Skip to main content

Help us improve the Digital Marketplace - send your feedback

Brookcourt Solutions

Secure Email Relay - Proofpoint

Proofpoint Secure Email Relay (SER) consolidates and secures transactional emails. It prevents compromised third-party senders from sending malicious email using your domains and enables DKIM signing to help you meet DMARC compliance. As a hosted solution, Proofpoint SER helps you achieve your cloud migration initiatives.

Features

  • Security and compliance controls on emails that use your identity
  • Integrates third-party SaaS partners such as Salesforce, ServiceNow and Workday
  • Service includes invoices, authentication codes, confirmations and the like
  • Extend protection to your customers and partners.
  • Stop email fraud targeting your employees, customers, and partners.
  • Maintain the trust people place on your email communications.

Benefits

  • Secures transactional email from internal applications
  • Secures transactional email from SaaS providers- Salesforce, ServiceNow and Workday.
  • Accelerates DMARC implementation by enabling DKIM signing of emails
  • Enables DKIM-signing of emails from all sources prior to sending
  • Secures your trusted domain from abuse involving compromised senders
  • Secures from vulnerable email service providers on your SPF records
  • Protects sensitive data in application emails with payload encryption/DLP
  • Replaces on-premises relays with a secure, cloud-based alternative
  • Prevents disruption of user-mail by isolating from your application mail

Pricing

£44,640.00 a gigabyte a year

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at contact@brookcourtsolutions.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 14

Service ID

2 5 3 0 8 7 7 2 2 0 4 4 2 4 4

Contact

Brookcourt Solutions Phil Higgins
Telephone: 01737 886111
Email: contact@brookcourtsolutions.com

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Extension to messaging platform services – eg On Premise Exchange, Office 365, Google Apps
Cloud deployment model
  • Private cloud
  • Community cloud
Service constraints
See Service Level Agreement
System requirements
Existing mail server, eg; Exchange, o365, Zimbra, Lotus Notes

User support

Email or online ticketing support
Email or online ticketing
Support response times
Dependant on Service Level Purchased.
- Support Portal - All Levels
- Telephone Support Business Hours
- Telephone Support 365x24x7
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Self-Service, Platinum, Premium & Global
Self-Service: primary access via portal, phone support limited to business hours P1 issues, 2 authorised support contacts.3
Platinum: access via portal and phone, phone support for all priorities during business hours plus P1 issues 24x7, 4 authorised support contacts.
Premium: access via portal and phone, phone support for all priorities during business hours plus P1 issues 24x7, 6 authorised support contacts, assigned Technical Account Manager.
Global: available to Platinum and Premium only. phone access for all cases, all priorities 24x7x365, 12 authorised support contacts.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Installation and training / knowledge share available with dedicated engineer
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Data extraction tools driven by customer.
End-of-contract process
Services cease to function.

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • MacOS
  • Windows
  • Windows Phone
  • Other
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
None
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
Utilisation of a reporting dashboard - eg Palo Alto
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
No
Customisation available
No

Scaling

Independence of resources
All Proofpoint SaaS systems are actively monitored with local agents collecting hundreds of metrics specific to hardware, networking, and OS. All metrics are measured against a baseline compiled from historical data. Acceptable thresholds are defined based on a combination of optimal performance targets and historical baselines.

Analytics

Service usage metrics
Yes
Metrics types
Granular Reporting of message flow, deep analysis into threats.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Proofpoint

Staff security

Staff security clearance
Other security clearance
Government security clearance
Up to Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Other
Other data at rest protection approach
Information upon request
Data sanitisation process
Yes
Data sanitisation type
  • Explicit overwriting of storage before reallocation
  • Deleted data can’t be directly accessed
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data export approach
Data extraction tools driven by customer.
Data export formats
Other
Data import formats
Other

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
  • Other
Other protection between networks
Proofpoint has documented information security program consisting of policies, procedures and standards that aligns with the requirements of NIST 800-53 and ISO 27001. The program is owned by the Proofpoint Global Information Security group, and includes a continuous monitoring program consisting of monthly and quarterly evidence collection and review, and an annual SOC 2 Type II audit of the program.
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
https://www.proofpoint.com/sites/default/files/general_terms_hosted_services_sla_-_mar_2016.pdf
Approach to resilience
https://www.proofpoint.com/sites/default/files/general_terms_hosted_services_sla_-_mar_2016.pdf
Outage reporting
https://www.proofpoint.com/sites/default/files/general_terms_hosted_services_sla_-_mar_2016.pdf

Identity and authentication

User authentication needed
Yes
User authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
All access to the Proofpoint production environment, where services are hosted, is via a 2FA encrypted VPN and granted based on role.
Access restriction testing frequency
At least once a year
Management access authentication
  • 2-factor authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Description of management access authentication
All access to the Proofpoint production environment, where services are hosted, is via a 2FA encrypted VPN and granted based on role.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber essentials plus
No
Other security certifications
Yes
Any other security certifications
SOC 2 Type II audit report, available here: https://go.proofpoint.com/soc2_report_request.html

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Proofpoint has a documented information security program that broadly aligns with the requirements of NIST 800-53 and ISO 27001.
Information security policies and processes
Proofpoint's information security program is aligned with the requirements of NIST 800-53 and ISO 27001. However, we are not certified to the ISO 27001 standard.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Proofpoint has a documented change management policy that includes requirements around documented change tickets and review and approval by the Change Review Board.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Proofpoint performs internal and external vulnerability scanning and remediates applicable findings in line with the Proofpoint patch management policy.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Proofpoint has distributed monitoring in place for availability, performance, capacity and security. Alerts are directed to a 24x7 NOC or SOC for review, remediation and/or escalation.
Incident management type
Supplier-defined controls
Incident management approach
Proofpoint has a documented Incident Response Plan that includes procedures to detect, investigate, remediate and communicate security incidents. A trained IRT team is responsible for the maintenance of the program.

