
Small businesses are targeted by cybercriminals more often than large enterprises — not because they have more to steal, but because they have less security to defeat. The average small business has no dedicated IT security staff, uses consumer-grade password practices, and runs software that hasn’t been updated in months. These are not difficult targets.
Financial data is among the most sensitive data a business holds. Your accounting software contains bank account details, payroll data, customer payment information, and the financial picture of your entire business. A breach doesn’t just steal money — it exposes employees, clients, and your own tax situation in ways that can take years to fully resolve.
This guide covers the most important cybersecurity practices for protecting your financial systems.
The Threat Landscape for Small Business Finance
Business Email Compromise (BEC)
The most financially damaging attack on small businesses. A cybercriminal impersonates a trusted contact (your bank, a vendor, your CPA, or a business partner) via email and requests a wire transfer, ACH change, or payment to a new account. The FBI’s Internet Crime Complaint Center (IC3) reports BEC caused over $2.9 billion in losses annually — with small and mid-sized businesses representing the majority of victims.
How it works: The attacker either compromises a legitimate email account (by stealing credentials) or creates a look-alike domain (cpaone-billing.com instead of cpaone.net). The email requests an urgent payment or bank account change. The request looks legitimate. Money is transferred. By the time the fraud is discovered, funds are gone — wire transfers and ACH payments are difficult or impossible to recover.
Defense: Verify any request to change payment information or make a wire transfer by calling the requester using a phone number you already have on file — not a number in the suspicious email. Establish a formal policy: no payment account changes without voice verification.
Ransomware
Ransomware encrypts your business files and demands payment to decrypt them. Small businesses that do not maintain offline backups face a choice between paying the ransom and losing their data. Financial records, client files, and accounting data are common ransomware targets.
Defense: Maintain current offsite backups (at minimum, a weekly full backup stored separately from your network — cloud backup services like Backblaze Business, Carbonite, or Veeam are effective). Test your backup restoration process — a backup you’ve never tested may not work when you need it.
Credential Theft and Account Takeover
Attackers steal login credentials through:
- Phishing emails that direct victims to fake login pages for QBO, Xero, banking portals, or payroll platforms
- Data breaches at other companies where you reused a password
- Malware that records keystrokes or captures browser-saved passwords
Once an attacker has your accounting software credentials, they can view all your financial data, change bank account information, initiate payments, and export your client list — all without any other access to your computer.
Defense: Multi-factor authentication (MFA), unique passwords for every financial platform, and phishing-resistant email habits.
Insider Threats
Financial fraud by employees or bookkeepers is more common than external attack for small businesses. Common schemes:
- Ghost employees — fictitious employees added to payroll
- Vendor kickbacks — payments to vendors owned by or related to the employee
- Check tampering — altering payee names on paper checks
- Expense reimbursement fraud — inflated or fabricated expenses
Defense: Segregation of duties — the person who approves payments should not be the same person who processes them. Review bank statements and payroll reports yourself, even if someone else manages day-to-day bookkeeping. Require dual authorization for wire transfers above a threshold.
Priority Security Controls
1. Multi-Factor Authentication (MFA) — Non-Negotiable
Enable MFA on every financial account, without exception:
- QuickBooks Online
- Xero
- Your business bank accounts (online banking)
- Payroll platforms (Gusto, ADP, QBO Payroll)
- Email accounts (Microsoft 365 / Google Workspace)
- Document storage (Google Drive, Dropbox)
- IRS e-services (irs.gov online account, EFTPS)
- tap.utah.gov (Utah tax account)
MFA requires a second verification factor — typically a one-time code from an authenticator app — in addition to your password. Even if an attacker steals your password, they cannot access your account without the second factor.
Use an authenticator app (Google Authenticator, Microsoft Authenticator, Authy) rather than SMS text codes. SMS-based MFA is vulnerable to SIM-swapping attacks; app-based MFA is not.
2. Unique, Strong Passwords with a Password Manager
Every financial platform must have a unique password — a password used on one site and compromised in a data breach immediately exposes every account where you reused it.
Strong passwords: at least 16 characters, mix of letters, numbers, and symbols. Passphrases (4+ random words) are both strong and memorable.
Use a password manager (1Password, Bitwarden, Dashlane) to generate and store unique passwords for every account. You need to remember one master password; the manager handles the rest. This eliminates the practical barrier to unique passwords.
