Cloud Web Application Firewall - Thales Imperva Brookcourt
Imperva web application firewall protects websites and APIs from attacks like SQL injection, XSS, bots, DDoS, offers protection against the OWASP top 10 threats. It uses machine learning, global threat intelligence, and flexible deployment options to block malicious traffic while ensuring performance, availability, and compliance for modern enterprises at scale.
Features
- Protects again OWASP WAF Top-10 threats, without impacting legitimate users
- Protects against OWASP Top-10 API threats, without impacting legitimate users
- Basic service mitigates 1000+ unique bot types over 14 categories
- Industry-leading AI-assisted advanced bot protection optionally available
- Consistantly identified as a leader by multiple independant analyst reviews
- Provides critical infrastructural protection for large security-focused organizations globally
- Completely agnostic to application structure and payload size.
- Single stack solution with all protection services in all PoPs.
- Multiple UK-based PoPs for traffic sovereignty isolation and resiliency
Benefits
- Automatically protect applications from DDoS and OWASP Top 10 Threats
- Scalable cloud-based security without impacting application performance or additng latency
- Real-time threat intelligence with contextual insights and AI explanability
- Centralized dashboard for simplifed WAF management and policy automation capabilities
- High availability with 99.999% uptime through our global cloud infrastructure
- Managed ruleset by the Imperva SOC team
- 24/7 follow the sun support
- Accelerated time to value with simplifed onboarding and terraform integrations
- Fast incident-response through actionable alerts and contextual and forensic insights
- Protect applications whether they're cloud or on-premises
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 8 8 1 4 7 1 6 6 1 3 0 9 1 0
Contact
BROOKCOURT SOLUTIONS LIMITED
Phil Higgins
Telephone: 01737 886111
Email: contact@brookcourtsolutions.com
About the service
- Service categories
-
Systems Infrastructure Software
Security
- Endpoint security
- Security analytics
- Governance, risk and compliance
Network security
- Active application security
Data security
- Information protection
- Digital trust
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- No
- System requirements
- DNS Control
User support
- Email or online ticketing support
- Yes
- Support response times
-
Our support team have SLAs for tickets that are raised through our support portal.
Provide SLA document or write out SLAs. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We offer four tiers of support and escalation. Tier 1 support handles initial support requests. Tier 2 support provides a higher level of expertise and product depth. Tier 3 escalations may involve consulting from our security operations team or network operations team. Tier 4 support includes our engineering and product development organizations. All support is facilitated by Imperva employees. In addition, we can provide, at an additional cost, operational support through a Technical Account Manager (TAM), who becomes familiar with your application and network implementation, internal processes, business and technical requirements, and change management procedures to help plan, deploy, and maintain your environment. Assigned TAMs are responsible for engaging our product development team members as needed. We also offer 24x7x365 technical support via phone, e-mail, and our Customer Support Portal. Our support organization is strategically deployed across the globe to ensure immediate and timely assistance for all Imperva products and solutions.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Our enterprise services team will assist with the onboarding of new sites to the service, we also offer online training seats and our documentation portal to ensure the end user is well equiped with all the information they need to manage the platform and ensure fast time to value.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- N/A
- End-of-contract process
- As part of the contract, you'll get the Imperva Cloud WAF with the asbeforementioned technical capabilities, but additional bandwidth and sites come at an additional cost, with sites being a price per unit cost and bandwidth being a price per mbps cost. Total Bandwidth is calculated on clean bandwidth and on the 95 percentile, for additional detail, please see our documentation portal - https://docs-cybersec.thalesgroup.com/bundle/cloud-application-security/page/settings/account-bandwidth-calculation.htm
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The externally facing web interface offers users a self-service management portal with a homepage dashboard for quick visibility of protected assets. Through this portal, users can access services such as WAF (Dashboards, Policies), DDoS Protection, Advanced Bot Protection, Account Takeover Protection, Client-Side Protection, Attack Analytics, Reputation Intelligence, DDoS Protection for Networks, Individual IPs, and DNS. The portal enables configuration and monitoring, providing a single-pane-of-glass for managing security and operations. Users can interact via the UI, API calls, and Terraform, ensuring flexible management and integration options for various needs.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We have conducted accessibility interface testing using a combination of evaluation methods and tools to ensure usability for users of assistive technology. Our evaluation methods include the use of screen readers, visual code inspection, manual interface and components analysis. For assistive technology specifically, we utilize VoiceOver on MacOS and test with the Chrome browser. Evaluation tools employed in our process include Equal Access Toolkit: Accessibility Checker, Axe DevTools extension for Chrome, Accessibility Insights for Web extension for Chrome and Edge Chromium, Colour Contrast Analyser from the Paciello Group, and the WCAG Contrast checker. Both automated and manual testing are performed to validate accessibility features.
