For small accountancy practices

ICAEW made cyber security its 2025 review focus. Be ready for yours.

At most firms, overall responsibility for cyber security sits with a practice principal who is not an IT specialist. Only 26% had a specialist IT manager or director holding it. The job lands on someone who already has a practice to run.

I help small practices across Lancashire and the North West get the security side in order and keep it there — an assessment of where you actually stand, the work to close the gaps, and the evidence to hold ready for a monitoring visit.

Regulated-profession background Cyber Essentials support Chorley, Lancashire
The published figures

What ICAEW found when it asked

Cyber security was the area of focus for ICAEW's 2025 Practice Assurance reviews. It discussed the topic with 121 larger firms during that year's monitoring activity, and published what it found.

54%

had completed the Cyber Essentials basic self-assessment questionnaire

29%

had gone on to Cyber Essentials Plus, which adds independent on-site testing

15%

were certified to ISO 27001 or the IASME Cyber Assurance Standard

45%

included cyber security risks in their organisational risk register

Source: ICAEW Practice Assurance Monitoring Report 2026. These percentages are of respondents from the 121 larger firms who discussed cyber security during ICAEW’s 2025 monitoring activity — not of all firms reviewed, and not of small practices specifically. They are quoted here because they are published and precise, which is rarer than it should be in this field.

The gap is usually evidence, not effort

The same firms were doing a great deal right. What the figures show is not a profession ignoring the problem — it is one where the controls are largely in place and the paperwork behind them is patchy.

99%

felt they had a good level of awareness of cyber security threats

88%

required two-factor or multi-factor authentication to reach the network

87%

had a data retention policy — though ICAEW notes these do not always comply with GDPR

86%

kept a list of critical assets: data, software, devices and infrastructure

81%

had contingency or business continuity planning for those critical assets

Same source and same basis as above. The retention finding is ICAEW's own observation, and it is the one worth dwelling on: having a policy and following it are different things, and only one of them survives being asked for evidence.

What gets looked at

The security themes, in plain English

Practice Assurance is principles-based. It does not hand you a checklist or require any particular certificate — it asks whether your practice manages and protects its information sensibly, and whether you can show it. In practice, on the technology side, these are the things that come up.

Who owns it

Someone has to be accountable for cyber security by name, and be able to describe what the firm does. At most firms that is a principal rather than a specialist, which is fine — provided the arrangement is deliberate and written down.

Whether cyber is on the risk register

Fewer than half of the firms ICAEW spoke to had cyber risks on their organisational risk register. It is one of the cheapest gaps to close and one of the most visible if it is open.

Access, devices and authentication

Multi-factor authentication, access limited to managed devices, separate guest Wi-Fi, administrator rights kept away from everyday accounts, and encryption on anything that leaves the office.

Patching and supported software

A stated timescale for security updates, and evidence it is met — not an intention. Anything out of vendor support identified and dealt with.

Backup and business continuity

Backups that have been restore-tested, and a plan for carrying on if a system is unavailable. A green backup report is not a tested restore, and reviewers do ask.

Secure transfer of client data

How records, returns and identity documents reach clients and HMRC. Email attachments are where most small practices are genuinely exposed, and where an M365-native fix is straightforward.

Retention and destruction

How long client data is kept and what happens at the end of it. ICAEW observes that retention policies exist but do not always comply with GDPR — having one is not the same as following it.

Staff guidance and training

Evidence that people have been told what is expected of them, with records. A policy nobody has been shown is not a control.

Incident response

A route for reporting something suspicious, and a plan for what happens next — including the 72-hour UK GDPR reporting clock where personal data is involved.

Suppliers and third parties

Due diligence on the people who can reach your client data, including your IT provider. You are expected to have assessed them and to hold the record.

How I help

Three stages, and you can stop after any of them

Most practices start with the review. It is a small commitment on purpose — until somebody has looked at your systems, neither of us can honestly say what the rest would involve.

One-off

Practice Cyber Review

Find out what a reviewer would find.

A structured assessment of your practice against the data protection and security themes ICAEW looks at, checked against your systems rather than taken from a questionnaire.

  • Assessment against the data protection and security themes
  • Microsoft 365, Entra, Intune and Defender configuration review
  • Cyber Essentials gap analysis against the current requirements
  • Written report with a RAG-rated findings table
  • Prioritised remediation plan, split by who has to do it
  • A draft cyber risk entry set you can drop straight into your risk register
Fixed fee · quoted after a short call
Get a quote
Most practices
Project

Practice Cyber Ready

Close the gaps and get certified.

Everything in the review, then the work to fix what it found — and the Cyber Essentials certificate at the end if you want it.

  • Everything in Practice Cyber Review
  • Intune device compliance, encryption and device policy
  • MFA and Conditional Access, with administrator separation
  • Microsoft Defender deployment and managed patching
  • Cyber Essentials submission support, with a Plus pathway
  • Business continuity and incident response one-pagers for a small practice
  • Secure client file transfer set up natively in Microsoft 365
Project fee · scales with your size
Get a quote
Monthly, per person

Practice Cyber Managed

Stay ready between reviews.

