Skip to main content

Help us improve the Digital Marketplace - send your feedback

INSIGHT DIRECT (UK) LTD

Governance, Risk and Compliance

Lack of governance and unmanaged risks lead to data breaches, regulatory fines, and operational inefficiencies. Microsoft 365 GRC enforces policies, monitors compliance, and mitigates risks—resolving audit gaps, reducing legal exposure, and ensuring secure, transparent operations while maintaining productivity and trust across the organization

Features

  • Automated policy enforcement across Microsoft 365 applications and services.
  • Compliance Manager for continuous regulatory assessment and improvement.
  • Data Loss Prevention to prevent unauthorized sharing of sensitive information.
  • Information barriers to control communication between restricted user groups.
  • Advanced eDiscovery for legal investigations and data retrieval.
  • Insider risk management to detect and mitigate internal threats.
  • Audit logging for detailed activity tracking and compliance reporting.
  • Retention policies to manage lifecycle of business-critical data.
  • Risk-based compliance scoring for proactive governance improvements.
  • Integration with Microsoft Purview for unified compliance and data governance.

Benefits

  • Ensures regulatory compliance across global standards and frameworks.
  • Reduces risk exposure through proactive monitoring and mitigation.
  • Prevents data leaks with robust Data Loss Prevention controls.
  • Improves transparency with detailed audit logs and reporting tools.
  • Supports legal processes via advanced eDiscovery and case management.
  • Strengthens governance through automated policy enforcement and retention rules.
  • Protects sensitive data with classification and labeling capabilities.
  • Detects insider threats early using risk-based analytics and alerts.
  • Simplifies compliance management with integrated dashboards and scoring.
  • Enhances trust by maintaining secure and compliant digital operations.

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at pstenderteam@insight.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 3 0 5 5 4 3 5 7 0 0 5 3 5 4

Contact

INSIGHT DIRECT (UK) LTD Public Sector Tender Team
Telephone: 0344 846 3333
Email: pstenderteam@insight.com

About your service

Service categories

Systems Infrastructure Software

Security

  • Governance, risk and compliance
Multi cloud support
No

Service scope

Software add-on or extension
Yes
What software services is the service an extension to
M365 subscriptions include Privilege Identity and access management. Such subscriptions extend to multiple other productivity features.
Cloud deployment model
  • Public cloud
  • Hybrid cloud
Service constraints
M365 Product Specific
System requirements
M365 Subscriptions.

User support

Email or online ticketing support
Yes, at extra cost
Support response times
SLAs are agreed during the provisioning of a Managed Service contract.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
We have conducted web chat testing with assistive technology users to ensure that our platform is fully accessible. This testing involved engaging users with various disabilities who utilize screen readers and other assistive devices. Feedback from these users was instrumental in refining our chat interface to ensure seamless navigation and interaction. Our team ensured that the web chat complies with WCAG 2.2 Level AA standards, enabling effective communication for all users. We also regularly update our testing protocols based on the latest accessibility guidelines and user feedback to maintain and enhance usability for those relying on assistive technologies.
Onsite support
No
Support levels
We provide three support levels: Standard, Enhanced, and Premium. Each level offers different response times and access to resources, allowing clients to choose the appropriate level of support based on their needs.

Standard support includes access to our online help centre and email support during business hours. Enhanced support offers faster response times and additional access to resources, including phone support during extended hours. Premium support provides the highest level of service, including 24/7 assistance and dedicated resources for urgent issues.

Clients can opt for a technical account manager or a cloud support engineer, depending on the chosen support level. Our technical account managers provide strategic guidance and oversight, while cloud support engineers focus on technical issues and operational support to ensure optimal performance of our software platforms.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
We provide comprehensive onboarding support to help users start using our service effectively. Our onboarding process includes online training sessions tailored to the specific needs of users, along with user documentation that is accessible and meets WCAG 2.2 Level AA standards. This documentation is available in multiple formats, including PDF and HTML, ensuring users can access it in a way that suits them best.

Additionally, we offer role-based access control and multi-factor authentication (MFA) to ensure secure access to the platform from the outset. Users are guided through the setup process, including configuring workflows and automation tools such as Ansible and Terraform, to maximise the benefits of our software platform.

Furthermore, we emphasize user adoption and change management principles in our training to facilitate a smooth transition to our platform. Our dedicated support team is available to address any questions during the onboarding process, ensuring users feel confident and supported as they begin their journey with our service.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
Upon contract termination, users can extract their data through a streamlined process designed to ensure data portability and integrity. Prior to the end of the contract, we will provide users with detailed instructions and support to facilitate the data extraction. Users can access their data via our RESTful API, allowing for secure and efficient data transfer. The data will be available in a commonly used format to ensure compatibility with other systems. Additionally, we recommend users perform a final data backup prior to contract conclusion to ensure no data is lost. After extraction, users can confirm that all data has been successfully retrieved, and we will assist in addressing any queries or concerns throughout the process. This approach not only safeguards user data but also aligns with our commitment to transparency and customer support.
End-of-contract process
At the end of the contract, we ensure a smooth transition for our clients. Included in the contract price is the provision of data extraction support, where users will receive detailed guidance on how to retrieve their data securely using our RESTful API. This process is designed to be straightforward and ensures data integrity.

Additionally, we offer assistance in confirming that all data has been successfully extracted, which is part of our commitment to customer support.

Any further services beyond this data extraction support, such as extended assistance or additional data migration services, may incur additional costs. Clients will be informed of these options well in advance, allowing for informed decisions regarding their data management needs post-contract. Our goal is to facilitate a seamless offboarding experience while maintaining high standards of data security and compliance.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The mobile service is optimised for smaller screens, ensuring a responsive design that maintains core functionality and usability. Users can access essential features such as dashboards, notifications, and key workflows seamlessly on mobile devices. However, some advanced configuration options and integrations available on the desktop version may be limited or presented differently on mobile to enhance user experience. Overall, both platforms provide a consistent interface, but the mobile version prioritises simplicity and ease of navigation for on-the-go access.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service interface is intuitive and user-friendly, designed to facilitate seamless interaction. Users can access the platform via a cloud-native web application that supports mobile responsiveness. Role-based access control ensures that users have appropriate permissions, while multi-factor authentication enhances security. The platform features RESTful APIs for integration with third-party services, and configurable workflows allow for automation tailored to specific needs. Comprehensive training and onboarding support users in adapting to the system, ensuring they can effectively navigate the interface and utilize its functionalities.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
NA
API
Yes
What users can and can't do using the API
Users can set up the service through the API by creating an account, configuring user roles, and defining access permissions via RESTful API endpoints. They can also establish integrations with third-party applications and configure workflows to automate processes. Changes can be made through the API by updating user settings, modifying workflows, and adjusting integration parameters as required. However, there are limitations; users cannot alter core system configurations or modify underlying security protocols via the API. Additionally, certain administrative functions may be restricted to users with elevated permissions to ensure system integrity and security.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can customise our service in several ways to meet their specific needs. They can alter the user interface by selecting themes and configuring dashboard layouts to better suit their workflow. Additionally, users can define and automate workflows using Ansible and Terraform, allowing for tailored process management that aligns with their organisational requirements. Role-based access control enables users to manage permissions effectively, granting access to certain functionalities based on team roles.

Customisation can be performed by users who possess the appropriate permissions. Typically, administrators or designated personnel with sufficient access rights will handle these customisation tasks. Comprehensive training is provided to ensure users understand how to make these adjustments, ensuring a smooth transition and effective use of the platform. Overall, our software platform is designed to empower users to adapt the system to their specific operational needs while maintaining robust security and compliance standards.

Scaling

Independence of resources
We guarantee users are unaffected by demand through our robust cloud-native architecture, which includes auto-scaling capabilities. This ensures resources dynamically adjust based on real-time usage, maintaining consistent performance levels. Additionally, our infrastructure is built on VMware and AWS, which provides high availability and redundancy. We implement load balancing to distribute user requests evenly across servers, preventing any single point of failure. Regular performance monitoring and capacity planning further ensure optimal service delivery, thereby minimising the impact of concurrent user demand.

