Published 05 October 2026
Essential Eight for accountants and bookkeepers in Australia
Your accounting or bookkeeping practice runs on logins, not locked filing cabinets. Xero or MYOB holds every client's bank feeds and payroll. The ATO's Online services for agents holds authority to act on their behalf. A shared inbox holds years of correspondence with their tax file numbers in it. None of that felt like "Essential Eight" when you set it up. It was just how the practice ran. Insurers, bigger clients, and the criminals targeting accountants and bookkeepers all see it differently.
This isn't legal, tax, or insurance advice. What follows is a self-assessment guide, not a certification or an audit, and describes patterns commonly seen in the Australian market.
Why a bookkeeping or accounting practice is a target
A practice holds financial data for every client it serves: bank details, payroll, trust account movements, tax file numbers, sometimes direct authority to lodge and transact on a client's behalf. That concentration is exactly what makes accounting and bookkeeping firms attractive targets, regardless of how many staff sit in the office. A solo BAS agent working from a home office carries the same category of data as a ten-person firm, just spread across fewer logins.
The Essential Eight, published by the Australian Signals Directorate (ASD), is a prioritised list of eight controls built from real incident patterns. It wasn't written with accountants specifically in mind. But almost every control maps cleanly onto the handful of systems a practice actually runs.
The Essential Eight, mapped to what a practice actually runs
You don't need a server room or an IT department for any of this to apply. It's about the software and logins already in daily use.
Multi-factor authentication on Xero, MYOB and practice email
This is the one most commonly asked about, and the one treated as close to a baseline. Multi-factor authentication adds a second step beyond the password, usually a code from an app. Xero, MYOB and most email providers already offer it as a setting. If it isn't switched on for every staff member with access, that's the answer most likely to cause trouble on an insurance application.
Separately, and worth knowing regardless of Essential Eight status: the ATO requires a Digital ID credential, myID, to log in to Online services for agents and Relationship Authorisation Manager. Each staff member needs their own myID on their own device; accounts and devices can't be shared. It's an ATO system requirement, not an Essential Eight control, but it functions in a similar way, proving who's logging in beyond a password alone.
Backups of client files and ledgers
If the only copy of a client's ledgers and source documents lives inside one accounting file on one machine, losing that machine to theft, a hardware fault or a ransomware lockout stops the practice doing its job for every client at once, not just one. Insurers and backup best practice both ask the same three questions: does a backup exist, is it kept somewhere a compromised login couldn't also reach, and has anyone actually tested restoring from it.
Patched devices and practice software
Laptops, the practice-management platform, and any remote-access tool used to help a client over the phone all need updates applied when they ship, not whenever there's time. Unpatched software is one of the more common ways an attacker gets a foothold, and it's unrelated to whether the practice itself did anything wrong.
Who holds admin access across a small team
Many small practices give every staff member full admin rights in the accounting platform "because it's simpler", or keep one shared login for a software subscription seat. Insurers and client questionnaires ask about this because a shared, unmanaged login is harder to lock down quickly if a staff member leaves or a credential is compromised. Restricting administrative access to the people who genuinely need it, each on their own account, is the kind of answer that holds up.
Why clients and insurers are starting to ask
Three pressures point the same way without any new law forcing it. Cyber insurers commonly ask about MFA, backups and patching at application and renewal, and a practice holding concentrated financial data for many clients tends to draw closer attention than an average small business. Larger clients, especially ones with their own compliance obligations, are increasingly running supplier security questionnaires before engaging a bookkeeper or accountant. And referral relationships (a broker or an industry body recommending a practice) increasingly factor in whether the practice can answer basic security questions about its own systems.
This is not a certification, audit, or guarantee of cover, a contract, or a referral. What these groups generally want is a practice that knows its own answers and can document them, not a certificate.
The data and trust angle
Client financial data sits in a slightly different place to ordinary personal information. Even where a small practice's turnover might otherwise put it near the edge of Privacy Act coverage, the relationship itself runs on trust: a client hands over bank access, payroll details and tax file numbers on the understanding the practice will look after them. For the fuller picture of what "reasonable steps" generally means for a small business handling personal information, see Privacy Act for Australian small business.
Checking your own practice without hiring a consultant
You don't need a security firm to answer these questions honestly. A sensible order:
- Check where the practice actually stands. Our free Essential Eight self-assessment runs through plain-English questions on MFA, backups, patching and admin access, with an indicative Level 0–3 for each. About 20 minutes, no account needed.
- Fix the cheap, high-impact gaps first. MFA on the accounting platform and a tested backup are usually the quickest wins, and they're what gets asked about first.
- Answer honestly, not optimistically. If a claim or a client relationship is ever examined and a control attested to wasn't actually in place, that can affect the outcome itself.
- Talk to your broker about what a specific policy actually covers, and read the Essential Eight explained for small business guide if you'd like all eight controls laid out together first.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of what any insurer, client, or regulator will decide. For how the same questions look in a different setup, see cyber insurance for trades or cyber insurance for medical clinics, both facing their own version of the same concentrated-data problem.
Know your answers before the application, renewal or client questionnaire arrives: take the free Essential Eight self-assessment. 20 minutes, plain English, built for practices that don't have an IT department.
FAQ
Does the Essential Eight apply to a sole-trader bookkeeper? The Essential Eight isn't a law, so nothing forces a sole trader to adopt it. But a one-person practice holds the same category of client financial data as a larger firm, on the same software, often behind the same single login. The controls that matter (MFA, backups, who has admin access) don't scale down with headcount, and the questions an insurer or a client asks don't either.
Is the ATO's myID login itself a form of MFA? myID is the Australian Government's Digital ID system for logging in to Online services for agents, and it's a separate government requirement, not an Essential Eight control. It functions similarly to multi-factor authentication for that one system. It doesn't cover MFA on your practice's own tools, such as Xero, MYOB or your email, which is where the Essential Eight question applies.
What's the cheapest first fix for a small practice? Turning on multi-factor authentication for your accounting software and practice email. It's usually a setting already built into Xero, MYOB and most email providers, and takes minutes per staff member. It's also commonly the first thing a cyber insurance application or a client's security questionnaire asks about.
Do clients or insurers actually check this? Many cyber insurance applications and renewals ask about MFA, backups and patching, and a growing number of larger clients run their own supplier security questionnaires before engaging an accountant or bookkeeper. Neither guarantees a particular outcome. What they commonly want is evidence you know your own answers, not a certificate.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).