Mobile Data Connectivity
TalkTalk Business (TTB) offers high speed mobile data connectivity to provide highly effective solutions that address customers’ overall networking requirements of being always-on, highly available and secure.
TTB services utilise 4G/ 5G mobile data networks to deliver robust, resilient primary or backup data services.
Features
- Multi network 4G/5G connectivity across all UK providers
- Unlimited data SIMs
- Unsteered multi network connectivity
- Supports dynamic and static IP addresses
- Primary or back up connectivity
- SIM only or managed CPE options
- Access to 960 networks across 185 countries
- Usage alerting and monitoring via smart portal
- Single helpdesk for the whole solution
- Single Helpdesk for the whole solution
Benefits
- Ensures resilient connectivity for critical public services anywhere
- Predictable costs with no risk of unexpected data overruns
- Automatically selects strongest signal to maintain service continuity
- Enables secure access to systems and remote operations
- Guarantees service availability during outages or emergencies
- Flexible procurement to match organisational needs and budgets
- Supports global operations and international public sector teams
- Improves cost control and oversight across departments
- Simplifies support and reduces operational burden on IT
- Resolve problems more quickly and accurately
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 4 7 3 5 8 9 2 8 2 4 8 8 1 1
Contact
TALKTALK BUSINESS DIRECT LIMITED
Andrew Stokes
Telephone: 07976911843
Email: andrew.stokes@talktalk.business
About your service
- Service categories
-
Systems Infrastructure Software
System and service management
- IT operations management
- IT service management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Service can be a back-up to a fixed line solution or a primary connectivity solution in its own right
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
-
Due to the nature of mobile technology, it is impossible to provide a fault-free service and the network does not have guaranteed uninterrupted service availability.
For example, the services may be affected by local terrain, weather, number of users accessing a base station, and compatibility and availability of any equipment, and systems used by Customer.
For this reason, in common with all providers of mobile based solutions, TalkTalk Business strives to provide uninterrupted services, but we cannot guarantee 100% uptime.
Our multi-network unsteered solution can provide mitigation against this risk as it can select the best MNO network connection. - System requirements
-
- CPE or SIM only options are available
- Where SIM only, customer can specify CPE and test functionality
- We assist customers to map their solution to work optimally
User support
- Email or online ticketing support
- Yes
- Support response times
- Support is available 24/7/365. All questions and queries will be acknowledged immediately upon receipt by our support teams, and we will endeavour to respond as quickly as possible during the working day.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- No
- Support levels
-
The customer will select the required standard care levels on a site-by-site basis at the point of order.
Care level 2 (default) – target 48 hours to fix
Care level 3 (default) – target 24 hours to fix
Care level 4 (default) – target 7 hours to fix
We would provide an Account Manager and support from the pre-sales team if needed. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Mobile data solutions are designed with the customer to meet their overall TalkTalk Business requirements. We will provide the following support during onboarding:
• Agree sites that need connectivity and mobile coverage availability at a site level.
• [Impart2.1][WP2.2]Confirm Mobile at location
• Coverage checks at the point of sale and order will be performed to ensure appropriate coverage is available at the required site(s). This coverage checker is an industry-wide used, government managed checker and assesses coverage across all major UK networks.
• Where a known strong coverage location exists, the solution has options to choose from, with a single network solution possibly providing the most cost-effective option.
• Additional antennas, if required, to ensure more robust signal strength.
Customer access to the management portal is also enabled at an agreed time during the above process. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Customers have access to their data which is available for extraction at any time up to when the service ends.
- End-of-contract process
- Customer can choose from SIM only or CPE inclusive solutions. IP addressing, data packages from the different mobile providers are also offered, as well as unsteered options. These are all priced individually. The contract will detail what is selected and its price.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Documentation can be provided in a larger font version if required.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- N/A
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- There is a service management portal.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The management portal is accessed via an Internet browser. End-user capabilities are defined in the description.
- Accessibility testing
- N/A
- API
- Yes
- What users can and can't do using the API
-
Customer can understand usage and request a report, and can set up the following through the API:
• SIM activation/suspension/termination
• Network routing profiles
• Global connectivity settings
• Alerts, reporting, and usage controls
• Tariff and cost‑control policies
Users can set up and make changes:
• Network selection preferences
• Automatic network failover (via multi‑network SIMs)
• Routing and connectivity behaviour
Via API or dashboard, users can configure:
• Usage alerts
• Connection health monitoring
• Diagnostic/traffic reporting
Limitations:
Users can manage SIM lifecycles and connectivity, but cannot change:
• The underlying mobile network architecture
• Core routing infrastructure
• SIM firmware or SIM security domain parameters
These elements are controlled by the MNO/MVNO. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
-
The solution uses mobile networks to deliver connectivity. If a single network SIM is selected, the solution is wholly dependent on their connectivity at a location.
For TTB, in addition to Unsteered multi-network connectivity, which mitigates against a single network provider being down, TTB non-consumer services use private APNs which have dedicated routes for access and provide protection against this dependence.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Metrics provided as part of the service include:
• Multi network Resilience & Automatic Failover
• Global Network Availability (Coverage Metric)
• Platform-Level Management Metrics
• Tariff Flexibility & Scalability Metrics
• Built‑in Network‑level Security Compliance
• Configuration
• SIM and data package history
• Usage by session/ by network provider
• SIM Rules including notification history of trigger threshold events - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- PlatformX Communications Limited (PXC)
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
- Other
- Other data at rest protection approach
- Data at rest is encrypted. There is an access control policy. We also have a data security standard that details the requirements for classification, storage, use, processing and destruction of all data. The access control policy and data security standard are both internal documents, so we are unable to share them.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- The portal contains customer site related data. The customer has access to usage data while sites are live, which they can extract if needed before the service ends.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Excel
- Data import formats
-
- CSV
- Other
- Other data import formats
- Excel
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- IPsec or TLS VPN gateway
- Data protection within supplier network
- Other
- Other protection within supplier network
-
Security measures help customers “comply with data regulations”, meaning their network infrastructure is designed with regulatory mandates in mind (e.g., data protection, privacy, lawful interception frameworks).
In summary, we will protect the network through:
• Enterprise‑grade network security controls
• Automatic multi‑network failover, protecting data continuity
• Regulatory‑aligned security design
• Secure SIM lifecycle management and access controls
• Layered IoT architecture, ensuring secure data flow
Availability and resilience
- Guaranteed availability
- This information is available via Pangea.
- Approach to resilience
-
The mobile solution uses unsteered multi‑network SIMs, meaning the SIM does not prioritise any single mobile operator. Instead, it continuously evaluates all available networks and automatically connects to the strongest one.
• Eliminates dependency on a single MNO
• Reduces connection failures
• Provides continuity if one network experiences downtime
IoT connectivity is specifically described as having “built‑in resilience and redundancy” — ensuring devices stay connected even in challenging environments or during outages, providing:
• Redundant connectivity paths
• Protection against localised failures
• Robustness for mission‑critical deployments (healthcare, emergency services, security, etc.)
Resilience isn’t only about connectivity—it's also about operational control. Pangea provides a centralised portal allowing partners to:
• Remotely activate/deactivate SIMs
• Diagnose issues through analytics
• Apply alerts and automated rules
• Monitor network behaviour in real‑time
Resilience benefit:
• Faults can be identified and mitigated instantly, reducing downtime and improving recovery.
• Portal supports full SIM lifecycle management and diagnostic tools. - Outage reporting
-
Incident reporting and support requests should be raised by telephone on 0333 003 4333 or via email ttbenterpriseassurance@talktalk.business. Our team aims to diagnose faults within 30 minutes. Support requests which are less time sensitive should be raised by email.
TTB will prioritise the incident according to the criteria and record the appropriate value for each of the following categories:
· Service
· Incident Type
· Work Type
· Reported Source
· Product Categorisation Tier
Our Internal and/or External Communications teams will send an email to all recipients in the Major Incident Communications Content & Distribution Lists document, describing:
· Impact
· Symptoms
· Manual workaround (if available)
· Instructions or additional information for customers and/or agents (if available)
· Provide a progress update
Email alerts will be provided in the event of a major service outage (MSO).
