Proofpoint Identity Threat Defense & Response (ITDR)
Proofpoint ITDR enables proactive discovery and remediation of the identity risks used in ransomeware and advanced persistent threats. The platform enables active management of the attack surface to remove the risk of privilege escalation and leverages deception technology to detect and respond to attacker lateral movement.
Features
- Discover identity-risk across the attack-chain
- Automatically surface prioritised list of identity-vulnerabilities
- Manually/automatically remediate vulnerabilities like Shadow Admins
- Gain Risk visibility across subsidiaries/acquired entities
- Intelligent reporting on risk trends over time
- enhance security posture on a dynamic basis
- Gain visibility across ActiveDirectory, EntraAD, PAM, LAPS and Endpoints
Benefits
- Ensure early attacker-detection/comprehensive threat investigations
- Reduce false positives through high-fidelity alerts
- Agentless technology with low deployment/IT overhead
- Continous/active defense through dynamic-adjustment to IT/network changes
- Scales across networks of more than a million endpoints
- Fills the gaps left by signature/anomaly based threat-detection tools
Pricing
£17.10 a user
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
4 1 2 4 7 3 4 6 5 2 5 2 6 9 6
Contact
INTEGRITY360 LIMITED
Paul Momirovski
Telephone: +44 20 3397 3414
Email: bidreviewboard@integrity360.com
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
Extends and enhances EDR solutions, integrates with PAM, SIEM, SOAR technologies
Integrations to Proofpoint TAP dashboard and TAP Account Takeover - Cloud deployment model
-
- Private cloud
- Community cloud
- Service constraints
- The ITDR solution requires points of presence (connectors) into on premise environments in order to manage identity risks and deploy deceptions
- System requirements
-
- Management Server - Windows 1 server required
- Hybrid and SaaS-only installations (ITD SaaS tenant): No server required
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- Dependent on Service Level Purchased
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Self-Service, Platinum, Premium & Global
Self-Service: primary access via portal, phone support limited to business hours P1 issues, 2 authorised support contacts
Platinum: access via portal and phone, phone support for all priorities during business hours plus P1 issues 24x7, 4 authorised support contacts
Premium: access via portal and phone, phone support for all priorities during business hours plus P1 issues 24x7, 6 authorised support contacts, assigned Technical Account Manager
Global: available to Platinum and Premium only. phone access for all cases, all priorities 24x7x365, 12 authorised support contacts - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Installation and training / knowledge share available with dedicated engineer
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Not accessible from the service
- End-of-contract process
- Services cease to function. Proofpoint support team will carry out full offboarding process
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- All core services are accessible via the API
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Findings and risks can be customised to allign with the enterprise enviroment
Scaling
- Independence of resources
- On premise the service can be installed on dedicated hardware. On SaaS the environment will be in a dedicated VPC
Analytics
- Service usage metrics
- Yes
- Metrics types
- Granular Reporting of message flow, deep analysis into threats
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
Resellers
- Supplier type
- Reseller (no extras)
- Organisation whose services are being resold
- Proofpoint
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Access to the Proofpoint production environment, where services are hosted, is granted based on role and occurs via a 2FA encrypted VPN.
- Data sanitisation process
- Yes
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation
- Deleted data can’t be directly accessed
- Equipment disposal approach
- In-house destruction process
Data importing and exporting
- Data export approach
- Data can be exported from the system
- Data export formats
- CSV
- Data import formats
- Other
- Other data import formats
- Data is not required to be uploaded
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Other
- Other protection between networks
- Proofpoint has documented information security program consisting of policies, procedures and standards that aligns with the requirements of NIST 800-53 and ISO 27001. The program is owned by the Proofpoint Global Information Security group, and includes a continuous monitoring program consisting of monthly and quarterly evidence collection and review, and an annual SOC 2 Type II audit of the program.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Policies, procedures, and standards comprising the Proofpoint information security program are reviewed and updated annually by the Proofpoint Global Information Security group and approved by the Proofpoint CFO.
Availability and resilience
- Guaranteed availability
- https://www.proofpoint.com/sites/default/files/general_terms_hosted_services_sla_-_mar_2016.pdf
- Approach to resilience
- The services run in active/active mode between a pair of geographically-diverse co-location facilities.
