Barrier Networks Menlo Cloud Secure Browser Platform and Remote Browser Isolation (RBI)
The Menlo Cloud Secure Browser Platform eliminates the possibility of malware reaching user devices via compromised or malicious websites or documents, or via phishing and credential harvesting attacks with a 100% effectiveness warranty.
Features
- Browser Isolation prevents browser-based attacks
- Document Isolation prevents attacks from weaponized documents
- Email Isolation - prevent attacks from weaponized links / attachments
- Global Cloud Proxy - URL Database, SSL Decryption
- Advanced Traffic Visibility - DLP, CASB, Analytics
- Phishing Awareness Training - customisable content served to users
- Advanced Reporting and Analytics of both Web and Email traffic
- Automatically scaled Cloud environments based on traffic volumes
- Advanced Reporting and Analytics of all associated logs
- Secure Application Access
Benefits
- Reduce Web-Based Malware Containment Cost
- Prevent Zero-hour phishing attack and credential harvesting
- Reduce Security Operations Engineer Workforce Cost
- Reduce Patching Cost
- Replace legacy VPN with secure application access
- Mitigate Brand / PR Damage Risk
- Provide URL filtering and appropriate use controls
- Prevent Data Leakage and Insider Threat
- Reduce cost by Replacment of legacy Virtual Desktop Infrastructure (VDI)
- Reduce risks of Generative AI usage
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 8 5 8 5 1 3 7 1 7 4 3 2 2 1
Contact
BARRIER NETWORKS LIMITED
Iain Slater
Telephone: 0141 356 0101
Email: sales@barriernetworks.com
About the service
- Service categories
-
- Systems Infrastructure Software
- Security
- Identity and access management
- Access
- Privilege
- Endpoint security
- Endpoint security
- Network security
- Trusted network access and protection
- Active application security
- Identity and access management
- Security
- Systems Infrastructure Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
-
No cloud based contraints as cloud enviroment managed, maintained and patched by Menlo (SLA 99.9 availability).
Constraints for On-premise environment : would need to be maintained by customer for hardware / software, updates, configuration and patching. - System requirements
- HTML 5 enabled Web Browser
User support
- Email or online ticketing support
- Yes
- Support response times
-
Menlo Security Customer Success provides three levels of Support with differing SLAs for responses based on the priority/urgency level. The Support levels are Basic, Premium and Platinum.
Basic Support Response Times:
P1 (Urgent) – 1 Hr
P2 (High) – 4 Hr
P3 (Normal) – 4 Hr
P4 (Low) – 4 Hr
Premium Support:
P1 (Urgent) – 30 Min
P2 (High) – 1 Hr
P3 (Normal) – 3 Hr
P4 (Low) – 4 Hr
Platinum Support:
P1 (Urgent) – 15 Min
P2 (High) – 30 Min
P3 (Normal) – 2 Hr
P4 (Low) – 4 Hr - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- AI chatbot
- Yes
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Menlo Security’s web chat support (when available on its website) is designed to quickly connect visitors with the right help channel and speed up issue resolution. It can route customers to Menlo’s 24/7 global support, help open a support case (“ticket”) through the Support Portal, and guide users to track existing requests and updates. Chat also supports self-service by pointing to relevant knowledge resources such as documentation, troubleshooting articles, release notes, advisories, and other support materials, and it can direct users to training/certification resources when the need is educational rather than incident-based. If there’s a suspected outage or service degradation, chat may steer users to Menlo’s platform status page to confirm current system health. It can also route security-related concerns—such as vulnerability reporting—into the correct dedicated process. Typically, chat collects key details (like contact information and a description of the problem) so the support team can respond efficiently, escalate appropriately, and maintain continuity if the conversation turns into a formal case. Overall, the function of Menlo’s web chat is triage and guidance: answering quick questions when possible, and otherwise moving users into the correct structured support workflow with the right context attached.
- Web chat accessibility testing
- N/A.
- Onsite support
- Yes
- Support levels
-
Menlo Security Customer Success provides three levels of Support - Basic, Premium and Platinum. All three levels provide the following functions:
- Technical support access
- Support case analytics
- Online learning and training
- Technical onboarding, including configuration guidance
Basic Support operates Mon-Fri for 12 hours per day. Premium Support operating hours increase to a 24x7 model. Platinum Support also operates 24x7 though also includes a Designated Technical Account Engagement (TAM)
Additionally, there is the Menlo Security Resident Support Engineer Service Program, whereby an Engineer is provided on-site for all support and expertise.
