Skip to content

Bookkeeping · Tools & Practice · Brief · Working level

Backup and data security for bookkeeping practices

A bookkeeper holds the keys to clients' financial lives: bank access, payroll data, tax IDs. The obligations are backups that actually restore, access granted narrowly and revoked promptly, and a standing defense against the phishing aimed specifically at bookkeepers.

By The Carryforward Desk3 min read · May 27, 2026

A bookkeeping practice is a concentration of exactly what attackers want: bank credentials, payroll data, Social Security numbers, and standing authority to request payments. Security for a small practice is not an IT project; it is four habits — real backups, narrow access, immediate offboarding, and phishing skepticism — applied without exception.

Backups that actually restore

A backup you have never restored is a hope. The baseline:

  1. Export or back up each active client's ledger weekly; archive the document store (organized per document management) on the same cycle.
  2. Keep at least one copy independent of the primary system — a different service or offline media — so one compromised account cannot destroy both.
  3. Test a restore monthly: open the export, confirm it contains the trial balance you expect.
  4. Cloud ledgers count as one copy, not a strategy. Locked accounts, lapsed subscriptions, and vendor incidents all happen; your periodic export is the client's insurance, and retention obligations under Publication 583 remain yours to meet regardless of any vendor.

Access control

Grant narrowly, log everything:

  • Unique logins for every person on every system — never shared credentials, which erase the audit trail your internal controls depend on.
  • Least privilege: view-only bank access for reconciliation; payment rights only where the engagement genuinely requires them, and then with thresholds.
  • Multi-factor authentication on everything that offers it, starting with email — email is the master key that resets all other passwords.
  • A password manager, so "unique and strong" is achievable rather than aspirational.
  • A written access register per client: system, who has access, at what level. You will need it at offboarding, and it belongs in the engagement letter conversation at the start.

The offboarding checklist

Departures — an employee leaving, a client ending an engagement, a subcontractor rolling off — are the moment access rot starts. Same day, from the access register:

StepWhat you doWhat proves it's done
1Remove ledger-software userUser list no longer shows them
2Revoke bank and payroll portal accessBank user roster confirmed
3Remove document-store sharingShare list reviewed
4Rotate any credential they ever knewPassword-manager entries updated
5Recover or wipe practice data on their devicesWritten confirmation
6Update the access registerRegister dated and signed off

Phishing aimed at bookkeepers

Attackers target bookkeepers because you can move money and you answer email fast. The recurring patterns:

  • The urgent transfer: "It's [owner] — traveling, need a wire out today, will explain later." Spoofed or compromised mailbox, manufactured urgency.
  • The vendor bank change: a known vendor "updates" remittance details. The next real payment goes to the attacker.
  • The payroll redirect: an "employee" asks to change their direct deposit before payday.
  • The credential harvest: a fake login page for your ledger or bank, delivered as an "action required" notice.

One procedure defeats all four: any request to move money or change payment details gets verified by voice, at a number you already had. Not the number in the email; not a reply to the email. Write the procedure into the engagement letter so clients expect the callback rather than resenting the delay — and so a client who pressures you to skip it is exhibiting a red flag, not a preference.

If you handle federal tax information or payroll deposits, note the deposit systems themselves — like EFTPS — will never ask for credentials by email. Anything that does is not them.

Frequently asked questions

What should a bookkeeper back up, and how often?
Everything that cannot be regenerated: ledger-file exports or backups, the document store (statements, receipts, payroll records), and working papers. Cloud ledgers still need periodic exports — your subscription can lapse, accounts can be locked, and vendors can lose data. Weekly exports for active clients and a monthly restore test is a defensible baseline.
What is the most common scam targeting bookkeepers?
Payment-redirection phishing: an email that appears to come from the client or a known vendor asking to change bank details or urgently wire funds. The addresses are spoofed or the real mailbox is compromised, and the timing exploits your authority to move or request money. The defense is procedural — verify every payment-detail change by calling a known number, never one in the email.

Keep reading