Skip to main content

Help us improve the Digital Marketplace - send your feedback

VISIONET EMEA LIMITED

Visionet Platform Based Security Operations

Visionet’s Security Operations service helps organisations detect, respond to and mitigate security threats across cloud, infrastructure, endpoints, and applications. The service provides continuous monitoring, threat detection, incident response, and security governance to reduce risk and improve security posture. Enabled by Ops Studio, Visionet unifies security telemetry, automation, and workflows.

Features

  • Continuous endpoint monitoring and threat detection
  • Real-time endpoint alerts and incident correlation
  • Endpoint malware, ransomware, and exploit protection
  • Behavioral analysis for suspicious endpoint activity
  • Automated endpoint isolation and containment
  • Remote endpoint investigation and remediation
  • Endpoint vulnerability and patch status monitoring
  • Centralised endpoint security dashboards and reporting
  • Policy-based endpoint security enforcement
  • Platform-enabled endpoint operations through Ops Studio

Benefits

  • Detect endpoint threats in real time
  • Respond faster to endpoint security incidents
  • Isolate compromised devices remotely
  • Reduce manual investigation through automated responses
  • Maintain consistent endpoint security policies
  • Improve visibility across all managed endpoints
  • Minimise business disruption from security incidents
  • Speed up endpoint threat remediation

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at jawad.a.khan@visionet.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 4 6 4 0 4 8 8 7 8 3 5 9 8 2

Contact

VISIONET EMEA LIMITED Jawad A Khan
Telephone: +447721235694
Email: jawad.a.khan@visionet.com

About your service

Service categories

Systems Infrastructure Software

Security

  • Endpoint security
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
The service is an extension of enterprise IT operations software platforms, including IT Service Management (ITSM), infrastructure and cloud management, monitoring and observability tools, automation platforms, and security operations (SOC/SIEM) systems.
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
The service has no inherent constraints that limit standard endpoint security operations. Planned maintenance activities, where required, are scheduled in advance within agreed maintenance windows to minimise impact. The service depends on supported endpoint operating systems and the deployment of approved endpoint security agents. Any limitations related to legacy devices, unsupported operating systems, or customer-imposed tooling restrictions are identified during onboarding and agreed as part of the service scope.
Planned maintenance activities are scheduled in advance, performed during agreed maintenance windows, and communicated proactively to minimize business impact.
System requirements
  • Supported endpoint operating systems deployed
  • Endpoint security agent installation permitted
  • Valid endpoint security software licenses
  • Secure network connectivity for telemetry
  • Administrative access for agent deployment

