bcom ICT supports professional services firms across the Gold Coast — accountants, lawyers, financial planners, brokers and consultants. These firms hold concentrated client financial and identity information, carry professional and in some cases regulatory obligations over it, and increasingly have to evidence how it is protected. Call 07 3041 8993.
Concentrated information, portable work
You hold more than you think
Tax file numbers, identity documents, financial statements, wills, contracts. A professional services firm holds a density of sensitive information that would take a retailer years to accumulate, and it is all in one place.
The obligations vary by discipline
AFS licensees carry cyber resilience obligations under their licence. Lawyers carry professional confidentiality duties. Accountants handle TFNs under specific rules. The compliance answer is not the same across the corridor.
Clients are now asking
Larger clients and government buyers ask suppliers how they protect information before engaging them. "We take security seriously" does not survive a procurement questionnaire; a documented position does.
The work goes home
Hybrid working is normal in this sector, which means client information travels on laptops and phones. Security has to apply wherever the device is, not only inside the office.
What we put in place
- Multi-factor authentication everywhere — the control that stops most account compromise, and still missing from someone's account at most firms we assess
- Document management and file access structured so people reach what their role requires, not the entire client base
- Device management for laptops and phones that leave the office, including remote wipe if one is lost
- Email security — filtering, plus the SPF, DKIM and DMARC records that stop someone invoicing your clients in your name
- Backup held separately with tested restores, because a firm that cannot produce a client file has a professional problem as well as a technical one
- An Essential Eight position you can point at when a client or insurer asks
For AFS licensees specifically
If your firm operates under an Australian Financial Services licence — planners, brokers, some accountants — cyber resilience sits inside your general licence obligations, and ASIC has shown increasing willingness to treat it that way.
That means implemented controls, documented evidence of them, oversight of outsourced arrangements including your IT provider, and a workable incident response plan. We cover that specifically on ASIC cybersecurity compliance, including the evidence pack you would actually produce when asked.
Questions Gold Coast businesses ask us
What IT security do professional services firms need?
At minimum: multi-factor authentication on every account, document access structured by role rather than open to everyone, managed devices for laptops that leave the office, email authentication to prevent impersonation, and backups held separately with tested restores. AFS licensees carry additional obligations under their licence. bcom ICT supports Gold Coast accountants, lawyers, planners and consultants. Call 07 3041 8993.
A client is asking how we protect their information. What do we send them?
A documented position rather than an assurance — what controls you operate, how access is managed, where data is held, and what happens in an incident. If you don't have that written down, a security health check produces most of it and is the fastest route to being able to answer.
Does the Privacy Act apply to our firm?
It depends on turnover and what you handle, and there are exceptions that catch firms out. Many professional services businesses are over the threshold, and those handling TFNs or credit information have specific obligations regardless. Worth establishing before an incident rather than during one.
Can staff work from home securely?
Yes, if the security travels with the device rather than living in the office. That means managed laptops with encryption and remote wipe, MFA on everything, and access to documents through a controlled system rather than files copied to a desktop.
What about our practice or document management system?
We support the environment it runs in — server or cloud tenancy, backups, access control, updates and connectivity — and work alongside your software vendor for the application itself.
We're an AFS licensee. Is that different?
Yes. Cyber resilience falls within your general licence obligations and requires documented evidence rather than good practice alone. See our ASIC cybersecurity compliance page for the gap assessment and evidence work.
Being asked questions you can't answer?
A health check turns "we take it seriously" into a document you can actually send.
