DataOps Excellence: Premium Database Administration Service
Comprehensive database administration for enterprises seeking optimal data management, security, and scalability. Ideal for organisations requiring expert oversight, proactive tuning, and seamless database lifecycle management.
Features
- 24/7 proactive database monitoring and incident response
- Automated backup, recovery, and disaster resilience strategies
- Performance tuning for complex, mission-critical workloads
- Regular security audits and vulnerability management
- Advanced database patching and version upgrades
- Robust user access control and role management
- Seamless integration with DevOps pipelines and CI/CD
- Capacity planning and predictive resource optimisation
- Comprehensive compliance and audit reporting
- Expert support for hybrid, cloud, and on-prem environments
Benefits
- Minimise downtime with rapid incident detection and resolution
- Protect vital data assets against loss and security threats
- Accelerate application performance for superior user experience
- Mitigate compliance risks with up-to-date security practices
- Reduce operational overhead via automated maintenance tasks
- Ensure data integrity with zero-compromise user access control
- Enable agile development through integrated DevOps support
- Maximise resource use and control infrastructure costs
- Confidently pass audits with transparent, automated reporting
- Future-proof your data estate for evolving business needs
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 7 3 2 4 5 2 1 1 8 0 9 9 7 2
Contact
INSIGHT DIRECT (UK) LTD
Public Sector Tender Team
Telephone: 0344 846 3333
Email: pstenderteam@insight.com
About your service
- Service categories
-
Application Development and Deployment
Data management
Database administration and development
- Database Administration
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- Requires access to source databases, supporting infrastructure, and relevant IT stakeholders.
- System requirements
-
- Requires valid software licenses for all deployed applications.
- Anti-virus solution must be installed on machines.
- Insight's ServiceNow ITSM preferred and integrated for service requests.
- Multi-Factor Authentication is mandatory for all system access.
- Data encryption must be enabled for storage and transmission.
- Operating systems must be supported: Windows, Linux, macOS.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Insights Managed Service response times are detailed at the below web link :
https://www.insight.com/en_US/help/managed-services-service-levels-and-requests.html - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
Our web chat support has undergone testing with assistive technology users to ensure it meets accessibility standards and provides an inclusive experience. We have collaborated with users who rely on screen readers and other assistive tools during the testing phase. Feedback from these users has been instrumental in optimising the web chat interface for better navigation and usability.
Key improvements include ensuring that the chat interface is fully compatible with screen readers, allowing users to easily read messages and navigate through conversation history. We have also implemented keyboard navigation features, enabling users to engage with the web chat without relying solely on a mouse.
Regular testing and updates are part of our commitment to accessibility, ensuring that our service remains compliant with WCAG 2.2 Level AA standards. We actively seek feedback from users with disabilities to further enhance the accessibility of our web chat support. This demonstrates our dedication to providing equitable access to all clients, fostering an inclusive environment in our service delivery. - Onsite support
- No
- Support levels
-
We provide three support levels: Standard, Enhanced, and Premium. The Standard level offers basic support with response times tailored to critical issues. Enhanced support includes faster response times and proactive monitoring. Premium support provides the highest level of service, including dedicated resources and priority incident resolution.
Each support level is designed to cater to varying operational needs and complexities. A technical account manager is available for Enhanced and Premium support levels to ensure a seamless experience and facilitate ongoing service improvements. For Standard support, a cloud support engineer is assigned to assist with technical queries and operational issues. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
To help users start using our service, Insight provides a comprehensive onboarding process tailored to their needs. We offer both onsite and online training sessions, ensuring that users can choose the method that works best for them. Our onboarding includes detailed user documentation in various formats, including PDF and Word, which outline the functionality of our service, as well as best practices for effective use.
During the onboarding phase, we engage clients through structured training grounded in Adoption & Change Management principles, which ensures that all stakeholders are equipped with the knowledge and skills necessary to maximise the benefits of our service. Additionally, clients have access to our ServiceNow portal for submitting service requests, which is designed to be user-friendly and compliant with WCAG 2.2 Level AA standards, further enhancing accessibility.