Analytics

Service usage metrics
Yes
Metrics types
NA
Reporting types
Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Other
Other data at rest protection approach
Data at rest is protected through multiple layers of security. In addition to AES-256 encryption, we implement strict access controls governed by role-based access and multi-factor authentication (MFA). All data is stored in secure, monitored environments with regular vulnerability assessments aligned with ISO 27001 standards. We also maintain comprehensive audit trails with logs retained for 6-12 months, ensuring continuous oversight. Furthermore, our platforms undergo annual third-party penetration testing to identify and address potential vulnerabilities. This holistic approach safeguards customer data effectively against unauthorized access and threats.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Users can request their data through our GDPR compliant process
Data export formats
Other
Other data export formats
Request-specific data delivered in formats like Excel or PDF.
Data import formats
Other
Other data import formats
Users can request their data through our GDPR compliant process

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
We implement additional protection measures for data in transit, including secure virtual private networks (VPNs) that encrypt data traffic between the buyer's network and our services. We also employ advanced firewalls and intrusion detection systems to monitor and filter network traffic, ensuring only legitimate data flows are permitted. Furthermore, our robust access control policies restrict network access to authorised personnel only, reducing exposure to potential threats. Regular security assessments and audits are conducted to identify and mitigate vulnerabilities, ensuring ongoing protection of data during transmission.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
We protect data within our network through a multi-layered security approach. This includes advanced encryption protocols such as AES-256 for data at rest, ensuring sensitive information is safeguarded. Additionally, we enforce strict access controls with multi-factor authentication (MFA) for all system access, minimising the risk of unauthorised access. Our network is continuously monitored by 24/7 XDR for any suspicious activity, with comprehensive logging and audit trails retained for up to 12 months. Regular third-party penetration testing is conducted to identify and remediate vulnerabilities, ensuring our environment remains secure against emerging threats.

Availability and resilience

Guaranteed availability
We guarantee a 99.9% availability for our software platform, supported by a comprehensive Service Level Agreement (SLA). In the event that we do not meet this guaranteed level of availability, users are entitled to a service credit. Our SLA outlines the specific conditions and processes to claim these credits, ensuring transparency and accountability. We continually monitor our systems 24/7 using extended detection and response (XDR) to swiftly identify and resolve any issues that may impact availability. Additionally, we conduct annual third-party penetration testing to ensure the robustness of our security measures, further enhancing the reliability of our service.
Approach to resilience
Our service is designed with resilience at its core, employing a multi-tiered approach to ensure continuity and reliability. We operate data centres that are geographically distributed, each equipped with redundant power supplies, cooling systems, and network connectivity. This setup allows for automatic failover between locations, ensuring that services remain operational even in the event of a localised failure. We implement regular backup procedures, allowing clients to define workloads, frequencies, and retention policies to safeguard their data.

Furthermore, our cloud-native architecture supports rapid scaling and load balancing, distributing workloads across multiple resources to prevent any single point of failure. All infrastructure is monitored 24/7 through extended detection and response (XDR), enabling us to proactively identify and address potential issues before they impact service availability.

While specific details of our data centre setup can be provided upon request, we maintain compliance with government security principles, ensuring asset protection and resilience in line with NCSC guidelines. Our commitment to maintaining Cyber Essentials Plus certification and relevant ISO standards underpins our dedication to delivering a secure and resilient software platform.
Outage reporting
Our service reports any outages through a combination of a public dashboard, an API, and email alerts. The public dashboard provides real-time visibility into system status and any incidents affecting service availability. Users can also access outage information through our comprehensive API, which allows for integration with other systems for automated monitoring. Additionally, we send timely email alerts to notify users of any outages or service interruptions, ensuring that our clients are informed promptly. This multi-channel approach allows for transparency and effective communication regarding service availability.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Other
Other user authentication
User authentication for our service is enforced through Multi-Factor Authentication (MFA), ensuring robust security measures. Users must provide multiple forms of verification before accessing the platform, which includes their credentials and an additional authentication factor. We support role-based access controls to restrict access based on user roles, enhancing security further. All authentication attempts are meticulously logged, and we maintain comprehensive audit trails for compliance and security monitoring. Regular access reviews are conducted to ensure adherence to security protocols and mitigate any risks associated with unauthorised access.
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted through Multi-Factor Authentication (MFA), ensuring that only authorised personnel can gain access. Role-based access control is employed, limiting user permissions based on their specific roles. All access attempts are logged, with comprehensive audit trails maintained for security compliance. Regular reviews of access permissions are conducted to ensure ongoing adherence to security policies, thereby minimising the risk of unauthorised access to sensitive information and systems.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Other
Description of management access authentication
Management access to our service is authenticated through Multi-Factor Authentication (MFA), ensuring that only authorised personnel can access critical systems. We implement strict role-based access control, requiring MFA for all system access. Additionally, all login attempts are logged, and comprehensive audit trails are maintained for security and compliance purposes. Regular reviews of access permissions are conducted to ensure ongoing security adherence.

