<15 min Response

20+ Years Experience

Cyber Essentials Certified

Check Your IT Score

Remote SOS Support

Cyber Security for Accountants: What UK Practices Need in Place in 2026

ATS Connection engineers working on a client's IT support

The short answer: Accountancy practices hold exactly what criminals want: client financial data, identity documents and access to HMRC agent accounts. The essentials are multi-factor authentication on every account (HMRC is switching it on for all remaining agent accounts between 28 September and 15 October 2026), protected and patched devices, defences against email impersonation, tested backups, and a breach plan that meets the UK GDPR 72-hour reporting deadline. Cyber Essentials is the usual way to prove the basics are in place.

Last updated: 1 October 2026. Checked against HMRC’s Tax Agents Handbook and Agent Update, ICO guidance, the Money Laundering Regulations and ICAEW’s 2026 Practice Assurance monitoring report on that date.

In this guide

Why are accountancy firms targeted?

Accountancy firms are targeted because one compromised mailbox or login can unlock many clients at once. As ACCA puts it, “Cybercriminals know that accounting firms hold the kind of high value data that they can sell, use to commit crimes or use as a springboard to launch further attacks.” A practice typically holds bank details, payroll data, passports and utility bills from client due diligence, and the credentials to file on behalf of hundreds of taxpayers.

HMRC has warned agents directly. Its Agent Update of September 2025 said: “Criminals are using increasingly sophisticated methods to target tax agents, including phishing emails claiming to be from realistic companies, clients and HMRC.” An earlier update described criminals “often tricking tax agents into downloading legitimate commercial software that gives them remote access to their devices”, and warned that HMRC may suspend a compromised account without notice. For a practice, a suspended agent account in January is a serious problem in its own right.

Phishing is still the most common attack UK businesses report. The Government’s Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses had a cyber security breach or attack in the last 12 months, and that phishing was by far the most common type, experienced by 38% of businesses.

What is changing with HMRC agent accounts?

HMRC is adding multi-factor authentication (MFA) to agent online services accounts. After entering your Government Gateway user ID and password, you are asked for a one-time access code, and HMRC says “This extra step helps protect your account, even if your sign in details have been compromised.” According to the Tax Agents Handbook, “All remaining accounts will automatically be activated between 28 September 2026 and 15 October 2026”, and HMRC cannot give a specific date for each account.

Three practical points for practices:

  • Decide where the codes go. Shared logins and a single partner’s phone become a bottleneck the first week MFA is live. Each person who files should have their own access.
  • Remove leavers. HMRC’s guidance is that “you should remove access for any staff who leave your organisation or no longer need access to your HMRC online services.” The same applies to Microsoft 365 and your practice software.
  • Use the security console. HMRC says agents can now report suspicious activity using the security console in their agent online account, as long as MFA is activated. Suspected phishing that mentions HMRC can be forwarded to phishing@hmrc.gov.uk.

HMRC’s Standard for Agents already expects agents to keep “online access and HMRC account credentials safe from unauthorised use at all times” and to “maintain the security of client information they hold”. MFA makes that much easier to show.

What do the rules require of an accountancy practice?

No single rule sets out an IT standard for accountants, but several obligations land on your systems. The main ones are:

ObligationWhat it means for your ITSource
UK GDPR breach reportingA notifiable breach must be reported to the ICO “without undue delay, but not later than 72 hours after becoming aware of it”. You need logging and alerting good enough to know what happened, fast.ICO
Money Laundering Regulations record keepingCustomer due diligence records must be kept for at least five years after the business relationship ends. That means secure, backed-up storage for ID documents with access limited to the people who need it.MLR 2017, reg 40
HMRC Standard for AgentsKeep HMRC credentials safe from unauthorised use and keep client information secure.HMRC
Professional body monitoringICAEW’s Practice Assurance reviews now cover cyber security and data protection. Its 2025 report found 34 firms that had not registered with the ICO.ICAEW 2025, ICAEW 2026
Making Tax Digital for Income TaxSole traders and landlords with qualifying income over £50,000 should have started from 6 April 2026, with £30,000 from April 2027 and £20,000 from April 2028. More clients, more software connections and more data to protect.HMRC
Obligations that affect IT in a UK accountancy practice.

On anti-money laundering supervision: accountancy service providers are currently supervised by their professional body or, if they have none, by HMRC. The government decided in October 2025 that the FCA will take over supervision of the professional services sector, with the start date “heavily dependent on the availability of parliamentary time”. The record-keeping duty does not change either way.

Which cyber security controls should an accountancy practice have?

Most of the risk is covered by a short list of controls, applied consistently to every account and device. ICAEW’s 2026 monitoring report recommends firms develop an incident response plan and test it at least annually, sign up to the NCSC’s Early Warning service and run staff training and awareness. In practice, a well-run practice has:

  1. MFA everywhere. Microsoft 365, HMRC agent services, practice management and cloud accounting software, banking and remote access. The NCSC says turning on two-step verification “is one of the most effective ways to protect online accounts when passwords are still in use”.
  2. Email that resists impersonation. SPF, DKIM and DMARC on your domain, impersonation protection for partners’ names, and alerts when someone creates a mailbox forwarding rule.
  3. Managed, encrypted devices. Every laptop encrypted, patched and running endpoint protection, including home-working machines. No client data on unmanaged personal devices.
  4. Controlled remote access. Remote access software only where you have chosen it, given HMRC’s warning about criminals persuading agents to install it.
  5. Least-privilege access and a leaver process. Staff see the client files and systems their role needs. Leavers lose access on their last day, across every system.
  6. A secure way to receive documents. A client portal or secure upload rather than passports and bank statements arriving as email attachments.
  7. Independent, tested backup. Microsoft 365 and practice data backed up outside Microsoft’s own retention, with restores tested, not assumed.
  8. A written incident plan. Who to call, how to contain an incident, and how you would meet the ICO’s 72-hour deadline. Tested once a year.

These map closely onto the five Cyber Essentials controls, which is why most practices start there. Our IT support for accountants service puts these controls in place and keeps them running.

Does an accountancy practice need Cyber Essentials?

Cyber Essentials is not a regulatory requirement for accountants, but it is the recognised baseline and the easiest way to show clients, insurers and your professional body that the basics are in place. ICAEW’s 2026 report describes certificates like it as helpful but often only a starting point, to be underpinned by strong cyber governance. Of the 121 larger firms ICAEW discussed cyber security with during its 2025 monitoring, 99% were aware of the scheme, 54% had completed the basic Cyber Essentials self-assessment and 29% had completed Cyber Essentials Plus (ICAEW Practice Assurance monitoring report 2026).

Our guide to Cyber Essentials cost sets out the fees, and the Cyber Essentials requirements checklist explains what you need in place first. ATS is Cyber Essentials certified and helps practices prepare for it.

What should a practice do if it is breached?

Act quickly, and in this order:

  1. Contain it. Call your IT provider, reset the affected passwords, revoke sessions and remove any forwarding rules or unknown remote access software.
  2. Protect your HMRC access. HMRC says that if you notice suspicious activity on your agent account you should not try to correct anything yourself and report it to its online services team straight away.
  3. Assess whether the ICO needs to know. A notifiable breach must be reported without undue delay and no later than 72 hours after becoming aware of it, and affected individuals must be told directly and without undue delay if it is likely to result in a high risk to them (ICO).
  4. Report fraud. Fraud and cyber crime in England, Wales and Northern Ireland is reported to Report Fraud, which replaced Action Fraud.
  5. Tell your insurer straight away if you have cyber cover. Many policies require notice before you incur recovery costs.
  6. Learn from it. Record what happened and what changed, which is what your professional body will want to see.

Frequently asked questions

Do accountants need Cyber Essentials?

No regulator requires it, but it is the recognised baseline and some clients and insurers ask for it. ICAEW’s 2026 Practice Assurance report found that 54% of the larger firms it discussed cyber security with had completed the basic Cyber Essentials self-assessment, and 29% Cyber Essentials Plus. See our guide to Cyber Essentials cost.

Is MFA mandatory for HMRC agent accounts?

HMRC is adding multi-factor authentication to agent online services accounts, and says all remaining accounts will be activated automatically between 28 September 2026 and 15 October 2026 (Tax Agents Handbook).

How long must accountants keep anti-money laundering records?

Under regulation 40 of the Money Laundering Regulations 2017, customer due diligence records must be kept for five years from the end of the business relationship, or from completion of an occasional transaction (legislation.gov.uk).

Do accountancy firms have to report a data breach?

If a personal data breach is notifiable, it must be reported to the ICO without undue delay and within 72 hours of becoming aware of it. If it is likely to result in a high risk to the people whose data is involved, they must be told directly and without undue delay too (ICO).

How much does cyber security cost for a small accountancy practice?

With ATS, practices handling client financial data typically sit on Complete IT and security at £55 to £90 per user per month, excluding VAT, which includes managed cyber security, Microsoft 365 management and independent backup. The full breakdown is on our IT support pricing page.

Sources

Free • 12 minutes • Written PDF report

Who actually holds the keys to your systems?

List the systems your business runs, answer plain-English questions about how they are controlled, and get a report with a red, amber and green rating for every area and what to fix first. Nothing on your systems is touched.

Cyber Essentials certified · Microsoft Partner · rated 5.0 on Google

Take the free IT Security Review

Free • No obligation • Senior engineer • 30 minutes

Want a straight answer about your own IT?

We look after IT, cyber security and phones for businesses across Sussex and the UK, on a fixed monthly price from £30 per user. Book a free review and a senior engineer will tell you plainly what is worth fixing first.

Your free IT review

  • Review WiFi, devices and network infrastructure
  • Benchmark Microsoft 365 and security posture
  • Assess backup, recovery and operational continuity
  • Map a clear, costed IT & security roadmap

Book your free IT & cyber review



Free, no obligation. We only use your details to arrange the review. Privacy policy.