Security · Small Firms
Twenty practical controls for law, accounting and consulting firms, grouped by people, devices, email, data, suppliers and preparedness.
Last updated: October 2026. Written by Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions.
Quick answer
Small professional firms can stop most attacks with basic habits: multi-factor authentication, a password manager, least-privilege access, prompt offboarding, regular updates, device encryption, phishing training, email authentication, payment verification, tested backups using the 3-2-1 rule, secure file sharing, supplier reviews and an incident response plan. Prioritise MFA, updates, a password manager and tested backups first.
Key takeaways
- Start with MFA, updates, a password manager and tested backups.
- Train staff on phishing and verify payment changes by phone.
- Follow 3-2-1 backups and actually test restores.
- Review access, suppliers and offboarding regularly.
- Write and rehearse an incident response plan.
In this guide
Small professional firms hold exactly what attackers want: client identities, financial details, privileged communications and access to bank accounts and systems. They are also less likely to have a dedicated security team. The good news is that most successful attacks exploit basic gaps, and basic habits close most of them.
This checklist covers twenty cybersecurity basics for small law, accounting and consulting firms. It is general guidance, not a substitute for professional security advice or your regulator’s requirements.
The 20-point checklist
People and access
- Multi-factor authentication everywhere it is offered, especially email, cloud storage and financial systems.
- A password manager for staff, with unique strong passwords for every account.
- Least privilege. Give people access only to what they need, and review it regularly.
- Prompt offboarding. Remove access the day someone leaves.
- Separate admin accounts from everyday accounts.
Devices and software
- Keep everything updated. Operating systems, browsers and applications should receive security updates promptly.
- Antimalware or endpoint protection on all computers.
- Encrypt laptops and phones, so a lost device does not mean a data breach.
- Screen locks and automatic timeouts.
- Control which software people can install.
Email and phishing
- Staff awareness training on phishing, with realistic examples.
- A clear way to report suspicious messages, and a culture of no blame.
- Email authentication. SPF, DKIM and DMARC protect your domain from being spoofed.
- Verification for payment changes. Confirm new bank details by phone using a known number before paying.
Data and backups
- Backups that are tested, with at least one copy kept separate from your main systems. A common approach is three copies, on two types of storage, with one offsite.
- Know where client data lives, and keep it in approved, access-controlled systems.
- Secure file sharing. Use a portal or encrypted sharing, not plain email attachments.
- Retention and secure disposal of data and old devices.
Network and suppliers
- Secure Wi-Fi and a separate guest network.
- Review suppliers and cloud services. Check their security, data location and breach notification terms.
Preparedness
- An incident response plan. Know who does what, who to call and what to report, and to whom, if something happens. Practise it.
How to prioritise
| Priority | Actions | Why |
|---|---|---|
| Do first | Multi-factor authentication, updates, password manager, tested backups | Block the most common attacks and enable recovery |
| Do next | Phishing training, offboarding process, encryption, payment verification | Reduce human and device risk |
| Then | Least privilege review, supplier reviews, incident plan, email authentication | Build resilience and reduce exposure |
What frameworks can guide you?
Recognised frameworks give structure. In the UK, the National Cyber Security Centre’s Cyber Essentials scheme sets out basic controls, and in the US, the NIST Cybersecurity Framework is widely used. Your regulator or insurer may also set expectations, so check what applies to you.
What should you do if something goes wrong?
- Isolate affected devices, but do not switch off or wipe them without advice.
- Change passwords and revoke access for affected accounts.
- Contact your incident lead, your IT or security adviser and, where relevant, your insurer.
- Work out what data may be affected.
- Meet your legal and regulatory duties on notification, which often have strict deadlines.
- Record what happened and learn from it.
How does this apply to the software you use or build?
The same principles apply to custom systems: enforce roles and privacy rules, keep keys private, log activity, test with multiple accounts and plan for backups. See our Bubble.io security guide and what to cut before you build. Our Discovery Sprint includes security requirements in the plan: $345, delivered in 24 hours and credited toward a build starting at $3,500.
Frequently asked questions
What are the most important cybersecurity steps for a small firm?
Multi-factor authentication, prompt updates, a password manager, tested backups and staff training on phishing cover the most common risks.
What is the 3-2-1 backup rule?
Keep three copies of your data, on two different types of storage, with one copy offsite or offline.
Do small firms need an incident response plan?
Yes. Knowing who does what and whom to notify saves time and reduces damage when something happens.
How often should we train staff?
At least annually, with shorter reminders and realistic phishing examples through the year.
Is cloud software less secure than on-premise?
Not necessarily. Security depends on the provider, configuration and your habits. Review providers and use strong access controls.
Want your client systems built securely from day one?
Email us what data your systems hold and who needs access. We will build security into the plan.
Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions
About Simple Automation Solutions (SA Solutions)
Simple Automation Solutions is a Bubble.io development studio led by Athar Ahmad, a Certified Bubble.io Developer and Tech Architect. It builds web and mobile apps, client portals and SaaS products for founder-led businesses such as law firms, accounting firms, boutique agencies and consultants. Services include a free 30-minute Idea Audit, a $345 Discovery Sprint (a Product Requirements Document delivered within 24 hours, credited toward the build) and builds starting at $3,500. Website: sasolutionspk.com.