Receipts sorted into piles on a bookkeeper's desk, cyber insurance for bookkeepers

BOOKKEEPER AND BAS AGENT INSURANCE

Does a Bookkeeper Need Cyber Insurance?

A bookkeeper's practice is a concentration of other people's financial data: bank feeds, payroll files, tax file numbers and a login to the ATO's online services for agents. Professional indemnity responds when your work is wrong. It is not designed to respond when your inbox is compromised and a client's supplier payment is redirected, and most PI wordings exclude it. That is what cyber insurance is for, and why practices with staff, offshore support or payroll clients generally look at both.

PICovers your errors
CyberCovers the breach
TFNsPrivacy and breach notification obligations can apply regardless of size
BothWhat practices with staff have generally taken

Premiums and outcomes described are specific to this client and indicative only. Your own terms will depend on your circumstances and the insurer.

THE SHORT ANSWER

Does a bookkeeper or BAS agent in Australia need cyber insurance as well as professional indemnity?

Cyber insurance is not required by the Tax Practitioners Board, but a bookkeeper's professional indemnity policy is generally not designed to respond to a data breach, a compromised email or ransomware. Those are security incidents, and the client's loss flows from the incident rather than from your bookkeeping. Handling tax file numbers brings a practice within the Privacy Act's tax file number provisions even where the small business exemption would otherwise apply, and can bring it within the Notifiable Data Breaches scheme, so a breach can carry assessment and notification obligations. Cyber insurance typically pays for incident response, restoration, notification, business interruption and client claims arising from the incident, subject to the wording and sub-limits.

Practices with staff, offshore support or payroll clients that we place have generally taken both. A cyber quote for a small practice is priced on records, revenue and three controls: multi-factor authentication, off-system backups and staff training. Check your own Privacy Act position with your adviser.

TPB requirement
PI yes, cyber no
Privacy Act
TFN provisions apply regardless of size
PI covers
Your errors
Cyber covers
The incident and its costs, subject to wording

The table shows how these policies are generally structured. Whether any particular claim is covered depends on the policy wording, its exclusions and sub-limits, and the facts. Indicative only.

ScenarioProfessional indemnityCyber insurance
You enter a supplier's bank details wrongly and the client pays the wrong accountTypically responds, subject to the wording: an error in your professional serviceGenerally no
Your email is compromised, a fake invoice goes to the client, and the client pays a criminalUsually no. The loss came from a security failure, not your advice or workUsually responds to your own response costs, and to a client claim where the wording provides third-party liability. Funds transfer cover varies
Ransomware locks your practice files and you cannot lodge BAS for a weekGenerally noTypically responds, subject to sub-limits: restoration, forensic IT, business interruption, and client claims for late lodgement where third-party cover is included
A laptop with client TFNs and payroll data is stolenGenerally noTypically responds: breach assessment, notification to affected people and the OAIC, credit monitoring, legal costs, within the policy's sub-limits
Your ATO online services for agents login is used by someone else to change client bank detailsPossibly, if a failure of your process is allegedTypically responds to the incident costs, and to third-party claims where the wording provides for them
Some PI wordings for accountants include a small cyber or privacy extension. Read the sub-limit and the trigger: they are usually a fraction of the PI limit and do not include incident response.
OAIC

The Privacy Act and the Notifiable Data Breaches scheme

Handling tax file numbers brings a practice within the Privacy Act's tax file number provisions even where the small business exemption would otherwise apply, and many bookkeeping practices fall outside that exemption for other reasons as well. A breach involving client TFNs can therefore trigger assessment and, where serious harm is likely, notification to the OAIC and to the affected individuals. Whether the scheme applies to your practice and to a particular incident depends on the circumstances, so take your own advice on your obligations. Cyber policies typically pay for that assessment and notification, subject to the sub-limits in the policy.

TPB

The TPB's cyber security expectations

The TPB has published cyber security guidance for registered agents, and the Code of Professional Conduct in the Tax Agent Services Act 2009 requires you to keep client information confidential. The TPB's PI guideline does not require cyber insurance, but a breach that leads to a client complaint is examined against both.

Placed

Tax and accounting practice, Queensland

With staff including offshore support, and a book that included payroll and ASIC work, placed $2,000,000 PI at approximately $2,100 a year and added a cyber policy alongside it.

Enquiry

Accountant registering as a tax agent

A sole practitioner who asked for PI and cyber together from the first enquiry.

Enquiry

Bookkeeper moving into payroll and HR consulting

For around $150,000 in fees, asked for PI, cyber and a business pack in one enquiry.

A cyber policy for a small practice is quoted on the number of records, revenue, and the controls you have in place. Those three controls carry real weight with underwriters and can be the difference between a standard quote and a loaded one. For pricing on the PI side see how much bookkeeper PI costs.

01

Multi-factor authentication

On email and accounting software.

02

Off-system backups

Backups held off the main system.

03

Staff training

So the fake invoice gets questioned before it gets paid.

FREQUENTLY ASKED QUESTIONS

Bookkeeper Cyber Insurance FAQs

No. The TPB requires professional indemnity insurance as a condition of registration and does not require cyber insurance. Cyber is a commercial decision, driven by the fact that a bookkeeper holds client bank, payroll and tax file number data and a PI policy does not respond to a breach of that data.
Generally not. PI responds to claims that your professional work was negligent or wrong. A data breach, a compromised email, or ransomware is a security incident, and the client's loss flows from that rather than from your bookkeeping. Some accountant PI wordings carry a small privacy extension with a low sub-limit and no incident response cover. Cyber insurance is the policy that responds to the incident itself.
Handling tax file numbers, as a BAS or bookkeeping practice generally will, brings a practice within the Privacy Act's tax file number provisions even where the small business exemption would otherwise apply, and a practice can fall outside the exemption on other grounds too. Whether the Notifiable Data Breaches scheme applies to a given practice and a given breach depends on the circumstances. Confirm your own obligations with the OAIC's guidance or your adviser.
Typically: incident response and forensic IT, data restoration, business interruption while systems are down, breach notification costs, cyber extortion, funds transfer fraud arising from a compromised system, and claims from clients whose data or money was affected. Cover for money lost through invoice redirection varies between insurers and is worth checking specifically.
It is quoted on records held, revenue and controls, and for a small practice it usually sits well below the PI premium. Multi-factor authentication on email and accounting software, off-system backups and basic staff training move the price and, with some insurers, whether the risk is accepted at all.
If you hold client bank feeds, payroll data or TFNs and log in to the ATO's online services for agents, the exposure exists whether you have staff or not. On our placements sole practitioners in their first year have often taken PI alone and looked at cyber once the client list grows or payroll work starts. Getting both quoted at the same time shows the actual gap. We are paid by commission from the insurer if you place cover, as set out in our Financial Services Guide.

QUOTE REQUEST

Quote PI and cyber together

Tell us roughly how many client files you hold, whether you have staff or offshore support, and whether multi-factor authentication is on. We will quote both policies side by side.

Specialist broker review Australian business insurance
Lever-arch folders on a shelf, cyber insurance for bookkeepers

Cover the Error and the Breach

PI for the work, cyber for the data. Quoted together from the markets that write bookkeepers and tax practitioners, with the sub-limits and triggers of any PI privacy extension spelled out against a standalone cyber policy.

Last updated: 05/09/2026

Call Us Now +61 2 9000 1155