- API
- Yes
- What users can and can't do using the API
- The end user is able to manage and make changes through an API with all the information available in our documentation - https://docs-cybersec.thalesgroup.com/bundle/api-docs/page/api/api-overview.htm
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Users can customize our service in several ways. They can configure customized response pages, including error responses, through the platform as described in the documentation. Policy Management enables users to centrally configure and manage settings, save them as policies, and apply those policies to multiple sites within an account. Policies can be created at the parent account level, made available to subaccounts, and set as default to automatically apply to new websites. At the website level, users can view, edit, apply, or remove policies. Imperva offers several policy types, each with specific configurable fields. Users can also customize which tasks and domains common users may modify. Customization is possible via multiple methods, including the user interface, API calls, and Terraform. Professional Services and certified partners are available to assist with deployments, configuration, tuning, upgrades, and custom integrations, tailoring installations to meet specific client needs. Advanced options are available for building custom security policies using the customer policy rule engine, allowing specialized adjustments for unique use cases.
Scaling
- Independence of resources
- We guarantee users are not affected by the demand other users place on our service by maintaining a fully scalable redundant platform with over 10 Tbps of on-demand scrubbing capacity and the ability to process 65 billion attack packets per second. Our global network is designed for robustness and resiliency, delivering premium performance and low latency. Controls are in place to prevent one client from compromising another in a resource pooled environment. Advanced caching and optimization techniques further ensure seamless user experiences during high traffic periods.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide comprehensive service metrics including performance (round-trip time, throughput, jitter) and availability (packet loss) for all Points of Presence (PoPs), as well as performance and availability between Imperva edge and customer origin servers. Traffic reports include metrics such as requests, response codes, page views, origin offload, browser and OS, with a 3-month data retention period. Cross-service line metrics are available via Attack Analytics within the management console.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Thales Imperva
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- No
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- We protect data at rest using encryption, including AES 256 for sensitive information, and store audit files in a proprietary format on hardened gateway appliances accessible only via SSL encrypted connections. Data masking, pseudonymization, and hashing technologies further minimize exposure to sensitive data. Security controls such as password protection, physical protections, and monitoring are applied to prevent unauthorized access, modification, or theft of stored data. Centralized management of protection policies ensures consistent standards across environments, and recovery options are available to maintain data integrity.
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Degaussing
Data importing and exporting
- Data export approach
- N/A
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- .xls
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- .xls
- XML
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We guarantee a 100% uptime SLA for Network DDoS protection when the origin is connected to 3 Imperva PoPs, and our network protection base plan includes 8 router connections for high availability. Imperva commits to a Network Infrastructure annual uptime of 99.999% and a Peripheral Infrastructure annual uptime of 99.95%. Our Always-on Services offer a 99.999% network uptime SLA and a 3-second mitigation SLA. If service levels are not met, remedies and refund procedures are detailed contractually. For application and disaster recovery scenarios, we maintain the highest level of availability through real-time monitoring, optimal load distribution, and automatic site failover. Service level agreements are supported and include mechanisms for monitoring and enforcing SLAs, such as 24x7x365 coverage, escalation procedures, and status updates through our Customer Support Guide.
- Approach to resilience
- Our service is designed for resilience through a fully redundant architecture operating in active/active mode across multiple data centers worldwide, supporting a 99.999% uptime commitment. Each data center is strategically located and equipped with high-capacity infrastructure, leveraging advanced hardware and software to ensure maximum throughput and minimal latency. Cloud WAF security proxies are deployed in clusters within each PoP for high availability and resilience to DDoS attacks, with PoPs in each region backing each other up. Network configuration requires at least two data centers to serve any single customer at any time, minimizing the risk of downtime. Redundancy between data center PoPs enables automatic failover if infrastructure goes offline. For customer-managed environments, we implement a global load balancing design and support both on-premises and public cloud deployments without location restrictions. Additional planning for rolling power outages is unnecessary due to our resilient network and service design. Detailed data center specifications are available on request.
