INTEGRITY360 LIMITED

Proofpoint Threat Protection Suite

Proofpoint Threat Protection Suite is made up of Email Protection and Targeted Attack Protection (TAP). Email Protection (SEG Secure Email Gateway) includes AV antivirus, spam detection and authentication (SPF, DKIM and DMARC). TAP includes sandboxing attachments and URLs as well as URL rewritting and BEC Business Email Compromise detection.

Features

  • Spam Detection
  • End User Digest
  • Reporting
  • Email Authentication
  • Attachment Sandboxing
  • URL Sandboxing and Rewriting
  • Imposter (Business Email Compromise) Detection
  • Cloud Account Monitoring
  • Data Loss Prevention
  • Very Attacked People index

Benefits

  • Improve email hygiene to increase productivity
  • Reduce workload on admins with a self service quarantine option
  • Allows data driven decisions on improving secuirty posture
  • Reduces domain based identity deception to minimise fraud
  • Blocks targeted attacks over email
  • Increases efficacy of blocking threats and protects user clicks
  • Reduces the risk of employees being defrauded over email
  • Provides visibility of suspicious activity in cloud accounts
  • Reduces financial and reputational damage caused by data loss
  • Allows prioritisation and tailoring of security controls applied to users

Pricing

£10.33 a user

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidreviewboard@integrity360.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 13

Service ID

8 1 4 5 4 9 7 6 7 3 3 2 4 9 9

Contact

INTEGRITY360 LIMITED Davide Poli
Telephone: 02083721000
Email: bidreviewboard@integrity360.com

Service scope

Software add-on or extension
Yes
What software services is the service an extension to
Extension to messaging platform services – eg On Premise Exchange, Office 365, Google Workspace
Cloud deployment model
Community cloud
Service constraints
N/A
System requirements
  • Capability of routing email to a Proofpoint email gateway.
  • Valid delivery destination for email filtered by Proofpoint.

User support

Email or online ticketing support
Email or online ticketing
Support response times
P1 First Response - 1 hour
P2 First Response - 4 business hours
P3 First Response - 8 business hours
P4 First Response - 16 business hours
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
No
Support levels
Support is included in quotes provided for the related Proofpoint products. There is Self Service Support, Platinum Support and Premium Support. Customers with Platinum Support or Premium Support also have the ability to purchase the optional Global Add-On. A Technical Account Manager can also be provided at an extra cost.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Proofpoint Professional Services provides an implementation service. Each customer is aligned with a Professional Services consultant who will onbaord them. There is also online training and documentation provided as well as access to the articles, forums, etc. in the Proofpoint community portal.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Data extraction tools driven by customer.
End-of-contract process
Implementation is included in the price of the contract and there is no additional charge for offboarding. At the end of the contract the service ceases to function.

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The experience of the Proofpoint email filtering service will be the same no matter how email is accessed (e.g. via desktop or mobile mail clients).
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Administrators can connect to an admin GUI to configure settings. End Users will not be aware of the majority of the email filtering that takes place. End Users may receive an End User Digest email that lists certain types of email addresssed to them (e.g. bulk) that has gone into quarantine since the last digest was generated. End Users may also be given access to the End User Web Application where they can release certain type of emails from quarantine and maintain their own safe and block lists.
Accessibility standards
None or don’t know
Description of accessibility
Using a web browser.
Accessibility testing
Access is via a web browser, so standard web browser accessibility options apply.
API
Yes
What users can and can't do using the API
Admins can configure an API so that reporting details from Proofpoint email filtering are fed into a SIEM tool.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
No
Customisation available
No

Scaling

Independence of resources
Each customer has a separate email filtering cluster just for them as well as their own decicaed IP addresses. The cluster for each customer is sized according to the compute resources needed to handle their mail flow and this can be adjusted if mail flow volumes change.

Analytics

Service usage metrics
Yes
Metrics types
Various reports are generated on things such Inbound Email Summary, Inbound Spam and Bulk Summary, Inbound Threat Summary, Outbound Email Summary.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request

Resellers

Supplier type
Reseller (no extras)
Organisation whose services are being resold
ProofPoint

Staff security

Staff security clearance
Other security clearance
Government security clearance
Up to Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Other
Other data at rest protection approach
AES 256 bit encryption
Data sanitisation process
Yes
Data sanitisation type
  • Explicit overwriting of storage before reallocation
  • Deleted data can’t be directly accessed
Equipment disposal approach
In-house destruction process

Data importing and exporting

Data export approach
Data extraction tools driven by customer.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Proofpoint has documented information security program consisting of policies, procedures and standards that aligns with the requirements of NIST 800-53 and ISO 27001. The program is owned by the Proofpoint Global Information Security group, and includes a continuous monitoring program consisting of monthly and quarterly evidence collection and review, and an annual SOC 2 Type II audit of the program.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Policies, procedures, and standards comprising the Proofpoint information security program are reviewed and updated annually by the Proofpoint Global Information Security group and approved by the Proofpoint CFO.

Availability and resilience

Guaranteed availability
https://www.proofpoint.com/sites/default/files/general_terms_hosted_services_sla_-_mar_2016.pdf
Approach to resilience
The services run in active/active mode between a pair of gegraphically-diverse co-location facilities.
Outage reporting
https://www.proofpoint.com/sites/default/files/general_terms_hosted_services_sla_-_mar_2016.pdf

Identity and authentication

User authentication needed
Yes
User authentication
Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
All access to the Proofpoint production environment, where services are hosted, is via a 2FA encrypted VPN and granted based on role.
Access restriction testing frequency
At least once a year
Management access authentication
  • 2-factor authentication
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 1 month and 6 months

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber essentials plus
No
Other security certifications
Yes
Any other security certifications
  • SOC 2 Type II audit report, available here:
  • https://go.proofpoint.com/soc2_report_request.html

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
The Proofpoint security program is led by the Proofpoint CSO. The program is based on identifying and mitigating risk to our personnel, the organization and the customer.
Information security policies and processes
Proofpoint's information security program is aligned with the requirements of NIST 800-53 and ISO 27001. However, we are not certified to the ISO 27001 standard.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Proofpoint has a documented change management policy that includes requirements around documented change tickets and review and approval by the Change Review Board.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Proofpoint performs internal and external vulnerability scanning and remediates applicable findings in line with the Proofpoint patch management policy.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Proofpoint has distributed monitoring in place for availability, performance, capacity and security. Alerts are directed to a 24x7 NOC or SOC for review, remediation and/or escalation.
Incident management type
Supplier-defined controls
Incident management approach
Proofpoint has a documented Incident Response Plan that includes procedures to detect, investigate, remediate and communicate security incidents. A trained IRT team is responsible for the maintenance of the program.

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Social Value

Fighting climate change

Fighting climate change

Proofpoint operates in approximately 20 countries, and as a global corporate citizen, we are committed to environmental sustainability, positive social impact, and supporting people and communities around the world.

Some examples of how Proofpoint supports environmental sustainability are:

Usage of highly efficient virtualized servers for our global IT infrastructure, supplemented by a diverse mix of leading cloud services, which are delivered out of energy efficient data centers in the countries that we deliver our services from.
Our new headquarters in Sunnyvale, CA meets LEED Gold certified standards for the core, shell and interior;
Requiring LED lighting as standard for all new real estate projects, and launching a project to replace the majority of our fluorescent lights with LED lighting by mid-2021 globally
Implementing recycling programs in every Proofpoint office globally; and
Adoption of teleconferencing solutions to reduce unnecessary air travel.
Proofpoint is committed to the communities it operates in.
Tackling economic inequality

Tackling economic inequality

We believe that diversity, inclusion, and opportunity is a journey and we are committed to building a diverse and inclusive company and society for our employees, customers, partners, and shareholders. In order to create a more diverse and inclusive work environment, we provide education, training and tools so that all employees can become aware of bias, how it exists and how to mitigate it. As we continue to shape our work environment and world-class organization to be more inclusive and inviting, we are actively striving to build an extensive pipeline of talent through various programs. Our internal programs enable and empower our hiring managers to identify alternative and emerging talent pools and to create an inclusive candidate experience.
Equal opportunity

Equal opportunity

Our Chief Human Resource Officer (“CHRO”), who reports directly to our Chief Executive Officer (“CEO”), leads the development and implementation of the Company’s human capital strategy, including the attraction, acquisition, development and engagement of talent; however, it is the responsibility of all of Proofpoint, its management and its employees, to execute and build a collaborative and engaging workplace where all employees have an opportunity to do their best work and where we act as a team to solve our customers’ most challenging security issues.

Our CHRO, with our CEO and executive management team, are responsible for developing the Company’s diversity and inclusion vision and roadmap and integrating these into the Company’s culture and operations. The roadmap includes framing the Company's global policies and programs for leadership and talent development, compensation, benefits, staffing and workforce planning, human resources systems, education and organization development, workplace strategies, and global sourcing and indirect procurement, and ensuring effective and efficient internal company operations.
Wellbeing

Wellbeing

The physical health, financial well-being, life balance and mental health of our employees is vital to the Company’s success. Throughout the year, we encourage healthy behaviors through regular communications, educational sessions, voluntary progress tracking, wellness challenges, and other incentives. Creating a culture where all colleagues feel supported and valued is paramount to our corporate mission.

The ongoing COVID-19 pandemic has led to unique challenges and through it all, the health, safety and the general well-being of our employees has remained our primary objective.

Pricing

Price
£10.33 a user
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
A limited time period to try the solution.
Link to free trial
https://www.proofpoint.com/us/free-trial-request

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bidreviewboard@integrity360.com. Tell them what format you need. It will help if you say what assistive technology you use.