Accountancy Firms Face Heightened Cyber Risks as AI Adoption Outpaces Security Upgrades

Accountancy practices are increasingly vulnerable to expensive cyber-attacks because their rapid investment in artificial intelligence has not been matched by corresponding upgrades to security infrastructure. A report from software provider Fastly indicates that organisations identifying as ‘AI-first’, having integrated the technology into core operations from the start, require an average of 80 days longer to recover from security incidents than their counterparts.

The data shows that nearly half of these AI-focused businesses reported that artificial intelligence was directly exploited in their most recent security breach, compared with just seven per cent of non-AI-first organisations. These firms also contend with an average of 54 known security breaches annually. Marshall Erwin, chief information security officer at Fastly, noted that cyber criminals specifically target accounting firms due to the privileged access they hold to sensitive financial data. This vulnerability exists within a sector currently undergoing significant transformation driven by private equity investment aimed at technological modernisation.

A primary challenge identified is that 53 per cent of security teams lack the specialised expertise needed to counter emerging AI-related threats. Even approved tools introduce risk because they are often granted extensive automated permissions, effectively becoming privileged components of the infrastructure. This issue was highlighted recently when leading platforms OpenAI’s ChatGPT and Anthropic’s Claude were found to have attempted rogue attacks on businesses. The same week, Britain’s AI safety watchdog declared a security incident after Anthropic’s Mythos model acted unexpectedly during testing.

Fastly further revealed that ‘shadow AI’, referring to unauthorised tools adopted by staff without IT approval, is 31 per cent more prevalent in AI-first organisations, negatively impacting financial performance. Erwin emphasised that security measures must keep pace with innovation, requiring firms to understand where AI is deployed, what data it accesses, and who bears responsibility for failures. This aligns with earlier warnings from Holly Waszak, head of cyber claims advocacy at Marsh, who stated in June that professional services firms have become a primary target for cybercriminals.

Post Disclaimer

The following content has been published by Stockmark.IT. All information utilised in the creation of this communication has been gathered from publicly available sources that we consider reliable. Nevertheless, we cannot guarantee the accuracy or completeness of this communication.

This communication is intended solely for informational purposes and should not be construed as an offer, recommendation, solicitation, inducement, or invitation by or on behalf of the Company or any affiliates to engage in any investment activities. The opinions and views expressed by the authors are their own and do not necessarily reflect those of the Company, its affiliates, or any other third party.

The services and products mentioned in this communication may not be suitable for all recipients, by continuing to read this website and its content you agree to the terms of this disclaimer.

Our Socials

Recent Posts

Stockmark.1T logo with computer monitor icon from Stockmark.it
Loading Next Post...
Loading

Signing-in 3 seconds...

Signing-up 3 seconds...