Questions, answered plainly
Last updated 3 August 2026
The questions schools actually ask before they sign up, including the ones where the answer is no. If yours is not here, ask us — we would rather tell you plainly than have you find out later.
Getting started
Do we need technical knowledge to use it?
None. Everything is written in plain English with a recommended action beside it. If you can read your readiness score you can use Ceidwad. The technical detail is there when your IT team wants it, and never required to get value from the page.
How does it connect to our systems?
Through each provider's own read-only connection. Today that means Microsoft 365, Microsoft Defender, Microsoft Entra ID and Sophos Central. Ceidwad reads your posture, explains what it finds and prepares fixes for you to approve — it does not change your settings on its own. Setup takes under an hour.
Do we need to change our firewall or open any ports?
Not for the Microsoft connectors. They run cloud to cloud, so nothing is installed and no ports open. A connector reading from equipment on your own network may need one address allowed, and we tell you exactly which if it applies to you.
We outsource our IT to a provider. Does that still work?
Yes, and the authority stays with the school. Ask your provider to make the one-time read-only connection, or make it yourself if you hold admin consent. Either way you can see every connection in your own account and remove any of them whenever you like. Responsibility for cyber security sits with the school and its governors, and Ceidwad gives you the oversight to hold a provider to account rather than take their word for it.
What Ceidwad is, and is not
Does it replace our IT team?
No. Ceidwad does the watching, the compliance tracking and the translating, so an IT lead or a leadership team can decide without being security specialists. It sits alongside whoever runs your IT and does not replace them.
Is Ceidwad a SIEM, or a 24/7 security operations centre?
No. We do not ingest your logs, we do not watch your network in real time and we will not ring you at three in the morning. Ceidwad makes sense of where you stand and what to fix next. Live monitoring and response stay with your managed provider or with Microsoft.
Does it replace Defender or our antivirus?
No. Ceidwad does not sit on your devices and does not block anything — that is Defender's job, or Sophos's. Ceidwad reads what they report and tells you whether they are actually configured to protect you, which is a different and frequently unanswered question.
Do you scan or penetration-test our network?
No. Ceidwad does not probe, scan or attack anything. It reads the posture your existing tools already report, and the public DNS and certificate records anyone can read. Nothing is intrusive and nothing needs a testing window.
Is this a safeguarding or KCSIE tool?
No. Safeguarding stays with your DSL and Ceidwad is not part of your KCSIE obligations. Pupils are not users of Ceidwad and are never targeted by a phishing simulation or a drill.
Data, compliance and trust
Where is our data stored?
Core platform data at rest sits in Microsoft Azure UK South, encrypted in transit and at rest, with a separate encryption key for each school. Some third-party services, including AI processing where it is enabled, may involve processing outside the UK under contractual safeguards. We hold the least we need to assess your posture. Our security page and privacy policy set out the detail, and your data protection officer is welcome to review our processing terms.
Can one account cover every school in our trust?
Yes. A trust gets a central view with every academy scored on its own and rolled into one aggregate, so oversight does not mean signing into eleven systems. Pricing is per academy on a single invoice.
Do you help us get Cyber Essentials?
We do not certify anyone, and we will not display a badge we have not earned. What we do is track your readiness against it continuously and prepare the evidence, so certification becomes an afternoon rather than a project.


