In this podcast episode, Alvin Madar, cybersecurity, privacy and financial crime partner and national leader for cybersecurity at PwC Canada, outlines how CPA firms can reduce cyber risk and respond to breaches.
Cybersecurity incidents are a very real threat for accounting firms of all sizes, with the number of cyber attacks in Canada increasing sharply in both number and severity over the past two years.1 For CPA firms, the consequences can go beyond operational disruption to include reputational harm, regulatory exposure, and loss of client trust. Although all firms face these risks, many smaller practices still assume they’re unlikely targets—a misconception that can leave them particularly exposed.
Against this backdrop, preparation is essential. We spoke with Alvin Madar, a cybersecurity, privacy, and financial crime partner and national leader for cybersecurity at PwC Canada, about the practical steps firms can take to strengthen their controls, respond effectively to incidents, and reduce the likelihood of future breaches.
Some accounting firms might assume they’re too small to be targeted. Why is that a dangerous assumption?
Cybersecurity is an issue for all firms. Breaches are on the rise, and the emergence of AI has made it easier for attackers to automate tasks that once required specialized expertise. AI also multiplies the scale and speed of expert attackers, enabling them to probe more systems faster than ever before.
I equate cybersecurity to building a fence around your house—whatever its size, you still need protection. While attackers can cause significant disruption in larger organizations and potentially harvest more data, they often cast a wide net and probe many organizations to find easier targets. Small and medium-sized firms can be particularly vulnerable if foundational controls are not in place.
It’s also important to remember that accounting firms hold extremely sensitive information, from social insurance numbers to confidential financial data, making them high-value targets, no matter their size.
What are the minimum cybersecurity controls every firm should have in place?
Every firm should have somebody responsible for cybersecurity and, where possible, allocate funds to IT and cybersecurity functions. Even with limited funds, a firm can implement foundational controls, including:
- Multi-factor authentication – Don’t rely solely on usernames and passwords.
- Frequent, continuous patching – Aim to patch within days or even hours when security gaps are identified.
- Logging – Maintain logs to trace activity and root causes if a breach occurs.
- Security awareness training – Provide regular training to ensure staff are cyber aware; social engineering (i.e., manipulating people to reveal information by exploiting their trust) is still the easiest way for hackers to get into an organization.
- Culture – Create an environment where employees feel safe sharing their missteps so that issues can be addressed promptly.
Together, these controls form the baseline for cyber incident detection, response, and prevention.
How else can a firm prepare for an attack?
Every firm should have a formal incident response plan that outlines how it will detect, respond to, and recover in the event of a breach. Firms should also run an annual tabletop exercise to simulate an attack so that staff understand how the plan works and can identify areas that need updating. Firms should also assess third-party risk to identify how their service providers are protecting data. The NIST Cybersecurity Framework is an industry standard and a useful starting point.
If a firm doesn’t have an incident response plan, where should it begin?
Start with these three foundational elements:
- A contact list that identifies who needs to be informed if an incident occurs, including internal responders, external vendors, legal counsel, insurers, and relevant regulatory bodies.
- A decision tree that clarifies who is responsible for making key decisions, including whether systems should be disconnected, when clients or regulators should be notified, and how to respond in a ransomware scenario.
- Backup verification through regular monitoring and testing. This is important even if IT is outsourced, since third-party systems can also be compromised or corrupted.
If a firm has a limited budget to build an incident response plan, it can access the free checklists and guidance from the Canadian Bankers Association’s Cybersecurity Toolkit for small businesses2 and the Government of Canada’s Get Cyber Safe website.
What should a firm do if it suspects or confirms it’s been hacked?
Staff should always be vigilant for the warning signs of a breach, especially during busy periods like tax season. These can include unusual login activity, slow systems or networks that may indicate ransomware encryption, or increased phishing or social engineering attempts.
If an organization does identify a breach, within the first 24 to 48 hours it should:
- Disconnect infected systems to prevent attackers from moving into the rest of the environment;
- Change all passwords, especially administrative credentials;
- Preserve evidence—don’t restart systems unnecessarily or delete logs;
- Notify cyber insurance providers;
- Freeze access to the backup, take a snapshot of it, and encrypt it;
- Verify that backups are clean and restorable before deciding how to respond to the breach;
- Contact legal counsel for guidance on both internal and external attacks;
- Identify a single spokesperson to communicate with the public;
- Document all actions taken;
- Implement multi-factor authentication if it’s not already in place; and
- Engage external specialists like cybersecurity or forensic specialists to assist with recovery.
In terms of what not to do, a firm should avoid:
- Paying a ransom prematurely in the event of a ransomware attack;
- Announcing the breach publicly before performing due diligence, including taking steps to investigate, contain, and remediate the breach, as well as contacting legal counsel; and
- Ignoring the breach, as regulators and stakeholders expect organizations to be transparent about incidents and to take timely action.
What should a firm look for when choosing an external partner to help it respond to an attack?
I strongly recommend bringing in an external forensic or cyber incident response partner. Your organization’s cyber insurance may cover the costs of these services.
Look for proven experience in incident response, 24/7 availability, and relevant certifications such as the Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), and GIAC Certified Incident Handler (GCIH). A partner should also have experience working with accounting firms, established relationships with cyber insurance providers, and clear and transparent pricing.
How can a firm reduce the likelihood of a repeat incident?
To help reduce risk, strengthen resilience, and improve a firm’s ability to respond to future incidents, firms can consider implementing:
- Zero trust architecture that continuously authenticates, authorizes, and validates communication between users, systems, and devices;3
- Annual penetration testing (or ethical hacking) to identify vulnerabilities;
- Continuous monitoring of systems and logs to detect potential cyber events;
- A robust AI policy that includes staff education about appropriate AI use and data protection, as well as systems to monitor AI usage.
- Data classification and “crown jewel” identification to prioritize critical assets and guide cybersecurity investments.
What steps can firms take today to start building cyber awareness among staff?
From a culture perspective, firms should create an environment where employees feel comfortable reporting cybersecurity issues or mistakes. From a technical perspective, enabling multi-factor authentication is one of the most effective steps an organization can take to protect against attacks.
Cyber threats will continue to evolve, but so can your firm’s ability to withstand them. Establishing strong controls, practising incident response, and engaging trusted experts will enable you to reduce the risk of an attack and respond decisively if a breach occurs.
Leah Giesbrecht is a communications specialist at CPABC.
This article was originally published in the September/October 2026 issue of CPABC in Focus.
Footnotes
1 Canadian Centre for Cyber Security, National Cyber Threat Assessment 2025-2026, (5) cyber.gc.ca/en/guidance/national-cyber-threat-assessment-2025-2026.
2 Canadian Bankers Association, “Protect Your Small Business from Scams and Cyber Threats with the CBA’s Fraud Prevention Toolkit,” cba.ca/article/small-business-fraud-prevention-toolkit.
3 Canadian Centre for Cyber Security, A Zero Trust Approach to Security Architecture, cyber.gc.ca, March 15, 2023.