Call Book the Fire Drill
For accounting & bookkeeping firms · Toronto & GTA

One changed bank detail at tax time, and a client’s refund lands in a thief’s account.

Your team runs the tax-season scams safely, until verify-before-you-pay is automatic when it counts. Because you move other people’s money and hold their most sensitive data - SINs, T-slips, bank details - and the attacks peak at exactly the moment everyone is too busy to look twice.

  • Run a safe invoice-fraud and CRA-impersonation scenario with your team
  • Build the “verify before you pay or send” habit that stops the loss
  • Leave with a payment-change SOP and a scored 30-day action plan

A 20-minute scoping call, then one flat quote. No jargon, no pressure.

An accounting professional
Built for accounting firms like yours
What your firm walks away with

Live and on-site for your whole team - then a plan you can act on the next morning.

  • A payment / banking-change verification SOP
  • A tax-season phishing routine for the whole team
  • A client-data handling checklist (SINs, T-slips, portals)
  • A scored 30-day plan, prioritized by real risk
Book the Fire Drill

20-minute call · no obligation · flat quote after.

The Cyber Fire Drill
live · on-site · GTA
Insured & authorized in writing - certified senior partners for deep technical work Safe & authorized - no malware, no shaming Built around invoice fraud, CRA scams and client-data theft - the tax-season trifecta Toronto & the GTA
The attack that targets you

The banking-change at tax time

Accounting firms sit on money movement and a goldmine of personal data, and busy season is when guard is lowest. Here is how the most common loss happens.

  1. 1
    The way in

    An attacker compromises a mailbox - yours or a client’s - usually with a reused password or a fake login page during the tax-season rush.

  2. 2
    The setup

    They watch the back-and-forth about invoices, payroll runs and refunds, learning who pays whom and how requests normally sound.

  3. 3
    The ask

    A clean email arrives: “please update our banking details for this payment,” or “the CRA refund needs to go to this account.” It fits the conversation perfectly.

  4. 4
    The loss

    The payment goes out before anyone calls to confirm. With client data, the same access can quietly export SINs and T-slips - a privacy nightmare on top of the dollars.

These attacks don’t break your software - they borrow your trust. A single out-of-band phone call to verify a change defeats almost all of them, and that is the reflex we build.

Rehearse it before it’s real
In the room

What your team will face in the room

We run the attacks that actually hit accounting and bookkeeping firms - authorized, safe, and tuned to your busy season. No malware, no real payments, no shaming anyone.

Invoice & banking-change fraud

The signature scenario: a request to change where a payment goes, timed to a real run. The Fake Invoice War Room teaches verify-before-you-pay until it’s automatic.

CRA & refund impersonation

The “refund waiting” / “account locked” / “audit notice” lures that spike every spring. Your team learns to tell the real CRA from the fake in seconds.

Client-data theft

How one compromised inbox can leak SINs, T-slips and statements - and the simple handling rules that keep client data from walking out the door.

The fake-partner ask

A text or email “from the partner”: an urgent wire, a gift-card errand, a quiet favour during crunch. The Boss-Voice Scam, shut down with one rule.

What you walk away with

Not a slide deck. A plan, and new habits.

Every Fire Drill ends with something you can use the next morning - written down, scored, and built for how your team actually works.

A payment / banking-change verification SOP your firm adopts immediately
A client-data handling checklist for SINs, T-slips and portal logins
A plain-English leadership readout: where you stand and what to fix first
A scored 30-day action plan, and a follow-up office hour to keep it moving
Simple pricing
Fire Drill 90 (live team training) from $1,800 +HST

The Cyber Fire Drill, tailored to accounting and bookkeeping firms. One flat fee, on-site, scheduled around your busy season. See the full offer ladder - from the $750 baseline checkup to the Cyber Readiness Day - on the pricing page.

Book the Fire Drill See all pricing
Questions

The things teams in your sector ask first.

Will you phish our staff during busy season?

We schedule around you - many firms book us just before tax season so the habits are fresh when volume peaks. Everything is authorized and safe: no malware, no real payments, no stealing passwords, no shaming.

We use QuickBooks / Xero / CaseWare - is this relevant?

Very. We tune the scenarios to the tools and workflows your team uses, so the verification habits attach to your real process - approvals, payment runs, client portals and all.

Does this help protect client trust and our data obligations?

Yes. You leave with a client-data handling checklist and a clearer view of your risks. For formal privacy policies, retention rules and cyber-insurance prep, our insurance-readiness service picks up where the training leaves off.

How long is it, and who should attend?

About three hours for your whole team - anyone who touches payments, payroll or client data. We work around your calendar, including evenings during crunch.

When you need proof on paper
Firms that need client-data protection on paper

We build the data-handling policies and the insurer- and client-questionnaire evidence firms your size get asked for - practical readiness in plain English, with vetted specialist partners on tap for formal advisory work.

See insurance readiness

Rehearse the attack before it’s real.

Book a 20-minute scoping call. We’ll tailor the drill to your accounting & bookkeeping, send one flat quote, and get a date on the calendar.

Book the Fire Drill (647) 835-6368

Not ready to book? Grab the free Tax-Season Fraud-Defense Pack

contact@bastani.org · WhatsApp