CertIQ
Cyber risk for schools and education providers

You hold children's data, and you hold it for decades.

Education providers keep sensitive records about minors long after they leave, on budgets that rarely stretch to dedicated security staff. Attackers know both facts, and the reputational consequences of a breach involving students are unlike any other sector.

Takes 45 seconds · No sales call · Australian businesses

What actually goes wrong

Three ways schools and education providers get hit.

01
Minors' records, held long term
Enrolment, welfare and medical information about children, retained for years and subject to the strictest expectations of any data you hold.
02
Open by design
Campus networks, learning platforms and parent portals built for easy access, which is the same property an attacker relies on.
03
Sprawl without oversight
Departments and year levels adopting their own tools, each one a subdomain and a login nobody centrally reviews.
What we check first

The three that matter most for schools and education providers.

Your score covers all six checks. These are the ones that most often explain a low score in your industry.

Forgotten systems
Subdomains and old hosts still attached to your domain.
Leaked passwords
Staff addresses appearing in public breach databases.
Certificate health
Expired or weak encryption on your website.
Where you stand

The obligations that apply to you.

Privacy Act obligations apply to most providers, and state education departments impose their own standards. Breaches involving minors attract regulatory attention regardless of the provider's size.

General information only, not legal advice. CertIQ scores your operational posture — it does not assess your compliance.

Decades
How long student records are retained

See where you actually stand.

Enter your website and CertIQ scores your cyber health out of 100 in about 45 seconds. Free, no account needed.