User support

Email or online ticketing support
Yes
Support response times
All our services are as per agreed SLAs. We provide options like 8x5, 16x5, 24x7 etc.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Yes, we use Microsoft Teams for chat.
Onsite support
Yes, at extra cost
Support levels
At Visionet, our comprehensive support framework adheres to ITIL standards, delivering 1st, 2nd, and 3rd line support to both public and private sector clients. Our incident management process ensures swift resolution. Each client receives a dedicated Account Manager and Client Partner for personalized attention. We offer a unified support model manned by cloud support engineers, with optional weekend phone support available upon request. Our proactive approach prioritizes short-term issue resolution alongside long-term fixes. An established escalation process guarantees swift resolution, overseen by designated Account Managers who conduct monthly reviews, either remotely or on-site. Performance is monitored through KPIs aligned with SLAs and other critical support metrics. Security clearance is a fundamental aspect of our staff training and policy.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
We help users start using the service through a structured onboarding and transition process. This includes service kick-off sessions, environment discovery, and knowledge transfer workshops. We provide role-based onboarding, user guides, standard operating procedures, and runbooks, supported by online documentation. Where required, we deliver remote or onsite training for administrators and support teams, along with walkthroughs of dashboards, workflows, and escalation processes to ensure smooth adoption and operational readiness.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At contract termination, users can extract their data through a structured offboarding process. Visionet supports secure data export from operational tools, dashboards, reports, and ticketing systems in standard, machine-readable formats. Data extraction scope, format, and timelines are agreed during exit planning. All customer data is returned or securely transferred to the customer or their nominated provider, followed by certified data deletion from Visionet-managed systems in line with contractual, security, and compliance requirements.
End-of-contract process
At the end of the contract, Visionet executes a structured offboarding and transition process. This includes service handover, knowledge transfer, documentation finalisation, and secure return or transfer of customer data. Standard exit activities—such as transition planning, final reporting, and data export in agreed formats—are included in the contract price. Any additional activities beyond the agreed exit scope, including extended transition support, bespoke data transformations, tooling extensions, or parallel run support, are treated as additional costs and charged on a mutually agreed basis.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The Ops Studio platform provides a responsive web interface and native mobile applications for iOS and Android. Mobile users can submit requests, view tasks, receive notifications, and perform approvals. Desktop access provides the full user interface and administrative capabilities, including configuration, reporting, and advanced workflow management.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service interface is delivered through the web-based platform, providing a single, role-based interface for end users, agents, and administrators. Users access services through configurable service portals with catalog-driven requests, self-service capabilities, and real-time status visibility. Service teams use standardised ITSM and Service Management workspaces for incident, request, change, and case management, supported by dashboards, reporting, and SLA/XLA tracking.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Visionet relies on platform-level accessibility testing, which includes testing with assistive technologies such as screen readers and keyboard-only navigation. During implementation, Visionet configures and validates service portals and workflows using accessibility best practices and guidance, and supports user acceptance testing where buyers choose to include users of assistive technology.
API
Yes
What users can and can't do using the API
The platform's REST and SOAP APIs can be used to integrate external systems, create and update records (such as incidents, requests, cases, users and assets), automate workflows, and retrieve real-time service data. Initial platform setup, configuration of core Enterprise Service Management processes, security roles, and complex integrations are typically not performed solely through APIs and require administrative access and guided configuration. API usage is subject to ServiceNow platform controls, role-based access, rate limits, and supported data models. Visionet helps users design secure integrations, configure API access, implement automation, and ensure API usage aligns with best practices and governance standards.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can customise the service by configuring endpoint security policies, alert thresholds, response actions, reporting views, and escalation workflows. Customisation is carried out during onboarding and through ongoing configuration changes within Ops Studio, supported by change management and regular service reviews. Customisation requests can be initiated by customer-designated IT and security administrators, with implementation and governance managed by Visionet’s Security Operations team under agreed approval and access controls.

Scaling

Independence of resources
We ensure users are not impacted by demand from other customers through logical service isolation, capacity planning, and controlled resource allocation. Each customer operates within a dedicated service scope with segregated access, data, and workflows. Capacity is planned and monitored proactively using demand forecasting and threshold-based scaling. Where shared platforms or tools are used, role-based access, workload prioritisation, and SLA-based queue management ensure consistent performance and service levels for each customer.

Analytics

Service usage metrics
Yes
Metrics types
The service provides endpoint-focused security metrics covering threat detection, response, and posture. These include number of endpoint alerts, incident severity, Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), malware and ransomware detections, endpoint isolation events, patch and vulnerability status, and policy compliance. Metrics are delivered through real-time dashboards and periodic reports to support visibility, accountability, and continuous security improvement.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users export their data through a controlled data exit process managed by Visionet. Data is extracted from operational systems, ticketing tools, dashboards, and reports using standard export mechanisms and APIs, and provided in commonly used, machine-readable formats (such as CSV, JSON, or PDF, as applicable). The scope, format, and delivery method are agreed during exit planning, and data is securely transferred to the customer or their nominated provider in line with security, privacy, and contractual requirements.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Visionet operates under defined Service Level Agreements (SLAs) covering service availability, incident response, and resolution across infrastructure, end-user, and security operations. Availability targets are agreed per service tower and documented in the contract or Statement of Work. SLAs are measured continuously and reported through regular service reports.
Approach to resilience
The Security Operations service is designed for resilience through layered security controls, continuous monitoring, and automated response. Endpoint telemetry is collected continuously with redundancy and validation to handle transient failures. Automated containment and remediation reduce dependency on manual intervention. Standardised incident response playbooks, regular testing, backup configurations, and monitored availability ensure consistent protection and rapid recovery, even during high alert volumes or platform disruptions.
Outage reporting
Outages are reported through controlled, customer-specific channels. Visionet provides email alerts to designated contacts for confirmed outages, updates, and resolution notices. Operational dashboards within Ops Studio display real-time service status and incident details for affected customers (no public dashboard). Where required, outage information can also be exposed via APIs or integrated into customer ITSM tools, enabling automated consumption and tracking within existing workflows.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted through layered identity, access, and governance controls. Role-based access control (RBAC) ensures users and support personnel only have permissions required for their role. Strong authentication mechanisms, including multi-factor authentication, are enforced for privileged access. Administrative access is limited to authorised personnel and logged for audit purposes. Support channels such as service desks and portals are secured through authenticated access, approval workflows, and segregation of customer environments to prevent unauthorised access or data exposure.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
Information security policies and processes
Compliant with SOC 1 and 2, ISO27001, PCI-DSS, GDPR
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Visionet follows structured configuration and change management processes aligned to ITIL practices. All service components—including infrastructure, applications, endpoints, and security controls—are recorded in a configuration repository and tracked throughout their lifecycle from onboarding to decommissioning. Configuration changes are versioned and auditable.

