Education / Flow

FlowAustralian rules

Cyber security for BAS agents

BAS agents in Australia are responsible for providing a range of financial and taxation services to clients. These services often involve the handling of sensitive financial data, which can make BAS agents an attractive target for cyber criminals, especially in the context of Cyber Security for BAS Agents.

As such, these agents need to be aware of the cyber security considerations and requirements that are relevant to their work as part of maintaining effective Cyber Security for BAS Agents.

This article will examine cyber attacks in Australia, the consequences of a cyber attack on a practice, how to prevent cyber attacks from occurring, and where BAS agents can learn more about Cyber Security for BAS Agents.

Cyber attacks in Australia

Cyber attacks are a growing threat in Australia. In 2021-22, the Australian Cyber Security Centre (ACSC) received over 76,000 reports of cyber crime incidents, with losses totalling over $98 million. These attacks ranged from phishing scams and malware infections to ransomware attacks and data breaches.

Cyber attacks are perpetrated by both governments and non-state actors. Australia announced in July 2021 that Microsoft Exchange vulnerabilities were exploited, and China’s Ministry of State Security had a role to play. Those vulnerabilities were also exploited by an Iranian state actor. Ransomware attacks were the most destructive cybercrime, with criminal groups stealing and releasing the personal information of hundreds of thousands of Australians.

The ACSC reports that the average cost per cyber crime report is over $39,000 for small business, $88,000 for medium business, and over $62,000 for large business. This is a 14 per cent increase from the previous year.

Cyber attacks against tax professionals

Professionals in tax and superannuation are not immune to the threat that cybercriminals present.

It is easy to see why. These industry professionals, including BAS agents, will have access to individual’s tax file numbers, banking details, information about people’s mortgages, families, business and superannuation.

As such, tax professionals like BAS agents are considerably exposed to cyber attacks, and face a significant cost to their business if they are forced to repair the consequences of a cyber breach, highlighting the importance of Cyber Security for BAS Agents.

The Australian Tax Office (ATO) reported trying to combat as much as 3 million cyber attacks every month. They have issued warnings to tax and superannuation professionals they are prime targets for hackers, due to the sensitive consumer data they hold, highlighting the importance of cyber security for BAS agents.

Understanding Cyber Security for BAS Agents is crucial to safeguarding sensitive information and maintaining client trust.

Examples of data breaches against tax professionals

A data breach happens when an unauthorised third party gains access to confidential information related to taxpayers. There are various examples of data breaches that can occur, including but not limited to:

  • theft of computers, records, or data in both paper and digital formats,
  • the misuse of data by authorised personnel for fraudulent purposes,
  • the exploitation of vulnerabilities in IT security controls through hacking or phishing,
  • accidental disclosure of information,
  • stealing payroll information and credentials such as myGovID.

It is important to note that data breaches can also occur from in-person theft of equipment or documents, as well as letterbox theft, or theft of briefcases or laptops.

The ATO has highlighted that reports of stolen equipment and data are frequent, and theft can occur in a range of different ways, such as through unattended paper or electronic files, theft from wallets, or stealing equipment from cars. In one instance, a tax agent had their laptop and documents containing confidential client information stolen from their vehicle. The stolen data was later used to commit identity theft.

What will the ATO do in the event of a cyber breach?

Once you experience a data breach, the ATO may engage in different courses of action depending on the seriousness of the breach and any resulting fraudulent activities.

The ATO may:

  • request further proof of identity from the client or perform additional monitoring of their accounts to verify any suspicious activity (this process may delay the processing of tax returns and other forms),
  • enforce additional security measures, such as restricting online access to the client record and pre-fill data, or
  • require tax or BAS agents to request the ATO to generate statements.

The agency may also assign a data breach manager to help the agent and the client in their recovery of the data breach.

The consequences of a cyber attack on your BAS practice

A cyber attack on a BAS practice can have serious consequences. The theft or loss of sensitive financial data can result in significant financial losses, reputational damage, and liability.

If client data is compromised, BAS agents may be in breach of their legal and ethical obligations to protect client confidentiality and privacy.

We’ll outline in more detail the consequences of a cyber attack below.

Financial Losses

A cyber attack can result in significant financial losses for a BAS practice. For example, a ransomware attack may result in losing access to critical systems and data until a ransom is paid. The cost of restoring systems and data can be high, and even if the ransom is paid, there is no guarantee that the attacker will provide access to the data.

In addition, if sensitive financial data is stolen, there may be fines and legal fees to pay, as well as reputational damage that can impact the bottom line.

Reputational Damage

A cyber attack can also cause significant reputational damage to a BAS practice. Clients may lose trust in the practice’s ability to safeguard their sensitive financial data, which can lead to a loss of business.

The practice may also suffer damage to its reputation in the wider community, which can impact its ability to attract new clients and retain existing ones.

Legal Liability

If client data is compromised in a cyber attack, a BAS practice may be liable for any financial losses that result.

Additionally, the practice may be in breach of its legal and ethical obligations to protect client confidentiality and privacy. This can result in lawsuits, fines, and regulatory action, all of which can be costly and time-consuming to resolve.