We believe that a well-supported onboarding process is crucial for user satisfaction and long-term success, and we are committed to providing the resources needed to facilitate a smooth start with our managed services. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- At the end of the contract, users can extract their data through a well-defined process initiated by Insight. We provide a structured offboarding procedure that includes data retrieval as part of our commitment to ensure a smooth transition. Clients will receive detailed guidance on how to access and download their data, which can be facilitated through our ITSM system, ServiceNow. Additionally, we ensure that data extraction is secure and compliant with relevant standards, with data encrypted at rest and in transit. The offboarding documentation will outline the necessary steps and support available to assist users in this process, ensuring all data is retrieved effectively before access is removed.
- End-of-contract process
- At the end of the contract, Insight will initiate a structured offboarding process, which is included in the contract price. This includes the transfer of any relevant documentation, data retrieval, and the removal of access to systems and services. Clients will receive a final report detailing the services rendered and any outstanding items. Any additional costs may arise if the client requires extended data retention beyond the standard period or if specific requests for additional support services are made during the offboarding process. Insight is committed to ensuring a smooth transition and will work closely with the client to fulfil any end-of-contract obligations.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Our mobile service offers a streamlined experience tailored for smaller screens, ensuring ease of access to key functionalities. While the core features remain consistent with the desktop version, the mobile interface is optimised for touch navigation, allowing users to manage requests and incidents efficiently on the go. Additionally, certain advanced features may be simplified or restructured to enhance usability and performance, ensuring users can effectively engage with our managed services from any device.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Our service interface is provided through the ServiceNow portal, which is fully integrated into our clients' ITSM systems. This portal allows users to submit service requests, track incidents, and access support features efficiently. It is built to comply with WCAG 2.2 Level AA accessibility standards, ensuring that all users, including those with disabilities, can navigate and utilise the services effectively. The interface includes features for user authentication, service catalog browsing, and real-time updates, enhancing user experience and operational efficiency.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We have conducted extensive interface testing with users of assistive technology to ensure our managed service is accessible and user-friendly. Our ServiceNow portal, which serves as the primary interface for users, has been rigorously assessed to meet WCAG 2.2 Level AA standards. This testing involved collaboration with users who rely on assistive technologies such as screen readers and alternative input devices. Feedback from these users was integrated into the portal design to enhance navigation, readability, and overall usability. Specific adjustments included optimizing keyboard navigation and ensuring that all interactive elements are easily accessible. By prioritising accessibility in our service design, we aim to create an inclusive environment that empowers all users to effectively engage with our managed services.
- API
- No
- Customisation available
- Yes
- Description of customisation
- Insight works with it clients to ensure our managed services fit the specific needs of their solution during the pre-sales and contracting phase of the buying process.
Scaling
- Independence of resources
- We ensure user independence by implementing a robust resource allocation strategy that includes dynamic load balancing and resource pooling. Our architecture guarantees dedicated resources for each client, preventing performance degradation during peak demand. Additionally, continuous monitoring and proactive management through our 24/7 service operation centre enable us to anticipate and mitigate any potential resource contention, ensuring consistent service delivery. Regular performance optimisation and capacity planning further reinforce our commitment to maintaining service quality regardless of user demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide comprehensive service metrics including performance, availability, and incident response times. Metrics are accessible via our ServiceNow portal, ensuring real-time visibility. Regular reports detail service usage, incident trends, and overall service health. We also track compliance with SLAs, ensuring transparency and accountability. Our approach includes proactive monitoring with 24/7 oversight, allowing us to identify and address potential issues swiftly. Additionally, we retain logs for 6-12 months, providing complete audit trails to support continuous improvement and regulatory compliance.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
