You hold the most sensitive client data there is, and everyone knows it.

Accounting practices and financial services businesses sit on identity numbers, tax records, banking details and payroll for every client they serve. That makes them a target well out of proportion to their headcount.

Why are accounting practices targeted so heavily?

An accounting practice concentrates exactly what a criminal wants: identity numbers, tax records, banking details and payroll data for many businesses at once, plus authority that clients act on without question. A single compromised practice mailbox can be used to redirect payments across dozens of client businesses before anybody notices.

What does POPIA require of a financial services business?

POPIA Section 19 requires appropriate and reasonable technical and organisational measures to secure personal information, and financial services businesses also fall into the categories where specific breach reporting timelines can apply. In practice that means documented access control, encryption, tested backup, monitoring, and a written incident response process that has been rehearsed rather than filed.

The Information Regulator’s stated plan for 2026 and 2027 shifts from reacting to complaints toward proactive compliance audits, and names financial services and insurance among its target sectors.

What is payroll diversion fraud?

Payroll diversion fraud is an email, apparently from an employee, asking payroll to update their bank account before the next run. It is short, polite, plausible and arrives at the busiest point of the month. It succeeds because it asks for something payroll does routinely, and because nobody telephones the employee to check.

What does LANTEK put in place for a practice?

Enforced multi-factor authentication on every account, email security that detects behavioural anomalies such as a first ever banking change, encrypted devices, independent Microsoft 365 backup with tested restores, dark web monitoring, awareness training aimed at payroll and accounts, and the documented control set needed to answer a client security questionnaire the same day.

How do we prove to clients that we handle their data properly?

With evidence rather than assurance. A current asset register, dated access reviews, a written incident response plan, data processing agreements with every supplier that touches client information, and a record of backups actually restored. LANTEK produces those as a by-product of running the environment, rather than assembling them when somebody asks.

Before you call

Do you support Sage and other accounting packages?
Yes. LANTEK has accounting software consultants in house and supports Sage alongside the rest of the environment, so a problem in the accounting package does not become an argument between two suppliers while month end waits.
Is our data allowed to be hosted outside South Africa?
Often yes. POPIA Section 72 permits cross border transfer where the receiving jurisdiction has comparable protection, where the data subject consents, or where it is necessary to perform a contract. POPIA is not a South Africa only hosting law, which is a common and expensive misunderstanding.
What is the fastest thing we can fix this week?
Disable the accounts of people who have left, and introduce a telephone verification rule for any change to banking details. Those two take a morning between them and remove the most common route to a real loss.

A free dark web scan
and thirty minutes.

We scan for your company email addresses, passwords and customer data in the places stolen and leaked data gets traded, then spend thirty minutes walking you through what came back and what it actually means. No pressure, no jargon, no obligation. You keep the report either way.

Worried about what it takes to move?

Changing IT provider is the single biggest reason businesses stay somewhere they have outgrown. We plan the move around your working week, and we help carry the cost of getting across. Ask us how that works when we speak.