CertIQ
Cyber risk for retailers

Your storefront is the part of your business an attacker can see for free.

A retail website is public by definition, which means every weakness in it is public too. Card data, customer accounts and the checkout itself are all reachable from the open internet — and so is every abandoned campaign microsite you have ever launched.

Takes 45 seconds · No sales call · Australian businesses

What actually goes wrong

Three ways retailers get hit.

01
Checkout skimming
Injected scripts that read card details at the point of entry, invisible to the customer and often to the merchant for months.
02
Customer account credential stuffing
Passwords exposed in unrelated breaches replayed against your login, at a scale that looks like ordinary traffic.
03
Forgotten campaign sites
Seasonal and promotional subdomains left running years after the campaign, unpatched and still trusted by your customers.
What we check first

The three that matter most for retailers.

Your score covers all six checks. These are the ones that most often explain a low score in your industry.

Certificate health
Expired or weak encryption on your website.
Forgotten systems
Subdomains and old hosts still attached to your domain.
Domain reputation
Whether security vendors have flagged your domain.
Where you stand

The obligations that apply to you.

PCI DSS applies to any business handling card data. The Privacy Act's notifiable breach scheme applies above $3m turnover, and to any business trading in personal information at any size.

General information only, not legal advice. CertIQ scores your operational posture — it does not assess your compliance.

Public
How much of your attack surface a customer can already see

See where you actually stand.

Enter your website and CertIQ scores your cyber health out of 100 in about 45 seconds. Free, no account needed.