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Social Value

Social Value

Social Value

  • Covid-19 recovery
  • Equal opportunity
  • Wellbeing

Covid-19 recovery

As Proofpoint has grown, so have our programs continued to evolve to meet our colleagues’ needs, which we believe is essential to attract and retain employees of the highest caliber. We regularly and frequently communicate with and listen to our employees through small group surveys, interactive forums and townhalls, emails and online resources, to then iterate our processes and programs to improve the employee experience. For example, at our weekly townhall meetings, our CEO and other members of the executive team engage our global workforce with updates on the COVID-19 pandemic, our ongoing business operations, and other topics of interest. Over the past year the employee experience has changed. They have encountered, observed and felt a transition from our traditional programs to virtual offerings that employees and their families can participate in, balancing a mix of live and on-demand activity. These online programs include educational classes taught by our fellow colleagues, mental health courses (mindfulness, resilience, meditation), cooking classes, financial well-being support, and “Vacation at Home” ideas. We realized that many of our parents sometimes need a little additional support, and because of this, Proofpoint created programming for Proofpoint kids, which included week-long STEAM camps during the summer, and offered ongoing story time, trivia games, art and dance, writing and oral presentation classes. We launched in the summer of 2020, ProofpointEDU, a series of classes for Proofpoint kids taught by Proofpoint employees including topics like math, science, history, and cybersecurity for kids ages 5-15. Further, we introduced virtual team building programs such as trivia, bingo, escape rooms, and other group activities, all done via Zoom. Our Mindfulness program included music concerts, meditation, and resilience training. In recognition of what we created for our employees, in July 2020, Proofpoint won the Espresa Innovation and Excellence Award for Culture Benefits.

Equal opportunity

We embrace and foster the diversity of our team members, customers, stakeholders and consumers. Everyone is valued and appreciated for their unique backgrounds, experiences, thoughts and talents, all of which contributes to the growth and sustainability of our business. We strive to cultivate a culture and vision that supports and enhances the Company’s ability to recruit, develop and retain diverse talent at every level. As a global and distributed workforce, we recognize and celebrate our team members, their varied backgrounds and cultures. Our career development opportunities are designed to foster inclusivity through ongoing career conversations that actively advance and develop people of all backgrounds. We believe that diversity, inclusion, and opportunity is a journey and we are committed to building a diverse and inclusive company and society for our employees, customers, partners, and shareholders. In order to create a more diverse and inclusive work environment, we provide education, training and tools so that all employees can become aware of bias, how it exists and how to mitigate it. As we continue to shape our work environment and world-class organization to be more inclusive and inviting, we are actively striving to build an extensive pipeline of talent through various programs. Our internal programs enable and empower our hiring managers to identify alternative and emerging talent pools and to create an inclusive candidate experience.

Wellbeing

Together with our employees we are building a secure future, and it starts with securing our most important asset—our people. Our commitment to wellbeing is built on a foundation of helping employees get access to great programs and resources for maintaining their health. We offer global programs that provide and enhance a healthy, balanced lifestyle. Our localized benefits keep both the individual and family in mind, so our employees can take full advantage of what matters most to them, for where they are in life. We offer employer-paid life, disability and employee assistance programs. We also offer global programs for our employees’ physical, mental and financial health. Since the COVID-19 pandemic was declared in early 2020 and our employees began working from home, we quickly transitioned to virtual offerings that employees and their families can participate in. These online programs include educational classes taught by our fellow colleagues, mental health courses (mindfulness, resilience, meditation), cooking classes, financial wellbeing support, and “Vacation at Home” ideas. Realizing that many of our parents sometimes need a little additional support, Proofpoint created a series for Proofpoint kids, which included week-long STEAM (Science, Technology, Engineering, Art and Math) camps during the summer, and offers ongoing story time, trivia games, art and dance classes. Also launched in the summer was ProofpointEDU, a series of classes for Proofpoint kids taught by Proofpoint employees including topics like math, science, history, and cybersecurity for kids ages 5-15. All of our programs are a balanced mix of live and on-demand activity.

Pricing

Price
£44,640.00 a gigabyte a year
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Full service offering as a Proof of Concept for 2 weeks as standard at customers request
Link to free trial
Provided by a Proofpoint Engineer once requirements are confirmed or via Brookcourt Solutions.

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at contact@brookcourtsolutions.com. Tell them what format you need. It will help if you say what assistive technology you use.