Monitoring visits come round, and so does Cyber Essentials renewal. This keeps the controls running and the evidence accumulating so neither is a scramble.

  • Ongoing management of Defender, Intune, patching and Microsoft 365 backup
  • Annual Cyber Essentials renewal support
  • An annual review-ready evidence pack to hold ahead of a monitoring visit
  • A quarterly security summary written for the principal who owns cyber
  • Optional: external security monitoring, managed password manager, same-day device replacement
Monthly, per person · minimum applies
Get a quote

Everything is quoted in writing before any work starts, and no VAT is chargeable — the figure quoted is the figure you pay. Cyber Essentials certification fees are set by the certification body and passed through at cost.

Why me

Regulated-profession security, at small practice scale

Regulated-profession experience

Before founding Lewis McKee Consulting I worked in information security across the legal sector, including securing systems at five top-100 law firms and rewriting firm policy sets to meet Lexcel requirements aligned with ISO 27001. Accountancy practices face the same shape of problem: a professional body asking for evidence, and nobody in-house to produce it.

Microsoft stack, properly configured

Microsoft 365, Entra ID, Intune and Defender — configured and managed, not just licensed. Most of what a reviewer asks about is already available in the licence you hold; it is usually switched off.

Managed password manager

Bitwarden, deployed per person with individual vaults, so shared credentials stop being the way the practice works.

Lancashire, and one person

Based in Chorley, working with small practices across Lancashire and the North West. You deal with me rather than a ticket queue.

FAQ

Common questions

Does ICAEW Practice Assurance require Cyber Essentials?+

No. Practice Assurance is a principles-based scheme — it does not mandate Cyber Essentials, ISO 27001 or any other certification. Its standards cover data protection and security in general terms: securing data, business continuity, secure transfer of sensitive information, retention and destruction, and ICO registration. What has changed is emphasis rather than obligation: ICAEW made cyber security the area of focus for its 2025 reviews. Certification is one convenient way to evidence good practice, not a requirement, and anyone telling you otherwise is selling you something.

We’re ACCA or AAT, not ICAEW. Does any of this apply?+

The underlying obligations do, because they do not come from ICAEW. UK GDPR applies whoever regulates you, the Money Laundering Regulations 2017 require you to keep records securely, and HMRC’s Standard for Agents sets expectations about protecting client data. ACCA and AAT both run their own practice monitoring. The ICAEW figures on this page are useful because they are published and specific, not because the scheme itself applies to you — the controls a reviewer looks for are much the same either way.

We only have two or three staff. Isn’t this overkill?+

The scale of the work should match the practice, and for a three-person firm it is genuinely modest — the review is a day, and most of the fixes are configuration in a tenant you already pay for. What does not scale down is the obligation: a three-person practice holds the same client data, the same identity documents and the same payroll as a much larger one, and is asked the same questions about them. The honest answer is that a small practice needs less work, not less evidence.

Do you replace our existing IT support?+

Not necessarily, and the review works perfectly well alongside them. It is an assessment, not a takeover, and a good proportion of what it finds is usually something your current provider can fix once somebody has identified it — the report tells them exactly what. If you would rather I carried out the remediation, that is a separate conversation we can have after you have seen the findings.

How long does Cyber Essentials take?+

For a small practice already on Microsoft 365 and reasonably well set up, a few weeks: a gap review, the remediation, then the questionnaire and submission. Where there is an unsupported operating system, an old server, or no device management, it takes longer because those have to be dealt with first. From 26 April 2026, Cyber Essentials v3.3 makes missing multi-factor authentication on cloud services an automatic fail, as is not applying critical and high-risk updates within 14 days — so a renewal after that date is a stricter assessment than the one you passed last time.

What do we actually get at the end?+

A written report covering every theme, a RAG-rated findings table with evidence for each one, a prioritised remediation plan split into quick wins and 30- and 90-day actions, and a draft set of cyber entries for your risk register. On the managed tier you also get an annual evidence pack to hold ready for a monitoring visit, so the questions are answered by an export rather than an investigation.

Will you tell us if we’re already fine?+

Yes, plainly, and it happens. A practice with a well-configured tenant and untidy paperwork is a real and common outcome, and saying so is worth more to you than a padded findings list. The report records what was checked and how, so a clean result is itself evidence you can keep.

Find the gaps before a reviewer does

A fixed-fee practice cyber review tells you where you actually stand, what it would take to close it, and gives you a draft set of cyber entries for your risk register.

Book a practice cyber review
Enquire

Book a practice cyber review.

Tell me roughly how many of you there are, which practice software you run, and whether you have a monitoring visit on the horizon. I'll come back within one working day with a straight answer on what is involved and what it costs.

I'll only use your details to reply to your enquiry. No newsletters, no sharing.