Skip to main content

Help us improve the Digital Marketplace - send your feedback

iomart Managed Services Limited

CREST Penetration Testing and Vulnerability Assessment

We provide CREST approved penetration testing across cloud, web applications and infrastructure. Our point-in-time simulated attack provides insight and assurance to the identified assets. We replicate common and sophisticated tactics, techniques and procedures (TTPs) used by real threat actors, attempting to exploit vulnerabilities. All tests are evidenced with remediation activities.

Features

  • UK-based, security cleared (SC) penetration testers.
  • CREST, CRT, CCT INF and CCT APP penetration testers.
  • IT health check across physical and cloud infrastructure.
  • Identify exploitable security weaknesses targeted by cyber attackers.
  • Vulnerability assessment of public facing systems and networks.
  • Ad-hoc or routine penetration testing services.
  • External Infrastructure Testing & Internal Infrastructure Testing.
  • Network Device Configuration Review, Build Review Testing.
  • Spear Phishing Campaign, Mobile Application Testing, Cloud Configuration Review.
  • Web Application Penetration Test (OWASP), Physical Access Testing.

Benefits

  • Evidence based test reports supported by remediation activities
  • Adherence with CREST penetration testing standards and practices.
  • Support compliance with GDPR, ISO 27001, PCI DSS.
  • Increased quality assurance through regular penetration testing.
  • Actionable and strategic recommendations to support business security.
  • Highly experienced UK-based penetration testing consultants with Security Clearance (SC).
  • Prevent intrusion and exploitation of business critical assets.
  • Evidence to support prioritisation of business risk.
  • Provides assurance on new or existing IT assets.
  • Increased service up-time through proactive prevention and detection.

Pricing

£950.00 a unit a day

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gcloud@iomart.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 14

Service ID

1 6 1 0 4 7 2 7 9 0 1 3 8 6 1

Contact

iomart Managed Services Limited Seema Griffiths
Telephone: 0800 040 7228
Email: gcloud@iomart.com

Planning

Planning service
Yes
How the planning service works
We work with the customer to ensure the penetration test we supply are planned in accordance with their needs and their environment. During the initial stages of communication, we will share a scoping questionnaire that allows our testers to understand the intended target requirements and complexity of the customers environment.
A proposal penetration test will be supplied, highlighting the penetration tests we believe to be the most viable for the customers’ requirements, as well as a set amount of days to conduct the test against. These days are based on the size and complexity of the chosen target to be tested against and will be tailored to the customers individual needs.
Planning service works with specific services
No

Training

Training service provided
No

Setup and migration

Setup or migration service available
No

Quality assurance and performance testing

Quality assurance and performance testing service
Yes
How the quality assurance and performance testing works
Penetration testing and other vulnerability assessments are a key part of establishing security awareness, robustness and resilience for organisations.
Whilst our penetration tests do not directly replace quality assurance or performance testing, they can complement these efforts by uncovering security-related defects or weaknesses. Uncovering these weak points allows the organisation to fortify their security, further improving their quality assurance and performance testing as an indirect result of penetration testing results.

Security testing

Security services
Yes
Security services type
  • Security strategy
  • Security risk management
  • Security design
  • Cyber security consultancy
  • Security testing
  • Security incident management
  • Security audit services
Certified security testers
Yes
Security testing certifications
  • CHECK
  • CREST

Ongoing support

Ongoing support service
Yes
Types of service supported
  • Buyer hosting or software
  • Hosting or software provided by your organisation
  • Hosting or software provided by a third-party organisation
How the support service works
Reliance Cyber will provide the necessary ongoing cyber security support service to meet your requirements based on the demands of your programme and the service you need. Specific support levels are agreed for each engagement. A dedicated named specialist is assigned as a single point of contact for each engagement.

Service scope

Service constraints
Activities required for the service will be conducted during UK business hours of 09:00 - 17:00.
Customers employees will be expected to share all necessary details in order for our testers to complete their work. We expect swift responses to ensure the ongoing success of the scheduled testing.

