IT and Cybersecurity Checklist for Accounting Firms: A Practical Guide for Canadian CPA Practices

An accounting or CPA firm needs the same IT foundations as any small business, with less room for error: every account protected by multi-factor authentication, email that is hard to impersonate, managed and encrypted laptops, a safe way to exchange files with clients, backups that are proven to restore, and support that is reachable in the weeks before a filing deadline. What makes a firm different is what it holds. A small practice can keep social insurance numbers, income, banking details and identity documents for hundreds of clients, and the people who want that data know it.
This guide is a practical checklist for partners and office managers at accounting, bookkeeping and tax practices in Ontario and across Canada. It covers the controls that matter most, how to prepare for tax season, how client files should move, what to do when someone joins or leaves, and what to look for when you choose an IT provider. It is written by IT Rapid Support, a managed IT and cybersecurity provider at 7810 Keele St in Vaughan, so read it with that in mind; the checklist applies whoever runs your IT.
Why Accounting Firms Are a Target
Attackers go where the value is and the defences are thin. An accounting practice holds the information needed for identity theft and for redirecting refunds or payments, and it routinely sends documents and payment instructions by email, which is exactly the channel fraud uses. The incidents that reach small firms are rarely sophisticated: a phishing email that captures a Microsoft 365 password, a mailbox entered because multi-factor authentication was not enforced on every account, an old shared login nobody removed, or ransomware arriving through an unpatched workstation. Each of these is prevented by ordinary controls applied without exceptions.
The Core IT and Security Checklist
Work through this list with whoever manages your IT. Anything you cannot answer yes to is a gap worth closing before the next busy season.
Accounts and sign-in
- Multi-factor authentication is enforced on every Microsoft 365 or Google Workspace account, including partners, admins, shared mailboxes and service accounts, with no standing exceptions.
- Each person has their own login for every system. No shared passwords for the tax software, the practice management system or government portals.
- Administrator accounts are separate from day-to-day accounts and are held by at least two trusted people.
- A business password manager is used instead of spreadsheets, sticky notes or browser-saved passwords on shared machines.
- Email filtering catches phishing and malicious attachments before they reach staff.
- SPF, DKIM and DMARC are set up on your domain, and DMARC is moved beyond monitoring to a policy that tells receiving servers to quarantine or reject forged mail. Our guide to SPF, DKIM and DMARC explains what each record does.
- Automatic forwarding to outside addresses is blocked, and new inbox rules are reviewed, because attackers use them to hide replies.
- Staff know that any change to banking details or a request to send money is confirmed by phone, using a number already on file, never one from the email.
Devices
- Every laptop and workstation is managed, patched on a schedule and running managed endpoint protection.
- Laptops have full-disk encryption turned on, so a lost or stolen device is an inconvenience rather than a disclosure.
- Windows versions are supported. Machines still on Windows 10 need a plan; see our Windows 10 end of support guide.
- Personal devices that open client files or email are covered by a policy and, where possible, by device management.
Data and backups
- You know where client data lives: the file server or SharePoint, the practice management and tax software, mailboxes, and any local folders.
- Staff reach only the client files their role requires, and access is reviewed at least once a year.
- Backups are automatic, encrypted, include Microsoft 365 or Google Workspace data, and keep at least one copy that ransomware on your network cannot reach.
- A restore has actually been tested in the past few months, not just a backup report read. Our disaster recovery plan guide covers recovery targets and testing.
Monitoring and response
- Someone is watching for suspicious sign-ins and endpoint alerts outside business hours, not only when a ticket comes in.
- There is a written one-page plan for a hacked mailbox, a ransomware infection and a fraudulent payment, with phone numbers for your IT provider, bank and cyber insurer.
Getting Ready for Tax Season
Most firms feel IT problems hardest between February and the April 30 personal filing deadline, and again before June 15 for self-employed returns. The work that prevents a crisis happens before then:
- Schedule hardware replacement, operating system upgrades and migrations well before the busy period, and agree a freeze on non-urgent changes during it.
- Confirm your tax software is updated to the current year's release on every workstation and that licences cover seasonal staff.
- Check storage space, backup success and internet capacity before volumes peak.
- Set up accounts, devices and multi-factor authentication for seasonal staff in advance, with an end date for their access.
- Make sure your helpdesk is reachable during the hours you actually work in deadline weeks, which are rarely nine to five.
Client Portals and File Exchange
Email attachments are the weakest way to move tax slips, statements and identity documents. They sit in two mailboxes indefinitely, are easy to send to the wrong person and are the first thing an attacker reads in a compromised account. A better pattern is a client portal or managed sharing links with expiry, access logging and multi-factor authentication on the staff side. Whichever tool you use, decide how long files stay available, who in the firm can share externally, and how clients are told to verify a request that appears to come from you.
CRA Access, Confidentiality and Privacy Rules
Several sets of rules shape how a firm handles data, and IT is how most of them are met in practice:
- CRA online services for representatives are tied to named individuals. Credentials and the multi-factor authentication behind them should never be shared between staff, and access should be removed promptly when someone leaves.
- PIPEDA applies to most private-sector firms handling personal information in the course of commercial activity. It requires safeguards appropriate to the sensitivity of the data, a record of every breach of security safeguards, and reporting to the Office of the Privacy Commissioner and to affected individuals when a breach creates a real risk of significant harm. Our PIPEDA compliance IT checklist goes through the IT side in more detail.
- CPA members are bound by their professional code's confidentiality obligations, which in a modern practice depend heavily on access control, encryption and secure file exchange.
- Accountants and accounting firms can also have obligations under Canada's anti-money laundering legislation when they carry out certain financial activities for clients. FINTRAC publishes guidance on when those apply, including record-keeping requirements your systems need to support.
This is IT guidance, not legal or professional advice. Confirm your specific obligations with your professional body or legal counsel.
Staff Joining and Leaving
Most access problems in small firms come from people changing roles or leaving. Keep a short written checklist for both. When someone joins: their own accounts, multi-factor authentication set up on a firm-controlled or registered device, access only to the clients and folders they need, and a short briefing on phishing and payment-change verification. When someone leaves: disable their accounts on the day, revoke government portal access and any delegated authorizations held in their name, recover devices, transfer mailbox and file ownership, and change any shared credentials they could have known.
What to Look for in an IT Provider for an Accounting Firm
If you are comparing providers, ask questions that show how they work rather than what they promise:
- Will they enforce multi-factor authentication on every account, and how do they handle the partner who wants an exception?
- Do they monitor and test-restore backups, and can they show you the last test?
- Who watches security alerts at night and on weekends, and what happens when something is found?
- How do they schedule changes around filing deadlines, and is the helpdesk staffed in the hours you work in March and April?
- Do they work directly with your tax and practice management software vendors when a problem belongs to the vendor?
- Is the agreement clear about what is included, and is project work scoped and quoted in writing before it starts? Our guide on what a managed IT contract should include lists the clauses to check.
How IT Rapid Support Works With Accounting Firms
IT Rapid Support provides managed IT, cybersecurity and Microsoft 365 administration for accounting, bookkeeping and CPA practices across the Greater Toronto Area from our office at 7810 Keele St in Vaughan, with remote support for firms elsewhere in Canada. Support, security, backup and helpdesk sit on one agreement scoped to the users and devices we cover, and project work is scoped and quoted in writing. The service details are on our page for IT support for accounting and CPA firms. To review your firm against this checklist, call (289) 582-9930 or contact us.
Frequently Asked Questions
What IT security does an accounting firm need?
At minimum: multi-factor authentication on every account, email filtering with SPF, DKIM and DMARC on your domain, managed and encrypted devices with current patches and endpoint protection, role-based access to client files, a secure way to exchange documents with clients, and backups that are tested by restoring them. Monitoring outside business hours and a written incident plan close the remaining gaps.
Is it safe to email tax documents to clients?
It is common but it is the weakest option. Attachments stay in both mailboxes indefinitely and are exposed if either account is compromised. A client portal or managed sharing links with expiry, logging and multi-factor authentication are safer, and clients should be told how to verify any request that appears to come from your firm.
Do accounting firms in Canada have to report data breaches?
Under PIPEDA, private-sector organizations must keep a record of every breach of security safeguards involving personal information and must report a breach to the Office of the Privacy Commissioner and notify affected individuals when it creates a real risk of significant harm. Other rules may also apply depending on your province and practice, so confirm with counsel.
How should an accounting firm prepare its IT for tax season?
Do upgrades, replacements and migrations before February, then freeze non-urgent changes until after the filing deadlines. Update tax software on every workstation, check backups, storage and internet capacity, set up seasonal staff accounts in advance with an end date, and make sure your helpdesk is reachable in the hours your team actually works.
Can staff share a login for CRA or tax software?
No. Shared logins break the audit trail, make it impossible to remove one person's access cleanly, and generally conflict with the terms of government online services. Each person should have their own credentials and their own multi-factor authentication.
What should we ask an IT provider before hiring them?
Ask how they enforce multi-factor authentication, how and when they test backups, who monitors security alerts after hours, how they schedule work around filing deadlines, whether they deal directly with your software vendors, and what is included in the agreement versus scoped and quoted separately.
Share this resource

