Network and Environment Security
Value-added reseller and enablement service. We support solution selection, procurement, licensing, onboarding coordination, and integration guidance for technologies that secure network access, application connectivity, and data flows across hybrid environments.
We enable customers to deploy Zero Trust–aligned network and access controls without replacing internal teams or assuming operational ownership.
Features
- API-based integration with security and identity platforms
- Fully encrypted traffic inspection and control
- Common services and shared-platform access enforcement
- Network segmentation and micro segmentation
- Cloud Access Security Broker (CASB)
- Software Defined Perimeter (SDP) for application access
- Secure application proxy services
- Continuous device and network visibility
- Centralised policy management and monitoring
- Automated alerting and response integration
Benefits
- Secure application access without exposing networks
- Reduce lateral movement and breach impact
- Enforce Zero Trust access policies
- Protect encrypted and API-driven traffic
- Reduce reliance on legacy VPNs
- Simplify access to shared services securely
- Improve cloud and SaaS security posture
- Improve visibility into devices and network activity
- Automate policy enforcement across environments
- Strengthen compliance and audit outcomes
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 4 3 6 7 1 9 7 1 2 8 1 0 7 2
Contact
Excelsior Solutions
BABATUNDE ADEMIJU
Telephone: +12403437974
Email: tademiju@excelsortech.com
About your service
- Service categories
-
Systems Infrastructure Software
Security
Network security
- Trusted network access and protection
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Vendor services integrate with existing identity providers, cloud platforms, directories and enterprise applications, including Microsoft, AWS, Google Cloud, on-premise and SaaS systems. Recommended third-party solutions use IAM, Zero Trust and security tooling to deliver centralised governance, consistent policy enforcement, least-privilege access and improved visibility without replacing existing systems.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- Excelsior Solutions Ltd provides onboarding coordination and advisory support primarily on a remote basis. We do not provide technical configuration, integration, deployment, or managed service operations. OEMs provide product maintenance and platform updates in line with their published service terms.
- System requirements
-
- Supported modern web browsers: Chrome, Edge, Firefox, Safari
- Unsupported or end-of-life browsers may reduce functionality and security
- Supported operating systems required: Windows, Linux, macOS, iOS, Android
- Endpoint agents must run only on supported operating system versions
- Cloud integration requires access to Azure or Amazon Web Services
- Network connectivity allowing secure communication between service and customer systems
- Firewalls must permit required ports and protocols per documentation
- Integration supports standard identity protocols: SAML, OIDC, OAuth, LDAP, SCIM
- Compatible directory services required: Entra ID, Active Directory, LDAP
- Valid platform and third-party software licences must be maintained
User support
- Email or online ticketing support
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
- These are dependent on the level of subscription purchased from the original equipment manufacturer.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Getting started with the service is supported through structured onboarding, training and knowledge transfer delivered by the equipment manufacturers whose solutions we resell. Training is provided to ensure users are confident and able to realise full value from the solution. Programmes are tailored to the customer’s environment, user roles and operational context, supporting effective adoption, long-term usability and continuity. Training is designed for different audiences, including end users, administrators and support teams, ensuring each group receives guidance relevant to their responsibilities and level of interaction with the service.
To accommodate different preferences and constraints, vendors offer training through multiple delivery methods, including instructor-led sessions, virtual workshops and online learning materials. This allows customers to select the approach that best suits their workforce and schedules.
Vendors also support knowledge transfer through train-the-trainer approaches and administrative enablement. This helps customers build internal capability and reduces long-term reliance on external support, supporting sustainable service operation beyond initial implementation.
Training is reinforced with comprehensive documentation, including user guides, configuration notes and quick-reference materials, provided in accessible digital formats and updated as the service evolves. Vendors continuously review training effectiveness using feedback, completion tracking and post-training evaluations to refine content and improve user engagement. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- Microsoft Word
- End-of-contract data extraction
- We do not host, access, store or process customer production environments, security logs, network telemetry, identity data, privileged session information, or other operational security data. Technical service delivery, platform operation, hosting and data processing for these datasets are performed by the OEMs under their own service terms. Data extraction will be performed by the original equipment manufacturer in line with their own processes and procedures.
- End-of-contract process
-
Supporting a straightforward and secure exit process, our offboarding processes ensure users can leave the service at the end of the contract term or upon termination, without vendor lock-in or hidden costs. We:
1. Support contract closure or renewal non-continuation
2. Confirm OEM offboarding steps and buyer responsibilities (where applicable)
3. Provide final commercial reconciliation and invoicing closeout
OEMs will follow their own offboarding processes and procedures. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Accessible and usable by a wide range of users, our vendors write all documentation in plain English. Preventing confusion or reduced service quality, our vendors use clear headings and logical layouts. Adjusting the service to reflect individual user requirements, vendors provide reasonable adjustments or alternative formats on request.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- This is not applicable.
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Original equipment manufacturer platforms offer a high level of configurability, enabling customers to tailor services to their specific network, environment and security requirements. Customers can configure network segmentation and access-control policies, define identity, user and privileged-access rules, and apply encryption and security settings aligned with their internal standards. Monitoring thresholds, alerts and telemetry views can be customised to provide relevant operational insight, while integrations with external identity, security and service-management platforms support seamless alignment with existing tooling. The platforms also support automation and policy-driven workflows, helping organisations standardise controls and reduce manual effort.
Configuration activities are carried out through secure management consoles, vendor-provided APIs and infrastructure-as-code tools. This enables consistent, auditable configuration aligned with customer governance and compliance. Administrative users can complete most day-to-day configuration and policy changes independently through the administrative interface, allowing rapid adjustment as needs evolve.
