Mimecast
Email security services that provide advanced protection against threats. Mimecast's email security system uses sophisticated, multi-layered detection engines and the latest threat intelligence to stop malware, spear-phishing and zero-day attacks.
Features
- Email security services that provide advanced protection against threats.
- Stop malware, spear-phishing and zero-day attacks Provides 100% malware protection
- Email spam check technology provides 99% protection against spam
- Email continuity services enable uninterrupted access, live and historic email
- Internal Email Protect
- Fast email search tools
- Compliance requirements with support for e-discovery and litigation hold requests
- Stationary (branding, signatures and disclaimers) Impersonation Protection
Benefits
- Protects inbound, outbound and internal email flow
- Eliminate need for multiple single-purpose technologies
- Improve the user experience by ending mailbox size restrictions
- Offering fast access to archives and delivering continuous access
- Administrators can centrally manage retention policies and enforce security controls
- Advanced threats launched from URLs, Attachments, and Impersonation
- Detection and protection against known cyber security threats
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 1 7 8 2 2 6 7 1 1 1 3 7 2 3
Contact
Wavenet
Joe Ewins
Telephone: 0333 234 0011
Email: publicsector@wavenet.co.uk
About your service
- Service categories
-
Applications
Collaborative
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- M365, Exchange Online, Microsoft Exchange Server, Any application enabled compatible with SMTP routing.
- Cloud deployment model
- Private cloud
- Service constraints
- Comprehensive Defence Plan supports inbound and outbound mail flow along with internal mail flow.
- System requirements
- A corporate, SMTP-based email system
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- Wavenet support - 1 hour response time inside core working hours 9-5 Monday-Friday UK time. Extended hours 8-8 Monday-Friday available with same SLA. Out of Hours support available with 1 hour response for critical issues. Microsoft infrastructure-level support is 24/7/365 for underlying, abstracted hardware
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Any customers on managed support will have a dedicated account manager and will be assigned a support team of engineers ranging from 1st line to 3rd line in ability. Escalation points are available with optional to follow through with issues until resolution. Costs vary depending on the Azure resources being supported.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Wavenet are part of the Mimecast MSP program for purchasing and support with designated engineers who are fully trained on all the licensed Mimecast services.
Wavenet engineers perform the following tasks related to resolving any issues:
• Carry out initial analysis and attempt to replicate the problem in an effort to resolve simple end user-type errors.
• Co-ordinate the gathering of relevant information from the end-users, computer room operators and system
managers in order to diagnose reported problems.
• Distinguish between normal and abnormal operation of the services.
• Escalate to Mimecast technical support for cases that cannot be resolved.
All issues are investigated and followed up within our defined priority-based SLAs. Wavenet standard support hours
are Monday to Friday, 8:00 AM to 18:00 PM - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Mimecast provides egestion/extraction services along with the ability for administrators to export content directly from the Administration Console in pdf, csv or xls and Emails and attachments can be exported from the Archive in Zipped EML or PST formats.
- End-of-contract process
- Customers control the retention / destruction settings for their data through their accounts. Customers’ data retention periods are reflected in their account settings and, depending on the package purchased, policies can be created where specific data can have differing retention settings. Data is deleted after the retention period expires using Mimecast proprietary software.
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- No differences.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Single Web Based Administration console allowing access to all required controls and settings.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Not known
- API
- Yes
- What users can and can't do using the API
- Update policies, users, block lists, integrate with 3rd party systems such as SIEM and SOAR. With Awareness Training the API allows user management.
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Branding, various policies, settings, notifications, email signatures and disclaimers, authentication requirements options.
Scaling
- Independence of resources
- Mimecast’s cloud platform is capable of scaling horizontally as far as necessary. Today it handles more than one billion connections for service each day and delivers millions of "clean" messages. The system is scaled, with approximately 20% of capacity allowing for surge scenarios and simultaneous server outages. Mimecast can easily scale overall capacity by adding additional storage and processing resources to the relevant resource pools as required.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Built-in reporting includes visualizations of the top 10 accessed domains, accessed site categories, and blocked domains by site category, as well as DNS requests that were associated with malware or malicious sites. Additionally, transparent login enhances reporting to ensure all activity is tied back to an individual or device.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Mimecast
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Select the required messages.
Click on the Export icon in the message's toolbar.
Select the Microsoft Outlook folder to place the messages by clicking the arrow to the left of your email address.
Click the OK button. A progress notification popup dialog is displayed. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- XLS, XLSX
- EML
- ZIP
- Data import formats
-
- CSV
- Other
- Other data import formats
- XLSX, XLS
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- TLS Encryption (version 1.2 or above), A combination of TLS, SSL (HTTPS), LDAPS, SMTPS is used as well to secure all types of data in transit.
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Please see details at https://www.mimecast.com/globalassets/documents/termsandconditions/sla_and_support_terms.pdf
- Approach to resilience
-
This information is available on request.
In brief, the platform is completely resilient with data replicated across diverse physical locations ensuring no single points of failure. - Outage reporting
- Mimecast portal, public dashboard.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Users may interact with an authentication form requiring username and password input and optionally a second factor. Integrated Windows Authentication requires no interaction by the end user. Public key authentication usually requires no interaction by end users. SAML can vary based on a customer's own deployment as this is a third party product brokering the authentication but usually SAML products primarily authenticate using username and password prompt.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Wavenet is an ISO27001 certified company and we adhere to the standard and has an Information security management system drawn from ISO27002 and we follow the NIST standard for cyber security framework, we are audited on this standard annually, Wavenet is also a CE+ certified company
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Wavenet conform to ISO2000
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Wavenet conform to and follow the NIST standard and ISO27002
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We have continual monitoring with EDR solution feeding into a SIEM that is monitored 24/7 that is monitored by SOC
- Incident management type
- Supplier-defined controls
- Incident management approach
- Wavenet is ISO27001 certified and we follow the playbook as part of our certification.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 3%
- Between £2,500,001 and £5,000,000
- 4%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- United Registrar of Systems
- ISO/IEC 27001 accreditation date
- Thursday 18 July 2024
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- United Registrar of Systems
- ISO 9001 accreditation date
- Monday 12 August 2024
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 39aabf05-4ab8-4ee7-adcd-3318af1f9d2f
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 6cc5c85d-03f1-446c-9e9d-7338dfb9f0ce
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Plans for positive actions with community groups.
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-