Building Cyber Resilience in Accounting and Financial Services

header - cyber security for Financial Services

Today’s accounting and financial services firms navigate a landscape of escalating cyber risks and increasing compliance requirements. A single cyber attack can erode your firm’s operational, financial and reputational standing. Preventing such costs necessitates a proactive and comprehensive approach to cyber security.

This blog summarises the impacts of a cyber-attack, the most pressing threats facing accounting and financial firms, and practical strategies for mitigating risk. Financial and accounting providers can better position their firms to develop a robust and sustained approach to protecting business and client data by understanding these challenges.

The Finance Sector reported 58 data breaches to the OAIC between January and June 2024, the third-highest reporting industry.

Source: OAIC

The True Costs of a Cyber Incident

The immediate, measurable impacts most firms anticipate when experiencing a breach include:

  • Direct financial losses: Ransom payments and asset recovery are typically the first expenses incurred after an incident.
  • Immediate revenue loss: Some clients may feel compelled to sever ties if their data or assets are compromised. 34% of surveyed executives cited loss of clientele as a major long-term consequence of a cyber-attack.
  • Compliance fines or legal penalties: These can compound financial damage depending on regulatory breaches involved.

These longer-term, less visible consequences often go unnoticed until they begin to erode the firm’s stability and growth:

  • Reputational damage: 41% of CISOs and C-level executives state reputational damage as the most significant post-breach cost. Once news breaks that your firm has experienced a breach, people will be more reluctant to work with you or recommend you to others.
  • Increased staff attrition: Staff can lose trust in the organisation; 54% of office workers say a cyber breach would influence their decision to stay with their employer.

Current Cyber Threats for Accounting and Financial Services

Cybercriminals tend to target financial institutions due to the immense amount of valuable data they handle daily, such as banking details, financial records, tax file numbers, payroll data, and identification documents. The accounting and financial sectors are high-value targets and at risk without the appropriate protections and safeguards.

  • Ransomware: There were 3% more ransomware attacks compared to the previous year in FY 2023-24. Hackers steal and encrypt information during the attacks and threaten to publish the information if the ransom is not received.
  • Business Email Compromise (BEC) and Phishing: These threats hijack employee credentials or use false pretences to cause employees to participate in fraudulent transactions. In recent times, these risks have been even more problematic with attackers having devised a means to circumvent multi-factor authentication (MFA) using stolen session cookies. Such stolen cookies may be utilised to authenticate cloud services, bypass MFA, and gain access to sensitive information without authorisation.
  • Advanced Persistent Threats: Ongoing, targeted cyber-attacks by sophisticated aggressors, often state-sponsored, designed to steal sensitive financial data and compromise business operations.
cyber security for accounting services

Cyber Security Obligations for Directors

Cyber security is now a core priority for directors of financial and accounting firms, who are now expected to demonstrate leadership in ensuring their organisations are resilient against escalating threats and meet changing obligations, such as:

  • Privacy Act: Requires the protection of personal information, breach notification, and allows for class actions by affected individuals. Proposed Privacy Act reforms will further heighten these responsibilities, with the government agreeing to over 100 changes, including mandatory breach reporting within 72 hours and stronger protections for vulnerable groups.
  • Notifiable Data Breaches (NDB) Scheme: This scheme mandates prompt disclosure of data breaches likely to cause serious harm. Non-compliance penalties can be as high as $2.5 million for individuals and $50 million (or 30% of turnover) for companies.
  • ASIC Requirements (for AFS Licensees): Obligates firms to implement and maintain adequate cyber risk controls as part of their licence conditions, with enforcement actions taken for failure to comply.

Guidance and Best Practices for Minimising Threats

While the legislation sets the baseline, directors are expected to go beyond compliance and actively champion best practices. Frameworks like the Essential Eight and NIST Cybersecurity Framework offer clear, actionable roadmaps for doing so.

Essential Eight Maturity Model: A set of baseline security strategies developed by the Australian Signals Directorate (ASD), recommended for all accounting and financial services organisations. These foundational measures are designed to prevent common cyber threats through practical, technical controls and serve as a critical starting point for firms looking to build cyber resilience.

NIST Cybersecurity Framework: An internationally adopted model that helps organisations manage cyber risk across six key functions. It builds on foundational controls, supporting organisations in creating a comprehensive and adaptable cyber security strategy that evolves with their risk landscape.

NIST helps organisations manage cyber risk across six key functions:

  • Identify: Understand and catalogue information assets and assess associated cyber security risks.
  • Govern: Establish policies, procedures, and processes to manage and monitor the organisation’s cyber risk posture.
  • Protect: Implement appropriate safeguards to ensure the delivery of critical infrastructure services.
  • Detect: Develop activities to identify the occurrence of a cyber security event.
  • Respond: Establish response plans and capabilities to contain the impact of cyber security incidents.
  • Recover: Develop and implement appropriate activities to restore services and capabilities impaired due to a cyber event.

Cyber insurance may assist with costs like data recovery, legal advice, and third-party claims, but not all of them. Additionally, the insurance market is tightening—premium hikes, exclusions (especially for ransomware or unpatched systems), and rejected claims due to application errors are all increasing.

Additional Guidance

We recommend the following sources if you want further guidance on cyber security best practices:

Conclusion

Given the alarming rate at which attacks can happen and the potential for significant financial and reputational loss, cyber resilience is an urgent requirement for accounting and financial services firms. Educating teams and acting with intent—such as adopting models like the Essential Eight and NIST, developing preventative and response capabilities, and integrating cyber risk into more inclusive governance—allows firms to move beyond mere compliance. Following this blog’s practices, you can facilitate long-term stability, sustain client trust, and prepare your business to operate confidently.

Rodin Can Secure Your Books and Client Data

Selecting a dependable cyber security partner for your financial or accounting service business is a long-term investment in protecting your company and client data. With a specialist cyber security provider, accounting and financial firms can protect themselves from attacks, meet regulatory requirements, and guarantee client trust.

Visit our Accounting and Financial Services page for more information on how we support your industry’s unique needs.

Related Blogs

Ashley Brown

Head of Technical Services
Leading the technical services at Rodin, Ashley blends comprehensive technical knowledge with a strategic approach to IT management. His commitment to operational efficiency and customer satisfaction is evident in his leadership style, driving initiatives that enhance both the resilience and reliability of IT systems. Ashley’s expertise in managing complex IT projects and his insight into effective incident response strategies underscore his key role in equipping businesses to face cyber challenges confidently.
Ashley Brown

Subscribe to Our Newsletter

Sign up to receive all the latest news updates straight into your inbox.