CDW Limited

CDW Sophos Central Email Advanced (CEMA)

Sophos Email is a cloud-based secure email gateway solution for Sophos Central. Built to integrate seamlessly with popular email platforms, Sophos Email is engineered to keep businesses safe from email threats by simply stopping spam, phishing, malware, and data loss.

Features

  • Anti-Spam
  • Malware Scanning
  • Cloud Sandbox
  • Malicious URL Detection
  • SPF, DKIM, DMARC
  • Impersonation Phishing Protection
  • Microsoft 365 Mailflow Rules
  • S/MIME Encryption
  • Data Loss Prevention
  • Microsoft 365 Protection Post-delivery

Benefits

  • Single cloud management console
  • Comprehensive Reporting
  • Microsoft 365 Integration
  • Automatically identify high-profile targets for malware-free impersonation
  • Protect sensitive data with email encryption and data loss prevention

Pricing

£11.73 a unit

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@uk.cdw.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 13

Service ID

4 8 9 4 0 9 8 6 4 2 3 0 4 1 8

Contact

CDW Limited Andy Wood
Telephone: 0161 837 7744
Email: tenders@uk.cdw.com

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
N/A
System requirements
N/A

User support

Email or online ticketing support
Email or online ticketing
Support response times
Sophos Support is available 24 hours per day, 7 days per week, 52 weeks per year, including statutory, public, and bank holidays.

For Enhanced Support Plan:
Critical Within 4 hours
High Within 8 hours
Medium Within 24 hours
Low Within 24 hours

For Enhanced Plus Support Plan:
Critical Within 1 hour
High Within 2 hours
Medium Within 24 hours
Low Within 24 hours

Please see this link for details (page 9):
https://www.sophos.com/en-us/medialibrary/PDFs/Support/Sophos-Support-Services-Guide.pdf
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.1 AA or EN 301 549
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Web chat
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.1 AA or EN 301 549
Web chat accessibility testing
No testing has been completed at this time.
Onsite support
Yes, at extra cost
Support levels
Enhanced
• 24/7 multi-channel support
• Software downloads, updates, & maintenance
• Access to support knowledgebase and support forums
• Warranty (Appliances only)
• Hardware replacement (Appliances only)
• Remote assistance support

Enhanced Plus - includes all features of the Enhanced plan above and the following:
• Remote consulting
• Priority case and sample handling
• Phone calls routed to senior Technical Support Engineers

TAM - includes all features of Enhanced and Enhanced plus with the following:
• Named Technical Account Manager (TAM)
• Front of the line access to product information
• Personalized communications and alerts
• Performance and feature optimization
• Enhanced escalation
• Emergency Onsite Support

Please see this link for reference:
https://www.sophos.com/en-us/support/technical-support
Support available to third parties
Yes

Onboarding and offboarding

Getting started
The following resources are available:
https://docs.sophos.com/central/Customer/help/en-us/central/Customer/learningContents/EmailSecurity.html
https://docs.sophos.com/central/Customer/help/en-us/central/Customer/learningContents/EmailGateway.html
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Some reports such as Data Loss Prevention Violations and At Risk Users can be exported to CSV or PDF.

Users/People list can be exported to CSV.
End-of-contract process
.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Sophos Email Advanced is managed through Sophos Central.
Sophos Central has a simple and intuitive dashboard, offering easy navigation and alert functions.

The Sophos Email management console has the following sections:
• Dashboard
• Logs & Reports
• Mailboxes
• Quarantined Messages
• Policies
• Settings

The Policies page of the console is where Email Security and Data Loss Prevention policy settings can be configured.
Accessibility standards
None or don’t know
Description of accessibility
Sophos Central Admin Console can be accessed at https://cloud.sophos.com/ with supported web browsers.
Sophos Central currently supports the following browsers:
• Chrome.
• Edge.
• Firefox.
• Safari (Mac only).

It is recommended to install or upgrade to a supported version in the above list and to always run an up-to-date version. Sophos aims to support the latest version and previous versions of Google Chrome, Mozilla Firefox, and Apple Safari.

