Cybersecurity for Small Practices: Safeguarding Client Data in a Cloud Environment


Duration: 1 Hour

Price: R99.00

Video Type: Single

Presenter: Nestene Botha

AI & Technology

AI & Technology
...

Cybersecurity for Small Practices: Safeguarding Client Data in a Cloud Environment

Duration: 1 hour

Price: R99.00


Back
Title / Topic

Cybersecurity for Small Practices: Safeguarding Client Data in a Cloud Environment

Presenters : Nestene Botha


Overview

Small accounting and tax practices hold identity numbers, tax numbers, bank details and trusted client email relationships, which makes them attractive targets for fraud. Most have no full-time IT support. The incidents that cause real harm are rarely sophisticated. They come from reused passwords, convincing phishing emails, former employees who still have access, and payments approved on the strength of a spoofed email. Generative AI now makes those lures harder to spot.

This session sets out the threat model that realistically applies to a small practice. It then covers the controls that give the most risk reduction for the cost. These include multi-factor authentication, password managers, quarterly access reviews, Microsoft 365 tenant settings, device security, mailbox controls, tested backups and staff awareness sessions. Each control is anchored in recognised frameworks, including NIST CSF 2.0, the CIS Controls, the UK NCSC's Cyber Essentials and the IRS "Security Six", and in Information Regulator enforcement action under POPIA section 19(3).

The session then turns to client data in cloud and AI tools. It explains how to assess a vendor's data-handling position from its own documentation, why a promise that data is "not trained on" differs from a promise that it is "not stored", and what sections 20, 21 and 72 of POPIA mean for operators and cross-border transfers. It closes with the section 19(2) control cycle, the low threshold that triggers section 22 notification, the eServices reporting route, and a step-by-step response plan for the first hour after a suspected compromise.

No security budget or technical background is required.


Topics covered

  • The threat model that actually applies: ordinary, preventable incidents, AI-assisted social engineering, the 2026 Verizon DBIR findings and their limits, and why POPIA section 19(3) gives international frameworks legal weight in South Africa
  • Identity is the perimeter: multi-factor authentication on every account, the move to passkeys and away from SMS, password managers, protecting eFiling credentials, quarterly access reviews, tenant settings, Copilot permissions, device controls, mailbox forwarding controls, backups and staff awareness sessions
  • Client data in cloud and AI tools: the three questions to ask of any tool, how to read vendor data-use commitments, training versus retention, section 72 cross-border transfers, AI vendors and IT providers as operators under sections 20 and 21, and where client data typically leaves a practice
  • What POPIA actually requires: accountability under sections 8 and 19(1), the section 19(2) identify–safeguard–verify–update cycle, the five documents that make up a practice's security file, and recent Information Regulator enforcement action
  • When it goes wrong: the "reasonable grounds to believe" trigger under section 22, notification timing and content, the mandatory eServices portal, and the first-hour response sequence: contain, preserve, assess, notify, communicate

Learning outcomes

Practitioners will be able to:

  1. Describe the threat model that realistically applies to a small accounting or tax practice
  2. Identify the identity and access controls that deliver the greatest risk reduction per rand spent
  3. Assess a cloud or AI vendor's data-handling position from the vendor's own documentation
  4. State what POPIA section 19 requires of a practice in operational terms
  5. Recognise when a security compromise triggers the section 22 notification duty
  6. Take the correct first steps in the hour after a suspected compromise

Who should attend

Partners, sole practitioners, practice managers and Information Officers in small accounting, tax and bookkeeping practices who are responsible for protecting client data held in cloud and AI tools.

Related Webinars

AI & Technology
...

Fundamentals of AI for Tax Accountants


1 Hour
R99.00

AI & Technology
...

Integrating Systems for Seamless Workflow and Operations: From Manual to Digital


1 Hour
R99.00

AI & Technology
...

Advanced Application of AI


1 Hour
R99.00

Explore Smarty