The threats
The attacks accounting firms actually get.
Generic phishing training prepares your team for 2019. The attacks landing in your inbox today are AI-written, voice-cloned, and timed for the worst possible week of the year. Here's what your team is up against.
ATO impersonation
"Your client has an outstanding tax debt, click here to verify before it goes to a debt collector." Tailored for EOFY pressure. The links look exactly like ato.gov.au.
Trust-account wire fraud
A senior partner asks the junior to wire client settlement funds urgently. Voice cloned from a short sample on the firm's "Meet the Team" page. Cloning a voice now costs almost nothing.
EOFY business email compromise
30 June pressure means your team clicks before they verify. Attackers know this. The compromise often happens between 25 June and 5 July.
Client data phishing
Spoofed emails asking your team to share client tax files via a fake "secure portal." One successful click exposes years of client TFNs and BAS lodgements.
Why now
Annual training doesn't work. AI attacks don't wait for the next session.
Most accounting firms run security awareness once a year, usually a generic video and a tick-box quiz. That was fine before AI. Today's attackers personalise every message, clone an executive's voice from a LinkedIn video, and adapt their script in real time. The gap between what your training covers and what actually arrives in your team's inbox has never been wider.
is still a common way a breach begins
can be cloned from a short public clip
is exactly when these attacks are timed to land
How Vigil works for accounting firms
Simulate. Score. Train. Report. On autopilot.
Vigil runs in the background. You log in once a month for the dashboard view. Everything else is automatic.
SIMULATE
Simulate
Pick from six core attack types. ATO scams, voice-call deepfake simulations, fake Xero login pages, EOFY-themed phishing. AI writes every message from the context of your firm, and any cloned voice or likeness is only ever made from a person who has given consent.
SCORE
Score
Every employee gets a live human risk score. See who's vulnerable, which department needs work, and which staff are improving, without spreadsheets.
TRAIN
Train
When someone clicks, training is assigned automatically. Built for the exact scam type they fell for. Quizzes and completion records auto-tracked for compliance.
REPORT
Report
One-click PDF mapped to APES 110, Essential Eight, ISO 27001, and the Australian Privacy Act. A document you can share with your cyber insurer at renewal.
Compliance
Answer your insurer questionnaire and your APES 110 review from the same report.
Most Australian accounting firms now hold cyber insurance. Renewal questionnaires ask about regular security awareness training, attack simulations, and remediation tracking. Vigil's report documents all of it: APES 110 client-confidentiality controls, the human side of your Essential Eight programme, and the Privacy Act's APP 11 staff-training obligation. Regenerate any time, always current.
Built for Australian professional-services firms.
Also for
Other professional services teams using Vigil
See the full list on security awareness training by industry.
Train your team before the criminals do.
14-day free trial. No credit card. APES 110-ready report on day 1.
Start 14-day free trialor email us at hello@vigilsecurity.io