Changes are assessed through formal change management workflows that evaluate risk, business impact, and security implications. Security impact assessments are embedded into the change process, with mandatory approvals for high-risk changes. Automated checks, logging, and post-change validation are used to ensure changes do not introduce vulnerabilities or compliance gaps.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Visionet operates a structured vulnerability management process across infrastructure, applications, and security controls. Potential threats are assessed through continuous vulnerability scanning, configuration assessments, and risk-based analysis aligned to asset criticality and exposure. Patches are deployed based on severity and impact, with critical vulnerabilities remediated on an expedited basis and others addressed within agreed patch cycles and maintenance windows. Threat intelligence is sourced from cloud providers, software vendors, security advisories, CVE databases, and trusted threat intelligence feeds, and is continuously reviewed to prioritise remediation actions.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Visionet uses continuous protective monitoring to identify potential compromises across infrastructure, endpoints, networks, and cloud environments. Potential compromises are detected through real-time log monitoring, alert correlation, behavioral analysis, and threat intelligence–driven use cases. When a potential compromise is identified, incidents are triaged immediately, containment actions are initiated, and predefined response playbooks are executed, including isolation, remediation, and forensic analysis where required. Response times are governed by SLAs, with critical security incidents acknowledged and acted upon within minutes and managed through to resolution using structured incident response procedures.
Incident management type
Supplier-defined controls
Incident management approach
Visionet follows a structured, ITIL-aligned incident management approach to restore services quickly and minimise business impact. We maintain predefined incident workflows and runbooks for common events, enabling consistent triage, prioritisation, and resolution. Users can report incidents through multiple channels, including the service desk portal, email, phone, chat, or integrated customer ITSM tools. Incident status and progress are communicated through regular updates, and detailed incident reports—including root cause, impact, actions taken, and preventive measures—are provided after resolution as part of service reporting or post-incident reviews.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
1%
Between £1,000,001 and £2,500,000
2%
Between £2,500,001 and £5,000,000
3%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
GMS INTERCERT SERVICES
ISO/IEC 27001 accreditation date
Wednesday 23 June 2021
What the ISO/IEC 27001 doesn’t cover
Not Applicable
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
GMS INTERCERT SERVICES
ISO 9001 accreditation date
Thursday 13 March 2025
What the ISO 9001 doesn’t cover
Not Applicable
Quality management systems (QMS)
Yes
CSA STAR certification
Yes
CSA STAR accreditation date
Friday 1 March 2024
CSA STAR certification level
Level 1: CSA STAR Self-Assessment
What the CSA STAR doesn’t cover
Not Applicable
PCI certification
Yes
Who accredited the PCI DSS certification
Sysnet Global Solutions
PCI DSS accreditation date
Tuesday 12 December 2023
What the PCI DSS doesn’t cover
Not Applicable
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
E7f12ebf-757f-4ba2-b918-a2e69c4308b5
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
Dea421ad-56e2-44f5-ae1d-8208ca0ca92b
Other security certifications
Yes
Any other security certifications
  • SOC1 TYPE 2
  • SOC2 TYPE 2
  • ISO 27001:2022, 27701
  • HIPPA Compliant
  • GDPR

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at jawad.a.khan@visionet.com. Tell them what format you need. It will help if you say what assistive technology you use.