Telefónica Tech Backup as a Service (BaaS)
Backup as a Service (BaaS) from Telefónica Tech is a flexible, enterprise-grade solution that helps
organisations safeguard critical data across hybrid and on-premises environments. Built around Veeam technology and hosted on Telefónica Tech’s secure UK-based cloud platform, BaaS is available in two models:
Offsite BaaS and Full BaaS
Features
- Veeam Cloud Connect repository setup - secure, UK-hosted offsite backup
- Encrypted, logically separated storage.
- Initial setup support - includes scoping call and connectivity assistance
- Ongoing infrastructure maintenance
- Telefónica Tech monitors and maintains the cloud platform
Benefits
- Reduces operational burden
- Improves resilience and compliance
- Eliminates infrastructure overheads
- Supports hybrid environments
- Flexible to your needs
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 2 9 4 3 3 2 7 5 5 0 5 3 1 0
Contact
TELEFÓNICA TECH NORTHERN IRELAND LIMITED
Andrew Knight
Telephone: 028 90454433
Email: Bid.Management@telefonicatech.uk
About your service
- Service categories
-
PaaS
Data Management
- Database management systems
- Databases
- Database administration and development
- Data integration and intelligence
Service scope
- Service constraints
- None
- System requirements
- This will vary for each offering.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- Response times dependent on priority level of issue logged and whether via telephone or email.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes
- Support levels
- Support Desk: The Service Desk acts as the single point of contact for all end users, offering support via the Customer Portal, phone, and email. The Service Desk is staffed by highly skilled personnel and retains full lifecycle ownership of all incidents, problems, and changes recorded in the IT Service Management tool. Standard hours of operation are 8am-6pm Mon-Fri (excluding UK Bank Holidays), with 24x7x365 cover for Priority 1 incidents.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Telefonica Tech will manage the onboarding of services on behalf of the customer.
After receiving a sales order from the customer, a welcome pack, service guide, and provisioning worksheet will be sent. These documents introduce the service and begin the collection of information needed to configure the service.
On termination of the service, Telefonica Tech Transition Management will co-ordinate the offboarding of the service, which will constitute of the following activities at a minimum:
•Provide final billing and reporting to customer.
•Removal of customer IP address space from the platform.
•Request to remove all Telefonica Tech and customer accounts within the platform
•Delete any sensitive customer information and all contact information held that is no longer required.
•Disable service and/or customer within ITSM systems and disable any customer accounts no longer required. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Upon receiving notification of termination, if data extract has been requested - Telefónica Tech can first provide a raw export of logs (where appropriate).
Telefónica Tech will on a mutually agreed date, simply delete the customer’s data securely from the service application and disable the customer’s access. - End-of-contract process
-
On termination of the service, Telefonica Tech Transition Management will co-ordinate the offboarding of the service, which will constitute of the following activities at a minimum:
•Provide final billing and reporting to customer.
•Request to remove all Telefonica Tech and customer accounts within the platform
•Removal of customer IP address space from the platform.
•Delete any sensitive customer information and all contact information held that is no longer required.
•Disable service and/or customer within ITSM systems and disable any customer accounts no longer required. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Telefonica Tech will manage the onboarding of services on behalf of the customer.
After receiving a sales order from the customer, a welcome pack, service guide, and provisioning worksheet will be sent. These documents introduce the service and begin the collection of information needed to configure the service.
On termination of the service, Telefonica Tech Transition Management will co-ordinate the offboarding of the service, which will constitute of the following activities at a minimum:
•Provide final billing and reporting to customer.
•Removal of customer IP address space from the platform.
•Request to remove all Telefonica Tech and customer accounts within the platform
•Delete any sensitive customer information and all contact information held that is no longer required.
•Disable service and/or customer within ITSM systems and disable any customer accounts no longer required.
Using the service
- Web browser interface
- No
- API
- No
- Command line interface
- No
Scaling
- Independence of resources
- Resources are logically segregated to ensure customer data, configurations, and performance are isolated. Capacity is actively monitored and managed by Telefónica Tech to support changes in demand, user volumes, and workload intensity. The service is designed to scale without disruption, enabling customers to increase or decrease usage as required while maintaining consistent performance, availability, and service levels.
- Usage notifications
- Yes
- Usage reporting
-
- API
- SMS
- Optimising consumption
- Yes
- Automatic scaling
- Yes
Analytics
- Infrastructure or application metrics
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Microsoft and AWS
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Backup and recovery
- Backup controls
- Users can influence backup configuration by defining backup frequency, retention policies, and encryption needs for data at rest and in transit, ensuring compliance and security considerations are met. Backup performance is periodically reviewed and adjusted as necessary to optimise costs, improve efficiency, and ensure compliance with changing business needs.
- Datacentre setup
- Multiple datacentres with disaster recovery
- Scheduling backups
- Supplier controls the whole backup schedule
- Backup recovery
-
- Users can recover backups themselves, for example through a web interface
- Users contact the support team
- Backup and recovery
- Yes
- RPO/RTO
- Yes
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Telefónica Tech has SLA’s and Penalties (service credits) as standard offerings for each of our managed services.
Dependent on the provided service, services shall be deemed available when the customer is able to access and use the services hosted or provided by Telefónica Tech. This may include periods where the customer is unable to access applications and services, where it is demonstrated by Telefónica Tech to the customer’s satisfaction, or where any inability to access the customer’s applications and services is the result of permitted downtime.
Any reduced charges under this Service Level Agreement will be confirmed by credit note issued by Telefónica Tech to our customers, confirming any adjustment to be made to the following monthly charge.
99.95% availability is guaranteed. - Approach to resilience
-
The Telefónica Tech datacentres and the services provided from within have been architected in meticulous detail from the ground up, built upon enterprise class best of breed hardware and technology, ensuring services are provided from a fully resilient infrastructure of at least N+1 with no single points of failure, across geographically-diverse Tier 3+ datacentres.
From the power feeds from separate power grids, multiple generators and UPS's all tested weekly, to the fire suppression systems, resilient networking and WAN links, storage and compute clusters, all aspects have been carefully considered using best of breed technology with no single points of failure. - Outage reporting
-
Our Corrective action of Events & Incidents policy, which is in scope of our ISO27001, ISO9001, ISO20000, ISO27018 and ISO22301 certifications, following standard ITIL conformant Major Incident Management processes.
This includes informing stakeholders immediately without delay.
Identity and authentication
- User authentication needed
- No
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is strictly controlled using role-based access controls and the principle of least privilege. User access is authenticated using Multi-Factor Authentication, with integration to Microsoft identity services where applicable. Administrative access is limited to authorised personnel and is logged and monitored. Support access is restricted to named users and granted only where required to deliver support activities. All access to management interfaces and support systems is auditable, with actions recorded and retained in line with service policies to support monitoring, investigation, and compliance requirements.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Devices users manage the service through
-
- Dedicated device on a segregated network (providers own provision)
- Dedicated device on a government network (for example PSN)
- Dedicated device over multiple services or networks
- Directly from any device which may also be used for normal business (for example web browsing or viewing external email)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
A full-time compliance team is employed to manage and maintain our certifications and accreditations. Staff are fully trained and competent to work within our management systems, which are mature and continually improved, as proven in regular internal and external audits.
An overview of the diverse set of the externally assessed ISO standards and best practice accreditations Telefónica Tech adheres to are as follows:
ISO27001 (Information Security)
ISO22301 (Business Continuity Management System)
ISO20000 (ITIL Service Management)
ISO9001 (Quality)
ISO27018 Code of Practise (Protection of Personally Identifiable Information in the Cloud)
Government OFFICIAL Classification Supplier
Approved G Cloud Supplier
Approved Commercial N3 Aggregator transitioning to a HSCN Supplier
Health & Social Care Network (HSCN) Compliant
Cyber Essentials Certificate of Assurance
IASME Information Security Standard Certificate of Assurance
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Our methodology minimises the impact of change-related incidents on service quality and improves the day-to-day operations of the organisation. The procedures are designed to ensure that all changes are correctly planned, interested parties are notified and any service interruption is controlled. Changes can be initiated by the client or internally within Telefónica Tech. A robust Change Control process minimises the risk associated with changes. It enables all parties to keep track of changes made to systems, ensures implications of changes are assessed and that interdependencies are explored. A back-out process is also considered before any change is implemented.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Annual IT Health Checks are completed by a CHECK accredited independent organisation under the CHECK Scheme. The CHECK scheme enables penetration testing by CESG approved companies, employing penetration testing personnel, qualified to assess HMG and other public and private sector bodies. The testing personnel are CHECK Team Leaders who have proven their technical competency through lab examinations and written exams, they are skilled in application and infrastructure testing. They have also undergone thorough background checking. This technical compliance review is an extensive internal and external examination of operational systems to ensure that hardware and software controls have been correctly implemented.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
This is achieved through continuous monitoring of events and logs, advanced SIEM platforms and expert teams. Proactive threat detection and continuous risk assessment are carried out using xDR platforms and proprietary developments, with security event monitoring extended across all environments (on-premise/cloud).
When a potential compromise is found, the SOC team performs initial triage and analysis, followed by alerting and response, incident management, root cause analysis, and remediation escalation as required.
