Cyber Security for Sole Practitioners: Big Firm Risks, Small Firm Budgets
Updated: Sep 2
If you're a sole practitioner, you're carrying the same data risk as a 50-partner firm client tax records, bank details, ID documents, HNW private client files but without a dedicated IT team, a security budget line, or anyone else to catch what you miss. The good news is that most of the protection that matters doesn't require a big spend. It requires using the tools you already pay for properly.
Start with the software you already have
You don't need to buy new security products before you've configured the ones you're already using.
Xero / QuickBooks
Turn on multi-factor authentication (MFA) on every user account this alone blocks the majority of account takeover attempts.
Review the user list quarterly. Remove access for any bookkeeper, contractor, or old assistant who no longer needs it.
Restrict bank feed and payment permissions to yourself where possible; these are the functions attackers target first.
Enable login notifications/activity alerts if the platform offers them, so you see unfamiliar sign-ins.
Virtual Cabinet / Practice Engine (or any document management system)
Check who has access to client folders as a sole practitioner this is usually just you, but if you use a part-time bookkeeper or a virtual assistant, make sure their access is scoped to only what they need, not the whole client bank.
Confirm documents are encrypted at rest (most cloud DMS platforms do this by default, but check the vendor's security page rather than assuming).
If you exchange documents by email as well as through the DMS, that's your weakest link client portals or secure links are worth the switch.
Making Tax Digital submissions
Use dedicated MTD-compliant software rather than spreadsheet bridging tools where you can bridging introduces an extra file-handling step that's easy to mishandle securely.
Keep HMRC agent credentials in a password manager, not saved in a browser on a shared or family device.
Practical steps in Microsoft 365
If you're on M365 Business (Basic, Standard, or Premium), you already have security features sitting unused:
Enable MFA for every account, including yourself. Do this via Security Defaults or Conditional Access if you're on Premium.
Turn on Safe Links and Safe Attachments (Premium/Defender) to catch phishing emails before they reach you this is the single most common route into a sole practitioner's data.
Set up mail flow rules to flag or block emails impersonating HMRC, banks, or your own domain.
Encrypt sensitive emails M365 has built-in message encryption ("Encrypt" button in Outlook) for anything containing client financial or ID data.
Turn on unified audit logging so that if something does go wrong, you can actually see what happened.
Back up OneDrive/SharePoint separately M365's own retention isn't a substitute for a proper backup if ransomware hits.
Review third-party app permissions under Azure AD/Entra periodically; many sole practitioners accumulate connected apps over the years that no longer need access.
Where this leaves you
None of the above requires new spend it's a few hours of configuration inside software you already pay for. If you want a second pair of eyes on how your specific setup is configured, we're happy to help with a review scoped to what you actually run.

Comments