Tax season is fraud season. Here's the pack that gets your team ready.
Three things your firm can put to work this week: a verify-before-you-pay SOP for any banking-change request, a card that shows your team how to tell the real CRA from the fake, and a handling checklist for the client data you can't afford to lose - SINs, T-slips, portal logins. No fluff, no fear, no sign-in walls between you and the first useful page. Tuned to how QuickBooks, Xero and CaseWare firms actually work.
- A banking-change SOP your team can pin up and follow the same way, every time
- A CRA-impersonation tells card that ends the "is this real?" guessing in seconds
- A client-data handling checklist for SINs, T-slips and client portals
- Built for QuickBooks, Xero and CaseWare firms - and CASL-aware on the client side
Yours free - no signup wall. Want the editable templates or a hand rolling it out? Just ask.
Tool 1 - The verify-before-you-pay banking-change SOP
Almost every six-figure loss at a firm starts the same way: an email asks to change where money goes, and someone trusts it. This is the short, repeatable routine that defeats nearly all of it. Print it, pin it by the desks that move money, and run every banking-change or payment request through it - no exceptions, no matter who seems to be asking.
Tool 2 - The CRA-impersonation tells card
Spring brings a wave of fake CRA emails, texts and calls - "refund waiting," "account locked," "audit notice," "interac e-transfer of your refund." They're designed to rush a busy person into clicking or paying. Hand this card to everyone who touches client files or the firm's inbox. The Canadian Anti-Fraud Centre and the CRA both publish what the real agency does and doesn't do - this distils it into what your team can check in seconds.
Tool 3 - The client-data handling checklist (SINs, T-slips, portals)
Your firm holds the data criminals want most: SINs, T-slips, bank details, full financial pictures. One compromised inbox can quietly export all of it - a privacy problem on top of any dollars lost. These are the concrete handling habits that keep client data from walking out the door, written for a real firm at full tilt, not a security textbook.
Built to print: pin the banking-change SOP by every desk that moves money, tape the CRA tells card where the team opens email, and keep the client-data checklist with your busy-season onboarding. This is practical readiness, not legal or tax advice.
A checklist is a start. A drill makes it stick.
The Cyber Fire Drill runs these exact attacks against your team - safely - so the habits in this toolkit become muscle memory. Three hours, on-site, with a scored 30-day plan.
Is this really free, and what's the catch?
It's genuinely free and genuinely useful on its own - drop in your email and the whole pack is yours to print and use this week. The honest part: it's a paper tool. It makes your team safer, but a checklist on the wall isn't the same as your team having actually lived through the scam once. That's what the Cyber Fire Drill adds - a live, on-site session where your firm rehearses these exact attacks safely, so the verify-before-you-pay reflex is automatic when it counts. The pack is the warm-up; the drill is the real thing.
We use QuickBooks, Xero and CaseWare - does this fit how we work?
Yes. The SOP and checklist are written around the way accounting and bookkeeping firms actually move money and handle client files - payee approvals, payment runs, client portals, payroll deposits, and the SIN and T-slip handling that comes with tax season. When we run the Cyber Fire Drill for your firm, we tune the scenarios to the tools your team really uses, so the habits attach to your real process, not a generic one.
How does this connect to the Cyber Fire Drill?
The pack hardens your paperwork; the Cyber Fire Drill hardens your people. It's a live, roughly three-hour, on-site workshop for your whole team where a role-played attacker comes at your firm with a fake-invoice banking change, a CRA-impersonation lure, and a fake-partner ask - safely, with no malware, no real payments, and no one singled out. You leave with a scored 30-day plan and a leadership readout you can show an insurer or a client. If the pack made you think "we should practise this," that's exactly what the drill is for.
More resources in the resource library · questions? contact@bastani.org