Aside from the SuperAdmin account, only users with an admin role can access the management console. The login requires an email and password as well as an MFA (Multi-factor Authentication).
Accessibility testing
Sophos Central does not currently have a VPAT compliance attestation. As a central console, many separate Sophos products appear in Sophos Central. Some of these products are accessibility compliant and we continue to improve the accessibility of our individual products.
API
No
Customisation available
No

Scaling

Independence of resources
Sophos Central is segmented into a number of logically separate virtual networks based on the various workloads they perform (such as authentication or endpoint management). All workloads are then placed into auto-scaling groups, behind a load balancer, so that when a particular workload sees increased load/traffic, additional temporary resources can be allocated to give the group capacity to handle the load.

Analytics

Service usage metrics
Yes
Metrics types
The Sophos Email Dashboard shows the following information:
• Potential Threats Identified
• Mailboxes Protected
• Inbound Emails Scanned
• Outbound Emails Scanned
• Inbound Activity Summary
• Outbound Activity Summary
• Intelix Threat Summary
• At Risk Users
• Data Loss Violations
Reporting types
  • Real-time dashboards
  • Regular reports

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Sophos

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Data sanitisation type
Explicit overwriting of storage before reallocation
Equipment disposal approach
In-house destruction process

Data importing and exporting

Data export approach
Some reports such as Data Loss Prevention Violations and At Risk Users can be exported to CSV or PDF.

Users/People list can be exported to CSV.
Data export formats
  • CSV
  • Other
Other data export formats
PDF
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Transport-level encryption is used to secure management communication between the client software and Sophos Central platform via certificates and server validation.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
It is carried out using secured services such as SFTP, HTTPS, TLS encrypted, etc.

Availability and resilience

Guaranteed availability
Sophos Central does not provide a traditional SLA because the availability of our products is not dependent on the availability of the web portal. However, the availability of the web portal ranged between 99.99 and 100% over the past year, depending on geographic region.

Sophos Central status can be viewed here:
https://centralstatus.sophos.com/#!/
Approach to resilience
Sophos Central is hosted on Amazon Web Services (AWS), across a number of virtual machine instances and services that dynamically scale to handle the current Sophos Central workload.

Sophos Central is segmented into a number of logically separate virtual networks based on the various workloads they perform (such as authentication or endpoint management). All workloads are then placed into auto-scaling groups, behind a load balancer, so that when a particular workload sees increased load/traffic, additional temporary resources can be allocated to give the group capacity to handle the load.
Outage reporting
Sophos Central status can be viewed here:
https://centralstatus.sophos.com/#!/

It also has a subscribe button at the top right to receive status notifications.

Identity and authentication

User authentication needed
Yes
User authentication
  • 2-factor authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
Access to the Sophos Central admin console requires a login (email and password) as well as MFA (Multi-Factor Authentication).
Sophos Central also supports Azure AD Federation authentication.

Except for the SuperAdmin, Users need to have an admin role assigned to them to get access to the Sophos Centrla admin console.
Access restrictions in management interfaces and support channels
Sophos Central has a Role Management feature that provides admins the capability to assign pre-defined administrative roles to users who need access to the Sophos Central Admin Console. The following are the available pre-defined administrative roles:
• Super Admin
• Admin
• Help Desk
• Read-only

Please refer to this link for more information:
https://docs.sophos.com/central/Customer/help/en-us/central/Customer/concepts/AdminRoles.html
Access restriction testing frequency
At least every 6 months
Management access authentication
  • 2-factor authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Description of management access authentication
Access to the Sophos Central admin console requires a login (email and password) as well as MFA (Multi-Factor Authentication).
Sophos Central also supports Azure AD Federation authentication.

Except for the SuperAdmin, Users need to have an admin role assigned to them to get access to the Sophos Centrla admin console.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 1 month and 6 months

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
A-Lign
PCI DSS accreditation date
09/02/2021
What the PCI DSS doesn’t cover
It only covers our Sophos MTR Product.

Other Sophos Central products do not contain or protect any cardholder-related information and is therefore not required to be PCI Compliant.
Cyber essentials
No
Cyber essentials plus
No
Other security certifications
Yes
Any other security certifications
SOC 2 Type 2

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
The Sophos Information security framework (SISP) is based upon leading practices such as ISO 27001, SOX, and PCI as well as with Sophos priorities. Our ISPF and Security policy is part of a holistic approach to Information Security Management. Contents of ISP and security policy drives development of technical security standards, processes, and configurations will be utilized by staff and vendors to implement security controls. They also provide the context for training, awareness, audits, and compliance assurance activities. Lastly, they provide Sophos with necessary information to risk adjust business initiatives and improve the state of the Sophos Information Security Program.
Information security policies and processes
Ophos has a dedicated cybersecurity team. The team has developed and deployed security policies, standards, and procedures validated by an active governance and audit program.
Sophos aligns with the NIST Cybersecurity Framework and ISO 27001 controls.

Please see this link for the High-Level Overview of the Sophos Security Policy:
https://www.sophos.com/en-us/trust/high-level-security-policy-overview

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Changes to the production environment are strictly done after following our Change management process (including approval from the Security team if needed) and are reviewed by the operational team.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
The Security team (Red team) is tasked with scanning systems for vulnerability scans.
We follow a risk-based approach while deciding on the remediation of vulnerabilities.

Most of the systems are set for automated patch management. In cases where systems are set for manual patch updates, a time frame is mandated to the system owners to apply patches (especially security/ critical patches)
All relevant teams involved in patch management (like system owners, business units, IT, Security, etc.) are notified in advance for patch activity.
Patches are tested in a test environment before moving to the production environment.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We have developed our plans with guidance from the NIST 800-61 Computer Security Incident Handling Guide and we frequently review these plans for compliance with industry standards.

There are many ways Sophos identifies or becomes aware of security incidents. These include:
• Security monitoring capabilities, often in our products, or complementary methods we have developed
• Bug-bounty reports
• Penetration test findings
• Vulnerability analysis
• Code and application analysis
• Research and threat intelligence analysis
• Customer notifications
To report a potential security incident, please see our Responsible Disclosure Program.

Please see Sophos Incident Response overview:
https://www.sophos.com/en-us/trust/incident-response
Incident management type
Supplier-defined controls
Incident management approach
We have developed our plans with guidance from the NIST 800-61 Computer Security Incident Handling Guide and we frequently review these plans for compliance with industry standards.

There are many ways Sophos identifies or becomes aware of security incidents. These include:
• Security monitoring capabilities, often in our products, or complementary methods we have developed
• Bug-bounty reports
• Penetration test findings
• Vulnerability analysis
• Code and application analysis
• Research and threat intelligence analysis
• Customer notifications
To report a potential security incident, please see our Responsible Disclosure Program.

Please see the Sophos Incident Response overview:
https://www.sophos.com/en-us/trust/incident-response

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Social Value

Fighting climate change

Fighting climate change

CDW is committed to fighting climate change and protecting the environment. CDW has made a commitment to achieve Net Zero emissions by 2040, 10 years earlier than mandated by the UK government. To achieve this, CDW has implemented (and continues to implement) initiatives to reduce our emissions and carbon footprint, all of which are underpinned by CDW’s ISO14001 certified Environmental Management System (EMS) and our beGreen program.

CDW’s distribution centre and our flagship offices hold ISO 14001 environmental management certifications, with our UK distribution centre also holding REGO energy certifications. In parallel with our EMS and beGreen program, CDW has invested in and implemented a range of initiatives to help tackle our contribution towards climate change across our operational activities. These initiatives include (but are not limited to):

-Solar panel usage. As a result, in 2021, we were able to achieve 100% renewable energy sourcing for CDW-owned buildings.
-Energy-efficient lighting solutions, including indoor and outdoor LED lighting.
-Motion sensor lighting and conveyor systems that turn off in response to inactivity.
-Water consumption solutions, including rainwater harvesting efforts.
-“Smart” HVAC systems that adjust according to business hours and seasonal temperatures.
-A ‘Pin to Print’ program enabling enhanced print queue management to reduce wasted print jobs
-A goal to achieve 100% renewable energy sourcing for electricity by 2027. In 2021, 98% of electricity consumed in the UK was from renewable sources.

Additionally, at our distribution centres, we have recycled:

-2,966 tons of packaging material
-9,794 tons of cardboard
-636 tons of paper
-Thousands of wood and plastic pallets

Furthermore, at a coworker level, CDW has established a ‘WE GET Our Environment’ Business Resource Group and an Environment Committee with the purpose of increasing awareness of the environmental and social strategy, and to empower coworkers to get involved in environmental initiatives.
Equal opportunity

Equal opportunity

CDW is committed to creating a working environment for coworkers dedicated to inclusion, diversity and equal opportunities, as detailed in our CDW Way Code, which teaches all CDW coworkers to:

-Always do their best to make everyone at CDW feel welcome
-Treat other coworkers with respect and dignity
-Maintain an inclusive workplace in which all coworkers can demonstrate their full potential
-Respect the unique attributes and perspectives of every coworker

CDW provides equal treatment and opportunity without regard to:

-Race
-Skin colour
-Religion
-National origin
-Gender
-Sexual orientation
-Gender identity
-Disability
-Age

Our commitment to equality is underpinned by six Business Resource Groups (BRGs). BRGs ensure all coworkers have a voice, build awareness, and provide support to similar groups in their communities. The BRGs include:

-Armed Forces Network
-Black Coworker Network
-Disability Support Network
-PRIDE+
-United Support Network
-Women’s International Network

CDW coworkers are empowered to reach their highest potential, and we are focused on providing them with a wide variety of tools and development opportunities to help them achieve their career aspirations at CDW, regardless of origin, background or situation. Within our learning culture, all coworkers are surrounded by comprehensive resources and support, ongoing education and skills training, and robust advancement opportunities. We offer a variety of programs to help current and future leaders build diverse teams and to help diverse coworkers develop their leadership skills so they can continue to advance in the organisation.

Our commitment to equal opportunities and diversity is demonstrable across our organisation. As an example, CDW’s CEO and President, Chris Leahy, is female and CDW’s Executive Committee consists of 50% female and 50% male coworkers, with 42% coming from multi ethnic backgrounds.

CDW is also committed to reducing the gender pay gap and produces an annual gender pay gap report - https://www.uk.cdw.com/site-tools/pay-gap-report/.
Wellbeing

Wellbeing

CDW is committed to providing coworkers and their families with the knowledge necessary to make the best health and wellness choices for themselves and their families.

Our approach to wellness is designed to help coworkers be safe, healthy and successful. We understand that managing work and personal life is a balancing act of shifting priorities and so we offer a variety of benefits that supports a coworker’s physical, financial, emotional and social
wellbeing, including access to telemedicine, a suite of family benefits and a variety of wellness incentives and programs.

CDW provides coworkers with an Employee Assistance Program, which offers confidential, individualised coaching to help coworkers achieve personal or professional goals. It also features enhancements for crisis care, 24/7 phone support and an emergency referral system.

Ongoing coworker engagement is fostered through regular communications events, including:

-Monthly wellness e-newsletters promoting benefits available to coworkers
-Workshops and activities focused on timely topics
-Various campaigns to raise awareness for meaningful topics throughout the year, including mental health, emotional wellbeing and heart-mind gratitude

As a further example of our commitment, in response to the COVID-19 pandemic, our Coworker Services team implemented “coworker calls” - informal, but regular check-ins to ensure all coworkers are caring for their mental health and receiving the support they need.

CDW also established ‘The CDW Community’, an initiative set up to provide coworkers with activities that they could participate in to keep them physically and mentally active, and to give them a platform for social engagement with other coworkers during a time where many were feeling isolated.

Following its success during COVID, the CDW Community initiative has remained operational as we exit the pandemic, continuing to provide CDW coworkers with activities and resources centric to physical and mental wellbeing, as well as sessions to support a healthy family life.

Pricing

Price
£11.73 a unit
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
There is no free version, just a time limited trial version which limits this product to 100 users for a 30 day period
Link to free trial
A trial can be accessed at central.sophos.com

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@uk.cdw.com. Tell them what format you need. It will help if you say what assistive technology you use.