Proofpoint Email Fraud Defence
Email Fraud Defence stops email based identity deception. Access to a reporting portal and regular meetings with a Proofpoint consultant help to implement DMARC. Risky suppliers can be identified. SPF and DKIM can be hosted by Proofpoint and there is a Secure Email Relay option bss13
Features
- Support to implement DMARC into Reject Mode
- Supplier risk explorer
- View data from DMARC reports in our portal
- Managed Service
- Hosted SPF
- Hosted DKIM
- Secure Email Relay
- Domain Discover
- Virtual Takedown Service
Benefits
- Protect your domain from being spoofed by attackers
- Identify email risks from your supply chain partners
- Full visibility and control of email sent from your domains
- Get ongoing guidance and support from our Professional Services team
- Overcome DNS limitations for SPF records
- Simplify and standardise authentication for your outgoing email
- Email sent on your behalf is clean and passes authentication
- Discover lookalike, cousin domains attackers are using to impersonate you
- Proofpoint assists in taking down cousin / lookalike domains
Pricing
£8.18 a user a year
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 13
Service ID
2 6 6 8 3 7 1 3 0 5 7 2 4 9 3
Contact
Bytes Software Services
Chris Swani
Telephone: +44 (0) 7951 326815
Email: tenders@bytes.co.uk
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Community cloud
- Service constraints
- No
- System requirements
-
- Capability of routing email to a Proofpoint email gateway.
- Valid delivery destination for email filtered by Proofpoint.
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
-
P1 First Response - 1 hour
P2 First Response - 4 business hours
P3 First Response - 8 business hours
P4 First Response - 16 business hours - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- No
- Support levels
- Support is included in quotes provided for the related Proofpoint products. There is Self Service Support, Platinum Support and Premium Support. Customers with Platinum Support or Premium Support also have the ability to purchase the optional Global Add-On. A Technical Account Manager can also be provided at an extra cost.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Proofpoint Professional Services provides an implementation service. Each customer is aligned with a Professional Services consultant who will onbaord them. There is also online training and documentation provided as well as access to the articles, forums, etc. in the Proofpoint community portal.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Data extraction tools driven by customer.
- End-of-contract process
- Implementation is included in the price of the contract and there is no additional charge for offboarding. At the end of the contract the service ceases to function.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The experience of the Proofpoint email filtering service will be the same no matter how email is accessed (e.g. via desktop or mobile mail clients).
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Administrators can connect to an admin GUI to configure settings. End Users will not be aware of the majority of the email filtering that takes place. End Users may receive an End User Digest email that lists certain types of email addresssed to them (e.g. bulk) that has gone into quarantine since the last digest was generated. End Users may also be given access to the End User Web Application where they can release certain type of emails from quarantine and maintain their own safe and block lists.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Using a web browser.
- Accessibility testing
- Access is via a web browser, so standard web browser accessibility options apply.
- API
- Yes
- What users can and can't do using the API
- Admins can configure an API so that reporting details from Proofpoint email filtering are fed into a SIEM tool.
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- No
- Customisation available
- No
Scaling
- Independence of resources
- Each customer has a separate email filtering cluster just for them as well as their own decicaed IP addresses. The cluster for each customer is sized according to the compute resources needed to handle their mail flow and this can be adjusted if mail flow volumes change.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Various reports are generated on things such Inbound Email Summary, Inbound Spam and Bulk Summary, Inbound Threat Summary, Outbound Email Summary.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Proofpoint
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Up to Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
- AES 256 bit encryption
- Data sanitisation process
- Yes
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation
- Deleted data can’t be directly accessed
- Equipment disposal approach
- In-house destruction process
Data importing and exporting
- Data export approach
- Data extraction tools driven by customer.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- https://www.proofpoint.com/sites/default/files/general_terms_hosted_services_sla_-_mar_2016.pdf
- Approach to resilience
- The services run in active/active mode between a pair of gegraphically-diverse co-location facilities.
- Outage reporting
- https://www.proofpoint.com/sites/default/files/general_terms_hosted_services_sla_-_mar_2016.pdf
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- All access to the Proofpoint production environment, where services are hosted, is via a 2FA encrypted VPN and granted based on role.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- 2-factor authentication
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- Yes
- Other security certifications
- Yes
- Any other security certifications
- SOC 2 Type II audit report
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- The Proofpoint security program is led by the Proofpoint CSO. The program is based on identifying and mitigating risk to our personnel, the organization and the customer.
- Information security policies and processes
- Proofpoint's information security program is aligned with the requirements of NIST 800-53 and ISO 27001.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Proofpoint has a documented change management policy that includes requirements around documented change tickets and review and approval by the Change Review Board.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Proofpoint performs internal and external vulnerability scanning and remediates applicable findings in line with the Proofpoint patch management policy.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Proofpoint has distributed monitoring in place for availability, performance, capacity and security. Alerts are directed to a 24x7 NOC or SOC for review, remediation and/or escalation.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Proofpoint has a documented Incident Response Plan that includes procedures to detect, investigate, remediate and communicate security incidents. A trained IRT team is responsible for the maintenance of the program.
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Social Value
- Fighting climate change
-
Fighting climate change
We take our environmental management and the impact we have on the environment very seriously. We have environmental policies in place and hold the ISO14001 accreditation. Our environmental assessments are conducted annually by an external Lead ESOS Assessor; they are signed-off by the board and compliance reported to the regulator (the Environment Agency). Our environmental policy is published on our website at https://www.bytes.co.uk/company/sustainability/environmental.
Bytes achieved carbon net zero in March 2022 through approved carbon offsetting schemes. We are always seeking to reduce our impact on the environment. We aim to minimise waste, reduce pollutants and use renewable materials. Our offices have recycling facilities for cans, plastic and paper. We aim to reduce our office printing to zero within the next 10 years.
To drastically reduce our emissions, we have switched to renewable energy. Our Head Office has reached our first milestone of using a specialist 100% renewable electricity provider.
Our goal is to achieve carbon neutrality for our business and help our customers achieve this for their own organisations. We pledge to offset carbon emissions through the planting of green space.
We produce a SECR (Streamlined Energy and Carbon Reporting) report that details the companies energy consumption and carbon emissions. This report is produced annually by an independent assessor, Eshcon Ltd.
This report provides details of our emissions in Scope 1, 2 and 3 categories. It details the activities previously taken to reduce emissions and also recommendations for further improvements.
The improvement recommendations highlighted in our latest ESOS assessment have been reviewed and a number have been implemented or are in the process of being implemented. These include more efficient IT equipment, office lighting and efficient climate control systems.
Our plan is to achieve net zero operational emissions by 2025/26
Pricing
- Price
- £8.18 a user a year
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Full service offering as a Proof of Concept for 2 weeks as standard at customers request