Somerford Associates Limited

Varonis Data Security Platform and DatAdvantage Cloud

Varonis specialises in software for data security, governance, compliance, classification, and analytics. Varonis detects insider threats and external cyberattacks like ransomware by monitoring user behaviour helping mitigate risk in M365, Teams, Salesforce, Slack, Box, on-premise file servers and more by locking down sensitive data and remediating access.

Features

  • Full enumeration of all directories and Access Control Lists
  • Complete mapping of directory services' user and group memberships
  • Remediation of Collaboration Links in M365
  • Full auditing for file data, email and Directory Service actions
  • Over 150 predefined threat models for advanced and real-time alerts
  • Predefined data classification rules including full GDPR coverage and PCI
  • Permission and Membership Change
  • Advanced investigation and forensics dashboard interface
  • Enterprise search to facilitate Data Subject Access Requests
  • User behaviour analytics threat models

Benefits

  • Prioritise the most at-risk data and remediate to least-privilege access
  • Automated access remediation to secure data to least privilege
  • Analyse user behaviour for signs of inappropriate behaviour
  • Automate alert responses to minimise impact of ransomware/other threats
  • Identify and eliminate/manage stale and toxic data to reduce risk
  • Help satisfy auditing and compliance requirements and sustain secure operations
  • Increase efficiency through business user access provisioning and entitlement re-certification
  • Automate disposition, quarantining and data policy enforcement
  • Increased operational efficiency, devolving responsibility from IT to data owners
  • Provide identity, access and analytics data for security ecosystem integrations

Pricing

£122.58 a user

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at penny.harrison@somerfordassociates.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 13

Service ID

6 9 3 7 7 0 0 8 4 2 1 7 9 7 6

Contact

Somerford Associates Limited Penny Harrison
Telephone: 07897075103
Email: penny.harrison@somerfordassociates.com

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
Varonis can be implemented in your own cloud environment. The Varonis architecture requires to be run on Microsoft Windows Server with Active Directory for security and SQL Server for data storage, but can monitor and manage a plethora of Microsoft/LDAP/Linux/UNIX/NAS platforms.
System requirements
  • Windows Server 2008 R2 SP2 or newer
  • .NET Framework 4.7.2 and 3.5 SP1 installed on all nodes
  • Microsoft SQL Server 2014/2016/2017 - standard/enterprise

User support

Email or online ticketing support
Email or online ticketing
Support response times
Mon-Fri 9am-5:30pm excl bank holidays customers receive an initial response within one business hour
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Onsite support
Support levels
We provide support from priority 1 to priority 4 cases on any existing configuration or part of the platform that is in total or partial failure as well as not working as expected. We also provide configuration guidance and recommendations for use cases. Each customer receives their own Account Manager who works closely with Support and ensures that cases can be followed up. Somerfords Support desk is available as a value added service in addition to the maintenance and support purchased alongside the license.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Training can be completed by leveraging Varonis Education Services for standard training of the application and advanced/troubleshooting classes that are offered. All training is done online. In addition, Professional Services can provide online or on-site training that is more customised based upon specific products and use cases/business needs for the customer. Varonis also offers additional learning resources (ex: how-to documents and videos) in the Customer Community portal.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Varonis can be implemented in your own cloud environment. You control who has access to your Varonis environment, and we do not have access to your data or facilities. Varonis Systems does not host, process, or maintain access to any customer data or facilities. All data processing is performed at the customer facility, under the control of customer staff.
End-of-contract process
Varonis can be implemented in your own cloud environment. You control who has access to your Varonis environment, and we do not have access to your data or facilities. All data processing is performed at the customer facility, under the control of customer staff and therefore, before the contract is terminated, the data in the database can be exported, or afterwards, the database can be kept by the customer.

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Linux or Unix
  • Windows
  • Other
Designed for use on mobile devices
No
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
Varonis has exposed APIs in its core DatAdvantage, DataPrivilege and DatAlert platforms. These APIs expose reports, file system change information, the capability to change permissions and group membership through the Varonis Commit Engine, and Authorisation and Entitlement review workflows through SOAP and REST APIs.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
No
Customisation available
No

Scaling

Independence of resources
Varonis can be implemented in your own cloud environment. You control who has access to your Varonis environment, and we do not have access to your data or facilities. All data processing is performed at the customer facility, under the control of customer staff.

