Skip to main content

Help us improve the Digital Marketplace - send your feedback

E2E SECURITY CONSULTING LTD

E2ERisk GRC - Governance, Risk, Compliance (GRC) Platform

E2E Risk – GRC tool is a cost-effective governance, risk and compliance (GRC) software suite from E2E Security Consulting (E2E SC). It provides a highly configurable platform to manage risk, controls, assurance and compliance, actions, policies and performance, enabling consistent processes, clear ownership and improved organisational oversight.

Features

  • Integrated view of governance, risk, compliance and controls
  • End-to-end risk assessments across strategic, project and operations
  • Assign, track and manage risks with clear ownership
  • Centralised management of controls, actions and assurance
  • Evidence compliance against regulatory and standards requirements
  • Policy management with ownership, review cycles and attestation
  • Real-time dashboards for enterprise GRC and risk performance
  • Outcome-focused GRC improving accountability and decision-making
  • Proactive risk insight reduces unexpected loss and liability
  • Increased assurance for leadership and external stakeholders

Benefits

  • Provides a single, trusted source for enterprise GRC information
  • Reduces administrative effort through streamlined GRC processes
  • Improves risk visibility, enabling informed and timely decisions
  • Strengthens accountability through clear ownership of risks and actions
  • Supports demonstrable compliance with regulations and standards
  • Reduces likelihood of unexpected financial or operational losses
  • Enhances assurance for senior management and external stakeholders
  • Enables consistent risk assessment across the organisation
  • Improves governance maturity and control effectiveness
  • Scales easily to support changing organisational needs

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at dave.mccaw@e2esc.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 5 9 5 5 9 9 5 0 4 9 1 8 0 1

Contact

E2E SECURITY CONSULTING LTD dave mccaw
Telephone: 07502142901
Email: dave.mccaw@e2esc.co.uk

About your service

Service categories

Applications

Content workflow and management

Enterprise portals and digital workspaces

  • Multi-Audience Portals
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
E2ERisk GRC platform can be used as a fully standalone service. Where required, it may optionally integrate with the wider E2ERisk GRC platform or other governance, risk, and compliance tools, but it does not depend on any other software service to operate.
Cloud deployment model
Public cloud
Service constraints
The service is designed to deliver 99.9% availability, with scheduled maintenance outside normal business hours and customers notified in advance. Users must access the service using a modern, supported web browser. No other material constraints apply.
System requirements
  • Access requires a modern, supported browser (Chrome, Edge)
  • Multi-factor authentication (MFA) is required via SMS or authenticator app

User support

Email or online ticketing support
Yes
Support response times
All support requests are acknowledged and responded to within four business hours of receipt
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
All support is available via email or telephone. Requests are categorised as general queries or support tickets (P1–P4) in line with our terms and prioritised accordingly. Support is included in the standard subscription at no additional cost. Enterprise customers are assigned a dedicated technical Customer Success Manager.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Our dedicated Customer Success team ensures a seamless onboarding experience and delivers expert virtual training. We provide comprehensive onboarding documentation, access to an in-house consultant for tailored support during client adoption, and a rich, continuously updated knowledgebase. This combination of personalised guidance, expert advice, and self-service resources ensures organisations can embed the platform quickly, confidently, and effectively—delivering a superior onboarding and support experience compared to other providers.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
Users can export data directly from the platform in CSV, ODF, or PDF formats, or request a full CSV data dump via their Customer Success Manager. All data export options are included within the standard subscription at no additional cost.
End-of-contract process
At the end of the contract, clients who choose not to renew can export their data—either directly or with assistance from their Customer Success Manager—and have their accounts suspended or deleted. The entire process is managed by the Customer Success team to ensure a smooth transition.
Documentation accessibility standard
EN 301 549

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
EN 301 549
Description of service interface
Users access the platform via a web browser through an intuitive graphical interface
Accessibility standards
EN 301 549
Accessibility testing
We conducted accessibility testing with users, including those using assistive technologies, to evaluate color contrast and keyboard navigation. Users interacted with the platform while our product team observed and collected feedback on any challenges. Identified issues were addressed through subsequent product improvements.
API
No
Customisation available
Yes
Description of customisation
The platform offers a configurable GRC tool, enabling organisations to tailor risk, control, and compliance settings to their specific needs. Users can define risk categories, scoring criteria, thresholds, and approval workflows to align with internal policies and regulatory obligations. This flexibility helps organisations prioritise risks according to their risk appetite and operational context. Configuration changes are applied in real time, ensuring assessments always reflect current organisational preferences. An intuitive interface with guidance and tooltips allows adjustments without technical expertise, while role-based access ensures only authorised personnel can modify settings. Customisable dashboards and reporting views focus teams on the most critical risks while maintaining consistency across the organisation. Automated monitoring and alerts complement these capabilities, helping teams track emerging risks and remediate issues efficiently. By combining flexibility with control, the platform enables organisations to manage risk, compliance, and assurance effectively, aligning with internal frameworks, regulatory requirements, and operational priorities, and providing clear visibility across the enterprise.

