I've spent ~22 weekends building a cyber risk platform. Around 150 hours, mostly early mornings before the house woke up.

It's called CertIQ. You put in a domain, it runs six independent security checks, and about 20 seconds later you get a score out of 100 and a plain-English list of what to fix first. It's free.

This is the first of a few posts about building it... the decisions, the stack, the mistakes, and the considerably harder problem of getting anyone to use it.

Start with why it exists.

A benchmark you can share

I've worked in insurance for a long time. Some of that has been on the underwriting side, some of it building the software that underwriting runs on.

Here's a conversation that happens thousands of times a year in Australia, and it's nearly always the same.

A broker is renewing a client's cover. Cyber comes up. The broker asks a few sensible questions; do you have multi-factor authentication, do you back things up, has anything happened in the last twelve months. The client answers optimistically, because everyone answers optimistically, and because they genuinely don't know. The answers go onto a proposal form. The form goes to market.

At no point in that exchange does anyone have an objective benchmark.

The broker doesn't know whether the client's email can be spoofed by anyone with a laptop. The client doesn't know whether three of their staff passwords are sitting in a breach database. The underwriter is pricing a risk described entirely by the person who holds it.

Every other class of insurance has something to anchor on. Property has a building. Motor has a vehicle and a claims history. Cyber has a form and a hope.

That's the gap. It's been the gap for years, and the tools that exist to close it are mostly built for large enterprises, take days to return a result, and cost more than the policy they're informing.

What it actually does

CertIQ runs six checks against a domain, from the outside, without touching anything internal:

Whether remote access services are exposed to the public internet. Whether staff email addresses appear in known breach data. Whether the domain has been flagged by security vendors. Whether email authentication is set up in a way that actually prevents spoofing, rather than just appearing to. Whether the TLS certificate is healthy. And a few DNS hygiene items that are boring right up until they aren't.

That's the external half. It's 60% of the score.

The other 40% comes from seven plain-English questions, mapped to the Australian Signals Directorate's Essential Eight. Do you enforce MFA. Do you patch quickly. Are your backups tested and offline. No jargon, no IT knowledge required, and you can skip any of them.

Combine the two and you get a score out of 100 and a grade. Above a threshold, with the self-assessment complete and nothing critical outstanding, you're what I've called CertIQ Ready — which means your posture is good enough that insurers will look at you favourably, and you can request a cyber insurance quote straight from the report if you want one.

To be clear about what it isn't: it's not an Essential Eight maturity assessment, it's not a penetration test, and a good score is not a guarantee that nothing will happen to you. It's a starting point for a conversation that currently starts nowhere.

The honest version of the hours

I want to be precise about the time, because "weekend project" has become a phrase that means almost nothing.

Twenty-two weekends. Six to eight hours each, occasionally less. Call it ~150 hours across about five months. Nearly all of it early Saturday and Sunday mornings, which is the only reliably quiet time I have.

In that 150 hours: a scan engine with six independent checks running in parallel, a scoring model, PDF report generation, a set of guides written against the ASD framework, two landing pages, an admin, and a full insurance quote flow that talks to a completely separate codebase and survives that codebase being unavailable.

Two years ago that's a small team and half a year of their lives.

I'm not telling you this because I worked hard. I didn't, particularly. I worked on weekends, spent time with the family, baked and surfed in between. I'm telling you because the ratio has changed, and I don't think most people have internalised how much.

The tools get some of the credit, and I'll write about those properly. But the more interesting part of the answer is a framework choice I made in about ten seconds and didn't think about again until much later. That's the next post.

The weekend I found out my own product was lying

Two weekends ago I shared CertIQ with who a friend and founder and he ran it over his own domain. One he knows intimately. CertIQ told him the domain had no SPF record.

It does. It's been there for years. He had put it there.

The bug was in the DNS lookup. The resolver returned an empty result when a query times out...which is the same shape as a genuine "there is no record here." The code couldn't tell the difference between "I checked and found nothing" and "I didn't manage to check." So it reported a security failure that didn't exist.

That is the worst possible bug for a product whose entire value proposition is telling people the truth about their exposure.

I spent that Sunday rewriting the resolver to use DNS-over-HTTPS and to only trust definite answers. If a lookup can't be resolved now, the scan fails honestly and asks you to run it again. It doesn't guess, and it doesn't deduct points for something it couldn't verify.

The same weekend turned up a second one. CertIQ was reporting "domain transfer lock is not set" on .au domains. It turns out the .au registry doesn't offer that status at all — .au transfers are protected differently. The check was correct for .com and meaningless for .com.au, and I'd been applying it to both.

I mention both because build-in-public posts have a habit of being a highlight reel, and because the principle that came out of it is the one I'd want you to judge the product on: never report a problem you can't confirm.

What happens next

The plan is 100 Australian businesses through it in six weeks, and I'll publish the real numbers whether or not I get there.

Along the way I'll write about the stack and why Rails turned out to matter far more than I expected, how I use Claude Code, Codex and Antigravity differently, and how you market something in public when you only have weekends to do it in.

If you run a business in Australia and you've never had a straight answer about your cyber exposure, the check is free and takes about 90 seconds. I'd genuinely like to know what it tells you — and if it tells you something wrong, I'd like to know that even more.

Run the free check →


CertIQ is built by me, Ben Webster. If you'd rather talk to a person than read a report, my number is on the site and I answer it.