Bastani Security
Book the Fire Drill
Free resource · For accounting & bookkeeping firms · Toronto & GTA

Tax season is fraud season. Here's the pack that gets your team ready.

Three things your firm can put to work this week: a verify-before-you-pay SOP for any banking-change request, a card that shows your team how to tell the real CRA from the fake, and a handling checklist for the client data you can't afford to lose - SINs, T-slips, portal logins. No fluff, no fear, no sign-in walls between you and the first useful page. Tuned to how QuickBooks, Xero and CaseWare firms actually work.

  • A banking-change SOP your team can pin up and follow the same way, every time
  • A CRA-impersonation tells card that ends the "is this real?" guessing in seconds
  • A client-data handling checklist for SINs, T-slips and client portals
  • Built for QuickBooks, Xero and CaseWare firms - and CASL-aware on the client side
Email me the editable pack

Yours free - no signup wall. Want the editable templates or a hand rolling it out? Just ask.

01

Tool 1 - The verify-before-you-pay banking-change SOP

Almost every six-figure loss at a firm starts the same way: an email asks to change where money goes, and someone trusts it. This is the short, repeatable routine that defeats nearly all of it. Print it, pin it by the desks that move money, and run every banking-change or payment request through it - no exceptions, no matter who seems to be asking.

Treat ANY change to bank details, a payee, a payroll deposit, or a CRA refund destination as unverified until you confirm it out-of-band - the request itself is never the proof.
Verify by calling a phone number you already have on file (a prior invoice, your engagement letter, your contact record) - never the number, link, or reply address in the new message.
If it's a vendor or client banking change, say the new account details back to them out loud and have them confirm - attackers count on you reading the change off their email without re-reading it together.
Apply the same rule to requests that appear to come from a partner or the owner: a text or email saying "just push this through, I'm in a meeting" gets the same callback, every time. Urgency is the tell, not the exception.
In QuickBooks, Xero, or your payment platform, require a second person to approve any added or edited payee or supplier bank detail before the first payment runs to it.
Build in a deliberate pause: no banking change takes effect same-minute. A five-minute "confirm and call back" step costs nothing and stops the loss.
Write down who verified, how, and when - a one-line note in the file. It protects the firm and makes the habit visible.
Decide your rule in advance for after-hours and busy-season requests, when guard is lowest: the SOP doesn't relax in March, it matters most in March.
02

Tool 2 - The CRA-impersonation tells card

Spring brings a wave of fake CRA emails, texts and calls - "refund waiting," "account locked," "audit notice," "interac e-transfer of your refund." They're designed to rush a busy person into clicking or paying. Hand this card to everyone who touches client files or the firm's inbox. The Canadian Anti-Fraud Centre and the CRA both publish what the real agency does and doesn't do - this distils it into what your team can check in seconds.

The CRA does NOT demand payment by e-transfer, cryptocurrency, prepaid cards, or gift cards - that request alone is proof it's a scam, full stop.
The CRA does NOT text or email you a link to "log in and claim your refund" or "verify your account." Real refunds and notices appear inside My Account / My Business Account when you go there yourself - type the address, never follow the link.
The CRA does NOT threaten immediate arrest, deportation, or police at your door over a balance owing. Threats and countdowns are the scammer's signature, not the agency's.
Check the sender address, not just the display name: real CRA email comes from canada.ca domains. "cra-refund-secure.com" or a look-alike with extra words is fake - and a convincing display name proves nothing.
Hover before you click: if the visible link text and the real destination URL don't match, don't click. On mobile, press and hold to preview the link.
Be most careful in late February through April, when these spike alongside your workload - and remember the CRA's secure-portal messages are the channel to trust, not an unexpected inbox link.
When in doubt, stop and verify through the CRA's published business enquiries line or the Canadian Anti-Fraud Centre - not any number printed in the suspicious message.
Report it, don't just delete it: forwarding suspected CRA scams to the Canadian Anti-Fraud Centre helps everyone, and telling the team "I just got one of these" turns one catch into a firm-wide heads-up.
03

Tool 3 - The client-data handling checklist (SINs, T-slips, portals)

Your firm holds the data criminals want most: SINs, T-slips, bank details, full financial pictures. One compromised inbox can quietly export all of it - a privacy problem on top of any dollars lost. These are the concrete handling habits that keep client data from walking out the door, written for a real firm at full tilt, not a security textbook.

Move client documents through a secure client portal - not email attachments. A SIN or T-slip sitting in an inbox is one password reset away from a stranger; a portal keeps it behind a login you control.
Turn on multi-factor authentication for email, your portal, QuickBooks/Xero/CaseWare, and your payroll tools - it's the single biggest blocker to the "compromised mailbox" attack that starts most of these losses.
Never send a SIN, full account number, or password in the body of an email or a text. If a client emails you theirs, reply asking them to use the portal - and don't repeat it back in your reply.
Give each staff member their own login to every system - no shared accounts and no shared passwords - so access can be removed the day someone leaves and every action ties to a person.
Keep client data only as long as you need it: know where SINs and T-slips live, and have a routine to archive or securely delete files past their retention need. Less data sitting around is less data to lose.
Lock the client portal down: review who has access at least each season, remove old client and staff accounts, and confirm a former bookkeeper or seasonal hire can't still log in.
On the CASL side, when you email clients to gather documents or send reminders, keep your consent and unsubscribe basics in order - your client communications shouldn't look or behave like the scams you're warning them about.
Decide, before busy season, what happens in the first hour if a mailbox or portal is compromised: who you call, how you reset access, and which clients you notify - a plan beats improvising at the worst moment.
How to use this

Built to print: pin the banking-change SOP by every desk that moves money, tape the CRA tells card where the team opens email, and keep the client-data checklist with your busy-season onboarding. This is practical readiness, not legal or tax advice.

A checklist is a start. A drill makes it stick.

The Cyber Fire Drill runs these exact attacks against your team - safely - so the habits in this toolkit become muscle memory. Three hours, on-site, with a scored 30-day plan.

Book the Fire Drill See the accounting & bookkeeping page →
Is this really free, and what's the catch?

It's genuinely free and genuinely useful on its own - drop in your email and the whole pack is yours to print and use this week. The honest part: it's a paper tool. It makes your team safer, but a checklist on the wall isn't the same as your team having actually lived through the scam once. That's what the Cyber Fire Drill adds - a live, on-site session where your firm rehearses these exact attacks safely, so the verify-before-you-pay reflex is automatic when it counts. The pack is the warm-up; the drill is the real thing.

We use QuickBooks, Xero and CaseWare - does this fit how we work?

Yes. The SOP and checklist are written around the way accounting and bookkeeping firms actually move money and handle client files - payee approvals, payment runs, client portals, payroll deposits, and the SIN and T-slip handling that comes with tax season. When we run the Cyber Fire Drill for your firm, we tune the scenarios to the tools your team really uses, so the habits attach to your real process, not a generic one.

How does this connect to the Cyber Fire Drill?

The pack hardens your paperwork; the Cyber Fire Drill hardens your people. It's a live, roughly three-hour, on-site workshop for your whole team where a role-played attacker comes at your firm with a fake-invoice banking change, a CRA-impersonation lure, and a fake-partner ask - safely, with no malware, no real payments, and no one singled out. You leave with a scored 30-day plan and a leadership readout you can show an insurer or a client. If the pack made you think "we should practise this," that's exactly what the drill is for.

More resources in the resource library · questions? contact@bastani.org