Website Security7 min read3 October 2026

Website Security for Accountants and Bookkeepers in the UK

Accountancy firms hold more sensitive data per client than almost any other SME sector. Here's what UK accountants need to know about securing their website and client portal.

By Yrzo AI — UK cybersecurity specialists

The Data Profile That Makes Accountants a Target

A typical UK accountancy practice, even a small one with a dozen clients, holds an unusually dense concentration of sensitive financial data. Tax returns with NI numbers and income figures. Management accounts showing exactly how profitable a business is. Bank statements. Payroll data including salaries for every employee at a client company. Companies House filing information before it is public. In some cases, personal financial details for business owners — mortgages, investments, pension values.

That data profile is why accountancy firms appear consistently in NCSC reports on sectors targeted by cybercriminals. It is not that attackers necessarily know you specifically — it is that an accountancy firm's systems, once compromised, are a particularly rich source of financially useful data.

The website is the front door. The client portal — however you run it — is the safe.

What Attackers Are Actually After

**Client financial data for fraud** — tax return data, bank details, and salary information feed directly into identity fraud, fraudulent loan applications, and targeted phishing. A client whose NI number and P60 data is stolen is at risk of someone filing a fraudulent tax rebate claim in their name with HMRC.

**Business intelligence for competitor or investment targeting** — management accounts and forecasts for private companies are genuinely valuable to competitors, potential acquirers, or short sellers. This category of theft is less common than opportunistic financial fraud but worth being aware of for firms with high-value commercial clients.

**Business email compromise via accountant impersonation** — attackers who compromise an accountancy firm's email can impersonate the practice to its clients. "Please update your bank details for next month's payment run" is far more credible coming from a client's trusted accountant than from a cold phishing email.

**PAYE and payroll fraud** — access to payroll data lets attackers redirect salary payments, file fraudulent RTI submissions, or claim fraudulent furlough-type payments. HMRC has published guidance on payroll fraud specifically for the accountancy sector.

The Client Portal Risk

Most UK accountancy practices now use a client portal for document exchange — either a dedicated platform (Onvio, TaxCalc, Iris, MyWorkpapers, or a general document platform like ShareFile or Dropbox Business) or a section of their own website.

The security posture of these portals varies enormously. Specific things to check:

**MFA enforcement** — if clients can access a portal containing their tax returns and bank statements using only a username and password, that is inadequate. The same credential stuffing attacks that target consumer accounts will target your client portal. Most dedicated accountancy platforms now offer MFA; many do not enforce it by default. Turn it on and require it.

**Access controls** — can one client accidentally (or deliberately) access another client's documents? This is an IDOR-class vulnerability (see our separate article) and it has occurred in real accountancy portal implementations. Test this explicitly: log in as Client A and attempt to access a URL that belongs to Client B's documents.

**Document retention and deletion** — documents uploaded to a client portal that remain accessible indefinitely, including for clients who have left the practice, are an unnecessary data retention risk. A policy of removing departed clients' portal access promptly, and archiving rather than indefinitely hosting documents, reduces exposure.

**Third-party platform security** — if you use a SaaS portal, you are dependent on that vendor's security. Check whether your platform has had security incidents, whether it publishes a security page or SOC 2 report, and whether your contract includes breach notification obligations.

Your Own Website: The Overlooked Risk

Accountancy firm websites are often seen as brochureware — a contact page and a services list. They receive minimal security attention as a result. But even a simple website can be an attack vector:

**Contact forms** — names, email addresses, and initial enquiry details submitted through your contact form are personal data. If that form data is stored insecurely, transmitted without encryption, or accessible to anyone who knows the admin URL, it is a data breach waiting to happen.

**WordPress plugins** — many accountancy firm websites run on WordPress with a selection of plugins for forms, calendars, and staff directories. Unpatched plugins are the most common route into WordPress sites. A compromised website can be used to host phishing pages, harvest form submissions, or redirect visitors to malicious sites — all while looking completely normal to you.

**Google Business Profile** — not a website vulnerability, but closely related: your GBP listing is the first thing most prospective clients see, and profile hijacking (where someone gains access to your listing) can result in phone number replacement or fake reviews. Secure the Google account associated with your GBP with MFA.

ICAEW, ACCA and Professional Obligations

Both ICAEW and ACCA have published guidance on cybersecurity for member firms. ICAEW's technical guidance explicitly covers data security as a professional obligation under the Code of Ethics — members are expected to maintain confidentiality of client information as a fundamental principle.

The ICO takes a similar view: financial data and tax information are among the categories of personal data that attract heightened scrutiny in data breach investigations. A breach at an accountancy practice that exposes client financial data is the kind of incident that results in an ICO investigation, not just a letter.

Practical obligations: a written data security policy, staff awareness training, MFA on systems holding client data, and an incident response plan that covers how you would notify affected clients and the ICO within the 72-hour window.

Three Things to Do This Week

**Enable MFA on your client portal and your practice management software.** If you use Iris, TaxCalc, Xero Practice Manager, or any similar platform, check MFA settings today and enforce it for all users. This single change significantly reduces the risk from compromised credentials.

**Check who has access to your systems.** Former staff, former partners, and former contractors with live credentials to your practice management software or client portal are a common and avoidable security gap. Run an access audit and remove accounts that should no longer be active.

**Make sure your website is HTTPS with a valid certificate and current plugin versions.** If your WordPress site has not had plugin updates applied in the last three months, that is urgent. Log into wp-admin, apply all available updates, and check for any warnings about outdated PHP versions.

Yrzo AI scans the technical security of your firm's website — authentication weaknesses, form vulnerabilities, security header configuration, and exposed admin interfaces — in under 20 minutes. From £99 at yrzoai.dev.

Find out if your website has these vulnerabilities

Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.

Scan your website →