Blog | TaxCalc

Guarding the Gateway: A Cyber Security Playbook for UK Practices

Written by Elizabeth Suillivan | Sep 9, 2026, 7:00:00 AM

The Most Valuable Asset in Your Firm Is a Login

Ask a practice owner to name their firm's biggest asset and you will usually hear about the client base, the team or the recurring fee income. Very few will say "our agent services account". Yet that single set of credentials sits in front of the tax affairs of hundreds or even thousands of taxpayers, and it can be used to file returns, claim repayments and redirect money. Criminals worked this out some time ago.

While the profession has spent 2026 absorbed by quarterly updates, Companies House reform and the next wave of Making Tax Digital, the threat landscape has quietly become the most under-managed risk in UK practice. The Cyber Security Breaches Survey 2025/2026 found phishing to be by far the most common attack type, reported by 38 per cent of all UK businesses and present in 88 per cent of businesses that identified a breach. The Information Commissioner's Office receives data breach reports from roughly 100 UK accountants every quarter attributable to cyber attacks. Accountancy is not collateral damage in someone else's crime wave. It is a chosen target.

 

What an Attack on a Practice Actually Looks Like

Firms often picture a faceless hacker brute-forcing a password. The reality reported by practitioners is far more patient and far more convincing.

A typical pattern runs like this. The firm receives a phone call from a prospective client, using the name of a genuine local business, explaining that they are struggling with HMRC and some late filings. A follow-up email arrives with what appears to be a PDF of an HMRC letter. It is not a PDF. It is a disguised link that silently installs remote access software, and in some reported cases the intruders then disable or hijack the firm's antivirus. They sit quietly for weeks, watching, learning the naming conventions, the client list and the working rhythm of the practice.

Then they act. Fraudulent VAT returns with large repayment claims. Self Assessment returns claiming Construction Industry Scheme refunds. Bank details switched to accounts the criminals control. In several reported cases the firm only discovered the breach when a partner noticed unfamiliar bank details against a client record. One practitioner described the aftermath as the worst experience of their working life, and said they genuinely considered walking away from the business they had spent years building.

That is the real cost. Not just the money, which HMRC may eventually recover, but the client notifications, the ICO report, the professional body report, the insurance claim, the rebuilt machines, the lost weeks and the quiet erosion of trust that follows.

 

Why 2026 Raises the Stakes

Three things have changed the risk profile for practices this year.

  • More digital touchpoints. Quarterly reporting means far more data moving between clients, bookkeeping platforms, your software and HMRC, on a far more frequent cycle. Every additional connection is a potential entry point.
  • More credentials in circulation. Agent registration, ACSP registration, bookkeeping platform logins and client portals mean the average firm now manages more privileged access than ever, often without a formal register of who holds what.
  • A busier, more distracted profession. Social engineering works best on people under time pressure. The run-up to a quarterly deadline or the January filing peak is exactly when a plausible email about an urgent HMRC letter is most likely to be opened without a second thought.

There is also a hard truth about the agent services account itself. Multi-factor authentication on the agent gateway has long been a source of frustration for practitioners, who report that it is inconsistently enforced and does not always challenge a login from a familiar device or location. Firms cannot control HMRC's roadmap. They can control everything that sits in front of that login.

 

The Controls That Actually Move the Needle

You do not need an enterprise security budget. You need a short list of controls applied consistently.

  • Enforce multi-factor authentication everywhere it is available. Email, practice management, bookkeeping platforms, cloud storage and every government login. Cyber specialists consistently put this at the top of the list because it blocks the overwhelming majority of account-based attacks.
  • Use a password manager and unique passwords. One reused password is one breach away from becoming a master key.
  • Strip credentials out of retired software. If you have decommissioned tax or payroll software, remove the stored gateway credentials and close the account. Old software is a forgotten back door.
  • Verify inbound enquiries out of band. New client contacts and any request to change bank details should be confirmed using a number you have independently sourced, never a number or link in the original email.
  • Invest in business-grade email filtering and endpoint protection. Consumer antivirus is not a control framework, and many cyber insurance policies now require business-grade protection with scan logs.
  • Back up daily, store offsite, and test the restore. Cloud is not a backup if an intruder changes your login credentials.
  • Apply least privilege and a real leavers process. Not everyone needs full access. Nobody who has left should retain any.
  • Patch promptly and consider Cyber Essentials. Certification gives you a structured baseline and a credible answer when clients and insurers ask what you do about security.

 

Learn to Spot the Early Signals

Most compromises are visible before they become expensive, if someone knows what to look for. Treat the following as an alarm rather than an annoyance:

  • Password reset emails nobody requested
  • Two-factor authentication texts arriving at odd hours
  • Unexplained lockouts from your gateway or software
  • Sign-ins from device types your firm does not use
  • Calls from unrecognised numbers asking to move the conversation to a messaging app
  • Repayment claims or amended returns you do not recognise, or client bank details that have changed

Build a simple weekly habit of reviewing submissions and repayment positions across your client base. In the January and quarterly peaks, make it more frequent. If you are ever locked out of a government account, check daily until access is restored, because the criminals will be doing exactly that, and change the password the moment you get back in.

 

Have an Incident Response Plan Before You Need One

A breach is a project management problem under extreme time pressure. Decide the running order now, while you are calm, and write it down on one page:

  • Isolate affected devices and change credentials from a clean machine
  • Contact HMRC's online services helpdesk and report the compromise
  • Assess whether personal data is involved and report to the ICO within 72 hours where required
  • Notify your professional body, your professional indemnity insurer and your cyber insurer
  • Report to Action Fraud
  • Tell affected clients promptly, with a clear factual account and what you are doing about it
  • Rebuild rather than clean compromised machines, then review and evidence the improvements

Firms that handle the first 48 hours well tend to keep their clients. Firms that improvise rarely do.

 

Turn Your Own Discipline Into a Client Conversation

Here is the commercial upside. Your clients are being targeted by the same criminals, usually with fewer defences and no in-house expertise. A practice that has genuinely tightened its own controls has earned the right to raise the subject, and it is a natural extension of the advisory conversations that quarterly reporting has already opened up.

Talk to clients about verifying changes to supplier bank details, about invoice redirection fraud, about who in their business can authorise a payment, and about the repayment scams that circulate every January. Some firms are packaging this as a paid resilience review. Others simply use it as a differentiator at the renewal conversation. Either way it positions you as the adviser who protects the business, not just the one who files the return.

 

A 30 Day Plan for Your Practice

  • Week one: list every privileged login in the firm and who holds it. Enable multi-factor authentication on every account that supports it.
  • Week two: remove credentials from retired software, close dormant accounts, and run a leavers access audit.
  • Week three: confirm backups are running, offsite and restorable. Test one restore properly.
  • Week four: run a 45 minute team session on phishing and social engineering using the fake prospective client scenario, and write your one page incident response plan.

None of this is glamorous, and none of it will feel urgent until the day it is the only thing that matters.

 

Security Is Now Part of Compliance

The profession has spent 2026 proving it can absorb enormous regulatory change. Cyber resilience deserves the same seriousness. Every quarterly update, every digital link and every client portal login has expanded the surface area of your practice, and criminals are watching that expansion closely.

Firms that keep client data in one controlled, well governed system rather than scattered across spreadsheets, inboxes and shared drives are structurally harder to attack and far faster to recover. Centralised client records, controlled access, secure document exchange and a clear audit trail of what was filed and when are not just efficiency features. They are the foundations of a defensible practice.

If you want to see how a single integrated platform can reduce both your admin burden and your risk exposure, book a TaxCalc demonstration and see how firms are filing faster while keeping client data under proper control.