Governance Risk and Compliance Assurance Service
Ebeni’s Security GRC Service provides clients with the support and evidence required to demonstrate alignment to legislation, regulation, standards and policy. We provide a risk based approach, across our clients organisation, including Security, Safety and Systems Engineering (S3) aspects, minimising the risk of financial impact resulting from breach of legislation.
Features
- Implementation follows the Pragmatic, Appropriate and Cost Effective (PACE) principle.
- Accreditation assessments and compliance assurance including GDPR, NIS D, ISO27001
- Suitably Qualified and Experienced Personnel (SQEP) appropriate to your needs.
- Tailored Information Risk Assessments aligned to ISO31000 and ISO27005
- Experienced across regulatory frameworks e.g. NIS D, DPA, ONR SyAPS
- Decision quality information for board, project managers, and risk owners.
- Creation or Review and Update of all Security Documentation types.
- SyOps, Threat Assessments, Vulnerability Assessments, Risk Management
- Risk Assessments, Threat Analysis, Risk Treatment Plans and Risk Management
- Security Cleared specialists enables work across multiple classified systems
Benefits
- Vendor agnostic approach gives you unbiased, most appropriate solution options.
- PACE approach ensures best fit for requirements.
- Extensive knowledge of regulatory frameworks ensures security compliance.
- Sharing knowledge of industry best practice improves security across sector.
- Provision of decision quality information enhances effective risk management.
- Breadth and depth of knowledge improves successful implementation, minimising rework.
- Flexible risk assessments tailored to organisational needs.
- Increased risk understanding to inform strategic planning.
- Reduced through life management costs through improved compliance.
Pricing
£400.00 to £1,750.00 a unit a day
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
7 8 2 7 9 8 2 7 0 9 7 2 8 7 2
Contact
Ebeni Ltd
John Evans
Telephone: 07525718401
Email: DOS@ebeni.com
Planning
- Planning service
- Yes
- How the planning service works
- Prior to commencing a project Ebeni undergoes a planning phase where with the customer we establish a common understanding of the project scope. Planning includes understanding key stakeholders, establishing customer requirements, understanding timescales, establishing acceptance criteria, establishing reporting mechanism/frequency, understanding resource requirements, the development of a quality assurance plan and the development of a project risk register.
- Planning service works with specific services
- No
Training
- Training service provided
- Yes
- How the training service works
- Ebeni are able to offer a range of training options to enable the up skill the client’s team so that they are self-sufficient and are not reliant on Ebeni unless an ongoing relationship is desired. All of Ebeni’s services are delivered in a way that enables our customers to increase their knowledge and up skill their workforce.
- Training is tied to specific services
- No
Setup and migration
- Setup or migration service available
- Yes
- How the setup or migration service works
-
Migrating infrastructures, applications or services to the cloud requires careful preparation and planning. This starts by understanding that any cloud-based deployment, whether building out a new infrastructure or building a new application, requires clear communication between lines of business, IT and security teams. Ebeni provides a holistic approach to support the setup and migration processes required.
Ebeni’s approach is summarised in the following six steps that support your cloud migration:
1. Baseline your services before cloud migration
2. Plan for bandwidth requirements
3. Understand compliance issues and ensure resolution
4. Provide for business continuity and disaster recovery
5. Apply the right security at the right place in line with best practice
6. Establish a life-cycle management framework - Setup or migration service is for specific cloud services
- No
Quality assurance and performance testing
- Quality assurance and performance testing service
- Yes
- How the quality assurance and performance testing works
- Prior to commencing a project, as part of the planning phase the Ebeni Project Manager will develop a quality assurance plan that is reviewed and approved by Ebeni's Quality Manager in line with our ISO 9001 accreditation. The plan identifies the quality assurance activities that will ensure that a quality product is delivered in line with customer expectations. As part of the planning phase, acceptance test criteria (including performance testing) is established so that there is a common understanding of how the customer will accept Ebeni's deliverable.
Security testing
- Security services
- Yes
- Security services type
-
- Security strategy
- Security risk management
- Cyber security consultancy
- Security audit services
Ongoing support
- Ongoing support service
- Yes
- Types of service supported
- Hosting or software provided by your organisation
- How the support service works
- Ebeni's support service is governed by a service level agreement that is established at project start. The SLA is tailored depending on the clients support needs.
Service scope
- Service constraints
- None
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- Nominal response time is usually within 24 hours excluding weekends and bank holiday. Elevated or out of hours response times may be offered at additional cost
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Support levels
- Ebeni provide a standard support level of 09:00 - 17:00 Monday to Friday included in the rate card and pricing document aligned to this catalogue. Additional support can be provided and is assessed on a case by case basis.
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Developed Vetting (DV)
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- Yes
- Other security certifications
- No
Social Value
- Social Value
-
Social Value
- Equal opportunity
- Wellbeing
Equal opportunity
Ebeni’s Social Value Working Group is central to our company ethos and to realising client benefits and demonstrating integrity across all of our engagements. It includes representation from across the business, to ensure we are making progress against our agreed commitments and have an action plan to monitor and focus these initiatives. Following our latest continuous improvement process we are aligning current social value initiatives to reflect the government's 5 Pillars of Social Value.
To support a key Ebeni value of ‘benefit’ and to promote Equality, Diversity and Inclusion (EDI), we are working with Women in Rail and the Rail Industry Association RIA to support their newly launched ‘Equality, Diversity and Inclusion Charter’ which details a commitment to work together to build a better balanced and higher performing sector.
The EDI Charter reflects Ebeni’s commitment to ensuring fair treatment and opportunity for all, recognising the importance of an inclusive workforce. As an EDI Charter signatory, Ebeni continue to support improving EDI across the business and beyond.
We actively encourage our employees to participate in initiatives promoting STEM subjects within their communities, regularly working with local schools and education establishments to encourage young people to participate in related subjects. Many of our staff are active participants in their respective Chartered Institute, wider industry associations, Higher Education forums and sports and community groups, and this is actively encouraged. We attend events, produce and present papers and lead working groups which are often at the forefront of their field.
Our Social Value initiatives are led from the head of the company by Jo Latham, Director, supported by a working group of passionate Ebeni volunteers who help drive our social value commitments.Wellbeing
Ebeni is an SME founded to ensure benefit to employees and customers. Ebeni stands for Excellence, Benefit and Integrity. Ebeni’s continued success delivering excellent projects for customers relies on the wellbeing of employees and a culture and work environment where everyone is treated fairly with dignity and respect.
Our vision is for health, safety and wellbeing to be natural and integral to our culture by encouraging appropriate behaviours driven by effective leadership, supported by appropriate policies, procedures and flexible ways of working.
Ebeni has developed a H&W Strategic Plan, led by one of our Directors, which recognises improving mental health is everybody's concern. It focuses on:
• Promoting mental wellbeing and development, where possible, preventing mental health problems developing.
• Raising the profile and awareness of mental health by:
o Improving information on mental H&W.
o Making mental health matters more widely known and understood at work, home and in the community.
o Increasing employee involvement in decisions that impact their career.
o Changing attitudes to mental health by tackling stigma and discrimination.
• Addressing factors which can affect mental H&W.
A key part of our plan has been to invest in training. We now have 14 Mental Health First Aiders who work at all levels across the business. In addition, we were keen to understand how our people felt working for us. In November 2023 we used ‘Great Place to Work’ to carry out an employee survey (84% response rate), and have been certified as ‘A Great Place to Work’.
Pricing
- Price
- £400.00 to £1,750.00 a unit a day
- Discount for educational organisations
- No