- Outage reporting
- https://www.proofpoint.com/sites/default/files/general_terms_hosted_services_sla_-_mar_2016.pdf
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Other
- Other user authentication
- Via proofpoint SSO
- Access restrictions in management interfaces and support channels
- Via proofpoint SSO
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Other
- Description of management access authentication
- For the management interface users will need to be authenticated via proofpoint SSO
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber essentials plus
- No
- Other security certifications
- Yes
- Any other security certifications
- SOC 2 Type II audit report, available here: https://go.proofpoint.com/soc2_report_request.html
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- The Proofpoint security program is led by the Proofpoint CSO. The program is based on identifying and mitigating risk to our personnel, the organization and the customer.
- Information security policies and processes
- Proofpoint's information security program is aligned with the requirements of NIST 800-53 and ISO 27001. However, we are not certified to the ISO 27001 standard.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Proofpoint has a documented change management policy that includes requirements around documented change tickets and review and approval by the Change Review Board.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Proofpoint performs internal and external vulnerability scanning and remediates applicable findings in line with the Proofpoint patch management policy.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Proofpoint has distributed monitoring in place for availability, performance, capacity and security. Alerts are directed to a 24x7 NOC or SOC for review, remediation and/or escalation.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Proofpoint has a documented Incident Response Plan that includes procedures to detect, investigate, remediate and communicate security incidents. A trained IRT team is responsible for the maintenance of the program.
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
Proofpoint operates in approximately 20 countries, and as a global corporate citizen, we are committed to environmental sustainability, positive social impact, and supporting people and communities around the world.
Some examples of how Proofpoint supports environmental sustainability are:
Usage of highly efficient virtualized servers for our global IT infrastructure, supplemented by a diverse mix of leading cloud services, which are delivered out of energy efficient data centers in the countries that we deliver our services from.
Our new headquarters in Sunnyvale, CA meets LEED Gold certified standards for the core, shell and interior;
Requiring LED lighting as standard for all new real estate projects, and launching a project to replace the majority of our fluorescent lights with LED lighting by mid-2021 globally
Implementing recycling programs in every Proofpoint office globally; and
Adoption of teleconferencing solutions to reduce unnecessary air travel.
Proofpoint is committed to the communities it operates in.Tackling economic inequality
We believe that diversity, inclusion, and opportunity is a journey and we are committed to building a diverse and inclusive company and society for our employees, customers, partners, and shareholders. In order to create a more diverse and inclusive work environment, we provide education, training and tools so that all employees can become aware of bias, how it exists and how to mitigate it. As we continue to shape our work environment and world-class organization to be more inclusive and inviting, we are actively striving to build an extensive pipeline of talent through various programs. Our internal programs enable and empower our hiring managers to identify alternative and emerging talent pools and to create an inclusive candidate experience.Equal opportunity
Our Chief Human Resource Officer (“CHRO”), who reports directly to our Chief Executive Officer (“CEO”), leads the development and implementation of the Company’s human capital strategy, including the attraction, acquisition, development and engagement of talent; however, it is the responsibility of all of Proofpoint, its management and its employees, to execute and build a collaborative and engaging workplace where all employees have an opportunity to do their best work and where we act as a team to solve our customers’ most challenging security issues.
Our CHRO, with our CEO and executive management team, are responsible for developing the Company’s diversity and inclusion vision and roadmap and integrating these into the Company’s culture and operations. The roadmap includes framing the Company's global policies and programs for leadership and talent development, compensation, benefits, staffing and workforce planning, human resources systems, education and organization development, workplace strategies, and global sourcing and indirect procurement, and ensuring effective and efficient internal company operations.Wellbeing
The physical health, financial well-being, life balance and mental health of our employees is vital to the Company’s success. Throughout the year, we encourage healthy behaviors through regular communications, educational sessions, voluntary progress tracking, wellness challenges, and other incentives. Creating a culture where all colleagues feel supported and valued is paramount to our corporate mission.
The ongoing COVID-19 pandemic has led to unique challenges and through it all, the health, safety and the general well-being of our employees has remained our primary objective.
Pricing
- Price
- £17.10 a user
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Full service offering as a Proof of Concept for 2 weeks as standard at customers request