We will outline more about the statutory obligations of tax professionals below.

Downtime and Lost Productivity

A cyber attack can result in significant downtime and lost productivity for a BAS practice. Systems and data may be inaccessible while they are being restored, which can impact the ability of staff to do their work.

The practice may also need to invest time and resources in implementing new cyber security measures to prevent future attacks, which can further impact productivity.

Regulatory Consequences

If a BAS practice is found to be in breach of regulatory requirements related to cyber security, there may be regulatory consequences to face.

For example, the Australian Taxation Office (ATO) requires tax professionals to have adequate cyber security measures in place to protect client data. If a practice is found to be in breach of these requirements, it may face regulatory action, fines, and a loss of its license to operate. This can have significant implications for the future viability of the practice.

Obligations of tax agents in a cyber security context

Establishing robust cybersecurity measures is not only advisable for sound business operations, but it is also a means for registered agents to fulfill their legal responsibilities towards their clients.

Confidentiality (code item 6)

One of the primary sources of responsibilities for registered agents is the Code of Professional Conduct (the Code) in the Tax Agent Services Act 2009 (the TASA).

The Code requires registered practitioners to maintain client confidentiality and not disclose any information without client consent, unless required by law. TPB Practice Note TPB(PN) 1/2017 provides practical guidance to registered agents regarding their responsibilities under the Code.

To comply with Code Item 6 (which deals with confidentiality), registered practitioners must:

  • get permission from each client before disclosing any information to a third party, including cloud service providers. This can be achieved through a signed letter of engagement, signed consent, or other communication; and
  • establish appropriate controls like encryption, to ensure the confidentiality and integrity of client information is protected, and sensitive information cannot be leaked into the public domain.

If there is a breach of the Code, the TPB may impose administrative sanctions which can include terminating a practitioner’s registration. There may be associated legal consequences, such as a civil action.

Australian privacy laws

The Australian Privacy Principles (APPs) are a set of regulations under the Privacy Act 1988 (Privacy Act)that specify the appropriate usage, storage and dissemination of personal data and information. Detailed information about these provisions can be found on the website of the Office of the Australian Information Commissioner (OAIC).

It is recommended that tax practitioners consult with experts to determine if they are subject to the Privacy Act.

The Privacy Act includes the Notifiable Data Breaches (NDB) scheme, which mandates the reporting of significant data breaches that occur on or after February 22, 2018. The NDB scheme compels organisations hat fall under the Privacy Act to alert any individuals at risk of serious harm from a data breach. Recommendations for measures that should be taken in response to the data breach must also be provided.

Although the TPB and the ATO are not responsible for enforcing these guidelines, tax practitioners must be familiar with their responsibilities. Failure to comply with the NDB guidelines by a registered agent may result in a breach of the Tax Agent Services Act, including the Code.

Code item 6 considerations include:

  • Has the tax practitioner taken reasonable steps to have sufficient IT controls in place?
  • Was the practitioner reckless in their approach to cyber security?

Tax professionals must keep in mind that they may be asked those questions,

For additional information on the NDB program and notification requirements, refer to the OAIC website.

Disclosure of tax file number

The TPB recently issued Practice Note TPB(PN) 4/2021 to provide guidance on using and disclosing a client’s TFN and TFN information in email communications. The note advises that email communications may be susceptible to unauthorised access.

The TPB highlights several laws that apply to tax practitioners concerning TFNs, including the Privacy (Tax File Number) Rule 2015, the Privacy Act and APPs, as well as the NDB scheme (as outlined above).

Disclosing a TFN through an unsecured email, the TPB notes, may constitute an offence under the TASA. The note also outlines practical measures that tax professionals can put in place in order to protect TFN information when communicating over email.

Implications of cyber security issues on your insurance

Cybersecurity issues can have significant implications for BAS agents’ insurance policies.

Professional indemnity insurance requirements

As per Tax Practitioners Board’s (TPB) requirements, BAS agents are obligated to maintain PI insurance that adequately indemnifies them against any civil liability that may arise in the course of providing tax agent or BAS services.

You can read more about thee TPB’s PI requirements in Explanatory Paper TPB(EP) 03/2010.

The adequacy of the insurance policy depends on various factors, including the degree of risk, the number of clients, and the volume of business.

Note that failure to have appropriate PI insurance could result in considerable penalties, ranging from cautions all the way to termination of your registration.

Cyber insurance cover

One of the recommended policy features by the TPB is cyber insurance cover, which provides protection against cyber threats, including first-party losses.

First-party losses may arise from various cyber-attacks, such as denial of service attacks, damage to systems, and reputational damage, among others.

While PI insurance policies cover losses stemming from tax agent services, cyber insurance policies generally cover events like third-party cyber liability, first-party hacker damage, cyber extortion, data breach notification costs, and public relations costs.

Therefore, it is recommended that BAS agents obtain additional cyber insurance cover, in addition to their PI insurance policy, to ensure comprehensive protection against cyber threats.