Scaling

Independence of resources
The platform is designed to maintain consistent performance for all users, regardless of demand. It leverages scalable cloud infrastructure, load balancing, and resource isolation to ensure that one user’s activity does not impact others. System performance and usage are continuously monitored, and built-in redundancy and failover mechanisms ensure the service remains reliable even during periods of high demand.

Analytics

Service usage metrics
Yes
Metrics types
We provide a range of service metrics, including platform availability, supplier management and onboarding performance, and client-specific insights on how users manage their suppliers.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export their data directly from the platform in multiple formats, including CSV, ODF, and PDF. Exports are performed via the platform’s intuitive interface, allowing users to select specific datasets or full reports. For larger or full data exports, users can request assistance from their Customer Success Manager, who can provide a complete CSV data dump
Data export formats
  • CSV
  • ODF
Data import formats
  • CSV
  • ODF

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
E2ERisk web-based services are guaranteed to be available for at least 98% of each calendar month, excluding scheduled maintenance. “Available” means the platform is operational and core assessment, collaboration, and reporting functions are accessible to users. Availability is measured on a monthly basis. Where the availability target is not met, service credits may apply in accordance with the service level agreement and contractual terms agreed with the customer.
Approach to resilience
The platform is designed for resilience using cloud-native capabilities, including deployment across multiple availability zones and automated failover. Redundancy is built into core components to reduce the risk of service disruption. Detailed configuration and resilience information can be provided to customers under appropriate assurance arrangements.
Outage reporting
Service outages and significant service degradation are communicated to customers via email alerts as the primary notification method. Phone-based notifications can also be provided on request through the Customer Success team. All outage alerting options are included within the standard subscription at no additional cost.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is restricted to authorised personnel only and controlled through role-based access and formal approval processes. Administrative access is protected using secure access controls and network restrictions appropriate to the hosting environment. Support channels are secured using strong authentication controls, including multi-factor authentication. Access permissions are reviewed on a regular basis to ensure continued appropriateness.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials Plus. Governance is aligned with NCSC guidance, the Software Security Code of Practice, and CDDO secure-by-design principles.
Information security policies and processes
Our information security policies are fully aligned with ISO 27001 standards, ensuring that all aspects of the platform, data handling, and organisational processes meet internationally recognised security requirements. We maintain a comprehensive suite of policies covering areas such as data protection, access control, incident response, risk management, and supplier security. These policies are reviewed annually and formally approved by the board, ensuring they remain current, effective, and fully integrated with business operations. Compliance with these policies is closely monitored by the senior leadership team, who receive extensive and ongoing training in information security best practices, regulatory obligations, and emerging threats. Staff across the organisation are regularly trained and assessed to ensure adherence to security policies and procedures. Our approach combines policy, process, and culture to embed security across every level of the organisation. Regular audits, risk assessments, and internal reviews are conducted to identify gaps and implement improvements proactively. This structured, multi-layered approach ensures that client data is consistently protected, operational risk is minimised, and the organisation maintains a robust security posture that exceeds standard compliance requirements.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Configuration and change management is governed through defined processes to ensure the secure and controlled deployment of infrastructure and application changes. Infrastructure is built and maintained using approved, hardened configurations, with an up-to-date software bill of materials maintained. Changes are version controlled and reviewed prior to deployment, and automated tooling is used to identify vulnerable dependencies. Regular vulnerability scanning is performed to support timely remediation and maintain a secure hosting environment.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Vulnerabilities are identified through multiple inputs, including scheduled vulnerability scanning, additional scanning in response to emerging threats, automated monitoring of software dependencies, and monitoring of underlying cloud infrastructure. Identified vulnerabilities are risk assessed and prioritised based on severity and impact. Remediation actions are tracked and implemented in line with defined vulnerability management processes to maintain a secure and resilient service.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Protective monitoring is implemented using security monitoring and detection controls to identify indicators of suspicious or unauthorised activity within the hosting environment. Alerts are reviewed by authorised personnel and investigated in line with defined incident management procedures. Where required, incident response actions are initiated to contain and remediate security events. Monitoring outputs and response actions are logged and reviewed to support continuous improvement of security controls and service resilience.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
A documented incident management process is in place to identify, triage, and respond to incidents. Security incidents are prioritised and handled in line with defined incident response procedures. Customers can report incidents via support channels or through their Customer Success Manager. Following resolution, customers are notified and, where appropriate, provided with a summary of the incident, including root cause information and recommended remediation actions, in line with contractual terms.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
The service offers a free, time-limited trial providing access to the full feature set for evaluation purposes. The trial period lasts up to three months, allowing users to explore the platform, test functionality, and assess suitability before committing to a paid subscription.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
7.5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
11%
Between £2,500,001 and £5,000,000
12%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
    • How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at dave.mccaw@e2esc.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.