NIS2 for accountants: what to look out for
Does your accountancy firm fall under NIS2, and what do your clients expect from you? In this article you read how NIS2 affects accountants, often via the chain, and what you can arrange now.
By Max HoltropAccountancy firms work with sensitive financial data of many organisations. That is exactly why the question "do we fall under NIS2?" is extra relevant here. The answer is nuanced: possibly not directly, but via your clients. In this article you read how that works. Want the basics of the law first? Then read NIS2 for SMEs.
Do accountants fall directly under NIS2?
Usually not on the basis of the main rule, because accountancy is not listed as a separate sector in NIS2. But that is not the whole story. Many accountancy firms do face NIS2 via the chain: their clients fall under it and must safeguard the security of their suppliers. If you are that supplier, the requirements still land with you.
Why your clients will ask you about security
Because NIS2 obliges organisations to also assess their suppliers. If you work for companies in regulated sectors, they will want to know how you protect their data. If you cannot give a clear answer, you become a risk in their chain, and that can cost you assignments. Demonstrable security thus becomes a commercial argument.
What makes accountancy firms an attractive target?
The concentration of valuable data. At one accountant, the financial data of dozens to hundreds of clients is stored. For attackers that is a favoured target, and for you a reason to take security seriously, regardless of whether NIS2 formally applies.
What can you arrange now?
The basics, which are also good IT management:
- Secure sign-in with multi-factor authentication (MFA) on all accounts.
- Protection against phishing, technology plus awareness among your team.
- Backups that you have tested for recovery.
- Recording what you have arranged, so you can demonstrate it to clients.
You will find more steps in the NIS2 checklist for SMEs.
How IT-gemak helps accountants
We lay the technical foundation with our approach to IT security and NIS2 and help you get it demonstrably in order, so you can show your clients that their data is safe.
Want to know where you stand? Schedule a no-obligation consultation. We go through your situation and make a concrete plan.
Good to know
Do accountancy firms fall under NIS2?
Usually not directly, because accountancy is not a separate NIS2 sector. But you can be affected via the chain: clients who fall under NIS2 impose security requirements on their suppliers.
Why do clients ask accountants for security measures?
Because NIS2 obliges organisations to safeguard the security of their suppliers too. If you work for regulated companies, they will want to know how you protect their data.
What can an accountancy firm do now?
Start with the basics: MFA on all accounts, phishing protection, tested backups and recording your measures. That is immediately good IT management and demonstrable to clients.
Are accountants a target for cyberattacks?
Yes. At one firm the financial data of many clients is stored, which makes it an attractive target. Good security is therefore sensible, regardless of whether NIS2 formally applies.
Related services
ICT Security & NIS2
Control over your business information and demonstrable compliance, for the law and for your clients.
Read more →Keeper Password Security
Secure password management for your entire organisation: strong passwords, shared and under control.
Read more →Microsoft 365 security licenses
The right Microsoft security licenses for your organization: advice, setup and management.
Read more →Related articles
IT security check: is your business secure?
How do you know if your IT security is really in order? An IT security check scans your environment and delivers a clear report with concrete improvement points. Read what it involves.
Read more →MFA: why secure sign-in is the most important measure
What is MFA, and why is it the most important security measure for SMEs? In this article you read how multi-factor authentication works and why you want to enable it everywhere.
Read more →NIS2 vs ISO 27001: the difference and the overlap
NIS2 and ISO 27001 are often confused. In this article you read the difference, where they overlap and whether an ISO certification helps you to comply with NIS2.
Read more →Want to spar with a specialist?
Curious what this means for your organisation? Book a no-obligation consult — we’re happy to think along.