- Outage reporting
- Imperva network status is available through - https://status.imperva.com/
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- Two-factor authentication can be delivered via SMS, Email, or Google Authenticator for administration portal access.
- Access restrictions in management interfaces and support channels
- Access in management interfaces is restricted through a formal management process controlling allocation of access and passwords. Role-based access controls (RBAC) enable precise privilege management, allowing edit, view-only, or restricted access to specific objects. Multi-factor authentication (MFA) is enforced for login security. User access is regularly reviewed and managed via structured provisioning and deprovisioning processes. For support channels, all calls and emails must be submitted through official Imperva support channels to ensure proper tracking, assignment, and resolution of cases.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
- Two-factor authentication can be delivered via SMS, Email, or Google Authenticator for administration portal access.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Imperva's governance standards comply with ISO 27001:2022, SOC 2 Type II, PCI DSS 4.0 Service Provider Level 1, GDPR, APEC PRP, and TRUSTe GDPR Validation. These certifications and validations confirm adherence to internationally recognized information security, privacy, and data protection standards.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Our configuration management program utilizes platforms such as SCCM for Windows, Jamf for macOS, Puppet and Salt for Linux, and centralized management consoles for network devices to track components throughout their lifecycle. All configuration and system changes are governed by a formal change management program, which includes risk assessment, impact analysis, approvals, testing, and rollback planning to ensure potential security impacts are evaluated. Change candidates are scored based on risk level and routed to the Change Approval Board for review.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerability scanning and remediation is performed regularly. We also follow security trends and communicate with third party vendors regarding emerging vulnerabilities. When identified, vulnerabilities are managed according to the Threat and Vulnerability Management Policy and Standard.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We implement comprehensive protective monitoring through automated audit trails that reconstruct key events such as access to sensitive data, actions by privileged users, and invalid access attempts. Logs are reviewed daily in real time to identify potential compromises, with user identification, event type, date/time, and success/failure recorded for each event. Upon detection of a likely major security incident or data breach, our Incident Response Leader activates the Data Security Incident Response Team in consultation with Legal, ensuring rapid notification to impacted individuals, customers, regulators, and partners according to our DSIRP.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We have a documented (pre-defined) incident management process that requires employees, contractors, and third-party users to report potential incidents to the security team for initial investigation. Incidents may be escalated to the Crisis Management Team, which manages identification, containment, eradication, recovery, and communication coordination, including customer notifications. The Computer Emergency Response Team (CERT) operates according to established standards and records events in a ticketing tool, with a 4-hour SLA for containment recommendations. Impacted customers are notified within 24 hours of incident confirmation, and updates are provided until resolution. Incident reports are communicated to designated contacts as specified in service agreements.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Our preferred trial offering is through an engagement with our technical team to create a trial suited to the users requirements for a custom time period and aligned with the users success criteria.
- Link to free trial
- https://www.imperva.com/free-trial/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1%
- Between £250,000 and £500,000
- 1.5%
- Between £500,001 and £1,000,000
- 1.75%
- Between £1,000,001 and £2,500,000
- 2%
- Between £2,500,001 and £5,000,000
- 2.5%
- Over £5,000,001
- 3%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- URS Holidings
- ISO/IEC 27001 accreditation date
- Monday 3 November 2025
- What the ISO/IEC 27001 doesn’t cover
- ISO Certificate covers IT Solutions, Management Consultancy and Integration Services
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- URS Holidings
- ISO 9001 accreditation date
- Saturday 12 October 2024
- What the ISO 9001 doesn’t cover
- ISO Certificate covers IT Solutions, Management Consultancy and Integration Services
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- B1696668-7af9-4f0d-b3b7-34fc20cfc861
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- 0199f451-3f84-44cb-bb20-75e29b818ffe
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
- Mission: Break down barriers to opportunity
-
By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Understanding of issues relating to entering the contract workforce
- Mission: Build an NHS fit for the future
-
That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition