Comprehensive Endpoint Security Assurance
Holistic endpoint protection for enterprises seeking proactive defence and compliance. Safeguard all user devices against modern threats, tailored to complex IT environments.
Features
- End-to-end device threat assessment and mitigation
- Custom policy design for enterprise-grade device protection
- Advanced malware and ransomware prevention solutions
- Integrated vulnerability scanning and patch automation
- Real-time monitoring and incident response capabilities
- Zero Trust framework integration for endpoint access
- Automated compliance reporting and audit support
- Secure remote device provisioning and deprovisioning
- User behaviour analytics to detect anomalous activities
- Comprehensive endpoint data loss prevention strategies
Benefits
- Reduces the risk of costly security breaches
- Ensures consistent device compliance across the enterprise
- Accelerates threat detection and response times
- Minimizes downtime from cyber incidents
- Improves regulatory and audit readiness
- Enables secure remote and hybrid work models
- Instils user trust through consistent protection standards
- Optimises resource allocation with automated workflows
- Supports digital transformation initiatives securely
- Protects reputation by preventing data exfiltration
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 9 0 2 9 3 2 6 9 9 1 6 3 3 6
Contact
INSIGHT DIRECT (UK) LTD
Public Sector Tender Team
Telephone: 0344 846 3333
Email: pstenderteam@insight.com
About your service
- Service categories
-
Systems Infrastructure Software
Security
- Endpoint security
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- Requires supported modern device OS and network access for full functionality.
- System requirements
-
- Requires valid software licenses for all deployed applications.
- Anti-virus solution must be installed on machines.
- Insight's ServiceNow ITSM preferred and integrated for service requests.
- Multi-Factor Authentication is mandatory for all system access.
- Data encryption must be enabled for storage and transmission.
- Operating systems must be supported: Windows, Linux, macOS.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Insights Managed Service response times are detailed at the below web link :
https://www.insight.com/en_US/help/managed-services-service-levels-and-requests.html - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
"Insight uses ServiceNow for web chat. ServiceNow demonstrates commitment to accessibility through rigorous, multi-faceted testing aligned with WCAG 2.2 AA standards. Their testing methodology combines independent third-party assessments, automated checks, and human evaluation across complete workflows.
Assistive technology testing includes NVDA, JAWS, VoiceOver, TalkBack, and ZoomText, alongside keyboard-only navigation validation. Testing occurs across multiple browsers (Chrome, Safari, Edge Chromium) to ensure broad compatibility.
ServiceNow's Accessibility Centre of Excellence oversees an embedded accessibility approach integrated throughout their Product Development Lifecycle (PDLC). They supplement formal validations with an Accessibility Employee Engagement Panel comprising over 200 employees with diverse disabilities, providing early-stage feedback during development.
Their accessibility roadmap prioritises achieving higher WCAG 2.2 AA conformance levels across all Platform and Products, addressing high-impact defects and embedding automated accessibility testing guardrails. They publish detailed Accessibility Conformance Reports (ACRs) using the international Voluntary Product Accessibility Template (VPAT) standard.
For detailed component-specific compliance documentation, ServiceNow provides Accessibility Conformance Reports available through their compliance team (compliance@servicenow.com)." - Onsite support
- Yes, at extra cost
- Support levels
-
We offer three support levels: Standard, Enhanced, and Premium. Each level provides varying degrees of service responsiveness and features. The Standard level offers basic support with essential service management. The Enhanced level includes proactive monitoring and incident response within shorter timeframes. The Premium level provides the highest level of service, including dedicated resources and faster response times for critical incidents.
Each of these support levels comes with comprehensive service reporting and access to our ServiceNow portal for service requests, which is compliant with WCAG 2.2 Level AA.
We also provide a dedicated Technical Account Manager for our Premium support clients, ensuring tailored support and strategic guidance. Cloud Support Engineers are available across all support levels to assist with technical queries and issue resolution.
Our support structure is designed to meet diverse client needs while maintaining high standards of service delivery and security. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- To help users start using our managed services, we provide a comprehensive onboarding process that includes both onsite and online training options. Our training sessions are designed to cater to different learning preferences, ensuring that users feel confident and competent in using the service. We also provide detailed user documentation in PDF format, which includes step-by-step guides and best practices for effectively utilising our services. Additionally, our onboarding process is supported by a dedicated transition project, where we ensure that users receive tailored training grounded in Adoption & Change Management principles. This approach not only facilitates a smooth start but also promotes long-term engagement with our services. We are committed to providing ongoing support throughout the onboarding phase, ensuring that users have access to resources and assistance as they acclimatise to our managed services.
- Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
-
- Word Document
- Excel Spreadsheet
- CSV
- JSON
- HTML
- Markdown
- XML
- PowerPoint
- Plain Text
- End-of-contract data extraction
- At the end of the contract, users can extract their data through a well-defined process that ensures data integrity and security. We will provide users with a comprehensive data extraction plan, which includes the formats available for data retrieval, typically in CSV or JSON formats. Users will receive guidance on how to initiate the data extraction process via our ServiceNow portal, ensuring a smooth transition. The extraction will be performed in a secure manner, with data being transferred using TLS 1.2+ encryption protocols. We will schedule a dedicated session to assist users with the extraction, ensuring that all data is accurately retrieved and that any necessary support is provided during the process. Additionally, we will maintain logs of the extraction process for auditing purposes, ensuring compliance with our data retention policies. Our commitment is to facilitate a seamless exit process, allowing users to retain full access to their data throughout the contract period and during the offboarding phase.
- End-of-contract process
-
At the end of the contract, Insight ensures a seamless transition for clients. The included services cover the offboarding process, which incorporates data extraction, system decommissioning, and knowledge transfer. Clients will receive a comprehensive offboarding plan detailing all necessary steps and timelines. Our team will assist in the secure extraction of data, ensuring it is provided in agreed formats, such as CSV or JSON, and delivered securely using TLS 1.2+ encryption.
Any additional costs may arise for extended support beyond the contract period or for bespoke data extraction services that deviate from the standard process. The transition will also include a final service report summarising the support provided during the contract duration, which is part of the included service. Insight is committed to ensuring that clients retain full access to their data throughout the contract and during the offboarding phase, facilitating a smooth exit process. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile and desktop services operate on the same ServiceNow portal, ensuring a consistent user experience across devices. However, mobile users benefit from a streamlined interface optimised for touch navigation, featuring simplified access to key functionalities such as service requests and incident tracking. While both versions maintain accessibility standards, the mobile service may have certain limitations in terms of advanced features and data visualisation compared to the desktop version, which offers a more comprehensive view and additional functionalities. Overall, both services are designed for ease of use and accessibility.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service interface is a user-friendly portal powered by ServiceNow, designed for seamless interaction with our managed services. Users can submit service requests, track incidents, and access service reporting through a WCAG 2.2 Level AA compliant platform. The interface is optimised for both desktop and mobile devices, ensuring accessibility and usability. Additionally, the portal features multi-factor authentication (MFA) for secure access, with comprehensive logging for audit trails. Regular updates and maintenance ensure the interface remains efficient and responsive to user needs, facilitating effective service management and support.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Users can access our managed service through a ServiceNow portal, which is WCAG 2.2 Level AA compliant. They can submit service requests, track incidents, and access reports. However, users cannot alter system configurations or access sensitive data without appropriate permissions. All access is secured with multi-factor authentication (MFA), and user activity is logged for audit purposes. Our service is designed for ease of use and accessibility while maintaining strict security protocols to protect sensitive information and ensure compliance with government standards.
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Users can customise our managed service in several ways to meet their specific needs. Customisation options include configuring service request workflows, adjusting service level agreements (SLAs), and defining incident response protocols. Users can also personalise reporting options to focus on key performance indicators relevant to their operations.
To implement these customisations, users can engage with our dedicated Service Delivery Manager, who will guide them through the process and ensure their requirements are met. Customisation is typically carried out through our ServiceNow portal, where users can submit requests for changes or enhancements.
Only authorised personnel within the client's organisation, such as IT administrators or service managers, can perform these customisations. This ensures that changes align with organisational policies and maintain security integrity. Insight's team is always available to support and advise on best practices during the customisation process.
