NIS2 for accountants: what to look out for
Does your accountancy firm fall under NIS2, and what do your clients expect from you? In this article you read how NIS2 affects accountants, often via the chain, and what you can arrange now.
By Max HoltropAccountancy firms work with sensitive financial data of many organisations. That is exactly why the question "do we fall under NIS2?" is extra relevant here. The answer is nuanced: possibly not directly, but via your clients. In this article you read how that works. Want the basics of the law first? Then read NIS2 for SMEs.
Do accountants fall directly under NIS2?
Usually not on the basis of the main rule, because accountancy is not listed as a separate sector in NIS2. But that is not the whole story. Many accountancy firms do face NIS2 via the chain: their clients fall under it and must safeguard the security of their suppliers. If you are that supplier, the requirements still land with you.
Why your clients will ask you about security
Because NIS2 obliges organisations to also assess their suppliers. If you work for companies in regulated sectors, they will want to know how you protect their data. If you cannot give a clear answer, you become a risk in their chain, and that can cost you assignments. Demonstrable security thus becomes a commercial argument.
What makes accountancy firms an attractive target?
The concentration of valuable data. At one accountant, the financial data of dozens to hundreds of clients is stored. For attackers that is a favoured target, and for you a reason to take security seriously, regardless of whether NIS2 formally applies.
What can you arrange now?
The basics, which are also good IT management:
- Secure sign-in with multi-factor authentication (MFA) on all accounts.
- Protection against phishing, technology plus awareness among your team.
- Backups that you have tested for recovery.
- Recording what you have arranged, so you can demonstrate it to clients.
You will find more steps in the NIS2 checklist for SMEs.
How IT-gemak helps accountants
We lay the technical foundation with our approach to IT security and NIS2 and help you get it demonstrably in order, so you can show your clients that their data is safe.
Want to know where you stand? Schedule a no-obligation consultation. We go through your situation and make a concrete plan.
Good to know
Do accountancy firms fall under NIS2?
Usually not directly, because accountancy is not a separate NIS2 sector. But you can be affected via the chain: clients who fall under NIS2 impose security requirements on their suppliers.
Why do clients ask accountants for security measures?
Because NIS2 obliges organisations to safeguard the security of their suppliers too. If you work for regulated companies, they will want to know how you protect their data.
What can an accountancy firm do now?
Start with the basics: MFA on all accounts, phishing protection, tested backups and recording your measures. That is immediately good IT management and demonstrable to clients.
Are accountants a target for cyberattacks?
Yes. At one firm the financial data of many clients is stored, which makes it an attractive target. Good security is therefore sensible, regardless of whether NIS2 formally applies.
Related services
ICT Security & NIS2
Control over your business information and demonstrable compliance, for the law and for your clients.
Read more →Keeper Password Security
Secure password management for your entire organisation: strong passwords, shared and under control.
Read more →Microsoft 365 security licenses
The right Microsoft security licenses for your organization: advice, setup and management.
Read more →Related articles
Backup requirements under NIS2: why Microsoft 365 alone is not enough
Does NIS2 require a backup, and does Microsoft 365 not make one itself? In this article you read what the backup requirements mean for SMEs and why you need a separate backup of your Microsoft 365 environment.
Read more →Does my company fall under NIS2? The decision tree
Does my company fall under NIS2? Work through the decision tree based on your sector, your size and your role in the chain, and know where you stand by the end.
Read more →NIS2 checklist for SMEs: 10 steps
NIS2 compliance for SMEs in 10 concrete steps. From MFA and phishing protection to backups and an incident plan: this is how you get the basics in order step by step.
Read more →Want to spar with a specialist?
Curious what this means for your organisation? Book a no-obligation consult — we’re happy to think along.