- We implement multiple layers of protection for data at rest, including AES-256 encryption to secure sensitive information and ensure confidentiality. Our data is stored in ISO 27001 certified environments, and we enforce strict access controls based on the principle of least privilege. Additionally, we conduct regular security audits and vulnerability assessments to identify and mitigate potential risks. Logs are retained for 6-12 months, providing complete audit trails for compliance and monitoring purposes. We also plan for post-quantum cryptography to future-proof our encryption methods against emerging threats.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export their data using our ServiceNow integration, which includes a fully documented REST API. This allows for safe and efficient data extraction in various formats as required by users. The process is designed to ensure compliance with security standards, maintaining data integrity and confidentiality throughout. Users have the ability to schedule exports or initiate them on demand, depending on their needs. Additionally, the data export process is backed by our adherence to stringent security protocols, including encryption during transit and at rest.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- JSON
- XML
- XLSX
- TXT
- TSV
- HTML
- Parquet
- Avro
- YML
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- JSON
- XML
- XLSX
- TXT
- TSV
- HTML
- Parquet
- Avro
- YML
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- We protect data in transit between the buyer's network and our network using advanced encryption protocols, specifically AES-256 for data at rest and TLS 1.2+ for secure transmission. Additionally, we implement multi-factor authentication (MFA) for all system access, ensuring that only authorised personnel can access sensitive data. Our architecture also includes a proactive monitoring system to detect and respond to any potential threats in real-time, alongside regular third-party penetration testing to identify and mitigate vulnerabilities. These measures collectively enhance the security posture of data exchanged between networks.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- We protect data within our network through a combination of robust access controls, including mandatory multi-factor authentication (MFA) for all personnel. Our systems are monitored 24/7 by an internal and third-party Security Operations Centre (SOC), ensuring rapid detection and response to any anomalies. We employ advanced encryption standards, such as AES-256 for data at rest and TLS 1.2+ for data in transit, to safeguard sensitive information. Additionally, we maintain comprehensive logs with audit trails for 6-12 months to facilitate thorough investigations and compliance checks. Regular security assessments and third-party penetration testing further bolster our defenses.
Availability and resilience
- Guaranteed availability
- We guarantee 99.9% availability for our managed services, supported by our comprehensive Service Level Agreement (SLA). If we fail to meet this guaranteed level of availability, users will receive service credits as outlined in our SLA documentation. Our proactive monitoring system ensures that any potential incidents are identified and communicated within 24-48 hours, minimising disruption to services. Regular maintenance and patching are performed to uphold performance standards, alongside continuous optimisation and capacity planning. Data is encrypted both at rest (using AES-256) and in transit (utilising TLS 1.2+), ensuring the highest security levels. Our commitment to availability is further reinforced by our ISO certifications and Cyber Essentials Plus accreditation, providing additional assurance of our operational reliability.
- Approach to resilience
-
Our service is designed for high resilience through a robust data centre setup that includes redundancy at multiple levels. We utilise geographically distributed data centres, each equipped with failover capabilities, ensuring continuous operation during outages. Our infrastructure leverages virtualisation technologies such as VMware, Microsoft, AWS, and Google, allowing for dynamic resource allocation and load balancing.
Each data centre is connected via high-speed links, enabling seamless data replication and backup procedures. We implement rigorous disaster recovery protocols, including regular testing of recovery plans to minimize downtime. Our 24/7 monitoring system, combined with proactive incident management, ensures rapid response to any potential disruptions.
For security, we follow best practices including Cyber Essentials Plus certification and encryption standards (AES-256 for data at rest and TLS 1.2+ for data in transit). This comprehensive approach guarantees our services remain available and resilient, meeting the high standards required for government operations. Detailed specifications of our data centre resilience can be provided upon request. - Outage reporting
- Our service reports any outages through multiple channels to ensure transparency and timely communication. We maintain a public dashboard that provides real-time updates on service status and any ongoing incidents. Additionally, our fully documented REST API allows clients to programmatically access outage information, ensuring they have the data they need at their fingertips. For immediate notifications, we offer email alerts directly to our clients, informing them of any critical outages and subsequent updates. This multi-faceted approach ensures that clients are kept informed and can take appropriate actions during service interruptions.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Other
- Other user authentication
- Users are authenticated through a robust multi-factor authentication (MFA) process, ensuring secure access to our services. This requires users to provide two or more verification factors, which may include something they know (password), something they have (security token or mobile device), or something they are (biometric verification). Our identity and access management protocols are designed to adhere to the highest security standards, including Cyber Essentials Plus and ISO 27001, safeguarding user sessions and maintaining data integrity throughout the authentication process.
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted through multi-factor authentication (MFA) for all users. Role-based access controls ensure that only authorized personnel can access sensitive management functions. Additionally, all access is logged with complete audit trails retained for 6-12 months, allowing for transparency and accountability. Regular reviews of access permissions are conducted to maintain compliance with security standards.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Other
- Description of management access authentication
- Management access is authenticated through Multi-Factor Authentication (MFA), ensuring that only authorized personnel can gain entry to sensitive management functions. This process requires users to provide multiple forms of verification, such as a password and a security token or mobile device. Additionally, all management access is logged, with complete audit trails retained for 6-12 months to maintain accountability and transparency. Regular audits of access permissions ensure compliance with security standards, reinforcing our commitment to safeguarding data and services.
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- ISO/IEC 27001, NIST Cybersecurity Framework, GDPR, PCI DSS, and ISO 9001.
- Information security policies and processes
-
Insight follows a comprehensive suite of information security policies and processes aligned with best practices and regulatory requirements. Our security governance is anchored by Cyber Essentials Plus certification and ISO 9001, 27001, 20000, and 14001 standards. We implement a structured reporting hierarchy, where the Chief Information Security Officer (CISO) oversees security strategy and compliance, ensuring policies are consistently enforced across all operations.
We employ multi-factor authentication (MFA) for all system access, reinforcing our commitment to secure identity and access management. Regular security training and awareness programs are conducted for all staff, ensuring they are well-versed in our security protocols. Additionally, we utilise a Security Operations Centre (SOC) that operates 24/7, continuously monitoring for anomalies and potential threats.
Incident reporting is a critical component of our policies, with stakeholders notified within 24-48 hours of confirmed incidents, ensuring transparency and accountability. Our policies undergo regular reviews and updates to adapt to evolving security landscapes, thereby maintaining our high standards of security assurance. Through these measures, we ensure that our information security policies are not only robust but are also actively adhered to throughout the organisation. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Our configuration and change management processes involve tracking service components through a comprehensive asset management system, ensuring each component's lifecycle is documented from deployment to decommissioning. Changes are assessed for potential security impacts through a risk assessment framework. Each proposed change undergoes a review process, including security impact analysis, prior to approval. This ensures that all modifications maintain compliance with our security standards and do not introduce vulnerabilities. Regular audits and compliance checks are conducted to reinforce the integrity of our configuration management practices.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Our vulnerability management process includes regular assessments of potential threats through automated scanning tools and threat intelligence feeds from reputable sources. We deploy patches within 24 hours of their release, following a risk-based assessment to prioritise critical vulnerabilities. We gather information about potential threats from industry-standard repositories, security bulletins, and third-party security advisories. This proactive approach ensures that our services remain secure and resilient against emerging threats, safeguarding client data and operational integrity.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Our protective monitoring processes involve continuous surveillance utilizing advanced detection tools to identify potential compromises. We aggregate and analyse security logs from our ITSM system, ServiceNow, alongside third-party SOC insights for early threat detection. Upon identifying a potential compromise, we initiate an incident response protocol, notifying relevant stakeholders within 24-48 hours. This includes containment, eradication, and recovery steps managed by our security-cleared personnel. Our proactive approach ensures rapid identification and mitigation of risks, maintaining a secure operational environment for our clients.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Our incident management processes include predefined procedures for common events, enabling efficient and consistent handling of incidents. Users can report incidents through our ServiceNow portal, ensuring a streamlined and accessible reporting mechanism. We provide detailed incident reports following the resolution of incidents, which include a summary of the event, actions taken, and any recommendations for future prevention. This approach enables continuous improvement while maintaining clear communication with users throughout the incident lifecycle.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Atlas
- ISO/IEC 27001 accreditation date
- Sunday 13 April 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Atlas
- ISO 9001 accreditation date
- Tuesday 1 April 2025
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Be7ce590-de10-486e-8431-2e10891a8979
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Cd8b1a78-44c7-4bb0-84d6-59a7506f3bba
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
-