Incident response times are structured by alert severity, starting from 5=minutes for P1/P2 (high-severity) incidents. Level-1 analysts verify alerts and escalate, ensuring prompt and effective action for critical events. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- The Telefónica Tech Service Desk enables our team to co-ordinate the work of restoring supported systems as soon as possible and within agreed SLAs. The Service Desk determines the nature of incidents so they can be sent to appropriately skilled engineers for resolution. An IMS is incorporated within the Service Desk. When logging calls via the telephone Service Desk, the call operative uses the same call logging software that the customer will have access to via our secure web portal. Integrated with this functionality is our knowledge base, which is used to capture information and provide accurate incident reports.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Separation between users
- Virtualisation technology used to keep applications and users sharing the same infrastructure apart
- No
Energy efficiency
- Energy-efficient datacentres
- Yes
- Description of energy efficient datacentres
- Telefónica Tech provides services from four UK Tier 3 standard data centres located in Huntingdon, Northampton, London, and Reading, designed to deliver high standards of energy efficiency and resilience for [ClientName] workloads at Northampton or Huntingdon Data Centre. All data centres offer Tier 3 standard as a minimum, with a 99.9999% SLA on power and cooling uptime, uninterruptible power supply, multiple temperature and humidity sensors throughout the data halls, and fully monitored Building Management Systems (BMS) operating 24x7x365. Energy efficiency is further supported by fire detection and suppression systems, zonal swipe card access, and secure perimeter fencing. Telefónica Tech subscribes to ESG principles, implementing proprietary equipment startup and shutdown technology to reduce energy consumption and minimise our carbon footprint. Our cloud platform solutions carry the Eco Smart seal, enabling organisations to optimise energy use and reduce CO2 emissions through shared platforms, which are more efficient compared to traditional servers. All centres are ISO 14001 accredited for Environmental Management and ISO 27001 accredited for Information Security, ensuring compliance with recognised standards for sustainability and operational excellence. Telefónica Tech is committed to continuous improvement and transparent reporting, supporting EU Code of Conduct objectives for energy-efficient datacentre operation.
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount
- Provide your minimum discount applicable to your baseline prices
- 0%
Formula for calculating price of your services
- Formula for calculating price of your services
-
Which of the core deployment models you intend to offer
- Public Cloud
- Private Cloud
Public Cloud - Formula for calculating price of your services
- Total Cost
- The Total Cost for a buyer's call off requirement in a Public Cloud Deployment
- =
- Baseline Pricing
- Baseline pricing is available on request, via info@telefonicatech.uk. This is not publicly available.
- Baseline Pricing - Web link
- https://azure.microsoft.com/en-gb/pricing/calculator
- -
- Minimum Discounting
- 0%
- +
- Onboarding Activity
- Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
- +
- Additional sources of cost
- Management overheads, energy price fluctuations, exchange rate fluctuations and inflation.
- -
- Additional sources of cost reduction
- Source reductions include volume discounts, long-term commitment discounts and NHS specific pricing.
Private Cloud - Formula for calculating price of your services
- Total Cost
- The Total Cost for a buyer's call off requirement in a Private Cloud Deployment
- =
- Baseline Pricing
- Baseline pricing is available on request, via info@telefonicatech.uk. This is not publicly available.
- -
- Minimum Discounting
- 0%
- +
- Onboarding Activity
- Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
- +
- Additional sources of cost
- Management overheads, energy price fluctuations, exchange rate fluctuations and inflation.
- -
- Additional sources of cost reduction
- Source reductions include volume discounts, long-term commitment discounts and NHS specific pricing.
Mandatory certifications
- Mandatory certifications
-
Are you are bidding to offer IaaS and/or PaaS as a reseller or are you in sole control of the infrastructure
ResellerCloud service suppliers you intend to resell with evidence
Organisation 1
Organisation name
MicrosoftWebsite address/upload for organisation
Website addressWebsite address
https://marketplace.microsoft.com/en-us/partners/ca7d3eaf-db0d-4ff4-b526-af965a237315/overviewOrganisation 2
Organisation name
AWSWebsite address/upload for organisation
Website addressWebsite address
https://partners.amazonaws.com/partners/001E000000t0uuOIAQ/Telefonica%20Cybersecurity%20and%20Cloud%20TechISO 9001 certification
ProvidedISO 27001 certification
ProvidedISO 20000-1 certification
ProvidedAre you reliant on the Cloud Service Provider for some accreditations
Yes
Cyber Essentials
- Do you have a Cyber Essentials Plus certificate?
- Yes
- Cyber Essentials Plus certificate Number
- E6b63a4c-40e4-466f-8c2d-0c5236d81491
Non-mandatory Standards and certifications
- ISO 28000:2022 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Other security certifications
- Yes
- Any other security certifications
-
- ICO Data Protection
- HSCN
- ISO22301
- ISO2000-1
- ISO14001
- ISO9001
- ISO27001
- Cyber Essentials
- Cyber Essentials Plus
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
-