Professional services
A continuity plan for a Queensland professional services firm needs to protect client data, keep statutory deadlines moving, and cover for the loss of a key partner or system, because the product these firms sell is trust and availability, not stock. A firm that cannot access client files or answer the phone for two days loses more than time.

31 Oct / 15 May
Key ATO lodgement dates that do not move even if a firm has a bad week
1-2 people
Number of staff who typically hold sole knowledge of a client relationship in a small firm
30 days
Typical OAIC expectation for assessing a suspected data breach
The state of play
Queensland's accounting, legal and advisory sector is dominated by small and mid-sized firms, many of them partner-led practices with a handful of staff carrying deep client relationships and specialist knowledge. That structure is efficient day to day but creates a sharp continuity risk, because the loss of a single partner or senior associate, whether through illness, resignation or simply being uncontactable during a disaster, can stall active matters and statutory deadlines that clients are relying on the firm to meet.
What actually stops you trading
An attack locking practice management or document systems, or a compromised email account used to redirect client trust payments, is the most common and most damaging disruption in this sector. Firms without offline backups and a tested incident response plan face both operational and reputational damage.
A partner or senior associate being unavailable through illness, sudden resignation or being uncontactable during an emergency can stall active client matters with statutory deadlines attached. A named backup and up-to-date matter handover notes prevent this from becoming a client-facing failure.
Flood, fire or storm damage to an office, or being unable to access the CBD due to an evacuation or road closure, forces a firm to work remotely with little notice. Firms without a tested remote access setup for core systems lose days reconstructing basic capability.
A breach affecting trust accounting or client financial data carries regulatory reporting obligations beyond the standard Notifiable Data Breach scheme, and can trigger a formal review by the relevant professional body.
Tax lodgement, court filing and other statutory deadlines do not extend automatically because a firm is dealing with an outage. A plan needs a fallback process for meeting or formally extending critical deadlines during a disruption.
A breach that is not identified or assessed quickly enough can exceed the timeframe in which the OAIC expects notification, compounding the original incident with a compliance failure.
Who is asking for a plan
Clients, insurers, regulators and prime contractors increasingly want evidence, not assurances.
Firms holding client financial or legal information must assess and, where required, notify the OAIC and affected individuals of a data breach likely to cause serious harm, within the timeframe the scheme expects.
Legal and accounting bodies impose additional reporting and record-keeping obligations where trust money or regulated client funds are involved, which continuity planning needs to account for separately from general data breach rules.
PI insurers increasingly require evidence of cyber security controls, backup systems and a documented incident response plan as a condition of cover or favourable premium at renewal.
Larger corporate clients are increasingly writing continuity and data security expectations into engagement letters and panel appointment terms, particularly for firms handling sensitive financial or legal matters.
Why planning is worth the afternoon
For a professional services firm, the product is availability and trust, so a disruption that stops the firm answering the phone or accessing files for two days damages the client relationship in a way that is hard to repair with an invoice credit.
Clients in this sector switch firms quietly rather than complaining, and the first sign of lost business is often a slow decline in referrals rather than a single dramatic loss.
A missed statutory deadline carries direct financial and professional consequences, from ATO penalties passed on to a client to a struck-out court matter, and either outcome creates a professional negligence exposure for the firm on top of the client relationship damage.
Cyber incidents in this sector are expensive in a specific way: beyond the ransom or recovery cost, a breach of client trust or financial data can trigger regulatory reporting, professional body scrutiny and, in serious cases, a review of the firm's authority to hold trust money, which is existential for a small practice.
The fix is proportionate to the risk.
A written plan covering matter handover, offline backups, remote access and a data breach response process costs a fraction of one lost corporate client relationship, and most firms already have the technical pieces in place, they simply have not written down who does what and when.
A realistic morning
A 12-person accounting firm in Brisbane's CBD discovered that a client's email had been compromised and used to send a fraudulent request to redirect a payment into the firm's trust account.
Bookkeeper notices the redirection request has slightly unusual banking details and flags it before processing.
Practice manager activates the incident plan, freezes the pending payment and calls the client directly on a known number, not the email.
Client confirms their email was compromised; firm reports the incident via ReportCyber and notifies its cyber insurer.
IT provider resets all email credentials firm-wide as a precaution and reviews recent trust account activity for other anomalies.
Firm sends a short client notice about the incident and confirms no funds were lost, based on the documented process for exactly this scenario.
Because the plan specifically required phone verification for any payment redirection, no money was lost and the incident was contained within a day. A firm without that step in writing would have relied on the bookkeeper's individual judgement alone, which is a far less reliable control.
What good looks like
How we fix it
The ResilientQLD app has two modules. The Risk Register works out what could stop you trading. The Disruption Playbooks tell whoever is on shift exactly what to do when it happens. Enter your business once, use it on a phone or a laptop, and export a printed copy for the wall.
The Risk Register module helps a firm log key person dependency by client relationship, trust account exposure and data breach risk in a structured way that suits a professional services practice rather than a generic template.
Specific playbooks for business email compromise, ransomware and office loss give staff a step-by-step response, including the phone verification step that stops most trust account fraud.
Mobile and desktop access means a partner travelling for a hearing or a bookkeeper working from home can follow the same playbook as someone in the office.
The plan exports as a PDF suitable for a professional indemnity insurer renewal or a corporate client's panel due diligence request, without needing to draft a document from scratch each time.
Questions we get asked
There is no single law mandating it for every firm, but professional indemnity insurer conditions, trust account obligations and the Notifiable Data Breach scheme all push firms toward holding a documented plan, and most firms that suffer a serious incident wish they had one in place beforehand.
The firm may face penalties passed on to the client and potential professional negligence exposure, so a continuity plan needs a specific fallback process for meeting or formally seeking extensions on deadlines during an outage.
Assess the likely harm quickly, contain the breach with IT support, and notify the OAIC and affected individuals within the scheme's expected timeframe if serious harm is likely, while also checking any additional professional body reporting obligations.
Concentration of client knowledge in one or two people is usually the biggest risk, closely followed by cyber attacks targeting email and trust accounts, both of which are addressed by naming backups and requiring phone verification for payment changes.
Standard PI cover often does not fully cover cyber incidents, which is why many firms hold separate cyber insurance, and insurers for both increasingly expect a documented incident response plan as a condition of cover.
Most operators finish the first version in an afternoon. Start in the app, or have a 20 minute conversation with us first.