3. Keep Software Updated
Unpatched software vulnerabilities are a primary attack vector. Enable automatic updates for:
- Operating system (Windows, macOS)
- Browser (Chrome, Edge, Firefox)
- Antivirus software
- Accounting and business applications
Cloud-based accounting software (QBO, Xero) updates automatically — this is one of the security advantages of cloud vs. desktop software. Desktop software requires manual updates that many businesses neglect.
4. Email Security Practices
- Verify before clicking: Hover over links in emails to see the actual destination URL before clicking. Phishing links often use look-alike domains (paypa1.com, irs.gov.verify-account.com).
- Do not open unexpected attachments: Even from known senders — if you weren’t expecting an invoice PDF or a spreadsheet, call to verify before opening.
- Enable email spam filtering: Microsoft 365 Defender and Google Workspace’s spam filters catch the majority of phishing attempts.
- Set up DMARC/DKIM/SPF for your domain: These email authentication records prevent attackers from spoofing your domain to send fraudulent emails that appear to come from your business. Your IT provider or web host can configure these.
5. Limit User Permissions
Apply the principle of least privilege: every user should have only the access their role requires.
In QuickBooks Online:
- Bookkeeper: Can enter transactions, run reports — should not have bank transfer access
- Office manager: Can send invoices, manage A/R — should not have payroll access
- Owner: Full admin access
In Xero:
- Adviser: Full CPA access including locked periods
- Standard user: Can enter transactions and invoices
- Limited access: Read-only or specific function only
Review user access quarterly. Remove access immediately for any departed employee. The highest-risk credential is the active account of a former employee who still has valid login credentials.
6. Secure Remote Access
If employees access financial systems remotely:
- Use a VPN for connections to on-premises resources
- Never use public Wi-Fi (coffee shops, airports, hotels) without a VPN for financial platform access
- Ensure all remote devices have current antivirus and operating system updates
- Do not allow financial platform access from personal (unmanaged) devices if it can be avoided
7. Backup and Recovery
Maintain current backups of all financial data on a schedule that reflects your business’s tolerance for data loss:
- QBO and Xero: Export reports and transaction data at least quarterly; save to cloud storage (Google Drive, Dropbox) and an external drive
- Local files: Daily or weekly backup to an offsite location or cloud service
- Test your backups: Periodically restore a file to confirm the backup is functional and current
A backup you’ve never tested is a backup you cannot trust.
Incident Response: What to Do If You’re Compromised
If you discover or suspect a financial system breach:
- Change all passwords immediately — start with accounting software, banking, and payroll; extend to email and all financial platforms
- Revoke active sessions — in QBO, Xero, and banking portals, log out all active sessions in addition to changing passwords
- Notify your bank — if payment fraud is suspected, contact your bank’s fraud department immediately; wire recalls are time-sensitive
- Document everything — capture screenshots, preserve emails, log the timeline of events
- Contact law enforcement — FBI IC3 (ic3.gov) for cybercrime; local FBI field office for significant financial fraud
- Notify your CPA — financial fraud has tax implications; your CPA needs to know
- Review for secondary exposure — if an email account was compromised, assume all documents, contacts, and saved passwords in that email are exposed
- Consider a forensic review — for significant breaches, a cybersecurity firm can determine how access was gained and what was exposed
Do not pay ransomware demands without consulting law enforcement first. Payment does not guarantee decryption and may fund additional attacks.
Utah-Specific Resources
- Utah Division of Consumer Protection: consumer.utah.gov — handles consumer data breach notifications if customer data is compromised
- Utah Technology Council: utahtech.org — industry resources for technology businesses on cybersecurity best practices
- FBI Salt Lake City Field Office: (801) 579-1400 — report significant financial cybercrime
- FTC IdentityTheft.gov: identitytheft.gov — if business owner identity is stolen and used for fraudulent tax or financial filings
Call (801) 927-1337 or email admin@cpaone.net to discuss the security of your financial systems as part of your CPA relationship. We help clients configure cloud accounting systems with appropriate access controls, review user permissions, and identify security gaps before they become incidents.
About the Author: Missy Dennis, CPA is a Partner at FJ & Associates, PLLC in Kaysville, Utah. She holds a Master of Accounting degree from the University of Utah and is a licensed Certified Public Accountant with more than twenty years of public accounting experience. Missy specializes in tax preparation and advisory, bookkeeping strategy alignment, estate and trust taxation, audit and consulting services, low-income housing tax credits, non-profit accounting, and small- and mid-sized business advisory. She is committed to providing clear, accurate, and actionable guidance so clients can navigate complex financial decisions with confidence.
