CertIQ
Cyber risk for professional services firms

Your clients trust you with what they would not put in writing anywhere else.

Consultancies, agencies and advisory firms hold commercially sensitive material for clients much larger than themselves. That makes a small firm a practical route into a big one — and it is the reason enterprise clients increasingly ask for evidence of your controls before signing.

Takes 45 seconds · No sales call · Australian businesses

What actually goes wrong

Three ways professional services firms get hit.

01
Supply chain route in
You are the soft entry to a client with far better defences. Attackers target the adviser precisely because the adviser has trusted access.
02
Client security questionnaires
Larger clients now require documented controls before contract. Failing that review costs the engagement, not just the renewal.
03
Impersonation in flight
Invoice and scope-change fraud conducted from a spoofed version of your own domain, mid-project.
What we check first

The three that matter most for professional services firms.

Your score covers all six checks. These are the ones that most often explain a low score in your industry.

Email spoofing
Whether someone can send email that looks like you.
Leaked passwords
Staff addresses appearing in public breach databases.
Domain reputation
Whether security vendors have flagged your domain.
Where you stand

The obligations that apply to you.

Privacy Act obligations apply above $3m turnover, but enterprise client contracts routinely impose stricter requirements well below that threshold.

General information only, not legal advice. CertIQ scores your operational posture — it does not assess your compliance.

Before contract
When enterprise clients now ask for your security posture

See where you actually stand.

Enter your website and CertIQ scores your cyber health out of 100 in about 45 seconds. Free, no account needed.