The Platinum Support offering provides access to a designated Technical Account Manager (TAM) drawn from Menlo Security's senior support staff for additional support continuity. The TAM can support provide onsite support where necessary, however typically support is done remotely. Ongoing Professional Services is typically carried out as part of the Menlo Security Resident Support Engineer Service Program. A Menlo Security resident support engineer offers on-site support expertise and help. This is provided as an additional cost option. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- System Admins can take advantage of the Technical onboarding, including configuration guidance, that is included in all Customer Support packages. Typically, the Platform is set up, configured and tested on a small subset of users before being rolled out to the larger user base. Deployment to the wider user community is usually automated using the likes of Active Directory Group Policy to deploy any required components or settings to the users. Any required integrations are completed and tested prior to user deployment phase.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Although our onboarding and offboarding documentation has not been formally assessed against WCAG 2.2 or EN 301 549, we aim to make it accessible in practice. Documentation is provided in digital formats that support assistive technologies (e.g., searchable text rather than scanned images), uses clear headings and consistent structure to support screen readers and navigation, and avoids conveying critical information through colour alone. Links use descriptive text, and we include step-by-step instructions in plain language with defined terms where needed. Where diagrams or screenshots are used, we provide accompanying explanatory text.
If an employee or leaver requires an adjustment (for example, large print, alternative formats, or a guided walk-through), we can provide the documentation in an alternative format and offer additional support via HR/IT as part of our onboarding/offboarding process. - End-of-contract data extraction
- Only System Admins have access to the Web Access and Audit logs. These are maintained in the Menlo Cloud Secure Enterprise Browser (MCSEB) for the duration of the subscribed retention period; either 30 days or 3, 6 or 12 Months. Any data that is older than the subscribed retention period is automatically purged. Tenants and the associated log data can also be decommissioned and purged at the end of the contract on request. The Logging API can also be used to download all Log data as well as the ability to purge all or specific log data.
- End-of-contract process
- If customers choose not to renew their contracts with Menlo Security they can request that their Tenant be disabled. This would then be removed from our Global Cloud along with all related data and logs.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- None
- Service interface
- Yes
- Description of service interface
- The Menlo Cloud Secure Enterprise Browser is managed and configured centrally using the online Admin User Interface. This is accessible via a supported web browser and provides System Admins a centralised interface to configure policies across all users subscribed to Menlo Security Platforms. The Admin UI includes a SAML integration for authentication as well and the ability to enable Multi-Factor Authentication. Role-Based Access Controls allow for assigning granular access rights to other System Admins for both policy and reporting related tasks.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The Menlo Cloud Secure Enterprise Browser is managed and configured centrally using the online Admin User Interface. This is accessible via a supported web browser and provides System Admins a centralised interface to configure policies across all users subscribed to Menlo Security Platforms. The Admin UI includes a SAML integration for authentication as well and the ability to enable Multi-Factor Authentication. Role-Based Access Controls allow for assigning granular access rights to other System Admins for both policy and reporting related tasks.
- Accessibility testing
- Carried out during the Software Development Lifecycle
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
-
There are 3 APIs that can be used by System Administrators:
1. Logging API – to download the Access and Audit logs in various formats for SIEM integration.
2. File Extraction API – to send extracted files to a third party for analysis e.g. Sandbox or a Content Disarm and Reconstruction (CDR) service
3. Policy API – for Policy Automation and Orchestration - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- MCSEB is fully customisable from not only a Policy and Reporting perspective, but also with relation to banners, block pages and other messages presented to the user. All policies can be configured per Active Directory Users and Groups and a granular Exceptions Editor is provided to change the Policy Enforcement action for all request types. Role-Based Access Controls (RBAC) allow granular access rights to be assigned to individual Admins and a full audit trail is provided for details of any changes. Admins can be assigned both Read-Write or Read-Only access to portions of the Admin UI.
Scaling
- Independence of resources
- Menlo’s Global Elastic Cloud was built from the ground up for unlimited elastic scalability. Menlo monitors crucial components of the architecture, automatically adding or subtracting resources as load dictates across redundant data centers. All clusters scale elastically, ensuring immediate and transparent failover between regional data centers with independent power and redundant connectivity.
