speed so protection does not become the bottleneck.

How a business firewall works

Security layer

DNS filtering, in the office and at home

Why it matters. A fake CRA link only works if the page loads.

DNS filtering blocks known bad sites before they load. A roaming agent keeps it on when a laptop leaves the office, so staff working from home in March are covered too.

How DNS filtering works

Security layer

Huntress and BitLocker on every computer

Why it matters. A lost laptop full of client returns, or a quiet attack, should not become a breach.

Huntress Managed EDR is on every computer we manage, watched 24/7 by our security operations team (SOC), who send a text alert when something looks wrong. BitLocker disk encryption is on by default, unless your software vendor says otherwise, and comes with Microsoft 365 Business Premium, our standard plan for firms under 300 users, along with Intune, Defender for Business, Conditional Access and Purview Message Encryption.

How our cybersecurity works

Security layer

Multi-factor sign-in with number matching

Why it matters. A stolen password is far less useful on its own, and fake sign in pages are common in tax season.

Email and remote access ask for a number match on your phone. Remote desktop is never exposed to the internet. Remote access goes through a secured gateway instead.

How multi-factor sign-in works

Security layer

Backups locked for 30 days, with an offsite copy

Why it matters. Ransomware goes after backups first. A locked copy and an offsite copy mean there is always one it cannot reach.

The 3-2-1 plan: three copies, two kinds of storage, one offsite in Vancouver, BC. Each backup is locked for 30 days, and nobody can unlock it early, not even us. We spot check multiple copies and run a yearly disaster recovery test. When we restore a failed server from local storage, it has taken less than 2 hours.

How immutable backups work

Security layer

Email that is hard to fake

Why it matters. A fake email that looks as if it came from your firm, or from a client, can ask someone to change bank details or send a refund to a new account.

We recommend SPF, DKIM and DMARC on your firm’s domain, and we can set them up and check them.

Phishing, email takeover and ransomware

The rest of a good build

A Hyper-V server for your tax and accounting software

Why it matters. One dead server in March should not stop the firm.

We build at least 2 virtual servers: one for sign in (the domain controller) and one app server for software such as Caseware, QuickBooks, ProFile and Taxprep. On Hyper-V, the server is a set of files we can bring back on other hardware.

Why accounting firms run servers on Hyper-V

RAID 10 storage

Why it matters. A failed drive should not stop tax prep.

RAID 10 for virtual machine storage is standard in our builds. Built on ITIL best practices, so changes are planned and recorded. RAID is not a backup.

How RAID 10 works

Guest Wi-Fi kept separate

Why it matters. Clients in the waiting area should never share a network with client files.

We recommend separate networks (VLANs) on Layer 3 PoE switches, and we can set them up.

Printers and scanners on their own network

Why it matters. The file and scan station handles slips, ID and signed returns all day.

We recommend keeping printers and scanners on their own network, and we can set it up.

PDF sprawl and file naming

A UPS (battery backup)

Why it matters. A power blip should not corrupt the server on a filing day.

We recommend a UPS, plus a second internet line so one cut cable does not stop a deadline day. We can set up both.

Also on our list: patching (we keep your systems patched), awareness training for everyone, and a written plan for a breach and for downtime in tax season.

The call back rule for payments

Payment fraud often starts with a normal looking email: a client’s “new” bank account for a refund, a vendor’s changed payment details, or a partner asking for an urgent transfer.

  • Confirm any change to bank details by phone, on a number you already have. Never use the number in the email.
  • Have two people sign off on large or unusual payments.
  • Turn on multi-factor sign-in for every mailbox, so a stolen password cannot be used to send the email in the first place (item 4).
  • Make your domain harder to fake with SPF, DKIM and DMARC (item 6).

More from the Canadian Anti-Fraud Centre: frauds that target businesses.

What do cyber insurers ask accounting firms?

Cyber insurance renewals ask the same kinds of questions every year. Most answers are on this page.

What insurers tend to ask

  • Is multi-factor sign-in on for email, remote access and admin accounts?
  • Are backups tested, and is there a copy an attacker cannot change?
  • Are computers kept up to date and watched by security software?
  • Do staff get security awareness training?
  • Is your email domain protected against spoofing?

Where it is on this checklist

  • Multi-factor sign-in with number matching: item 4.
  • Locked, tested backups with an offsite copy: item 5.
  • Huntress on every computer: item 3. Patching: we keep your systems patched.
  • Awareness training: also on our list.
  • SPF, DKIM and DMARC: item 6.

Bring the questionnaire to your free IT consult and we will go through it with you. It does not replace your insurer’s own questions or legal advice.

Accounting firms we have helped

An accounting firm of about 75 people

We look after their managed IT. When COVID hit, we got their whole team working securely from home. Along the way we cut their email costs by $33,000 a year.

Reschke Fritz LLP

We helped Reschke Fritz get started, setting up their first servers and network. As they grew, we helped them open new offices in Whitecourt and St. Albert. When COVID hit, we moved the team to secure remote work with zero trust access.

We support the software your firm already uses, including Caseware, QuickBooks, Sage, Xero, Karbon, ProFile, Taxprep and TaxCycle. See the software we support.

What worries accounting firms most about IT

Six common worries. Each has a short, plain guide.

Will it hold up in February?

Everything slows down at once, and a bad day in tax season costs the most.

Tax season slowdowns and downtime

Tax season is phishing season

Fake client emails, a hijacked mailbox, and files locked on a Monday morning.

Phishing, email takeover and ransomware

If an EFILE password goes missing, who do we call?

Client confidentiality, the CRA and privacy, in plain words.

Confidentiality, CRA and privacy

Staff work from home and it crawls

Why a VPN is slow for QuickBooks, and the safer way to work remotely.

Safe remote access

We have backups. Have we ever restored one?

Why untested backups let people down, and how to prove yours.

Backups nobody has restored

Will every ProFile or Taxprep seat open?

Licences, installs and updates, before the rush.

ProFile and Taxprep setup

Use this as a checklist

Take it to your next IT quote or a second opinion, and ask which items are in place today. Every firm is a little different, so we are happy to go through it with you, ideally before tax season.

Back to accounting IT support

Talk to a person.

Emergency support 24/7. The phone is always answered by a person.

(604) 813-7881

24/7 emergency line
Mon to Fri, 7am to 5pm MT. Emergency support 24/7 at (604) 813-7881, always answered by a person.

Or send us a note