Skip to main content

Help us improve the Digital Marketplace - send your feedback

CTI Digital

Web Application Firewall (WAF) and Content Delivery Network (CDN)

We provide Web Application Firewall (WAF) and Content Delivery Network (CDN) services, as well as management of these services and ongoing support. This covers direct provision of the service, and managing existing setups with alternative providers already in use by the buyer.

Features

  • DDoS Protection
  • Web Application Firewall (WAF) and Content Delivery Network (CDN)
  • OWASP Top 10 mitigation
  • Custom WAF profiles for common applications
  • Custom WAF profiles for common attack vectors and libraries
  • Very fast DNS response and full record management
  • Granular implementation of features as required
  • Bespoke performance tools for improved site loads and response times
  • Custom routing behaviour via routing rules
  • Multiple SSL options

Benefits

  • Constant protection from DDoS attacks
  • Protection against the most common OWASP attack vectors
  • Configurable protection specific to your applications and use cases
  • Significant performance boosts through multiple technology routes
  • Responsive protection against emerging threats
  • Better response times for increased global reach and performance
  • Increased mobile response times
  • Filter malicious traffic before it hits your hosting infrastructure
  • Migration assistance, planned go live of functions, and after care
  • Fully managed and administered on your behalf

Pricing

£330 a licence a year

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@ctidigital.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 14

Service ID

2 6 0 7 7 8 7 4 7 2 4 4 0 9 7

Contact

CTI Digital Natalie Kennedy
Telephone: 0161 713 2434
Email: tenders@ctidigital.com

Planning

Planning service
Yes
How the planning service works
An initial audit of what may currently be present through other suppliers will be conducted. Depending upon access provided, a detailed assessment of current usage and best practices will be created.

Meetings with clients to define and understand project scope(s) and requirements will be held. It is important that historical usage and decisions are clear, as well as the current situation and goals, and future requirements with any growth and development plans accounted for.

Existing and predicted challenges will be detailed and a plan put in place to resolve.

A full report and assessment will be provided detailing recommendations for a future setup, with a choice of the most appropriate provider.

A full implementation and roll-out plan will be created with clear timelines and responsibilities at every stage. This is created according to agile project management practices, i.e. with defined sprints and milestones. This will include DNS migration, turning on features in a staged manner to minimise disruption, and working with the buyer to implement features together.

A dedicated team with an assigned Account/Project Manager and a Technical Lead will work with the appropriate client contacts to implement any recommendations and required work with the buyer.
Planning service works with specific services
Yes
Hosting or software services the planning service works with
  • Cloudflare
  • Stackpath
  • Amazon Shield

Training

Training service provided
Yes
How the training service works
This is entirely dependant on the needs of the buyer. An initial training needs assessment will be conducted to determine what areas of training may be needed for the client.

Training plans will then be developed and scheduled, with clear timelines, responsibilities, and agendas.

Multiple methods are available for training delivery and will be provided dependant on the needs of the client, for instance:

In-person workshops - from our Manchester office, or at your premises
Online training sessions via Google Meet or an online meeting platform of your choice if the buyer utilises a different system
Recording training sessions
Training material i.e. pdf guides
Attended training and guidance
Training is tied to specific services
Yes
Services the training service works with
  • Cloudflare
  • Stackpath
  • Amazon Shielf

Setup and migration

Setup or migration service available
Yes
How the setup or migration service works
Similar to our planning services.

Meetings with clients to define and understand project scope(s) and requirements will be held. It is important that historical usage and decisions are clear, as well as the current situation and goals, and future requirements with any growth and development plans accounted for.

Existing and predicted challenges will be detailed and a plan put in place to resolve.

A full report and health check assessment will be provided detailing recommendations for the future setup, and where it relates to the services that are being migrated.

A full migration and roll-out plan will be created with clear timelines and responsibilities at every stage. This will include test migrations, staged delivery, and a detailed go-live plan for the migration(s). After care will also be considered.

A dedicated team with an assigned Account/Project Manager and a Technical Lead will work with the appropriate client contacts to implement any recommendations and required work following completion of the above process with the buyer.
Setup or migration service is for specific cloud services
Yes
List of supported services
  • Cloudflare
  • Stackpath
  • Amazon Shield

Quality assurance and performance testing

Quality assurance and performance testing service
No

Security testing

Security services
Yes
Security services type
  • Security strategy
  • Security risk management
  • Security design
  • Cyber security consultancy
  • Security incident management
  • Security audit services

Ongoing support

Ongoing support service
Yes
Types of service supported
Hosting or software provided by a third-party organisation
How the support service works
Buyers are able to contact via telephone, email, or live chat support during office hours. Out of hours telephone and ticket support is also available where required, on a hosting and/or application level.

Depending on whether the domains are also hosted with ourselves, Domain name and DNS availability are monitored, as well as hosting resource usage and availability, auto-scaling events, and overall system health.

Service scope

Service constraints
Any domains covered by WAF or CDN solutions require DNS to be controlled via the chosen solution provider.

Access to the solution control panels, where available, may not be possible depending on account setup. Needs and the approach required will be determined at the planning phase.

User support

Email or online ticketing support
Email or online ticketing
Support response times
Monday to Friday - 9am - 5pm - 1 business hour
Saturday, Sunday, public holidays - 9am - 5pm - 3 business hours
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Support levels
We only provide fully managed solutions so there are no tiers of support to provide apart from these. Any costs associated with the support required and provided will be included in the cost of the solution itself. Support is triaged by our support team and directed to the appropriate teams for resolution. Specific account managers can be assigned if required for your needs as part of your agreement.

Resellers

Supplier type
Reseller (no extras)
Organisation whose services are being resold
Cloudflare, Stackpath, Amazon Shield

Staff security

Staff security clearance
Other security clearance
Government security clearance
Up to Baseline Personnel Security Standard (BPSS)

Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Centre for Assessment Ltd
ISO/IEC 27001 accreditation date
27/11/2023
What the ISO/IEC 27001 doesn’t cover
Our certification covers all assets, staff and facilities involved with the provision of strategic digital services, specialising in the design, development, marketing, hosting and support of websites on behalf of customers from CTI Digital's Manchester and Lancaster offices.
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
Yes
Other security certifications
No

Social Value

Social Value

Social Value

  • Fighting climate change
  • Tackling economic inequality
  • Equal opportunity
  • Wellbeing

Fighting climate change

We’re investing in strategies to become carbon neutral through the schemes operated externally. Employees are encouraged to use modes of public transport where they are required to travel for business, or to care share. Where feasible, meetings are also facilitated remotely utilising a number of online communication tools. Day to day, more of our employees are working from home, reducing our overall carbon emissions; but when travelling into the office we also promote use of the company’s cycle to work scheme, along with rail and tram season tickets. Further we aim to purchase products and services from third party suppliers that share similar environmental positioning goals as our own.

Tackling economic inequality

We’re mindful of differing needs of all sections of the community when it comes to employment opportunities - we don’t use any auto-decision making in our recruitment process and no vacancies or roles require a University degree which could otherwise limit employment opportunities for those in deprived areas. Offering true flexible working, whether it be reduced hours or altered working hours to fit with childcare and increased working from home. A training and development fund is provided each year for employees to take advantage of and an allotted number of days which can be used for Continued Professional Development, to gain recognised qualifications. Training days are hosted for clients to join and learn new skills (outside of projects) and we continue to operate ‘Lunch and Learn’ sessions internally, for employees to not only learn topics relevant to their role, but their knowledge across wider business services.

Equal opportunity

Our ED&I policy aims to ensure that everyone is aware of our commitment to equality, diversity and inclusion in all our activities; treating all employees and job applicant equally,
All employees are required to undertake mandatory training modules annually. These are: “Equality and Diversity in the Workplace” and “Unconscious Bias”. CTI’s employee-led intersectional ED&I Committee was founded in order to guide CTI on our journey to becoming a truly diverse and inclusive employer, by promoting community and wellbeing for all, championing inclusion throughout the company, celebrating diversity and keeping the Board accountable. They’ll also identify any specific training that they believe would be beneficial for employees to have.

Wellbeing

During employment our workforce receive a range of benefits that aid their financial, physical and mental wellbeing. This includes flexible working hours, cycle to work scheme, life cover and annual subscription to Leafyard (mental wellbeing platform). We have a health cash plan to encourage employees to keep healthy, accessing annual health checks and the ability to claim back for everyday health costs (e.g. eye tests, dental etc.); in addition to access to remote GP services and private health care cover. Our employee assistance programme includes a wellbeing portal which gives all employees access to support for stress, mental health difficulties, financial and legal advice. Across all technologies offered, we make active contributions to digital communities and have fostered great relationships within our partner network; both of which our employees are encouraged to be part of as subject to their role and ongoing CPD.

Pricing

Price
£330 a licence a year
Discount for educational organisations
Yes

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@ctidigital.com. Tell them what format you need. It will help if you say what assistive technology you use.