Analytics
- Service usage metrics
- Yes
- Metrics types
- MCSEB provides multiple Reporting tools - from high-level Dashboards to our detailed and fully customisable forensics and analytics tool called Insights. A detailed Log search facility is provided for all Logs – Web Access, Email Logs, DLP Logs and Audit Logs. Customers can create and schedule reports from any of the associated data – reports typically incorporate Productivity, Security and Bandwidth. Data Leakage Protection (DLP), Cloud Access Security Broker (CASB) and Secure Application Access reports are also included with these additional optional modules.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Menlo
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
-
All Data at Rest is stored encrypted using AES 256-bit encryption. The MCSEB SaaS offering is hosted in fully secure Amazon data centres. Amazon provide numerous security policies and controls around security practices in general, as well as the physical security of their associated data centres:
Security Processes: https://aws.amazon.com/whitepapers/overview-of-security-processes
Data Center Security: https://aws.amazon.com/compliance/data-center/controls/
Amongst numerous other controls, there is:
Physical Access Controls
- Tightly Controlled and Restricted Physical Access
- Based on Least Privilege
Surveillance and Monitoring Controls
- Physical access points to server rooms are recorded by CCTV
- Professional Security Staff man the Data Center Entry Points - Data sanitisation process
- Yes
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Only Web Access Logs and Audit Logs are actually stored in the Menlo Security Global Cloud and only the System Admins who have the necessary rights have visibility of these.
- Data export formats
- Other
- Other data export formats
-
- LEEF
- Key Value Pair (KVP)
- CEF
- JSON
- Data import formats
- Other
- Other data import formats
-
- User cannot upload any data to the MSIP.
- There is no requirement for users to upload data.
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- Menlo Security regularly implements and reviews the embedded controls to ensure the MSIP is secure, any compromise is contained, and most importantly, does not enable the attacker to have a path to the users’ endpoint. Specifically for communication between MCSEB and the Endpoint: - Uses TLS 1.2 AES 256 bit encryption - A purpose-built firewall enforces unidirectional content between the MCSEB and the endpoint. - From the MCSEB to the endpoint, only presentation (DOM) updates can be communicated - From the endpoint to the MCSEB, only user inputs (mouse or keyboard) can be communicated - all other communications are dropped
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- The Menlo Security Operations team manages & controls the Cloud SaaS service from a specific, highly controlled and protected network. Menlo Security employs internal security audits and third-party audits every 6 months. These audits include network and service penetration testing and Amazon AWS audits. We have restricted AWS Operational Access by using the least privilege principles and role-based access applied for all accounts. In addition, multi-factor authentication is required for all services including webmail (Google Apps), source control and cloud operations access. All Data stored at Rest and in Transmit is encrypted using AES 256 bit Encryption.
Availability and resilience
- Guaranteed availability
- Service Availability is guaranteed by SLA for 99.9% of the time
- Approach to resilience
- Resilience is achieved through complete redundancy in every deployment region across multiple data centers and transparent in-region failover to the nearest deployment region. A stateless design delivers seamless session continuity for users traveling between service regions. Geo- and latency-based routing logic ensures that users are guaranteed to always access the best region based on their location. A dynamic session management model allows new updates to be rolled out to customers without any service interruption or downtime. The service is closely monitored for any issues and has automatic recovery implemented wherever possible. The service is automatically scaled to provide further performance based on traffic thresholds.
- Outage reporting
-
Menlo Security follows the framework defined in the Incident Management Policy that specifies that customers are notified for all categories of incidents. Customer Admins are notified for an availability incident affecting a given deployment region or for any service incident resulting in a disruption to end users in that region via the Menlo Status page and other channels listed below. Notification is as soon as possible during the availability incident or following the incident when the service disruption is short lived.
Menlo Security uses Zendesk software to power our Helpdesk operations. Authorised Customers can be notified via this tool (tickets, notification emails, announcements, etc.)
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
-
1. Directory Based Authentication using SAMLv2 e.g. Local such as Active Directory Federation Services (ADFS) or a Cloud provider such as AzureAD, Okta, Ping, OneLogin, Centrify, SiteMinder CA, etc.
2. Anonymous Mode – users would be identified by a known Public IP Address that they connect to the Service from. This would need to be defined in the Admin UI.
3. Local Database Accounts – accounts created either by the user self-registering with their corporate email address or created by Menlo Security. Users would manage their own passwords - Access restrictions in management interfaces and support channels
- When a web request reaches Menlo Security a secure connection is established, and a check is made for an authentication token contained in a cookie in the user’s browser. If present, this indicates the user has previously authenticated against the system and the correct policy can be applied. If not present, then the system will first try to identify the user based on the IP Address they are connecting on. If known, the user will be authenticated using one of the mechanisms described above. If not-known the user will be presented with a login prompt via the browser.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
-
Menlo follows least privileged principle where, by default least privilege access is given and request for additional access must be approved from there.
