Skip to main content

Help us improve the Digital Marketplace - send your feedback

VODAFONE LIMITED

VBSE Vulnerability Scanning

Vulnerability scanning provides a means to scan assets in scope for CVEs (Common Vulnerabilities & Exposures). The service is provided by our experienced Cyber Engineering Team based in the UK. Service includes monthly reports showing CVEs ranked by severity.

Features

  • Scan assets in scope for Common Vulnerabilities & Exposures
  • Reporting - Monthly report of CVEs ranked by severity
  • Managed - Fully Managed Scanning solution
  • UK Onshore - Minimum Security Check (SC) clearance
  • 24x7 - Security Operations Centre (SOC)
  • Solution informed by National Cyber Security Centre guidance

Benefits

  • Help identify the points of weakness in your systems
  • Help identify activities to reduce the attack surface

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at frameworks_team@vodafone.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 6 4 5 8 4 0 9 1 2 4 1 7 4 4

Contact

VODAFONE LIMITED Frameworks Team
Telephone: 07775671027
Email: frameworks_team@vodafone.com

About your service

Service categories

Systems Infrastructure Software

Security

Network security

  • Trusted network access and protection

Data security

  • Information protection
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
SOC & SIEM, MDR, SD WAN
Cloud deployment model
  • Public cloud
  • Private cloud
Service constraints
None. If any constraints do appear, these will be discussed with the customer at point of contract.
System requirements
  • Appropriate connectivity in place to enable Vodafone’s remote management.
  • Site access to equipment

User support

Email or online ticketing support
No
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
No
Support levels
The VBSE Vulnerability Scanning Service is a fully monitored, managed and maintained service supported 24x7 by VBSE
Service Incident Management for Severity Level 1 & 2 Service
Incidents - 24/7/365
Service Incident Management for Severity Level 3 & 4 Service
Incidents - working hours
Service Request Fulfilment - working hours
VBSE offers a chargeable option for Service Level Management (“SLM”). SLM is a fundamental part of our Services Support Model providing specialised additional services to our Customers alongside our standard business support functions. Vodafone SLM aims to meet and exceed agreed service delivery and performance targets and ensure future services are also delivered in the same way; constantly striving to exceed expectations and drive continual service improvement. Price for SLM is on request
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Where agreed, Vodafone will carry out procurement and arrange for appropriate equipment to be shipped to Customer provided locations as defined in the Customer Solution Design or relevant Order. Vodafone will ensure the equipment is fitted, racked, powered and connected to the Customer’s LAN, all of which the Customer must ensure is provided and ready in advance. Vodafone reserves the right to charge the Customer for costs incurred in respect of the engineers attending any Site at which agreed prerequisites (as set out in these Service Terms and/or the Customer Solution Design) are not provisioned. Once evidence of connectivity has been ascertained, Vodafone engineers will then remotely configure and manage the device.
We have a tailored support model for Service Level Management delivering: KPI and SLA performance reporting, Regular operational service reviews, Continual Service Improvement, Trend analysis,
Customer satisfaction surveys, Optional scheduled reviews with assigned SOC Analyst, Vulnerability report provided within an agreed week of the month
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
Customers can request this to Vodafone when contract ends
End-of-contract process
If the customer does not continue their contract, then the service will end. Hardware bought for and installed for the customer will continue to be owned by them , unless stated otherwise in their contract with us
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Documentation can be provided in accessible formats where requested by the customer

Using the service

Web browser interface
No
Application to install
No
Designed for use on mobile devices
No
Service interface
No
User support accessibility
None or don’t know
API
No
Customisation available
Yes
Description of customisation
Vodafone will work to understand your requirements and provide an appropriate managed Vulnerability Scanning solution. This will be captured via a Customer Solutions Design (CSD) document.

Scaling

Independence of resources
Appropriate resources are aligned for each customer contract to ensure this isn't an issue. Where required, dedicated resources/set up for customers can be considered.

Analytics

Service usage metrics
Yes
Metrics types
Reports are generated from the Tenable.sc Management Console within our secure private cloud environment. Reporting template(s) are agreed during implementation, and used to present a summary of vulnerabilities, listed in order of severity as calculated within the
Common Vulnerability Scoring System
Reporting types
Regular reports
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
Physical access control, complying with another standard
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
  • Data Erasure
  • Degaussing
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users cannot directly export their data themselves (outside of the reporting agreed with them at contract), but they can request this via support services
Data export formats
Other
Other data export formats
To be agreed with the customer during their request
Data import formats
Other
Other data import formats
This is not applicable to this service

Data-in-transit protection

Data protection between buyer and supplier networks
  • IPsec or TLS VPN gateway
  • Other
Other protection between networks
Depending on the services provided by Vodafone, we can transfer data between organisations via IPsec tunneling established over public internet or via private MPLS or SD-WAN networks
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The Service Level for Service Availability of the Solution (“Availability Service Level”) is 99.7%
Where the Service Availability in a Quarterly Measurement Period falls below the Availability Service Level, Customer shall be entitled to a Service Credit.
The % of credit will depend on if the customer has selected the non resilient or resilient service, and severity level/ % Availability Service Level minus % Service Availability - these are detailed in full in tables in the service terms
Approach to resilience
Our data centres employ defence-in-depth physical, technical, and operational controls to ensure availability, integrity, and security even under stress or failure conditions. These include:

Redundant Powers supplies, with dual feeds from the local power grid into the building, UPS (Uninterruptible Power Supply) systems, and backup generators.

Cooling and HVAC (heating, ventilation, and air conditioning) redundancy, with redundant colling systems to prevent overheating.

Fire Suppression Systems covering the data halls and other operational spaces.

Physical Security controls, including multi-factor access controls, CCTV, mantraps and secure perimeter.

Redundant Network Links from the Vodafone network.

These controls are audited both internally and externally on a regular basis. Further details are available on request.
Outage reporting
Emails alerts - Outage reporting is managed through a comprehensive, ITIL-aligned service management framework, fully integrated with relevant service management and oversight systems. Outages are detected using automated, real-time monitoring across all critical service domains. When a fault or performance degradation occurs, alarms are generated by network management systems and processed automatically. These alarms are correlated and escalated into the service management platform, which can be electronically integrated with partner and oversight platforms via standard APIs.

This integration enables real-time, bi-directional synchronisation of incidents, ensuring that any outage is immediately visible to all relevant parties. Incidents are classified, triaged, and escalated according to predefined thresholds and operational agreements. Updates, root cause analyses, and resolution statuses are synchronised across platforms, providing stakeholders with unified dashboards and automated reports. Regular and ad-hoc reports detail incident trends, service level adherence, and improvement actions. All processes are validated through formal testing, with continual improvement mechanisms in place. This approach ensures transparency, accountability, and rapid response to outages, fully compliant with contractual and security requirements. The framework supports end-to-end service integration, with clearly defined roles, escalation paths, and governance structures, ensuring consistent service quality and continuity at all times.

Identity and authentication

User authentication needed
Yes
User authentication
Other
Other user authentication
Customer Representative: Customer must nominate a representative (the “Customer Representative”) who must be able to make financial and contractual decisions relating to the user requirements; this representative would be given the relevant access to provide to Vodafone what is needed for us to deliver the service
Access restrictions in management interfaces and support channels
Customer's do not have direct access into the service provided by Vodafone/VBSE, only to the reporting and customer services, via the agreed customer representative from the customer
Access restriction testing frequency
Less than once a year
Management access authentication
Other
Description of management access authentication
The customer does not have direct access into the product/service, only to the output reports and to customer service/support channels - this is via the customer advised customer representative

