Emergency support 24/7. The phone is always answered by a person.
What Every Accounting Firm Should Have: the IT checklist
An accounting firm cybersecurity checklist for tax season
T4 and T5 slips at the end of February, most personal returns by April 30, and a client’s SIN and bank details in every file. Tax season is the worst time to find out what is missing. This accounting firm cybersecurity checklist is the IT we would want in place at a Canadian firm before a server dies or a fake CRA email gets a click, drawn as one small office.
Bring your insurer’s cyber questionnaire to the free IT consult. We will go through it with you.
What you can count on
- Under 2 hrsto restore a failed server from local backups
- 30 days lockedbackups no one can delete early, not even us
- 3-2-1backup copies, one offsite in Vancouver, BC
- 24/7a person answers (604) 813-7881
Why does a tax file need more protection than most?
Once a year, clients hand you their whole financial life. Keeping it private is part of the job, and part of why they come back.
SINs, slips and bank details in one place
One client file can hold a SIN, a date of birth, T4 and T5 slips, banking details and past returns. Together, that is what someone needs to attempt identity theft or a fake refund. Service Canada asks people to keep their SIN confidential, and your clients trust you with it.
Fake CRA messages look real
Scammers copy the CRA, and tax season gives them cover. The CRA says its emails will not include a link asking you to enter personal or financial information, and that it will never email or text you a link to a refund. Your staff see these messages too, often dressed up as a client.
Your EFILE access is a key
The CRA asks EFILE filers to keep their EFILE number and password confidential, and to tell the CRA right away about any loss, or suspected loss, of client information from electronic filing. One stolen staff login can put both at risk.
Privacy law expects real safeguards
Canadian privacy law asks firms to protect personal information with safeguards that match how sensitive it is, and financial information is generally treated as sensitive. In BC and Alberta, the provincial Personal Information Protection Act usually applies. PIPEDA applies when information crosses provincial or national borders, and under PIPEDA a breach that creates a real risk of significant harm must be reported to the Privacy Commissioner and the people affected told.
General information, not legal advice. Ask your lawyer or professional body what applies to your firm. Sources: CRA, recognize a scam, CRA, EFILE responsibilities, Service Canada, protect your SIN, Privacy Commissioner of Canada, safeguards and which privacy law applies.
A real case, seen as a client
An Alberta accounting firm, in the middle of tax season
In early April, an Alberta accounting firm found ransomware on its network. It locked their computers, and staff could not reach their data.
They wiped every computer, storage device and server, and rebuilt from backups the attack had not touched. They reported it to the police. To meet tax deadlines, they rebuilt quickly and did not investigate how the attackers got in.
They also had to send their clients a breach notice. It said the information that may have been involved included:
We know this one from the other side. We were a client of this firm, and our own personal and business information was in that breach notice. We had raised security concerns with them before the attack. After the attack, from where we sat as a client, the firm could not work the way it used to, and we moved our accounting elsewhere. Your clients can do the same.
What changes the ending
- Backups locked for 30 days, with an offsite copy, and tested. A clean copy is there to restore, and you already know it works.
- Huntress on every computer. Watched 24/7 by our security operations team (SOC), with a text alert when something looks wrong.
- A written breach plan. Who to call, who decides, and how clients and regulators are told. We recommend one for every firm.
- Find how they got in before you rebuild. Otherwise the same door can still be open when the new systems go live.
The office, item by item
Green shields are the 6 security layers. Grey circles are the rest of a good build. The cards below explain each one.
- A business firewall at the front door
- DNS filtering, in the office and at home
- Huntress and BitLocker on every computer
- Multi-factor sign-in with number matching
- Backups locked for 30 days, with an offsite copy
- Email that is hard to fake
- A Hyper-V server for your tax and accounting software
- RAID 10 storage
- Guest Wi-Fi kept separate
- Printers and scanners on their own network
- A UPS (battery backup)
The checklist
The 6 security layers
These are the layers that keep client SINs, slips and banking details private. See how our cybersecurity works.
Security layer
A business firewall at the front door
Why it matters. Everything that comes in from the internet passes through here first.
A Cisco Meraki MX firewall with Advanced Security, sized to your internet speed so protection does not become the bottleneck.
Security layer
DNS filtering, in the office and at home
Why it matters. A fake CRA link only works if the page loads.
DNS filtering blocks known bad sites before they load. A roaming agent keeps it on when a laptop leaves the office, so staff working from home in March are covered too.
Security layer
Huntress and BitLocker on every computer
Why it matters. A lost laptop full of client returns, or a quiet attack, should not become a breach.
Huntress Managed EDR is on every computer we manage, watched 24/7 by our security operations team (SOC), who send a text alert when something looks wrong. BitLocker disk encryption is on by default, unless your software vendor says otherwise, and comes with Microsoft 365 Business Premium, our standard plan for firms under 300 users, along with Intune, Defender for Business, Conditional Access and Purview Message Encryption.
Security layer
Multi-factor sign-in with number matching
Why it matters. A stolen password is far less useful on its own, and fake sign in pages are common in tax season.
