Skip to main content

Help us improve the Digital Marketplace - send your feedback

NW SECURITY GROUP LIMITED

Video Surveillance as a Service (VSaaS)

Our open platform VSaaS offering is a cloud based CCTV system suitable for all camera makes and models, enabling central monitoring of multiple sites, or remote locations

Features

  • Remote CCTV Monitoring
  • Multi Site CCTV Monitoring - Centralised
  • AI Video Threat Detection
  • Solar Powered Options
  • AI Business Intelligence
  • High Level Cyber Security
  • Open Platform
  • Open Integrations for Access Control and sensor data
  • Centralised Management
  • Automated Updates

Benefits

  • Efficiently monitor multiple sites and remote locations
  • Cost effective CCTV for multi site operations
  • Improved safety and security
  • Easy installation and rapid deployment
  • Gain new business insights
  • Remove Cyber risks from corporate network
  • Compatible with most IP cameras and devices
  • Verify access with video information
  • Single pane of glass user friendly
  • Time saving keeping systems up to date and secure

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at frank.crouwel@nwsecuritygroup.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 1 5 1 2 6 7 8 5 4 0 1 7 8 5

Contact

NW SECURITY GROUP LIMITED Frank Crouwel
Telephone: 07917018130
Email: frank.crouwel@nwsecuritygroup.com

About your service

Service categories

Applications

Production and operations

  • Other operations

Service industry and public sector operations

  • Healthcare
  • Education
  • Public Order and Safety
  • Police
  • Defence
  • Adult Social Care
  • Children's Social Care
  • Other
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Milestone Xprotect Video Management System
Cloud deployment model
Private cloud
Service constraints
Video frame rate limitations to 15FPS
System requirements
Sufficient internet upload and download speeds

User support

Email or online ticketing support
Yes
Support response times
4 hour response time during working hours Monday to Friday with options to extend this to 2 hour response time and support provision during weekends and bank holidays, and a further option for 24/7/365 support.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Single level support with responses based on severity level; critical, severe, moderate, minor.
One simple standard cost per device connected
We provide 2 x technical account managers assigned to installation
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Fully configured and guided onboarding including online or onsite training and operating user guides
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
CSV Export of data
End-of-contract process
At the end of the contract user will be offered renewal with minimum of 30 days notice. If the user does not want to renew then the 30 days will be used for exporting any required data before the contract ends. Included in the price is the cloud hosting and support provision with options to include or exclude CCTV camera hardware
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Mobile service is via application (Android, IoS).

Mobile app limited to Live view, Playback and alarms
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
API available for third party integrations such as alarms, live view, playback, io, analytics.

Roadmap:
Audio, ANPR, Access Control
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
No
Customisation available
No

Scaling

Independence of resources
Elastic resource allocation

Analytics

Service usage metrics
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Milestone Systems

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Data Erasure

Data importing and exporting

Data export approach
MP4 Files for video
CSV for data
Data export formats
  • CSV
  • Other
Other data export formats
MP4
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
99.5% Service Uptime.
No user refund provided for short outages
Approach to resilience
Available on request
Outage reporting
Email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Within back end configuration, we operate on a lowest priviledge principal, RBAC Role based access control. Multiple approval stages for access. One user does not have access to all systems
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials Plus
Information security policies and processes
NW Security Group has an Information Security Policy (ISP) and policy-derived processes in place meeting the requirements of Cyber Essentials Plus, SSAIB and PCI DSS certifications. The ISP is annually reviewed and independently audited by qualified assessors for continued certification of Cyber Essentials Plus, SSAIB and PCI DSS compliance.
The company’s Technical Director is assigned the role of Information Security Officer responsible for all areas of information security, including: security infrastructure, planning against threats, vulnerabilities and risk, implementing and maintaining security policies are followed, continued security training is provided to all staff and stakeholders, ensuring IT infrastructure in place supports the ISP, response to security incidents and maintain a disaster recovery and business continuity plan. The Information Security Officer is supported in their actions by the company’s Managing Director and Technical Manager to ensure consistency in policy delivery. Incidents and concerns are reported immediately to the Information Security Officer for immediate activation of the company response plan.
To ensure polices are followed, the Information Security Office provides to the company’s staff quarterly, in-house training sessions, and two-weekly, short-form cybersecurity awareness training via the online human risk management platform ‘usecure.’
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Hardware components are asset tagged whilst configuration of hardware and software components are documented within our ISO9001 company processes whilst any changes to these will be logged in our contract management system. Any changes to configuration will be preceded by compliance to best practice cyber security standards applicable at the time.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
SOC 2 Type II certification. This includes centralised logging, security event correlation (SIEM), anomaly detection, and retention of audit logs to support incident investigations and compliance.

Vulnerability management is operated as a continuous, risk-based process. Potential threats are identified through automated scanning, configuration monitoring, penetration testing, threat intelligence from recognised sources (e.g. CVE/NVD, vendor advisories, and cloud provider security feeds). Vulnerabilities are assessed and prioritised based on severity, and business impact. Security patches and mitigations are deployed through controlled change management processes, with defined SLAs for critical and high-risk issues. We continuously monitor by a security operations function
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective monitoring is implemented in line with SOC 2 Type II (Security trust principle) requirements.

The Arcules service operates continuous security monitoring across infrastructure and applications, including centralised logging, real-time alerting, anomaly detection, and security event correlation. Monitoring covers access activity, system health, configuration changes, and security incidents. Logs are retained for audit and investigation purposes and are reviewed by a security operations function with defined escalation and incident response procedures. Monitoring controls and processes are independently audited as part of ongoing SOC 2 Type II assurance.
Incident management type
Supplier-defined controls
Incident management approach
Incident management is operated in accordance with SOC 2 Type II (Security trust principle) requirements.

The organisation maintains documented incident response procedures, including detection, classification, escalation, containment, remediation, and post-incident review. Incidents are monitored and handled by a security operations function with defined roles and response playbooks. Customer notification and regulatory reporting processes are aligned with contractual and legal obligations, including GDPR. Incident management controls and processes are independently audited as part of ongoing SOC 2 Type II assurance.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Fully featured trial for a limited time 2 months

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
10%
Between £250,000 and £500,000
15%
Between £500,001 and £1,000,000
15%
Between £1,000,001 and £2,500,000
20%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
20%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
World Certification Services
ISO 9001 accreditation date
Friday 27 December 2024
What the ISO 9001 doesn’t cover
None
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
57907745-fe0b-4371-9908-e8807c2f5989
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
6ad6cf94-2b9b-461b-b9d4-9f4539870f69
Other security certifications
Yes
Any other security certifications
SSAIB

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at frank.crouwel@nwsecuritygroup.com. Tell them what format you need. It will help if you say what assistive technology you use.