Most commonly the SAML identity provider is used to authenticate Admin Users. Here a Group is also most commonly used in the IdP to limit access to the correct set of Admins. All the security functionality provided by the IdP are thus extended to the Admin logins.
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Software Security Code of Practice
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Processes Menlo Security has an Information Security Management System (ISMS) in place as part of our ISO 27001 certification. Our series of Information Security Management System policies includes (i) Employee Handbook, (ii) Acceptable Use Policy, (iii) Access Control Policy, (iv) Change Management Policy, (v) Data Classification Policy, (vi) Disaster Recovery Policy, (vi) Incident Management Policy, (vii) Logging and Backup Policy, (viii) Mobile Devices and Teleworking, (ix) Password Policy, (x) Vendor Management Policy, (xi) Onboarding Procedure, (xii) offboarding Procedure, (xiii) Change Management, (xiv) Document and Record Control, and (xv) Asset Inventory.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Menlo Security leverages a formal change management process and internal ticketing system to track all requirements, changes, associated designs and testing requirements. This covers all production and non-production changes, including service software updates as well as both functional and security patches.
The Menlo Security Global Cloud is updated regularly with scheduled updates that include all latest security patches. Critical security patches are applied on-demand as/when Menlo Security is notified of newly identified vulnerabilities. All service updates and patches are applied with zero downtime or impact to customers. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- According to the Change Management Policy, any identified critical security patches are applied on-demand as/when Menlo Security is notified of newly identified vulnerabilities. Alternatively during the internal or third-party audit there are daily updates with partial readouts. A final report is produced and a readout is done. Based on the report, Jira tickets are created, labelled and prioritized. Critical and High-Priority issues are addressed during the engagement. Remaining issues are addressed as resources allow. Issues that are addressed or previously addressed during the engagement are re-tested. All service updates and patches are applied with zero downtime or impact to customers.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
All email is processed through the Menlo service which includes protections, DLP and encryption. Email configuration is centrally managed by IT. This is part of the Acceptable Use and Data Classification policies as part of the ISMS.
Endpoint management solutions are in place to ensure that endpoints are properly configured and secured. All laptops and devices must have encryption enabled.
Employees use the Menlo Security Isolation Platform for malware protection on endpoints. In addition there is policy, as part of the ISMS for Acceptable Use, Data Classification and Cryptography and Mobile devices and Teleworking. - Incident management type
- Supplier-defined controls
- Post-quantum cryptography secure
- No
- Incident management approach
-
1. Establish an incident management policy and form an Incident Response Team
2. Detection and reporting: Identify and report events and alerts that may or may not be an incident.
3. Assessment and decision: Assess the situation to determine whether it is in fact an incident and proceed accordingly
4. Response: Contain, eliminate, recover from and analyze the incident, where appropriate.
5. Lessons learned and Improvements: Improvements are made to the organization’s management of information and operational risks as a result of incidents experienced.
6. Incident notification/disclosure: Notification/disclosure is made in the most expedient time possible and without unreasonable delay.
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Menlo Security trials provide temporary “Evaluation Technology” access (software and/or cloud services) for internal testing. The evaluation term is 30 days unless Menlo agrees otherwise. It’s provided as-is: no warranty, indemnity, or support, and Menlo may modify or discontinue access. If not stopped at term end, list-price billing may apply.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- British Assessment Bureau
- ISO/IEC 27001 accreditation date
- Wednesday 7 June 2023
- What the ISO/IEC 27001 doesn’t cover
- Our certificate uses Statement of Applicability Version 1.3 (29 April 2025) but does not include exclusions or controls not covered.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- British Assessment Bureau
- ISO 9001 accreditation date
- Sunday 2 June 2024
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- Cbaed41f-aa61-4059-8968-3775daaa83a4
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- Ff1c64fb-7750-4095-8fbb-45aadf87260c
- Other security certifications
- Yes
- Any other security certifications
-
- CREST – SOC (Security Operations Centre)
- CREST – Penetration Testing
- NCSC - Assured provider of Cyber Incident Exercising
- NCSC - Assured Cyber Incident Response (CIR) Standard Level
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Mission: Break down barriers to opportunity
-
By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Mission: Build an NHS fit for the future
-
That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition