Governance, Risk and Compliance
Lack of governance and unmanaged risks lead to data breaches, regulatory fines, and operational inefficiencies. Microsoft 365 GRC enforces policies, monitors compliance, and mitigates risks—resolving audit gaps, reducing legal exposure, and ensuring secure, transparent operations while maintaining productivity and trust across the organization
Features
- Automated policy enforcement across Microsoft 365 applications and services.
- Compliance Manager for continuous regulatory assessment and improvement.
- Data Loss Prevention to prevent unauthorized sharing of sensitive information.
- Information barriers to control communication between restricted user groups.
- Advanced eDiscovery for legal investigations and data retrieval.
- Insider risk management to detect and mitigate internal threats.
- Audit logging for detailed activity tracking and compliance reporting.
- Retention policies to manage lifecycle of business-critical data.
- Risk-based compliance scoring for proactive governance improvements.
- Integration with Microsoft Purview for unified compliance and data governance.
Benefits
- Ensures regulatory compliance across global standards and frameworks.
- Reduces risk exposure through proactive monitoring and mitigation.
- Prevents data leaks with robust Data Loss Prevention controls.
- Improves transparency with detailed audit logs and reporting tools.
- Supports legal processes via advanced eDiscovery and case management.
- Strengthens governance through automated policy enforcement and retention rules.
- Protects sensitive data with classification and labeling capabilities.
- Detects insider threats early using risk-based analytics and alerts.
- Simplifies compliance management with integrated dashboards and scoring.
- Enhances trust by maintaining secure and compliant digital operations.
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 3 0 5 5 4 3 5 7 0 0 5 3 5 4
Contact
INSIGHT DIRECT (UK) LTD
Public Sector Tender Team
Telephone: 0344 846 3333
Email: pstenderteam@insight.com
About your service
- Service categories
-
Systems Infrastructure Software
Security
- Governance, risk and compliance
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- M365 subscriptions include Privilege Identity and access management. Such subscriptions extend to multiple other productivity features.
- Cloud deployment model
-
- Public cloud
- Hybrid cloud
- Service constraints
- M365 Product Specific
- System requirements
- M365 Subscriptions.
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- SLAs are agreed during the provisioning of a Managed Service contract.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- We have conducted web chat testing with assistive technology users to ensure that our platform is fully accessible. This testing involved engaging users with various disabilities who utilize screen readers and other assistive devices. Feedback from these users was instrumental in refining our chat interface to ensure seamless navigation and interaction. Our team ensured that the web chat complies with WCAG 2.2 Level AA standards, enabling effective communication for all users. We also regularly update our testing protocols based on the latest accessibility guidelines and user feedback to maintain and enhance usability for those relying on assistive technologies.
- Onsite support
- No
- Support levels
-
We provide three support levels: Standard, Enhanced, and Premium. Each level offers different response times and access to resources, allowing clients to choose the appropriate level of support based on their needs.
Standard support includes access to our online help centre and email support during business hours. Enhanced support offers faster response times and additional access to resources, including phone support during extended hours. Premium support provides the highest level of service, including 24/7 assistance and dedicated resources for urgent issues.
Clients can opt for a technical account manager or a cloud support engineer, depending on the chosen support level. Our technical account managers provide strategic guidance and oversight, while cloud support engineers focus on technical issues and operational support to ensure optimal performance of our software platforms. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
We provide comprehensive onboarding support to help users start using our service effectively. Our onboarding process includes online training sessions tailored to the specific needs of users, along with user documentation that is accessible and meets WCAG 2.2 Level AA standards. This documentation is available in multiple formats, including PDF and HTML, ensuring users can access it in a way that suits them best.
Additionally, we offer role-based access control and multi-factor authentication (MFA) to ensure secure access to the platform from the outset. Users are guided through the setup process, including configuring workflows and automation tools such as Ansible and Terraform, to maximise the benefits of our software platform.
Furthermore, we emphasize user adoption and change management principles in our training to facilitate a smooth transition to our platform. Our dedicated support team is available to address any questions during the onboarding process, ensuring users feel confident and supported as they begin their journey with our service. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Upon contract termination, users can extract their data through a streamlined process designed to ensure data portability and integrity. Prior to the end of the contract, we will provide users with detailed instructions and support to facilitate the data extraction. Users can access their data via our RESTful API, allowing for secure and efficient data transfer. The data will be available in a commonly used format to ensure compatibility with other systems. Additionally, we recommend users perform a final data backup prior to contract conclusion to ensure no data is lost. After extraction, users can confirm that all data has been successfully retrieved, and we will assist in addressing any queries or concerns throughout the process. This approach not only safeguards user data but also aligns with our commitment to transparency and customer support.
- End-of-contract process
-
At the end of the contract, we ensure a smooth transition for our clients. Included in the contract price is the provision of data extraction support, where users will receive detailed guidance on how to retrieve their data securely using our RESTful API. This process is designed to be straightforward and ensures data integrity.
Additionally, we offer assistance in confirming that all data has been successfully extracted, which is part of our commitment to customer support.
Any further services beyond this data extraction support, such as extended assistance or additional data migration services, may incur additional costs. Clients will be informed of these options well in advance, allowing for informed decisions regarding their data management needs post-contract. Our goal is to facilitate a seamless offboarding experience while maintaining high standards of data security and compliance. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile service is optimised for smaller screens, ensuring a responsive design that maintains core functionality and usability. Users can access essential features such as dashboards, notifications, and key workflows seamlessly on mobile devices. However, some advanced configuration options and integrations available on the desktop version may be limited or presented differently on mobile to enhance user experience. Overall, both platforms provide a consistent interface, but the mobile version prioritises simplicity and ease of navigation for on-the-go access.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service interface is intuitive and user-friendly, designed to facilitate seamless interaction. Users can access the platform via a cloud-native web application that supports mobile responsiveness. Role-based access control ensures that users have appropriate permissions, while multi-factor authentication enhances security. The platform features RESTful APIs for integration with third-party services, and configurable workflows allow for automation tailored to specific needs. Comprehensive training and onboarding support users in adapting to the system, ensuring they can effectively navigate the interface and utilize its functionalities.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- NA
- API
- Yes
- What users can and can't do using the API
- Users can set up the service through the API by creating an account, configuring user roles, and defining access permissions via RESTful API endpoints. They can also establish integrations with third-party applications and configure workflows to automate processes. Changes can be made through the API by updating user settings, modifying workflows, and adjusting integration parameters as required. However, there are limitations; users cannot alter core system configurations or modify underlying security protocols via the API. Additionally, certain administrative functions may be restricted to users with elevated permissions to ensure system integrity and security.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users can customise our service in several ways to meet their specific needs. They can alter the user interface by selecting themes and configuring dashboard layouts to better suit their workflow. Additionally, users can define and automate workflows using Ansible and Terraform, allowing for tailored process management that aligns with their organisational requirements. Role-based access control enables users to manage permissions effectively, granting access to certain functionalities based on team roles.
Customisation can be performed by users who possess the appropriate permissions. Typically, administrators or designated personnel with sufficient access rights will handle these customisation tasks. Comprehensive training is provided to ensure users understand how to make these adjustments, ensuring a smooth transition and effective use of the platform. Overall, our software platform is designed to empower users to adapt the system to their specific operational needs while maintaining robust security and compliance standards.
Scaling
- Independence of resources
- We guarantee users are unaffected by demand through our robust cloud-native architecture, which includes auto-scaling capabilities. This ensures resources dynamically adjust based on real-time usage, maintaining consistent performance levels. Additionally, our infrastructure is built on VMware and AWS, which provides high availability and redundancy. We implement load balancing to distribute user requests evenly across servers, preventing any single point of failure. Regular performance monitoring and capacity planning further ensure optimal service delivery, thereby minimising the impact of concurrent user demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
- NA
- Reporting types
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
- Data at rest is protected through multiple layers of security. In addition to AES-256 encryption, we implement strict access controls governed by role-based access and multi-factor authentication (MFA). All data is stored in secure, monitored environments with regular vulnerability assessments aligned with ISO 27001 standards. We also maintain comprehensive audit trails with logs retained for 6-12 months, ensuring continuous oversight. Furthermore, our platforms undergo annual third-party penetration testing to identify and address potential vulnerabilities. This holistic approach safeguards customer data effectively against unauthorized access and threats.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users can request their data through our GDPR compliant process
- Data export formats
- Other
- Other data export formats
- Request-specific data delivered in formats like Excel or PDF.
- Data import formats
- Other
- Other data import formats
- Users can request their data through our GDPR compliant process
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- We implement additional protection measures for data in transit, including secure virtual private networks (VPNs) that encrypt data traffic between the buyer's network and our services. We also employ advanced firewalls and intrusion detection systems to monitor and filter network traffic, ensuring only legitimate data flows are permitted. Furthermore, our robust access control policies restrict network access to authorised personnel only, reducing exposure to potential threats. Regular security assessments and audits are conducted to identify and mitigate vulnerabilities, ensuring ongoing protection of data during transmission.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- We protect data within our network through a multi-layered security approach. This includes advanced encryption protocols such as AES-256 for data at rest, ensuring sensitive information is safeguarded. Additionally, we enforce strict access controls with multi-factor authentication (MFA) for all system access, minimising the risk of unauthorised access. Our network is continuously monitored by 24/7 XDR for any suspicious activity, with comprehensive logging and audit trails retained for up to 12 months. Regular third-party penetration testing is conducted to identify and remediate vulnerabilities, ensuring our environment remains secure against emerging threats.
Availability and resilience
- Guaranteed availability
- We guarantee a 99.9% availability for our software platform, supported by a comprehensive Service Level Agreement (SLA). In the event that we do not meet this guaranteed level of availability, users are entitled to a service credit. Our SLA outlines the specific conditions and processes to claim these credits, ensuring transparency and accountability. We continually monitor our systems 24/7 using extended detection and response (XDR) to swiftly identify and resolve any issues that may impact availability. Additionally, we conduct annual third-party penetration testing to ensure the robustness of our security measures, further enhancing the reliability of our service.
- Approach to resilience
-
Our service is designed with resilience at its core, employing a multi-tiered approach to ensure continuity and reliability. We operate data centres that are geographically distributed, each equipped with redundant power supplies, cooling systems, and network connectivity. This setup allows for automatic failover between locations, ensuring that services remain operational even in the event of a localised failure. We implement regular backup procedures, allowing clients to define workloads, frequencies, and retention policies to safeguard their data.
Furthermore, our cloud-native architecture supports rapid scaling and load balancing, distributing workloads across multiple resources to prevent any single point of failure. All infrastructure is monitored 24/7 through extended detection and response (XDR), enabling us to proactively identify and address potential issues before they impact service availability.
While specific details of our data centre setup can be provided upon request, we maintain compliance with government security principles, ensuring asset protection and resilience in line with NCSC guidelines. Our commitment to maintaining Cyber Essentials Plus certification and relevant ISO standards underpins our dedication to delivering a secure and resilient software platform. - Outage reporting
- Our service reports any outages through a combination of a public dashboard, an API, and email alerts. The public dashboard provides real-time visibility into system status and any incidents affecting service availability. Users can also access outage information through our comprehensive API, which allows for integration with other systems for automated monitoring. Additionally, we send timely email alerts to notify users of any outages or service interruptions, ensuring that our clients are informed promptly. This multi-channel approach allows for transparency and effective communication regarding service availability.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Other
- Other user authentication
- User authentication for our service is enforced through Multi-Factor Authentication (MFA), ensuring robust security measures. Users must provide multiple forms of verification before accessing the platform, which includes their credentials and an additional authentication factor. We support role-based access controls to restrict access based on user roles, enhancing security further. All authentication attempts are meticulously logged, and we maintain comprehensive audit trails for compliance and security monitoring. Regular access reviews are conducted to ensure adherence to security protocols and mitigate any risks associated with unauthorised access.