For complex customisation, such as advanced third-party integrations, bespoke reporting templates or workflow automation beyond standard platform capabilities, original equipment manufacturers work collaboratively with customers. This ensures changes are implemented in line with security policies, governance frameworks and operational requirements. All customisations are designed to be non-disruptive to live services, allowing customers to maintain continuity while benefiting from expert vendor support.
Scaling
- Independence of resources
- N/A
Analytics
- Service usage metrics
- Yes
- Metrics types
- We can provide license management metrics. The original equipment manufacturer will provide technical detail in line with their own processes and service levels.
- Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Forescout, Cyolo, Illumio, and Netskope
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
Customers can export their data from OEM platforms at any time using open, non-proprietary formats where supported. Additional export formats may be made available by the OEM on request.
Exports may be completed ad-hoc or scheduled through OEM portals/API-based automation tools. At contract end, OEMs provide customer operational data in an agreed format.
Excelsior Solutions does not host, access, store or process customer operational security data. Technical service delivery, platform operation, hosting and data processing for these datasets are performed by the OEMs.
Data extraction is performed by the original equipment manufacturer in line with their own processes and procedures. - Data export formats
-
- CSV
- Other
- Other data export formats
- Dependent upon the original equipment manufacturers own processes and procedures.
- Data import formats
-
- CSV
- Other
- Other data import formats
- Dependent upon the original equipment manufacturers own processes and procedures.
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Our dedicated advisory support is available Monday to Friday from 09:00 to 17:00. While we do not operate or host customer systems, our guaranteed availability ensures that organisations have expert guidance whenever it is needed. This support helps customers make informed decisions, optimise configurations, and respond quickly to operational questions.
By providing reliable and accessible advisory services, we help organisations maximise the availability and resilience of their own systems. Our guidance ensures secure and effective configuration of network and access controls, supports integration across hybrid and multi-cloud environments, and enables customers to address issues promptly, reducing the risk of downtime. Where platform-specific issues arise, vendor support teams facilitate timely resolution in line with their own SLAs, providing customers confidence that their systems remain stable and continuously available. - Approach to resilience
- Original equipment manufacturers maintain their own practice of resilience which is available on request.
- Outage reporting
- Original equipment manufacturers will provide outage reports in line with their own policies and procedures.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Access restrictions in management interfaces and support channels
- Original Equipment Manufacturers will provide different authentication levels based on role, attribute and rules.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- We will continuously hold the Cyber Essentials accreditation throughout the framework lifetime.
- Information security policies and processes
-
Maintaining accountability and clear decision-making, we maintain comprehensive information security policies covering data protection, access control, incident management, and operational security. All policies are centrally controlled, enforced, and regularly reviewed to ensure ongoing compliance with ISO 27001, NIST CSF, ITIL security management practices, and our Software Security Code of Practice.
All controls and processes are subject to regular internal and external audits in line with:
• Zero Trust Architecture principles
• NIST Cybersecurity Framework alignment
• ISO/IEC 27001-aligned controls
• ITIL v4-aligned service management
• Agile onboarding and enablement practices - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
The services we sell operate a proportionate configuration/change management process designed to maintain security, stability, and traceability. Components supporting services, including devices, cloud services, security tools, configurations, and integrations, are recorded in a central asset/configuration register. This register tracks ownership, purpose, configuration baseline, and lifecycle status.
Changes are assessed before implementation to identify security, availability, or data protection impacts. Changes are reviewed by the designated service and security owner, with risk level, rollback requirements, and approval documented. Security-impacting changes are validated against our security policies and baseline controls before deployment. Post-change checks confirm successful implementation and no unintended security degradation. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Excelsior Solutions does not host or operate the underlying software platforms and does not deploy patches into customer environments. Vulnerability management for the resold services is performed by the OEMs in line with their processes. We monitor OEM security advisories and supplier notifications, and we communicate relevant vulnerability and patch information to buyers where it impacts licensing, service continuity, or customer assurance. Where customers request it, we support coordination of OEM-led remediation actions, including escalation, change planning support, and confirmation of resolution. Buyers retain control of configuration decisions and any customer-managed components such as identity integrations, endpoints, and access policies.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Our OEM partners protective monitoring approach provides effective threat detection while remaining proportionate to the size of our organisation.
We identify potential compromises through continuous monitoring of security alerts generated by our cloud platforms, endpoint protection, identity systems, and network security controls. Automated alerts are reviewed to detect unusual activity such as unauthorised access attempts, anomalous logins, or unexpected configuration changes. Potential compromises are immediately investigated, affected access is restricted or revoked, and containment actions are taken. Incidents are escalated to the designated security owner, with initial response actions typically initiated within hours and critical incidents addressed immediately. - Incident management type
- Supplier-defined controls
- Incident management approach
- OEM partners incident management process is designed to be clear, repeatable, and appropriate for a small organisation. We maintain pre-defined procedures for common security events such as suspected phishing, access attempts, device loss, and malware alerts, ensuring incidents are handled consistently. Users report incidents through designated internal contacts and shared communication channels, enabling rapid awareness and escalation. All incidents are logged and reviewed by the assigned security owner, who coordinates response and recovery actions. Where required, we provide concise incident reports that document the nature of the incident, actions taken, impact, and lessons learned, supporting transparency, accountability, and continuous improvement.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- This will be subject to original equipment manufacturer rules and service offerings.
- Link to free trial
- This will vary according to the original equipment manufacturer.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 28%
- Over £5,000,001
- 35%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Plans for positive actions with community groups.
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Introducing transparency to pay and reward processes
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-