User support

Email or online ticketing support
Email or online ticketing
Support response times
Support throughout the assessment will be provided by one of our penetration tester, during UK business hours of 09:00 - 17:00.
Any questions or support in line with this service will also be conducted within these business hours. They aim to get back instantly to any service related questions throughout the lifetime of the engagement.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Support levels
Support services are assumed to be provided during core UK business hours 09:00 - 17:00, Monday to Friday. Should there be the requirement for these support levels to be expanded, this can be discussed and finalised on a case-by-case basis.
The assigned penetration tester will act as the single point of contact throughout the engagement. An Account Manager will also be assigned to help manage the ongoing success of the customers relationship and support with any administrative requirements.

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Reliance Cyber

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Up to Developed Vetting (DV)

Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Alcumus ISOQAR
ISO/IEC 27001 accreditation date
11/09/2018
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
Yes
Other security certifications
No

Social Value

Social Value

Social Value

  • Fighting climate change
  • Covid-19 recovery
  • Tackling economic inequality
  • Equal opportunity
  • Wellbeing

Fighting climate change

iomart recognises the environmental impacts of our business operations and continually seeks to minimise this impact with a commitment to achieving Net Zero by 2050, or earlier. To control and reduce our environmental footprint, iomart implemented a sustainability and energy efficiency programme aligned with a number of the UN Sustainable Development Goals, specifically #13 – Climate Action, which aims to take urgent action to combat climate change. This programme complies with the requirements of ISO 14001:2015 and ISO 50001:2018, which form the basis of iomart’s Energy Management and Environmental Management Systems, respectively. As part of this programme, iomart: • Partners with Schneider Electric to establish carbon reduction targets and implement a roadmap to reduce our overall emissions in alignment with UK Government targets • Purchases Renewable Energy Guarantees of Origin (REGO) certified renewable energy across our entire UK data centre estate, resulting in a 99% decrease in total carbon emissions under the market-based reporting approach since our benchmark year of FY21 • Continues to meet the UK Government Streamlined Energy and Carbon Reporting (SECR) requirements, including energy use and carbon emissions information in its annual report • Carries out assessments under the Energy Savings Opportunity Scheme (ESOS), administrated by the Environment Agency to identify tailored measures to save energy and achieve carbon savings • Operates an ongoing programme of energy efficiencies across its data centre estate, including the installation of LED lighting and the upgrade of UPS battery power systems • Has relocated its headquarters to a more sustainable premises with green commuting encouraged • Maintains responsible business operations including recycling/segregation of waste, considering environmental factors during the procurement process and encouraging employee involvement in energy efficiency improvement initiatives • Is rolling out new initiatives to reduce environmental impact, including the installation of solar panels at its flagship data centre

Covid-19 recovery

iomart recognises the continued impact of Covid-19 on communities, businesses and staff. Having implemented a Business Continuity Plan aligned with ISO 22301 best-practice guidelines, iomart was able to seamlessly transition to a remote working policy for the majority of employees at the start of the global pandemic. Safe working practices were introduced for those working at our data centre sites to support Critical National Infrastructure during this time. Reflecting on this era, iomart recognised that many employees value the ability to work from home. In response, iomart introduced a hybrid working policy in order to balance the needs of the business with the flexibility for employees to work both from the office and remotely. As a managed services provider, iomart continues to provide the necessary infrastructure and support to many customers which allow them to offer their staff remote and hybrid working, enjoying the same benefits as many iomart employees. Having provided many customers with financial initiatives to delay invoice payments during the pandemic to help with their cashflow, iomart played a pivotal role in ensuring that a significant number of small and medium business continue trading today and continues to work closely with them to provide business-critical services. iomart continues to partner with the organisation Business Volunteers to support various charities within the local communities in which it operates. Through numerous volunteering engagements, iomart employees have supported a food-growing charity to encourage families to get outdoors, exercise and grow healthy food. They have contributed towards the rejuvenation of the site with a new seating space and raised beds, repairing compost bins and digging up areas that had overgrown. Our teams have also volunteered at a food bank warehouse, taking in food and household items and distributing parcels to local organisations that provide essential support to families, post Covid-19.