Scaling
- Independence of resources
- We guarantee that users are not affected by demand from others through a robust capacity management strategy. Our infrastructure is designed to scale dynamically, ensuring that resources are allocated efficiently based on real-time demand. We employ load balancing techniques to distribute traffic evenly across servers, preventing any single point of congestion. Additionally, proactive performance monitoring allows us to identify and address potential bottlenecks before they impact users. Our 24/7 support team is always on standby to respond to incidents swiftly, ensuring consistent service availability and reliability for all users, regardless of demand fluctuations.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
- We protect data at rest through multiple layers of security. This includes AES-256 encryption, ensuring that data remains secure even when stored. Additionally, we implement strict access controls, requiring MFA for all personnel access. Our data handling procedures are compliant with Cyber Essentials Plus and ISO standards, which define best practices for data protection. Regular audits and monitoring further enhance our security posture, ensuring that any anomalies are quickly identified and addressed. Comprehensive logging maintains an audit trail for accountability, supporting our commitment to maintaining the integrity and confidentiality of client data.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export their data via the ServiceNow portal, which supports multiple formats including CSV, XML, JSON, PDF, and TXT. This enables seamless data extraction for various applications, ensuring compatibility across different systems and facilitating data analysis. Our managed services ensure that the export process is secure, compliant with industry standards, and user-friendly, allowing clients to retrieve their data efficiently while maintaining data integrity and confidentiality.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- CSV format for spreadsheet applications and data analysis tools.
- XML format for structured data exchange between systems and applications.
- JSON format for lightweight data interchange, easily readable by humans.
- PDF format for document sharing that preserves formatting across devices.
- TXT format for plain text files, compatible with various applications.
- XLSX format for Microsoft Excel spreadsheets, supporting formulas and charts.
- SQL format for database imports and exports, facilitating data manipulation.
- HTML format for web pages, allowing data presentation in browsers.
- YAML format for configuration files, human-readable and easily editable.
- MD format for Markdown files, popular in content management.
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- CSV format for spreadsheet applications and data analysis tools.
- XML format for structured data exchange between systems and applications.
- JSON format for lightweight data interchange, easily readable by humans.
- PDF format for document sharing that preserves formatting across devices.
- TXT format for plain text files, compatible with various applications.
- XLSX format for Microsoft Excel spreadsheets, supporting formulas and charts.
- SQL format for database imports and exports, facilitating data manipulation.
- HTML format for web pages, allowing data presentation in browsers.
- YAML format for configuration files, human-readable and easy to edit.
- MD format for Markdown files, popular in content management.
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- We utilise a multi-layered approach to protect data between the buyer's network and our network, including the implementation of Transport Layer Security (TLS) 1.2+ for data in transit. Additionally, we enforce strict access controls and require multi-factor authentication (MFA) for all system access. Our infrastructure is monitored 24/7 by internal and third-party Security Operations Centres (SOC) to ensure any potential threats are swiftly identified and addressed. Regular audits and vulnerability assessments further enhance our security posture, ensuring compliance with Cyber Essentials Plus and ISO standards.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- We implement multiple layers of data protection within our network, including segmentation of sensitive data environments and strict access controls. All data is encrypted using AES-256 at rest and TLS 1.2+ during transit. Our network is monitored 24/7 by internal and third-party Security Operations Centres (SOC), which conduct regular vulnerability assessments and penetration testing. Additionally, we maintain comprehensive logging with audit trails retained for 6-12 months, enabling rapid incident response and forensic analysis when required. We adhere to Cyber Essentials Plus standards, ensuring our security measures meet the highest UK government requirements.
Availability and resilience
- Guaranteed availability
- We guarantee a minimum availability of 99.9% for our managed services, as outlined in our Service Level Agreements (SLAs). If we fail to meet this availability threshold, users are entitled to service credits in accordance with our SLA policies. Our services are monitored 24/7, ensuring proactive incident management and rapid resolution of issues. We commit to notifying clients of confirmed incidents within 24-48 hours, allowing for efficient communication and transparency. Regular maintenance and performance optimisation are integral to our service delivery, further enhancing reliability and user experience. This comprehensive approach ensures that our clients can depend on our managed services for their critical operations.
- Approach to resilience
-
Our managed service is designed with resilience at its core, ensuring the highest levels of asset protection as per the government's cloud security principles. Our data centre setup incorporates multiple layers of redundancy, including power supplies, cooling systems, and network connectivity, to prevent single points of failure. We utilise geographically dispersed data centres to ensure service continuity in the event of a regional outage or disaster.
Our infrastructure leverages advanced virtualisation technologies, allowing for rapid failover and recovery capabilities. Regular backups and a comprehensive change control process ensure that client workloads are preserved and can be restored quickly.
