CertIQ
Cyber risk for not-for-profits

Donor trust takes years to build and one notification email to lose.

Not-for-profits hold donor financial details and often deeply sensitive information about the people they serve, with less security resource than any comparable business. The damage from a breach lands hardest on the thing the organisation runs on, which is trust.

Takes 45 seconds · No sales call · Australian businesses

What actually goes wrong

Three ways not-for-profits get hit.

01
Donor payment data
Recurring giving arrangements and stored payment details, frequently across several fundraising platforms adopted at different times.
02
Vulnerable client information
Case notes about people for whom disclosure is not an inconvenience but a genuine safety risk.
03
Volunteer account sprawl
Accounts created for volunteers and campaign staff, rarely removed when they move on.
What we check first

The three that matter most for not-for-profits.

Your score covers all six checks. These are the ones that most often explain a low score in your industry.

Leaked passwords
Staff addresses appearing in public breach databases.
Email spoofing
Whether someone can send email that looks like you.
Certificate health
Expired or weak encryption on your website.
Where you stand

The obligations that apply to you.

Privacy Act obligations apply above $3m turnover and to any organisation providing health services at any size. ACNC governance standards expect responsible handling of donor and beneficiary information.

General information only, not legal advice. CertIQ scores your operational posture — it does not assess your compliance.

One email
What a notifiable breach costs in donor trust

See where you actually stand.

Enter your website and CertIQ scores your cyber health out of 100 in about 45 seconds. Free, no account needed.