With the increasing incidence of cyber-attacks, it is essential for BAS agents to assess their cyber risk and obtain the appropriate insurance cover to mitigate any potential losses.

How to prevent cyber attacks from occurring

Preventing cyber attacks requires a multi-faceted approach that includes technical, organisational, and human factors. Some key steps that BAS agents can take to prevent cyber attacks include:

Implement Strong Cyber Security Measures

One of the most important steps that a BAS practice can take to prevent cyber attacks is to implement strong cyber security measures. This includes the following:

  • Use strong passwords: Businesses should ensure that employees use strong passwords and that they regularly update them. Passwords should be complex and should contain a combination of letters, numbers, and symbols. For example, a password like “P@ssw0rd” is stronger than “password.”
  • Ensure only the right people have access to your systems: Businesses should limit access to sensitive information and ensure that only the right people have access to it. Access to information should be granted based on job function and the principle of least privilege. This means that employees should only have access to the information they need to do their job.
  • Ensure all devices are up-to-date on their security : Businesses should ensure that all devices, including computers, phones, and tablets, are up-to-date on their patches, anti-virus software, firewalls, and intrusion detection systems. This can help prevent vulnerabilities from being exploited by cybercriminals.
  • Use a spam filter on email content : Businesses should use a filter to block unwanted emails, which can contain viruses or other malicious software. This can help prevent employees from accidentally downloading or opening an infected email.
  • Do not use USBs or hard drives from unfamiliar sources : Businesses should not use USBs or hard drives from sources they are not aware of, as they can contain malicious software that can infect a business’s network. Employees should only use devices provided by the company.
  • Routinely monitor your accounts for unusual activity : Businesses should routinely monitor their accounts for unusual activity, such as logins from unfamiliar locations or at unusual times. This can help detect any potential security breaches early.
  • Secure your Wi-Fi network : Businesses should secure their Wi-Fi network with a strong password and encryption. They should also ensure that the network is hidden, so that it cannot be accessed by unauthorised individuals.

Train Staff in Cyber Security Awareness

Another important step is to ensure that all staff members are aware of the risks of cyber attacks and the importance of good cyber security practices.

This includes regular training on topics such as how to identify and avoid phishing scams, how to create strong passwords, and how to detect and report suspicious activity. Staff should also be encouraged to report any potential security incidents or vulnerabilities to management.

Develop a Cyber Security Plan

A comprehensive cyber security plan is essential for preventing cyber attacks. This plan should include a risk assessment to identify potential vulnerabilities and a strategy for mitigating these risks.

The plan should also outline the procedures that will be followed in the event of a cyber attack, including who will be responsible for managing the incident and what steps will be taken to contain and recover from the attack.

Back Up Data Regularly

Backing up data regularly is critical for ensuring that a BAS practice can quickly recover from a cyber attack.

The practice should ensure that all critical data is backed up regularly and stored securely, either on-site or in the cloud. Regular testing of backups should also be carried out to ensure that the data can be quickly and easily restored in the event of an attack.

Stay Up to Date with the Latest Threats

Finally, it is important for a BAS practice to stay up to date with the latest cyber security threats and trends.

This includes regularly reviewing industry news and trends, participating in cyber security forums and groups, and attending relevant training and conferences.

By staying informed about the latest threats and best practices, a BAS practice can better protect itself from potential attacks.

Where you can learn more about cyber security and how it affects your practice

BAS agents can learn more about cyber security from a range of sources. Some key resources include:

Australian Cyber Security Centre

The ACSC is a government agency that provides information and advice on cyber security for businesses, government agencies, and individuals.

Their website contains a wealth of resources for businesses, including guides on how to protect against cyber threats, information on the latest cyber security trends, and tools for assessing and improving cyber security.

The ACSC also offers training and support to help businesses develop their cyber security capabilities.

Australian Tax Office

The ATO is the government agency responsible for administering tax and superannuation in Australia. They are also responsible for regulating tax professionals, including BAS agents.

The ATO has developed a range of resources to help tax professionals protect client data and comply with cyber security regulations. These resources include Security advice for tax professionals, which provides practical advice on how to protect against cyber threats, as well as information on the ATO’s cyber security requirements for tax professionals.

Tax Practitioners Board

The TPB is a government agency that regulates tax practitioners in Australia, including BAS agents.

The TPB has developed a range of resources to help tax practitioners understand their obligations under the TASA including the requirement to have adequate cyber security measures in place to protect client data.

The TPB website contains information on the TPB’s expectations around cyber security, as well as links to other resources, such as the ACSC’s cyber security guides for small businesses.

Final Words

Cybersecurity is a pressing issue in the tax and accounting space, and it is integral that professionals are vigilant in ensuring that all their systems are adequately protected.

Failure to do so may lead to sensitive client information getting into the wrong hands, which could considerable damage to your business.

In addition to consulting the ACSC, ATO and TPB, BAS practices can also benefit from engaging with cyber security experts and industry groups, attending relevant training and conferences, and participating in cyber security forums and groups.

By staying informed about the latest threats and best practices, BAS practices can better protect themselves and their clients from cyber attacks.