We adhere to rigorous security protocols, including Cyber Essentials Plus certification and regular third-party penetration testing. Our incident response process is proactive, with notifications provided to clients within 24-48 hours of confirmed incidents.
For further details regarding the specific configurations and resilience features of our data centre setup, we are happy to provide that information upon request. - Outage reporting
- Our service reports any outages through multiple channels to ensure clients are promptly informed. We provide a public dashboard that displays real-time service status and outage information. Additionally, we have a fully documented REST API that clients can utilise to programmatically access outage notifications and service status updates. Clients also receive email alerts for any confirmed incidents, ensuring that they are kept updated on service availability. This multi-faceted approach allows for comprehensive communication regarding outages and enhances our clients' ability to manage their operations effectively.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted through a combination of multifactor authentication (MFA), role-based access controls, and strict user permissions. Only personnel with appropriate security clearances, up to SC level, can access sensitive areas. All access is logged and monitored, with audit trails maintained for 6-12 months. Our ITSM system, ServiceNow, integrates these controls, ensuring compliance with Cyber Essentials Plus and ISO standards. Regular reviews of access rights and security practices further mitigate risks and uphold data integrity.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials Plus, ISO 9001, ISO 27001, ISO 20000, ISO 14001, PCI-DSS.
- Information security policies and processes
-
Our information security policies and processes are designed to maintain the integrity, confidentiality, and availability of our services. We adhere to Cyber Essentials Plus and ISO standards, including ISO 9001, 27001, 20000, and 14001. Our reporting structure includes a designated Chief Information Security Officer (CISO) who oversees security initiatives and compliance across the organisation. The CISO reports directly to the board, ensuring that security policies are aligned with organisational objectives and are effectively communicated.
We implement a comprehensive security framework that includes regular risk assessments, policy enforcement, and incident management through our ITSM system, ServiceNow. All staff undergo training in security awareness, ensuring they understand and comply with our policies. Compliance is monitored through periodic audits and continuous monitoring of our systems, with logs retained for 6-12 months to provide a complete audit trail. Additionally, security practices are integrated into our service delivery, ensuring that all managed services meet the highest security standards. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Our configuration and change management processes involve meticulous tracking of all service components through their lifecycle via a dedicated configuration management database (CMDB) integrated with our ITSM tool, ServiceNow. Each component's status is updated in real-time, ensuring visibility and control. Changes are rigorously assessed for potential security impacts through a formal change advisory board (CAB) process, which evaluates risks and compliance with security standards. This includes reviewing proposed changes against our security policies and controls, ensuring any identified risks are mitigated prior to implementation.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Our vulnerability management process begins with continuous threat intelligence gathering from trusted sources, including government advisories and industry-specific security feeds. We assess potential threats through a systematic risk assessment framework to identify vulnerabilities in our services. Patches are deployed promptly, typically within 24-72 hours of a vulnerability being disclosed, following rigorous testing in a controlled environment. This ensures minimal disruption to our services while maintaining security integrity. We also engage in annual third-party penetration testing to further identify and mitigate vulnerabilities proactively.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Our protective monitoring processes involve continuous 24/7 monitoring of systems using advanced threat detection technologies and a dedicated Security Operations Centre (SOC). We identify potential compromises through automated alerts and analysis of log data retained for 6-12 months, which facilitate anomaly detection. Upon identifying a potential compromise, we respond immediately, initiating an investigation and notifying affected stakeholders within 24-48 hours. Our incident response team follows established protocols to contain, mitigate, and remediate any security incidents effectively, ensuring minimal disruption to services and maintaining compliance with relevant security standards.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Our incident management processes include pre-defined procedures for common events, enabling effective and prompt responses. Users report incidents through our ServiceNow portal, which is designed to be user-friendly and is compliant with WCAG 2.2 Level AA standards. We provide detailed incident reports regularly, summarising the incident's nature, response actions taken, and resolution status. Notifications of confirmed incidents are communicated within 24-48 hours, ensuring transparency and timely updates to affected users. Our comprehensive approach ensures that incidents are managed efficiently while maintaining high service standards.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Atlas
- ISO/IEC 27001 accreditation date
- Sunday 13 April 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Atlas
- ISO 9001 accreditation date
- Tuesday 1 April 2025
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Be7ce590-de10-486e-8431-2e10891a8979
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Cd8b1a78-44c7-4bb0-84d6-59a7506f3bba
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
-