Data Protection for Containers
Wavenet's Managed Veeam Microsoft 365 (Office 365) encrypted data backup service, backs up your critical Office 365 data from Exchange, SharePoint, OneDrive for Business and Microsoft Teams on a schedule and retention you define. Protect your data with built-in encryption at rest and in transit, with eDiscovery and granular recovery.
Features
- Safeguard Your Critical Data with comprehensive data protection
- Protect Office 365 data from accidental deletion and security threats.
- Recover Your Data When You Need It
- Quickly restore with industry-leading recovery and flexibility.
- Meet compliance requirements with fast search-and-find capabilities.
- Cloud-native integration
- Seamless Microsoft 365 Integration
- Provides advanced search capabilities and legal hold functionality
- Allows organisations to meet their compliance and Discovery requirements
Benefits
- Backup to on-premises, cloud, or hybrid storage options.
- Protect Office 365 data from accidental deletion and security threats.
- Quick Item-Level Restores
- Maintain Compliance
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 7 8 8 0 4 1 3 2 7 8 4 1 1 9
Contact
Wavenet
Joe Ewins
Telephone: 0333 234 0011
Email: publicsector@wavenet.co.uk
About your service
- Service categories
-
Systems Infrastructure Software
Storage
Data replication and protection
- Data Protection Software
- Backup and Recovery Reporting Software
- Storage Replication Software
- Replication Management Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Veeam BCDR, Microsoft 365, SharePoint, Exchange Online, OneDrive for Business
- Cloud deployment model
- Hybrid cloud
- Service constraints
- Requires Microsoft 365, backup server needs to be on windows and located in same place as the proxy, whether on premise or in a public/private cloud
- System requirements
-
- Microsoft Office 365 user licenses provided by client
- Microsoft Office 365 Administrator account assigned to Wavenet.
- Administrator account will not require a Microsoft Office 365 license.
User support
- Email or online ticketing support
- Yes
- Support response times
- Wavenet support - 1 hour response time inside core working hours 9-5 Monday-Friday UK time. Extended hours 8-8 Monday-Friday available with same SLA. Out of Hours support available with 1 hour response for critical issues. Microsoft infrastructure-level support is 24/7/365 for underlying, abstracted hardware
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Any customers on managed support will have a dedicated account manager and will be assigned a support team of engineers ranging from 1st line to 3rd line in ability. Escalation points are available with optional to follow through with issues until resolution. Costs vary depending on the Azure resources being supported.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- Our dedicated backup support team will configure the backups to match the customer requirements based on the users and data to be backed up, the retention policies and storage locations
- Service documentation
- No
- End-of-contract data extraction
- The backup data can be downloaded, copied to native format and transferred to the customer. This may incur additional cost for support and media (if used). Where customers are able to extract their data through their own methods, they are free to do so. Wavenet can assist in bulk data extraction although this may incur additional costs if specialized hardware or software is required. Wavenet will purge and destroy customer data from it's own equipment upon contract termination in accordance with it's ISO27001 policies. Additional data destruction measures may be pre-agreed with the client in advance and may incur additional costs.
- End-of-contract process
-
Clients can choose to ‘off-board’ services from Wavenet as follows:
• Provide notice in writing to their account manager within the contract terms & conditions, who will assist in arranging any required off-boarding services and the deletion of client data.
• Once the required works are agreed and the client has exported their data, Wavenet will shut down and destroy any remaining services.
• Fees may apply for off-boarding technical work and process management.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
- Windows
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The interface for Veeam Backup for Microsoft 365 typically features a user-friendly dashboard with options to configure backup jobs, monitor backup status, perform restores, and manage backup repositories. It often includes sections for each Office 365 application (Exchange Online, SharePoint Online, OneDrive for Business, Microsoft Teams) where users can define backup policies and settings tailored to each service. Additionally, the interface may offer reporting capabilities to track backup performance and compliance.
- Accessibility standards
- None or don’t know
- Description of accessibility
- N/A
- Accessibility testing
- N/A
- API
- Yes
- What users can and can't do using the API
- Veeam Backup for Microsoft 365 provides an API that allows integration with third-party systems and custom automation workflows. This API enables users to programmatically manage backup jobs, retrieve backup data, monitor backup status, and perform other administrative tasks.
- API documentation
- No
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- This includes configuring backup policies, choosing storage destinations, setting up retention policies, defining alert thresholds, and integrating with other systems through the API. However, customization may be limited to the features and options available within the software, and significant modifications or alterations to the underlying functionality may not be possible without extensive development efforts.
Scaling
- Independence of resources
- Veeam Backup for Microsoft 365 typically allows administrators to allocate dedicated resources such as storage repositories and processing power for each tenant or user. This ensures that one user's backup operations do not impact the performance of another user's backups.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Backup Job Status, Data Size and Growth, Repository Usage, Backup Performance, Retention Policy Compliance, Job History and Logs, Alerts and notifications
- Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Veeam
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
- Data in Azure is encrypted at rest by default
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Customers can request assistance with migrating datastore to a new location if wishing to retain historical backups
- Data export formats
- Other
- Data import formats
- Other
Data-in-transit protection
- Data protection between buyer and supplier networks
- Other
- Other protection between networks
- Veeam Backup for Microsoft 365 uses the 256-bit Advanced Encryption Standard (AES) for data encryption
- Data protection within supplier network
- Other
- Other protection within supplier network
- Role-Based Access Control (RBAC), Multi-Factor Authentication
Availability and resilience
- Guaranteed availability
- We provide a 99.95% uptime guarantee SLA on our Data Protection for Storage Cloud Service. This excludes planned and emergency maintenance.
- Approach to resilience
- Wavenet operates its own 100Gb low-latency Core network and resilient MPLS network, with all data centres on-net Wavenet’s Internet feeds into the data centres are delivered over our resilient core 10Gb MPLS network into peering points at other partner Points Of Presence (POPs). Where applicable all customer data stored by Wavenet is resilient across 3 DC sites.
- Outage reporting
- Any service outages are reported to the client via email and support tickets are raised with escalation. Any planned maintenance will be notified to the client in advance.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Access restrictions in management interfaces and support channels
- Administrative access to the Veeam Cloud Connect platform uses strong authentication, TLS VPN or SSH with Public Key Authentication for onward access to the infrastructure. Additional application-level access controls are implemented within the Veeam software.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Wavenet is an ISO27001 certified company and we adhear to the standard and has an Information security management system drawn from ISO27002 and we follow the NIST standard for cyber securit framework, we are audited on this standard annually, Wavenet is also a CE+ certified company
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Wavenet conform to ISO2000
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Wavenet conform to and follow the NIST standard and ISO27002
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We have continual monitoring with EDR solution feeding into a SIEM that is monitored 24/7 that is monitored by SOC
- Incident management type
- Supplier-defined controls
- Incident management approach
- Wavenet is ISO27001 certified and we follow the playbook as part of our certification.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 3%
- Between £2,500,001 and £5,000,000
- 4%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- United Registrar of Systems
- ISO/IEC 27001 accreditation date
- Thursday 18 July 2024
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- United Registrar of Systems
- ISO 9001 accreditation date
- Monday 12 August 2024
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 39aabf05-4ab8-4ee7-adcd-3318af1f9d2f
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 6cc5c85d-03f1-446c-9e9d-7338dfb9f0ce
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Plans for positive actions with community groups.
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-