CertIQ
Cyber risk for hospitality businesses

High card volume, high staff turnover, and systems nobody owns.

Hospitality processes a lot of card transactions through equipment that is often installed once and never revisited, run by teams that change constantly. Attackers target the combination — the payment volume is the prize and the turnover is the way in.

Takes 45 seconds · No sales call · Australian businesses

What actually goes wrong

Three ways hospitality businesses get hit.

01
Point-of-sale exposure
Payment terminals and back-office systems reachable from the internet, commonly through a remote-support tool the installer left enabled.
02
Shared and inherited logins
One account per venue rather than per person, handed on as staff change, and rarely rotated when they leave.
03
Guest wifi on the same network
Public wifi sharing infrastructure with the systems that process payments and hold booking records.
What we check first

The three that matter most for hospitality businesses.

Your score covers all six checks. These are the ones that most often explain a low score in your industry.

Exposed services
Open ports and remote access visible from the internet.
Certificate health
Expired or weak encryption on your website.
Leaked passwords
Staff addresses appearing in public breach databases.
Where you stand

The obligations that apply to you.

PCI DSS applies to any venue accepting cards. Booking and loyalty records bring Privacy Act obligations above $3m turnover.

General information only, not legal advice. CertIQ scores your operational posture — it does not assess your compliance.

Install day
The last time most venue payment systems were reviewed

See where you actually stand.

Enter your website and CertIQ scores your cyber health out of 100 in about 45 seconds. Free, no account needed.