Analytics

Service usage metrics
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Varonis

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Up to Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Varonis can be implemented in your own cloud environment. You control who has access to your Varonis environment, and we do not have access to your data or facilities. All data processing is performed at the customer facility, under the control of customer staff.
Data sanitisation process
No
Equipment disposal approach
In-house destruction process

Data importing and exporting

Data export approach
Varonis has a number of reports and APIs which can be used to pull data from the system into various formats or feed the information into other tools.
Data export formats
  • CSV
  • Other
Other data export formats
  • PDF
  • Excel
  • HTML
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Components can be made highly available and we offer DR best practice documentation with our solution.
Approach to resilience
Our support and professional services are located in 3 different continents, and act as a backup for each other in case of disaster. More information is available on request.
Outage reporting
Components can be made highly available and we offer DR best practice documentation with our solution. Varonis provides email alerts if there are component connection issues, and additional details are available in the Varonis Management Console, and in the Event Viewer logs.

Identity and authentication

User authentication needed
Yes
User authentication
  • 2-factor authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
Varonis authentications via Active Directory
Access restrictions in management interfaces and support channels
Varonis DatAdvantage has application Role Based Access Control and resource based custodianship. There are currently 28 different roles. RBAC and Custodianship provides:
• Separation of front end user roles and back end solution configuration roles
• Segregate resource views by administrative region or resource type
• Asia-Pac administrators can only see Asia-Pac Servers
• SharePoint administrators can only see SharePoint resources
• Content based access separation for lower level operational IT roles.
• Hide information views such as sensitive content locations from Help-Desk admins.
Access restriction testing frequency
At least every 6 months
Management access authentication
Other
Description of management access authentication
Varonis authenticates all access, including management access, using active directory. In cloud, using Azure AD.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Available upon request
ISO/IEC 27001 accreditation date
We should receive it within 30 days (as at 22 May 2018)
What the ISO/IEC 27001 doesn’t cover
We cover our services and information security. You will be able to see the description in the certificate as soon as we receive it.
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
Yes
Other security certifications
Yes
Any other security certifications
Common Criteria EAL2+

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Varonis maintains compliance with various standards and certification authorities. Varonis certifications are available here: https://www.varonis.com/trust.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Varonis provides customers with maintenance and upgrade releases periodically. We ensure that customers are notified of new versions via email and or the Varonis customer portal. When implemented within the customer's cloud environment configuration and change management processes are the responsibility of the customer.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Varonis has a Vulnerability and Threat Management Policy. Varonis systems are scanned and results are reviewed by the CISO and IT departments. Security vulnerabilities are remediated within the timeline defined within the policy which includes procedures decided by the CISO for zero-day and other urgent patches.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Varonis' Security Operations Center, which comprise information security personnel are responsible for the review and/or monitoring of information security incidents or events.
Incident management type
Supplier-defined controls
Incident management approach
Varonis has an Incident Response Policy that includes notification to the relevant stakeholders (including customers) as needed. Varonis will notify customers with all relevant information and cooperate with reasonable requests for information. This policy is aligned with industry best practices and included prepartion, identification, reporting, containment, discovery, eradication, recovery, and post incident report.

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)

Public sector networks

Connection to public sector networks
No

Social Value

Fighting climate change

Fighting climate change

As an organisation that works closely with the public sector, Somerford is keen to demonstrate our commitment to supporting the achievement of the Net Zero target of greenhouse gas emissions by 2050.

Management and staff at Somerford have been conscious of our impact upon the environment even before the Climate Change Act was introduced, and we’ve adopted environmentally friendly practices as the business has grown. Consequently, Somerford ‘s business already has a reasonably low carbon footprint, and will continue to strive for further reductions wherever possible because this is beneficial for our business, our stakeholders and the environment.

We will use our influence as a value added reseller of leading edge software products and supporting professional services to select supplier-partners whose own carbon reduction philosophy and plans are aligned with ours, and who can show commitment to the Net Zero target. In practical terms, this means we participate in a carbon-net-zero supply chain in the delivery of the solutions from our supplier-partners to our customers.

For further details, please see our Carbon Reduction Plan online at https://www.somerfordassociates.com/carbon-reduction-policy-and-plan/
Covid-19 recovery

Covid-19 recovery

During the Covid-19 pandemic, our robust business continuity measures, prudent fiscal policy, and the benefits of a highly flexible team, meant we were well prepared for the difficulties ahead.

Staff wellbeing has been at the forefront of our Covid-19 recovery plans, taking care of their physical and mental health, including;

* home working to avoid unnecessary exposure to the virus
* providing safe office space where staff personal circumstances dictated
* regular contact, albeit remotely, to prevent isolation
* organised e-based social events to maintain interaction;

As a result we have been able to:

* give uninterrupted service to our customers
* move our staff to home working
* avoid compulsory redundancies and minimised furlough
* in 2020, gain an 11% increase in revenues
* continue to grow the workforce by over 10% in the same year
* take on new partners to enhance our solutions portfolio
* invest in staff education to meet future customer needs.

Changes in business practices due to Covid-19 have shown that flexible work patterns can be very effective, and we’re unlikely to fully return to our previous style of working.

Our solutions have also helped customers to cope with their changing work patterns too - supporting their Covid recovery by providing the infrastructure, tooling and monitoring to support their own remote, flexible and sustainable ways of working.
Tackling economic inequality

Tackling economic inequality

Somerford is a healthily growing business, and actively strives to create employment opportunities that are inclusive of all socio-economic groups. For example:

* In the past 5 years, 20% of our staff entered our employment from leaving school, college or university;
* We have supported 12 apprenticeships;
* We run an internal academy scheme to build a broad range of technical skills in those who have the inherent skills, attitude and capability to become our next generation of experts;
* We actively participate in the Armed Forces Covenant Scheme and help to redeploy and reskill leavers from the Armed Forces. So far, 16 staff have joined us in this way;
* The ethnic mix of our staff is more diverse than that of our local community.

Strong technical skills are key to the delivery of services to our customers, so we’ve invested heavily in staff training - in 2020 alone, staff successfully completed over 100 technical courses.
Equal opportunity

Equal opportunity

Somerford is an equal opportunities employer and does not discriminate on the grounds of gender, sexual orientation, marital or civil partner status, pregnancy or maternity, gender reassignment, race, colour, nationality, ethnic or national origin, religion or belief or age.

We do not discriminate on the grounds of disability. We take particular care to respect the rights of those with disabilities, throughout all stages of recruitment and employment. We make reasonable adjustments to ensure those with disabilities are not disadvantaged in the workplace, eg. adjusting working hours or providing special equipment to help to do their job.
Wellbeing

Wellbeing

Somerford is committed to promoting and supporting the wellbeing of all of its staff. We aim to create a culture which focuses on prevention of issues in the workplace that can adversely affect staff health and wellbeing, and where issues are identified, they are managed promptly before they can have a detrimental impact.

This includes:
* providing staff with clarity and purpose regarding their job role;
* ensuring staff have the capability, training, support and encouragement to conduct their role confidently and effectively;
* providing a physical working environment that is suitable for the work to be carried out effectively;
* encouraging staff to maintain a sensible work-life balance;
* minimising the stressful impacts of work;
* ensuring bullying and harassment have no place in the working environment;
* managing sickness and absence effectively;
* considering requests for career breaks and sabbaticals;
* providing medical assistance to staff;
* encouraging employee fitness;
* promoting dignity at work.

Pricing

Price
£122.58 a user
Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Varonis offers a free Data Risk Assessment report - a free security assessment designed specifically for you. You'll receive a comprehensive report that highlights your at-risk sensitive data, flags access control issues, quantifies risk, identifies where weaknesses are across your data stores and recommends steps to improve your data security.
Link to free trial
https://www.somerfordassociates.com/varonis-dra-resource-page/

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at penny.harrison@somerfordassociates.com. Tell them what format you need. It will help if you say what assistive technology you use.