CRYPTON practical guides

Accounting practice IT guide

Ten practical questions about client files, payment changes, ATO access, email, devices and recovery.

Use these checks with your current IT provider. This guide is a starting point, not an audit or confirmation that your systems are secure.

Do not enter client names, tax information or confidential financial records.

Make my checklist

1. Client file access

client and financial records need access that follows each person’s role

Check: Review shared folders and practice-system access against current roles.

Ask your IT provider: A current access list and one recent role-change or leaver record.

2. Payment fraud

email compromise can make a fraudulent payment request look routine

Check: Require known-number verification and a second approval.

Ask your IT provider: The written changed-bank-detail verification and approval process.

3. Deadline systems

portal or access failure can quickly become a missed client deadline

Check: Write down the first fallback and named escalation owner.

Ask your IT provider: The fallback and escalation path for ATO and lodgement access.

4. Email security

mailbox compromise can expose client information and redirect payments

Check: Confirm who receives risky sign-in and forwarding-rule alerts.

Ask your IT provider: Alert coverage, response expectation, and a recent alert record.

5. Offboarding

access can remain in sessions, devices, and individual applications after an account is disabled

Check: Test the checklist against the most recent departure.

Ask your IT provider: A completed leaver checklist covering accounts, sessions, devices, and shared access.

6. Administrator access

administrator accounts can change security, data, and recovery settings

Check: Separate day-to-day and administrator access, then review the list.

Ask your IT provider: The current administrator list, MFA state, and last review date.

7. Devices

client information on an unmanaged device can remain exposed after loss or replacement

Check: Identify devices that cannot be remotely handled or verified.

Ask your IT provider: Device inventory with encryption and management status.

8. Backup

a backup only protects deadline work when it can be restored in time

Check: Schedule a controlled restore test if proof is missing or stale.

Ask your IT provider: The last restore-test date, scope, duration, and sign-off.

9. AI

public AI tools can retain or expose client and financial information

Check: Publish a short approved-use guide for staff.

Ask your IT provider: Approved tools, permitted use cases, and client-data rules.

10. Support ownership

multi-provider issues stall when nobody owns coordination and business decisions

Check: Name one coordinator for issues that cross providers.

Ask your IT provider: The urgent escalation path and named business owner.

Talk to CRYPTON

Tell us where IT gets in the way of your work. We can discuss the findings and a sensible next step.

Request this guide by email