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials Plus, ISO 9001, ISO 27001, ISO 20000, ISO 14001, PCI-DSS.
Information security policies and processes
Our information security policies and processes are guided by ISO/IEC 27001, ensuring a robust framework for managing sensitive information. We maintain a comprehensive reporting structure where security policies are overseen by our Chief Information Security Officer (CISO), who reports directly to the Board. This structure ensures accountability and high-level oversight of security practices.

All employees undergo regular training on security policies, which are reinforced through awareness campaigns. Compliance is monitored through regular audits and assessments, with findings reported to management for prompt action. We engage in third-party penetration testing annually to validate our security posture and identify areas for improvement. Additionally, we have established incident response protocols that mandate notification within 24-48 hours of a security incident, ensuring timely communication and remediation. Our policies also mandate maintaining complete audit trails with logs retained for 6-12 months, facilitating accountability and transparency in our security operations.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Our configuration and change management processes involve comprehensive tracking of service components throughout their lifecycle, utilising a change management tool integrated with our ServiceNow platform. Each component is logged, monitored, and version-controlled to ensure traceability. Changes are assessed for potential security impacts through a structured risk assessment process, considering factors such as vulnerability exposure and compliance with ISO 27001. This assessment is conducted prior to implementation, ensuring that security implications are identified and mitigated effectively. Regular audits and reviews further enhance our change management practices, maintaining alignment with industry standards and best practices.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Our vulnerability management process includes continuous assessment of potential threats through threat intelligence feeds, vulnerability scanning, and analysis of security advisories. We deploy patches within 24 hours of identifying critical vulnerabilities and 72 hours for high-severity issues, ensuring timely mitigation of risks. Our threat information sources include industry-standard databases such as CVE, vendor notifications, and threat intelligence platforms, allowing us to stay informed about emerging threats and vulnerabilities. Regular reviews and updates to our vulnerability management program align with ISO standards and Cyber Essentials Plus certification.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Our protective monitoring processes involve continuous monitoring of systems to identify potential compromises through automated alerts and anomaly detection. Upon detection, we initiate an incident response protocol within 30 minutes, assessing the impact and scope of the compromise. Our response includes containment, eradication, and recovery actions, followed by a thorough investigation to understand the incident's cause. We ensure stakeholders are informed within 24-48 hours. Regular reviews and updates to our monitoring tools and processes are conducted to enhance our detection and response capabilities, aligning with ISO and Cyber Essentials Plus standards.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Our incident management processes include predefined protocols for common events, ensuring a swift and effective response. Users can report incidents through our ServiceNow platform, which provides a streamlined interface for logging issues. We generate incident reports that detail the nature of the incident, actions taken, and resolution steps, which are shared with relevant stakeholders to maintain transparency. These reports are part of our commitment to continuous improvement and compliance with ISO standards, ensuring we learn from incidents to enhance our services.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Atlas
ISO/IEC 27001 accreditation date
Sunday 13 April 2025
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Atlas
ISO 9001 accreditation date
Tuesday 1 April 2025
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Be7ce590-de10-486e-8431-2e10891a8979
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
Cd8b1a78-44c7-4bb0-84d6-59a7506f3bba
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Ensuring new workers are informed of their right to join a trade union
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at pstenderteam@insight.com. Tell them what format you need. It will help if you say what assistive technology you use.