Common questions

Straight answers about cyber health checks and secure websites.

The questions small and medium businesses ask most often, answered plainly, including the ones where the honest answer is no.

Getting started

What actually happens in a Cyber Health Check?

We agree the scope in writing, then work through the areas you have approved: email and account access, multi-factor sign-in, devices and updates, backups and whether recovery has been tested, your website and its forms, and how customer information is handled. You get a plain-language summary of what is working, what needs attention, and a sensible order to tackle it in. Nothing is tested without your written permission.

How long does it take, and how much of our time does it need?

Most small businesses need one short conversation to agree the scope, then a review that runs in the background, then a walk-through of the findings. Your time is mostly in the first and last of those. The exact length depends on how many systems and people are involved, which is agreed before anything starts.

What does it cost?

Work is quoted per business rather than sold from a price list, because a sole trader with one laptop and a 30-person firm with a web application are not the same job. You get a written quote covering scope, deliverables and exclusions before any work begins, and there is no charge for the initial conversation.

Scope and boundaries

Will you try to hack into our systems?

No. A Cyber Health Check is a review, not an attack. We look at configuration, settings and process, and we only ever look at what you have authorised in writing. Full penetration testing is a separate, specialist engagement and is not part of this service.

Can you certify us for Cyber Essentials?

No. Certification has to come from a licensed certification body, and GSKordeven is not one. What we can do is help you understand where you currently stand against the kind of controls Cyber Essentials asks about, so that if you do go for certification later you are not starting cold. We will never describe you as certified when you are not.

Do you fix the problems you find, or just report them?

Either. Some clients take the action plan to their existing IT provider, some ask us to carry out the improvements, and some do the easy items themselves and hand over the rest. The report is written so it is useful whichever route you choose.

Working together

We already have an IT provider. Does this replace them?

No, and it is not meant to. Day-to-day IT support and an independent look at cyber risk are different jobs, and it is often healthier when they are not the same person. The findings are written so your existing provider can act on them directly.

We are small. Are we really a target?

Most attacks are not aimed at anyone in particular. They look for whatever is easiest to get into: a reused password, a missing second sign-in check, software that stopped being updated, an old administrator account nobody closed. Being small does not keep you off that list, and the UK government's own breach survey finds incidents across every business size.

Do you only work with businesses in Scotland?

GSKordeven is based in Scotland and works with businesses across the United Kingdom. Reviews, websites and applications are all delivered remotely, so location rarely affects the work.

Your information

What happens to the information we share with you?

It is used to do the work you have asked for and nothing else. Enquiries are kept in a restricted area of the website and in the business mailbox, are never published, and are reviewed for deletion once they are no longer needed. The Privacy Policy sets out the detail, including retention periods and your rights.

Should we send you passwords or access details?

No, and please do not send them through the enquiry form. If a piece of work genuinely needs access later, an appropriate method and a clear scope are agreed first. The form deliberately refuses anything that looks like a password, key, token or card number.

Websites and applications

Can you make our website completely secure?

No website or application can ever be guaranteed completely secure, and anyone who promises that is overselling. What can be done is to remove avoidable weaknesses, limit access, protect the information you hold, keep software supported and make sure recovery is possible when something does go wrong.

Still deciding whether a review is worth it?

A Cyber Health Check is the smallest useful step: it tells you what is already fine, what needs attention, and what can safely wait.

Book a Cyber Health Check