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- The Internal Network and Security Team has access and is responsible for user access management. The level of access is based on the principle of 'least privilege' and only those members of staff who need access will be granted it. We have a formal Joiners, Movers, Leavers (JML) process with role-based access governing the majority of applications and systems. Access is removed within 24hrs of an employee leaving the business. Recertification of user access is completed bi-annually.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials
- Information security policies and processes
-
TTB has a Master Security Policy in place and operates an Information Security Management System via its Security Operations Centre (SOC) for the reporting of all potential security breaches. The system is based on industry good practice (NIST CSF, PCI DSS) and is externally certified to ISO 27001. This covers a range of policies and procedures to ensure the confidentiality, integrity and availability of information, e.g., Master Security Policy, the Privacy Policy and the GDPR Policy.
We have in place a named DPO – Adam Rogers with the responsibility for GDPR/ISO27001 policies and processes.
The reporting of any security incidents is done directly to the Security team security@talktalkplc.com via the phishing report message button in the email toolbar. All incidents logged will go into the Security Team to process and escalate into the Head of Security.
All colleagues attend mandatory annual security training, and GDPR training to ensure they meet audit standards around data handling requirements and encourage them to share the responsibility for protecting data at all times. All colleagues have set timescales for training completion and this is reported against to ensure compliance. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Configuration changes are assessed, logged and components tracked through our Pangea portal which is managed by the Network Engineering team from the point at which we raise the initial change request until that change is closed off.
Quality comes as standard throughout the change process, with everyone involved having the requisite training. Managers of teams carrying out changes will be accountable for the quality of the work undertaken. There is zero tolerance for unauthorised changes.
Security impact will be assessed through a risk assessment and structured model to ensure all risks are captured and clearly identified. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- The Network Security Team conducts security scanning of all our infrastructure on a bi-weekly basis. We also conduct weekly threat and vulnerability scanning of all our network assets via InsightVM. Critical/high risk vulnerabilities patches will be applied within 14 days. All other updates are applied as soon as possible using a monthly patching cycle. Security updates will be assessed and prioritised based on threat level, likelihood of compromise, consequences of compromise, environmental characteristics and regulatory or accreditation-based requirements. We receive information about potential threats from InsightVM weekly scanning and we use Altiris for Patch Management.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
TTB operates a security incident management program for the alerting of potential compromises and deploys endpoint protection technology. Potential compromises will be logged by the security team, registered on the action tracker and updated with actions to mitigate risk.
Users can report Priority level 1/level 2 incidents by telephone, with a response given within 1 hour. Incidents can be reported by email/web portal.
Incident reports are provided on request. For network incidents, these reports are distributed to impacted customers via email. Reason for Outage reports for priority 1 faults are provided by email within 10 working days from root cause. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
We have a pre-defined process for common events and fault-related reporting through our 24/7 Technical Support Centre (TSC).
Users can report Priority level 1 and level 2 incidents by telephone (08454566541/08453103444) and by email/web portal.
Incidents, when resolved, will be notified to the customer as part of the logged ticket fault. Reports will be provided upon request for network incidents, and these reports distributed to impacted customers via email. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
-
A time limited trial connection can be provided, with the customer liable for any calls. The following could be included:
Access to multi‑network IoT SIMs for testing connectivity across networks
The Pangea SIM management portal
Access to partner support
Not included:
Custom integration work or engineering time
Dedicated account management
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 3%
- Between £2,500,001 and £5,000,000
- 4%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- ISOQAR
- ISO/IEC 27001 accreditation date
- Tuesday 27 January 2026
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Alcumus ISOQAR
- ISO 9001 accreditation date
- Monday 26 May 2025
- What the ISO 9001 doesn’t cover
-
Exclusions:
8.3 Design and Development of products and services
7.1.5.2 Measurement traceability
Location: Gateshead - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Viking Cloud
- PCI DSS accreditation date
- Monday 3 November 2025
- What the PCI DSS doesn’t cover
- None - The Non PCI is not covered by our certification, all PCI is covered under this certification.
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 41015739-ac20-4a9f-a558-edbab61126e0
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-