Email and remote access ask for a number match on your phone. Remote desktop is never exposed to the internet. Remote access goes through a secured gateway instead.
Security layer
Backups locked for 30 days, with an offsite copy
Why it matters. Ransomware goes after backups first. A locked copy and an offsite copy mean there is always one it cannot reach.
The 3-2-1 plan: three copies, two kinds of storage, one offsite in Vancouver, BC. Each backup is locked for 30 days, and nobody can unlock it early, not even us. We spot check multiple copies and run a yearly disaster recovery test. When we restore a failed server from local storage, it has taken less than 2 hours.
Security layer
Email that is hard to fake
Why it matters. A fake email that looks as if it came from your firm, or from a client, can ask someone to change bank details or send a refund to a new account.
We recommend SPF, DKIM and DMARC on your firm’s domain, and we can set them up and check them.
The rest of a good build
A Hyper-V server for your tax and accounting software
Why it matters. One dead server in March should not stop the firm.
We build at least 2 virtual servers: one for sign in (the domain controller) and one app server for software such as Caseware, QuickBooks, ProFile and Taxprep. On Hyper-V, the server is a set of files we can bring back on other hardware.
RAID 10 storage
Why it matters. A failed drive should not stop tax prep.
RAID 10 for virtual machine storage is standard in our builds. Built on ITIL best practices, so changes are planned and recorded. RAID is not a backup.
Guest Wi-Fi kept separate
Why it matters. Clients in the waiting area should never share a network with client files.
We recommend separate networks (VLANs) on Layer 3 PoE switches, and we can set them up.
Printers and scanners on their own network
Why it matters. The file and scan station handles slips, ID and signed returns all day.
We recommend keeping printers and scanners on their own network, and we can set it up.
A UPS (battery backup)
Why it matters. A power blip should not corrupt the server on a filing day.
We recommend a UPS, plus a second internet line so one cut cable does not stop a deadline day. We can set up both.
Also on our list: patching (we keep your systems patched), awareness training for everyone, and a written plan for a breach and for downtime in tax season.
The call back rule for payments
Payment fraud often starts with a normal looking email: a client’s “new” bank account for a refund, a vendor’s changed payment details, or a partner asking for an urgent transfer.
- Confirm any change to bank details by phone, on a number you already have. Never use the number in the email.
- Have two people sign off on large or unusual payments.
- Turn on multi-factor sign-in for every mailbox, so a stolen password cannot be used to send the email in the first place (item 4).
- Make your domain harder to fake with SPF, DKIM and DMARC (item 6).
More from the Canadian Anti-Fraud Centre: frauds that target businesses.
What do cyber insurers ask accounting firms?
Cyber insurance renewals ask the same kinds of questions every year. Most answers are on this page.
What insurers tend to ask
- Is multi-factor sign-in on for email, remote access and admin accounts?
- Are backups tested, and is there a copy an attacker cannot change?
- Are computers kept up to date and watched by security software?
- Do staff get security awareness training?
- Is your email domain protected against spoofing?
Where it is on this checklist
- Multi-factor sign-in with number matching: item 4.
- Locked, tested backups with an offsite copy: item 5.
- Huntress on every computer: item 3. Patching: we keep your systems patched.
- Awareness training: also on our list.
- SPF, DKIM and DMARC: item 6.
Bring the questionnaire to your free IT consult and we will go through it with you. It does not replace your insurer’s own questions or legal advice.
Accounting firms we have helped
An accounting firm of about 75 people
We look after their managed IT. When COVID hit, we got their whole team working securely from home. Along the way we cut their email costs by $33,000 a year.
Reschke Fritz LLP
We helped Reschke Fritz get started, setting up their first servers and network. As they grew, we helped them open new offices in Whitecourt and St. Albert. When COVID hit, we moved the team to secure remote work with zero trust access.
We support the software your firm already uses, including Caseware, QuickBooks, Sage, Xero, Karbon, ProFile, Taxprep and TaxCycle. See the software we support.
What worries accounting firms most about IT
Six common worries. Each has a short, plain guide.
Will it hold up in February?
Everything slows down at once, and a bad day in tax season costs the most.
Tax season is phishing season
Fake client emails, a hijacked mailbox, and files locked on a Monday morning.
If an EFILE password goes missing, who do we call?
Client confidentiality, the CRA and privacy, in plain words.
Staff work from home and it crawls
Why a VPN is slow for QuickBooks, and the safer way to work remotely.
We have backups. Have we ever restored one?
Why untested backups let people down, and how to prove yours.
Will every ProFile or Taxprep seat open?
Licences, installs and updates, before the rush.
Use this as a checklist
Take it to your next IT quote or a second opinion, and ask which items are in place today. Every firm is a little different, so we are happy to go through it with you, ideally before tax season.
Talk to a person.
24/7 emergency line
Mon to Fri, 7am to 5pm MT. Emergency support 24/7 at (604) 813-7881, always answered by a person.