IT Rapid Support Team
Managed IT & Cybersecurity, GTA
IT Rapid Support Team is a security expert with extensive experience in creating security guidelines.
More from this authorFurther Reading
Related Resources

IT and Cybersecurity Checklist for Nonprofits and Charities
The IT and security controls a charity or nonprofit needs: a systems inventory, donor data and CRM access, MFA, shared and volunteer accounts, offboarding, Microsoft 365 and Google nonprofit programs, donation and impersonation fraud, SPF/DKIM/DMARC, backups, board reporting and what to ask an IT provider.
Read more: IT and Cybersecurity Checklist for Nonprofits and Charities
IT and Cybersecurity Checklist for Schools: Accounts, Devices, Wi-Fi and Student Data
The IT and security controls a private or independent school needs: student and staff accounts with MFA, Chromebook and laptop fleets, separate student, staff and guest Wi-Fi, content filtering, student records privacy, tuition and vendor payment fraud, backups, the summer refresh and what to ask an IT provider.
Read more: IT and Cybersecurity Checklist for Schools: Accounts, Devices, Wi-Fi and Student Data
IT and Cybersecurity Checklist for Restaurants: Keeping the POS, Wi-Fi and Card Data Safe
The IT and security controls a restaurant needs: keeping the POS running during service, internet failover, separating guest Wi-Fi from payment systems, PCI DSS basics, staff turnover and shared logins, delivery platform and payment fraud, multiple locations and what to ask an IT provider.
Read more: IT and Cybersecurity Checklist for Restaurants: Keeping the POS, Wi-Fi and Card Data SafeNeed Expert Security Advice?
Our team of cybersecurity experts is ready to help you secure your organization. Schedule a free consultation today.
Get in Touch