Protecting Client Information in an Audit & Accounting Practice `

In-house course

4.5 Hours
Attendance at this seminar will secure 4.5 hour/s verifiable CPD points including other professional bodies (SAICA, SAIBA, SAIT, SAIPA , ACCA, IACSA & IRBA).
COVANNI HOHLS - DU PREEZ   covanni@probetatraining.co.za

Information security is no longer solely an IT responsibility—it is a professional and ethical obligation for every member of an accounting and audit practice. With increasing cyber threats, stricter privacy legislation and the widespread use of cloud technology and artificial intelligence (AI), staff play a critical role in protecting confidential client and employee information.

This practical half-day workshop provides accounting and audit professionals with the knowledge and practical skills required to identify information security risks, comply with the Protection of Personal Information Act (POPIA), and implement secure day-to-day working practices. The session focuses on real-world scenarios encountered in professional practices, helping delegates recognise risks, respond appropriately and contribute to a strong security culture within the firm.


Module 1: Information Security in the Accounting Profession

  • Why information security matters
  • Current cybercrime trends affecting accounting firms
  • Understanding confidential, personal and special personal information
  • The cost of a data breach
  • Professional and ethical responsibilities for protecting information

Module 2: POPIA Practical Compliance

  • Overview of POPIA
  • Processing personal information lawfully
  • Responsibilities of employees
  • Role and responsibilities of the Information Officer
  • Everyday POPIA mistakes made by accounting firms
  • Practical examples of compliant and non-compliant behaviour

Module 3: Protecting Client Information

  • Identifying confidential information
  • Secure handling of client documentation
  • Clean desk and clear screen practices
  • Secure printing and disposal of documents
  • Safe storage of electronic records
  • Protecting information when travelling or working offsite

Module 4: Password Security & Multi-Factor Authentication

  • Characteristics of strong passwords
  • Password managers
  • Common password mistakes
  • Multi-factor authentication (MFA)
  • Protecting firm and client accounts
  • Demonstration of password attacks

Module 5: Email Security, Phishing & Cybercrime

  • Recognising phishing emails
  • Business Email Compromise (BEC)
  • CEO fraud
  • Invoice fraud
  • Social engineering
  • Safe handling of email attachments and links
  • Practical phishing examples

Module 6: Secure Document Sharing & Remote Working

  • Secure file sharing
  • Encryption basics
  • Risks of WhatsApp and personal email
  • Microsoft 365 and cloud security considerations
  • Working securely from home
  • Public Wi-Fi risks
  • Physical security while travelling

Module 7: Artificial Intelligence & Information Security

  • Risks associated with AI tools
  • Preventing confidential information from being uploaded to AI platforms
  • Safe use of Microsoft Copilot, ChatGPT and similar tools
  • AI governance within professional firms
  • Practical AI dos and don'ts

Module 8: Data Breaches & Incident Response

  • What constitutes a data breach?
  • Recognising early warning signs
  • Immediate actions staff should take
  • Internal reporting procedures
  • POPIA breach notification requirements
  • Lessons learnt from recent cyber incidents

Module 9: Backups, Disaster Recovery & Business Continuity

  • Why backups matter
  • Cloud versus local backups
  • Ransomware recovery
  • Business continuity planning
  • Staff responsibilities during a disruption

Module 10: Creating a Security Culture

  • Internal information security policies
  • Acceptable use of technology
  • Bring Your Own Device (BYOD)
  • Reporting suspicious activity
  • Practical daily security checklist
  • Everyone's role in protecting client trust

Various Practical Activities Included to bring concepts home.