Tackling economic inequality

iomart takes its responsibility in this areas very seriously and is committed to acting ethically and with integrity in all of our business relationships. This commitment and subsequent efforts to operate responsibly are fulfilled through the operation of corporate governance processes and ISO-certified business procedures. iomart has implemented robust controls and checks, including continual monitoring, to ensure that there is no modern slavery or human trafficking in its supply chain or in any part of the business. We conduct internal risk and material assessments within our supply chain, requiring suppliers to undergo a due diligence process prior to product or service provision. Employees are paid fairly, with salaries paid directly into their own bank accounts. Cyber security risks are identified and managed via iomart’s Information Security Management System which is based on the requirements of ISO 27001, an internationally-recognised standard governing the protection of personal records and sensitive information. Conformity with this rigorous security standard is monitored continuously and assessed by iomart’s UKAS-accredited certification body, providing external assurance of the controls validated. iomart operates an Equality, Diversity and Inclusion programme which is aligned with the United Nations Sustainable Development Goal #8 - Decent Work and Economic Growth – which promotes sustained, inclusive and sustainable economic growth, full and productive employment and decent work for all. Actions and initiatives to support this goal include: • Mentoring partnerships with MCR Pathways, supporting equality of education outcomes, career opportunities and life chances • Regular engagements with SmartSTEMs, a charity which aims to provide equity of access and opportunity for all young people to STEM education and career opportunities • Partnership with and recruitment via Generation, a non-profit organisation transforming education to employment systems to prepare, place and support people into life-changing careers that would otherwise be inaccessible

Equal opportunity

iomart is committed tackling workforce inequality. Closely aligned with the United Nations Sustainable Development Goal #5 - Gender Equality, which aims to achieve gender equality and empower all women and girls, iomart’s approach aims to shine a spotlight on diversity, inclusion, belonging and talent whilst ensuring our policies, recruitment and frameworks are free from bias. To achieve this, iomart: • Operates a diversity and inclusion strategy devised to reduce any real pay gap in the longer term, with an annual Gender Pay Gap report published annually • Has implemented measures to monitor key demographic data, which allows us to set targets to improve representation in key areas • Continues to refresh and expand our employee networks, working towards a gender balance of 30% female representation by 2030 whilst tracking diversity statistics to ensure informed decision making across the business. • Partners with Empowering You, an organisation aiming to build an empowered community of diverse, authentic and confident leaders who can inspire a meaningful and sustainable cultural shift that benefits their organisation, wider industry and society at large • Has implemented an Equal Opportunities Policy in accordance with the Equality Act (2010) • Provides training for managers to better understand neurodivergent and disabled employees’ needs • Publishes a statement on Modern Slavery in accordance with section 54(1) of the Modern Slavery Act 2015, reflecting iomart’s commitment and efforts to operate responsibly • Redacts demographic information from CVs to reduce unconscious bias during the recruitment process • Operates a flexible working policy to promote a healthy work-life balance whilst allowing staff to fulfil other duties outside the workplace such as childcare and supports them working to their individual strengths

Wellbeing

iomart promotes the wellbeing of our people though a number of employee benefits and initiatives that impact physical and mental health. These include: • An Employee Assistance Programme with 24/7 support • A cycle to work scheme, with Head Office facilities designed to encourage green commuting • Enhanced benefits with length of service, such as medical and dental cover • Neurodiversity training • Flexible and hybrid working policies to promote a healthy work-life balance This commitment to wellbeing is extended throughout our local communities whereby iomart actively participates in charity engagement and volunteerism. Through our partnership with Business Volunteers, iomart works with local charities to support strong, integrated communities. We began hosting Volunteer Days at our Glasgow and Manchester sites in 2021. We have cooked and served Christmas dinners vulnerable people in Manchester and volunteered at the Glasgow Community Garden Trust to support a food-growing charity in encouraging families to get outdoors, exercise and grow healthy food. Employees helped to rejuvenate the site with a new seating space and raised beds, repairing compost bins and digging up areas that had overgrown. Additionally, iomart worked with FareShare UK to help deliver food that would prepare 40,000 meals for people in need. To further promote the physical health and wellbeing of staff and the wider community, iomart seeks to develop more sustainable business operations intended to reduce its environmental footprint.

Pricing

Price
£950.00 a unit a day
Discount for educational organisations
Yes

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gcloud@iomart.com. Tell them what format you need. It will help if you say what assistive technology you use.