CISSP-QUALIFIED MICROSOFT 365 AUDITS FOR ACCOUNTING & BOOKKEEPING FIRMS

Your Clients Trust You With Their Numbers. Don't Leave The Inbox On Default.

Tax file numbers, BAS lodgements, client financials — it all moves through Microsoft 365. Default settings weren't built for that level of exposure, especially in the run-up to EOFY. SecureMyEmail runs a specialist audit of your 365 environment, checked against CIS, NIST and Microsoft Secure Score baselines, and hands you a plain-English report on exactly what to fix, in order of priority.

Accountant reviewing a security audit dashboard on a laptop in an accounting office

THE RISK YOU CAN'T SEE

One Compromised Login Could Send A Fake Invoice To Every Client

Accounting firms are a favourite Business Email Compromise target — a compromised login used to send fraudulent invoices to your entire client list, a silent forwarding rule leaking tax file numbers and financial records, or a phishing email timed perfectly for EOFY chaos. Most generalist IT providers manage uptime and support tickets — not dedicated security audits. If nobody has specifically checked your Microsoft 365 against a recognised security baseline, you don't actually know where you stand.

THE PROCESS

Four Steps From Enquiry To Answers

01

Submit your details

A few quick questions, no obligation — tell us your platform, rough user count, and what's prompting you to look into this now.

02

Neil confirms access

Neil Frick will call you within 1 business day to confirm access credentials and scope the right tier for your environment.

03

We run the audit

Using Augmentt, your Microsoft 365 environment is assessed against CIS, NIST and Microsoft Secure Score baselines, with ongoing breach and configuration-drift monitoring flagged as part of the findings.

04

You get the report

A plain-English findings report, prioritised by risk, so you know exactly what to fix first — no jargon, no scare tactics.

IS THIS YOU?

Built For Accounting & Bookkeeping Firms Without An In-House Security Team

  • You're an accounting or bookkeeping practice with 10–50 staff on Microsoft 365
  • You handle tax file numbers, BAS or financial records, or client banking details daily
  • You don't have a dedicated in-house IT security specialist
  • You want a clear, independent check — not another subscription to manage

Not for: Individuals wanting help with a personal Outlook account, or large enterprises with an existing in-house security team.

COMPLIANCE CONTEXT

What Accounting & Bookkeeping Practices Are Expected To Have In Place

Handling tax file numbers and client financial data brings obligations from the OAIC, the Tax Practitioners Board and the ATO — and most of them come back to who can access your mail and files, and how that access is controlled.

Privacy Act 1988 & the Australian Privacy Principles

APP 11 requires you to take reasonable steps to protect personal information from misuse, interference and unauthorised access. Mailbox access controls, MFA, external sharing settings and forwarding rules are all part of those reasonable steps.

Privacy (Tax File Number) Rule 2015

TFN information carries additional handling requirements on top of the APPs: it must be protected against unauthorised access and securely destroyed when no longer required by law.

Notifiable Data Breaches scheme

If personal information is accessed without authorisation and serious harm is likely, you must notify affected individuals and the OAIC. Knowing whether audit logging and alerting are switched on is the difference between detecting a breach and finding out from a customer.

TPB Code of Professional Conduct

Registered tax and BAS agents must take reasonable care to protect client information and, since 2024, disclose matters that could affect a client's decision to engage you — including significant data incidents.

ATO Operational Framework expectations

Practices accessing ATO Online Services are expected to enforce strong authentication, control staff access and log activity. Weak Workspace or 365 identity settings undercut all three.

General information about obligations commonly relevant to Australian businesses in this sector — not legal advice. The audit reports on how your email and collaboration environment is configured against recognised security baselines; it does not certify you as compliant with any of these frameworks, and your own obligations depend on your size, structure and services.

WHO'S BEHIND THE AUDIT

No Client Case Studies Yet — Full Transparency Instead

As a new service, we don't have client testimonials yet — but every audit is run personally by Neil Frick, a CISSP-qualified auditor with over 40 years in Information Technology, using the same tools and baselines trusted by security-focused MSPs across Australia. His background includes work in highly secure environments, with military clearance to Top Secret level. We'd rather tell you that plainly than invent a review that isn't real.

THE PERSON DOING THE WORK

Meet Neil Frick

I've spent over 40 years in Information Technology, including time in highly secure environments with military clearance to Top Secret level. I'm CISSP-qualified, and I founded SecureMyEmail because too many small and mid-sized Australian businesses assume their generalist IT provider is “handling security” — when in reality, nobody has run a dedicated audit against a recognised baseline. Every audit that goes out under this business has been run personally by me, using the same tools and standards trusted by security-focused MSPs. No jargon, no scare tactics — just a clear report on where you stand.

— Neil Frick, Founder, SecureMyEmail

THE DETAILS

Straightforward Pricing, No Ongoing Contract

This is a point-in-time audit, not an ongoing managed security service. Pricing is based on user count. Pay online now to lock in your slot, or answer a few quick questions and Neil will call you before you commit.

Starter

Up to 10 users

$99

Full audit of Google Workspace or Microsoft 365, mapped to CIS, NIST and CISA SCuBA baselines, plus a plain-English findings report.

Growth

Up to 25 users

$199

Same full audit scope as Starter, priced for larger teams.

Enterprise

25+ users

Request a quote

Custom-scoped audit for larger environments.

Email Us For A Quote →

COMMON QUESTIONS

Before You Enquire

It's a point-in-time audit — a deep, specialist check of your environment against recognised security baselines, delivered as a plain-English report. It's not a subscription and there's no ongoing contract.

One audit. One plain-English report. Every gap accounted for.

It takes one enquiry to get started, and one call with Neil to confirm access and scope. No lock-in, no jargon, no guesswork about where your business actually stands.

Run personally by Neil Frick, CISSP-qualified — SecureMyEmail