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted through Multi-Factor Authentication (MFA), ensuring that only authorised personnel can gain access. Role-based access control is employed, limiting user permissions based on their specific roles. All access attempts are logged, with comprehensive audit trails maintained for security compliance. Regular reviews of access permissions are conducted to ensure ongoing adherence to security policies, thereby minimising the risk of unauthorised access to sensitive information and systems.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Other
- Description of management access authentication
- Management access to our service is authenticated through Multi-Factor Authentication (MFA), ensuring that only authorised personnel can access critical systems. We implement strict role-based access control, requiring MFA for all system access. Additionally, all login attempts are logged, and comprehensive audit trails are maintained for security and compliance purposes. Regular reviews of access permissions are conducted to ensure ongoing security adherence.
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials Plus, ISO 9001, ISO 27001, ISO 20000, ISO 14001, PCI-DSS.
- Information security policies and processes
-
Our information security policies and processes are guided by ISO/IEC 27001, ensuring a robust framework for managing sensitive information. We maintain a comprehensive reporting structure where security policies are overseen by our Chief Information Security Officer (CISO), who reports directly to the Board. This structure ensures accountability and high-level oversight of security practices.
All employees undergo regular training on security policies, which are reinforced through awareness campaigns. Compliance is monitored through regular audits and assessments, with findings reported to management for prompt action. We engage in third-party penetration testing annually to validate our security posture and identify areas for improvement. Additionally, we have established incident response protocols that mandate notification within 24-48 hours of a security incident, ensuring timely communication and remediation. Our policies also mandate maintaining complete audit trails with logs retained for 6-12 months, facilitating accountability and transparency in our security operations. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Our configuration and change management processes involve comprehensive tracking of service components throughout their lifecycle, utilising a change management tool integrated with our ServiceNow platform. Each component is logged, monitored, and version-controlled to ensure traceability. Changes are assessed for potential security impacts through a structured risk assessment process, considering factors such as vulnerability exposure and compliance with ISO 27001. This assessment is conducted prior to implementation, ensuring that security implications are identified and mitigated effectively. Regular audits and reviews further enhance our change management practices, maintaining alignment with industry standards and best practices.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Our vulnerability management process includes continuous assessment of potential threats through threat intelligence feeds, vulnerability scanning, and analysis of security advisories. We deploy patches within 24 hours of identifying critical vulnerabilities and 72 hours for high-severity issues, ensuring timely mitigation of risks. Our threat information sources include industry-standard databases such as CVE, vendor notifications, and threat intelligence platforms, allowing us to stay informed about emerging threats and vulnerabilities. Regular reviews and updates to our vulnerability management program align with ISO standards and Cyber Essentials Plus certification.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Our protective monitoring processes involve continuous monitoring of systems to identify potential compromises through automated alerts and anomaly detection. Upon detection, we initiate an incident response protocol within 30 minutes, assessing the impact and scope of the compromise. Our response includes containment, eradication, and recovery actions, followed by a thorough investigation to understand the incident's cause. We ensure stakeholders are informed within 24-48 hours. Regular reviews and updates to our monitoring tools and processes are conducted to enhance our detection and response capabilities, aligning with ISO and Cyber Essentials Plus standards.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Our incident management processes include predefined protocols for common events, ensuring a swift and effective response. Users can report incidents through our ServiceNow platform, which provides a streamlined interface for logging issues. We generate incident reports that detail the nature of the incident, actions taken, and resolution steps, which are shared with relevant stakeholders to maintain transparency. These reports are part of our commitment to continuous improvement and compliance with ISO standards, ensuring we learn from incidents to enhance our services.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Atlas
- ISO/IEC 27001 accreditation date
- Sunday 13 April 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Atlas
- ISO 9001 accreditation date
- Tuesday 1 April 2025
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Be7ce590-de10-486e-8431-2e10891a8979
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Cd8b1a78-44c7-4bb0-84d6-59a7506f3bba
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
-