CertIQ
Cyber risk for accounting practices

You hold every client's TFN, bank details and payroll in one system.

An accounting practice is a concentrated store of exactly the identity data that makes fraud possible at scale. One compromised practice can expose hundreds of businesses downstream, which is why insurers treat aggregation risk here as seriously as the firm's own controls.

Takes 45 seconds · No sales call · Australian businesses

What actually goes wrong

Three ways accounting practices get hit.

01
Client data aggregation
Tax file numbers, bank accounts and payroll records for every client in one ledger. A single breach is a notifiable event for the practice and for everyone it serves.
02
BAS and refund fraud
Compromised practice credentials are used to redirect refunds and lodge fraudulent activity statements, often undetected until the client queries a payment.
03
Portal credential reuse
Staff logins to ATO and superannuation portals reused elsewhere and exposed in unrelated breaches.
What we check first

The three that matter most for accounting practices.

Your score covers all six checks. These are the ones that most often explain a low score in your industry.

Leaked passwords
Staff addresses appearing in public breach databases.
Email spoofing
Whether someone can send email that looks like you.
Certificate health
Expired or weak encryption on your website.
Where you stand

The obligations that apply to you.

TPB obligations on client confidentiality, plus the Privacy Act. Practices handling TFNs are held to the Tax File Number Rule regardless of turnover.

General information only, not legal advice. CertIQ scores your operational posture — it does not assess your compliance.

3x
Downstream businesses exposed per compromised practice

See where you actually stand.

Enter your website and CertIQ scores your cyber health out of 100 in about 45 seconds. Free, no account needed.