You're offline — showing the last version we saved.
Tech stack · Security, backup & IT

Security, backup & IT

Access control, backup, and the obligations of holding client data.

4 tools listed

Guide

Choosing security, backup & it software for a practice

Updated 4 September 2026, reviewed annually. By Trent McLaren.

Security, backup and IT tools are the part of the stack a firm buys because someone asked: a client, an insurer, a regulator, or the tax authority that now expects a written security plan from anyone who prepares returns. Identity and sign-in, device management, backup of the cloud systems the firm relies on, email security, password management, and the monitoring that says something went wrong. This guide is about the minimum a small practice should be able to show, and how to buy it without becoming an IT department; the cards below are the tools.

What a small firm has to be able to show

A firm holds every client's identity documents, bank details and tax file, which makes it a target regardless of size. What a client, insurer or regulator asks to see is consistent: multi-factor sign-in on every system, a way to remove a departed staff member's access in one place, devices that are encrypted and can be wiped, backups of the cloud data the firm cannot afford to lose, email that stops the obvious phishing, and a written plan that says who does what when something happens. Each maps to a tool category, and none of them is expensive at practice scale.

What to look for

Identity first: a single sign-in layer that every other tool accepts, with multi-factor enforced and a leaver process that is one click. Password management for the systems that cannot use it, shared vaults per team. Device management that enforces encryption and updates on laptops and phones, and can wipe a lost one. Backup that covers the cloud systems (email, documents, the ledger data the firm holds), with a restore the firm has actually tested. Email security that filters and warns. And a monitoring or managed service that watches all of it, because a small firm has nobody to watch a dashboard.

For firms with offshore or outsourced staff, access scoped by role and by location matters as much as any of it.

Buying it as a service

Most small firms should not run this themselves. A managed provider that specialises in accounting practices brings the tools, the plan, the monitoring and the answer to the insurer's questionnaire. The firm's job is to choose one that knows the practice systems and ledgers, to own the leaver process, and to test the restore once a year. The cost is a line in overhead; the alternative is a partner's weekend.

The written plan matters more than any tool. It is what the tax authority in some countries requires of preparers, what the insurer reads, and what the team follows at two in the morning. It should fit on a few pages and name people.

Pricing and how firms recover it

Vendors price per user per month, per device, or as a managed bundle per user. The directory records what vendors publish; it does not say what a firm should charge, and nothing here is fee advice. Firms describe treating security as overhead inside every fee, and sometimes offering a security review to clients as an advisory service once the firm's own house is in order.

Client data in AI tools

The newest question a client asks is where their data goes when the firm uses an AI assistant. The answer belongs in the security plan: which tools are approved, what they may read, where the data is stored, and what the firm has agreed with the vendor. A firm that can answer in one paragraph keeps the client; one that cannot is guessing.

What to avoid

Multi-factor on some systems and not others. A leaver process that is a list of tools to remember. Backups never restored. A security plan written for the insurer and never read. Consumer tools on staff devices holding client files. And running all of this in-house with nobody whose job it is.

Common questions

Security, backup & IT software, answered

What security software does a small accounting firm need?
Single sign-in with multi-factor enforced, a password manager, device management with encryption and remote wipe, backup of the cloud systems with a tested restore, email security, and monitoring, usually through a managed provider that knows accounting practices. The directory lists the tools firms report running.
Does a small firm need a written security plan?
Yes. Tax authorities in some countries require one of anyone who prepares returns, insurers read it, and the team follows it when something happens. A few pages that name people and tools is enough; a plan nobody reads is not.
How is security and IT software priced?
Per user per month, per device, or as a managed bundle per user. Each listing records the vendor's published prices where they are public. The Firm does not publish recommended fees.
Should a small firm use a managed IT provider?
Usually. A provider that specialises in accounting practices brings the tools, the plan, the monitoring and the insurer answers. The firm keeps the leaver process and tests the restore once a year.
Does The Firm charge vendors to be listed?
No. Listing is free and claiming a listing is free. Paid placement is labelled as such, and every outbound link to a vendor carries a sponsored attribute. Paying never changes how a tool is described.
Other categories
Get your free seat →

AI in Practice Summit returns. What worked, what's next: two days on what AI actually did for firms this year, and where it goes in 2027. 11–12 November 2026, virtual and free.