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Vodafone maintains a robust Information Security Management System (ISMS) which has been certified against ISO/IEC 27001 since 2005. As a cornerstone of the ISMS, our cyber security policy documents the high-level statement of intent for information security, setting the tone and direction for security activities throughout the organisation. All colleagues receive mandatory information security and data protection training, with regular refreshers and targeted awareness campaigns. We conduct regular assurance reviews of our products and services and the underlying systems which support them. These includes proactive monitoring of day-to-day operational aspects by our second line risk management and compliance functions, and formal internal audits conducted by our team of experienced internal auditors. Any concerns raised by these reviews are managed in accordance with our formal risk management processes, where necessary escalating to senior management. In keeping with the requirements of ISO/IEC 27001, our policies are reviewed at least annually, with any changes filtering down into supporting framework of documents defines the cyber security controls required to ensure that we operate our organisation securely. This ISMS is subject to the required internal and external surveillance and recertification audits by independent internal audit teams and the relevant certification bodies.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All service components are tracked throughout their lifecycle using an integrated configuration management database, ensuring accurate asset and configuration data is maintained and synchronised with central oversight systems. Changes are managed through a formal, ITIL-aligned process: each proposed change is assessed for potential security and operational impact, with risk evaluations and approvals required before implementation. Where implemented, automated workflows and electronic integration with partner systems ensure traceability, auditability, and real-time updates. Security considerations are embedded in change assessments, and all changes are documented, reviewed, and subject to post-implementation validation to maintain service integrity and compliance.
Vulnerability management type
Undisclosed
Vulnerability management approach
Vodafone employs an internal vulnerability management process using the CVSS and MITRE ATT&CK Matrix to prioritise vulnerabilities. We are unable to share more details without further consultation due to the secure nature of our services
Protective monitoring type
Undisclosed
Protective monitoring approach
Specifically for Vulnerability Scanning product, it is a fully monitored, managed and maintained service 24x7.
Vodafone undertakes proactive monitoring for a range of fault conditions and use a range of monitoring and alarm tools to detect events on the application and infrastructure and provide the required expertise to ensure that the application and infrastructure are maintained according to Vodafone and Industry standards.
The platform connects to customer assets to perform the scan. Vodafone collects vulnerability information and presents through reporting. Centrally managed by Vodafone including maintenance, configuration and fault fixing.
Detailed response by incident type/severity is in the service terms.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Vodafone uses pre-defined, ITIL-aligned processes for managing common incidents, ensuring consistent and efficient resolution. Users report incidents through established channels, where each case is categorised, prioritised, and escalated according to impact and urgency. Incident progress is tracked throughout its lifecycle, with updates provided to relevant stakeholders. Regular service reports summarise incident volumes, trends, root causes, and performance against SLAs, supporting transparency and continual improvement. Processes are routinely reviewed and refined to maintain compliance, drive service quality, and ensure rapid response across all operational environments, regardless of time or complexity
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
LRQA
ISO/IEC 27001 accreditation date
Friday 16 August 2024
What the ISO/IEC 27001 doesn’t cover
The Information Security Management System covers Vodafone UK mobile, Fixed and UCS Services and the Business Units that enable and support those Services. Locations are identified by the Services and Business Units that they support. All Annex A controls have been deemed applicable in accordance with the Design, Build and Run model & the Statement of Applicability Version 0.1.

The Data Centre locations are covered by the Vodafone Group ISO27001:2022 certificate.

issued by LRQA - 08/07/25.
Information Security Management System of Vodafone Group functions covering:The Provision, Maintenance and Operations for
Cyber Defence, Data Centres, Network, Infrastructure and Application services for Local Markets and Vodafone Business; Office IT
services, Shared Service Centres and relevant Business Processes.Vodafone Business services includes International Network
Connectivity, Unified Communications, Internet of Things, Cloud & Hosting and Customer Service Desks. This is in accordance with
Statement of Applicability version 19.

Therefore all elements of the proposed services are covered by these certifications.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
LRQA
ISO 9001 accreditation date
Tuesday 15 September 2026
What the ISO 9001 doesn’t cover
Vodafone UK certificate does not cover Vodafone Group, this is covered by a Vodafone Group ISO9001 certification.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
NCC Group Security Services Ltd
PCI DSS accreditation date
Monday 7 July 2025
What the PCI DSS doesn’t cover
This does not cover UC, AWS or Azure. This are covered by separate certification.
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
E7b3eb7f-32e7-436f-9d63-b023df698463
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
Af87bed1-45db-4396-b5a5-0703ffdc35ce
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at frameworks_team@vodafone.com. Tell them what format you need. It will help if you say what assistive technology you use.