X
  • About
  • Advertise
  • Contact
Get the latest news! Subscribe to the SMSF Adviser bulletin
  • News
    • Money
    • Education
    • Strategy
  • Webcasts
  • Features
  • Events
  • Podcasts
  • Promoted Content
No Results
View All Results
  • News
    • Money
    • Education
    • Strategy
  • Webcasts
  • Features
  • Events
  • Podcasts
  • Promoted Content
No Results
View All Results
Home News

The Devil is in the Email

Promoted by Practice Protect

by Jamie Beresford, CEO of Practice Protect
November 4, 2019
in News
Reading Time: 3 mins read
Share on FacebookShare on Twitter

Are your emails really secure?

Accountants learn best from their peers 

Like all professional services providers, accountants see the most insightful and relevant learning opportunities coming from their peers. Hearing first-hand what other firms have done to solve specific problems in their business is when action takes place. The mantra of the smart man learning from someone else’s mistakes holds true. 

The problem with peer education around breaches and data security however, is that it’s embarrassing and painful to share. Breaches of data mean breaches of client trust. Nobody likes to put their hand up to relive a painful experience on how they let their client down and lost money because of something that seems so stupidly preventable with the benefit of hindsight. 

Why action is being taken 

What’s encouraging is the shift in focus that we are seeing in the accounting industry. Cyber-security is no longer relegated to the bottom of the agenda in the partners meeting, and firms are actively reviewing the form of tools, staff training and policies to manage their risk.  

Interestingly the driver hasn’t been the legislation itself. The real catalyst for action has been the weekly flow of emails that accountants are seeing from legitimate and credible businesses known to them that are clearly (or not so clearly) bogus followed by a cap in hand message apologising and requesting that it be deleted. Embarrassment now public! 

practice protect screen

A recent case in Far North Queensland saw an accounting firm infect three of its clients triggering a costly PI claim and a lengthy embarrassing reporting process.  

It’s an extra kick in the teeth when you’re trying to frame yourself as a trusted advisor, a trusted source of information, who happens to be spreading misfortune. There’s no catalyst for change greater than protecting and enhancing our reputation. 

X

The devil is in the email

email screen

With the ATO’s operational framework mandating accounting apps to increase security measures with two factor authentication and the like, the soft target is now an accountant’s mailbox. Frequently inboxes hold years of correspondence and information ripe for fraudulent behaviour, the added advantage of being able to communicate on the victim’s behalf to propagate itself.  

Making that even easier is the current turf war that Microsoft Office 365 and Google Apps are in to convince us how convenient their mail systems are to login to and access. Nobody likes getting held up when accessing their email and immediate convenience almost always trumps security. This means login pages are simple to use and simple to hack. Both systems are open to automated brute force password cracking tools from anywhere in the world. 

How is the problem solved? 

Most firms are by now using a password capture tool to consolidate cloud logins and remain in control of app access however, this becomes trickier with email passwords as users generally need to be privy to in order to login to mail on their phone or login to their desktops (often an Office 365 identity is the same as the company domain identity needed to access work computers).  

The solution for protecting mail is using SAML (Google) or Federation (Microsoft) to unify your desktop, cloud app, email and mobile device logins into the same identity that can be controlled and tracked by the firm.  

This unification bypasses the standard Microsoft/Google login technology providing enterprise level security functionality making the chances of overseas or brute force intrusion far less. 

Need more information about how to keep your firm’s email safe with SAML, or more tips and tricks to ensure your client data is safe? Click below to book a consultation with Practice Protect.

This article was written by Jamie Beresford, CEO of Practice Protect.

Tags: Promoted Content

Related Posts

Move assets before death to avoid tax implications: SMSF legal specialist

by Keeli Cambourne
November 25, 2025

Mitigating the impact of death benefit tax can be supported by ensuring the SMSF deed allows for the transfer of...

Investment rules can decide if crypto is a safe call

by Keeli Cambourne
November 25, 2025

Before investing in cryptocurrencies like bitcoin, SMSF trustees have to consider whether it complies with the SMSF investment rules, a...

Impact of EOY shutdown on new SMSF registrants

by Keeli Cambourne
November 25, 2025

The ATO has warned trustees that its end-of-year shutdowns may cause delays for new SMSF new registrants.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Join our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.
SMSF Adviser is the authoritative source of news, opinions and market intelligence for Australia’s SMSF sector. The SMSF sector now represents more than one million members and approximately one third of Australia's superannuation savings. Over the past five years the number of SMSF members has increased by close to 30 per cent, highlighting the opportunity for engaged, informed and driven professionals to build successful SMSF advice business.

Subscribe to our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

About Us

  • About
  • Advertise
  • Contact
  • Terms & Conditions
  • Privacy Collection Notice
  • Privacy Policy

Popular Topics

  • News
  • Strategy
  • Money
  • Podcasts
  • Promoted Content
  • Feature Articles
  • Education
  • Video

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited

No Results
View All Results
NEWSLETTER
  • News
  • Money
  • Education
  • Strategy
  • Webcasts
  • Features
  • Events
  • Podcasts
  • Promoted Content
  • About
  • Advertise
  • Contact Us

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited