CRYPTON practical guides
Accounting practice IT guide
Ten practical questions about client files, payment changes, ATO access, email, devices and recovery.
Use these checks with your current IT provider. This guide is a starting point, not an audit or confirmation that your systems are secure.
Do not enter client names, tax information or confidential financial records.
1. Client file access
client and financial records need access that follows each person’s role
Check: Review shared folders and practice-system access against current roles.
Ask your IT provider: A current access list and one recent role-change or leaver record.
2. Payment fraud
email compromise can make a fraudulent payment request look routine
Check: Require known-number verification and a second approval.
Ask your IT provider: The written changed-bank-detail verification and approval process.
3. Deadline systems
portal or access failure can quickly become a missed client deadline
Check: Write down the first fallback and named escalation owner.
Ask your IT provider: The fallback and escalation path for ATO and lodgement access.
4. Email security
mailbox compromise can expose client information and redirect payments
Check: Confirm who receives risky sign-in and forwarding-rule alerts.
Ask your IT provider: Alert coverage, response expectation, and a recent alert record.
5. Offboarding
access can remain in sessions, devices, and individual applications after an account is disabled
Check: Test the checklist against the most recent departure.
Ask your IT provider: A completed leaver checklist covering accounts, sessions, devices, and shared access.
6. Administrator access
administrator accounts can change security, data, and recovery settings
Check: Separate day-to-day and administrator access, then review the list.
Ask your IT provider: The current administrator list, MFA state, and last review date.
7. Devices
client information on an unmanaged device can remain exposed after loss or replacement
Check: Identify devices that cannot be remotely handled or verified.
Ask your IT provider: Device inventory with encryption and management status.
8. Backup
a backup only protects deadline work when it can be restored in time
Check: Schedule a controlled restore test if proof is missing or stale.
Ask your IT provider: The last restore-test date, scope, duration, and sign-off.
9. AI
public AI tools can retain or expose client and financial information
Check: Publish a short approved-use guide for staff.
Ask your IT provider: Approved tools, permitted use cases, and client-data rules.
10. Support ownership
multi-provider issues stall when nobody owns coordination and business decisions
Check: Name one coordinator for issues that cross providers.
Ask your IT provider: The urgent escalation path and named business owner.
Talk to CRYPTON
Tell us where IT gets in the way of your work. We can discuss the findings and a sensible next step.