Varonis SaaS Data Security Posture Management (DSPM)
Varonis is a leader in data security. The cloud-native Data Security Platform continuously discovers and classifies critical data, removes exposures, helps improve compliance and detects advanced threats with AI-powered automation. Helping to mitigate risk in M365 inc Co-Pilot, Windows file-shares, Active Directory and available on AWS Marketplace.
Features
- Accurate data inventory: Find, classify, label, secure sensitive data.
- Flexible policies: Library of hundreds of customisable classification rules.
- Data access intelligence: Control net permissions, reduce exposure/compliance risk
- Policy automation: Automated remediation for exposures, unnecessary permissions, misconfigurations.
- Cross-platform audit trail: Searchable data access and granular permissions.
- Data-centric UEBA: Detect abnormal activity to stop data breaches.
- MDDR: 24x7x365 incident response, threat hunting & forensics.
- DSPM: Reports and dashboards show meaningful risk reduction.
- Email security: Detect exposures, email-based attacks & insider threats.
- Compliance: posture against GDPR, CAF, NHS DSPT, NIST, ISO27001.
Benefits
- Improve your data security posture automatically.
- Enable the safe rollout/use of generative AI/LLMs (e.g. Co-Pilot).
- Accurately discover, classify, and label sensitive data.
- Monitor on-prem and cloud data activity and prevent exfiltration.
- Enforce least privilege, labels, and secure settings.
- Detect abnormal activity from APTs and insider threats.
- Fix critical SaaS misconfigurations and third-party app risk.
- Automate compliance regulations and frameworks.
- Lock down sensitive mailboxes and stop exfiltration.
- Reduce risk and minimise cyber insurance claims.
Pricing
£221 a user a year
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
8 9 2 2 9 1 7 1 7 5 2 8 9 0 2
Contact
Somerford Associates Limited
Penny Harrison
Telephone: 07897075103
Email: penny.harrison@somerfordassociates.com
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
-
The Varonis Data Security Platform offers both SaaS and self-hosted
deployment options.
Our cloud-native Data Security Platform is hosted by Varonis and
delivered as software-as-a-service (SaaS). Our SaaS platform can
monitor and protect both cloud and on-premises data. An on-prem Collector server for may be required for data collection.
Our self-hosted Data Security Platform can be deployed either on-
prem or in any private cloud that can run Windows servers (e.g.,
Azure, AWS, Google, etc.) and requires SQL Server for data storage. - System requirements
-
- Windows Server 2019/2022 Standard or Enterprise (x64) (Fully Patched).
- 8 Core, 2 GHz or better CPU
- 16 GB RAM minimum
- 250 GB Drive (required to be on C:\\)
- .NET Framework – 4.7.2 or 4.8
- For self-hosted Varonis: Windows Server 2012+
- For self-hosted Varonis: SQL Server 2016+ including SSRS
- For self-hosted Varonis: .NET Framework 3.5 SP1 and 4.7.2
- For self-hosted Varonis: 8-16 cores, 2.3 GHz or better.
- For self-hosted Varonis: 16-24 GBRAM, 250GB dedicated storage
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
-
Varonis standard support is available Monday to Friday from 9am to
9pm Central European Time. 24/7 support can be accessed for an
additional cost. Somerford support desk is available Mon-Fri 9am-5:30pm excl bank holidays and Christmas/New Year period, customers receive an initial response within one business hour. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Onsite support
- Support levels
-
Somerford provide support from priority 1 to priority 4 cases on any existing configuration or part of the platform that is in total or partial failure as well as not working as expected. Somerford also provide configuration guidance and recommendations for use cases. Each customer receives their own Account Manager who works closely with Support and ensures that cases can be followed up. Somerfords Support desk is available as a value added service in addition to the maintenance and support purchased alongside the license.
Tickets can also be raised directly with Varonis via the customer portal on help.varonis.com. Varonis Support has 3 tiers of response- FLS (T1), Tier2, Tier 3. Varonis Support has 3 tiers of response- FLS (T1), Tier2, Tier 3. Most
cases that are open by SEs/Partners/customers will be received by
FLS, and escalated according to need. SLA is defined upon the level of Support Services the customer has purchased and the severity of the
case. For further details, please see "Varonis Support Principles"
document. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Training can be completed by leveraging Varonis Education Services for standard training of the application and advanced/troubleshooting classes that are offered. All training is done online. In addition, Professional Services can provide online or on-site training that is more customised based upon specific products and use cases/business needs for the customer. Varonis also offers additional learning resources (ex: how-to documents and videos) in the Customer Community portal.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Users can create and extract Varonis reports on their environment
and data within the platform until subscription expires. Varonis only collects and stores metadata on the platform. No customer files are stored on the platform. - End-of-contract process
-
After the subscription has expired Varonis metadata collection and
Data processing will cease. The customer can then decommission
their collectors and disable relevant service accounts used by
Varonis.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Linux or Unix
- MacOS
- Windows
- Other
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- WCAG 2.1 AAA
- API
- Yes
- What users can and can't do using the API
-
Varonis has exposed APIs in its core SaaS, DatAdvantage,
DataPrivilege and DatAlert platforms. These APIs expose reports, file system change information, the capability to change permissions and
group membership through the Varonis Commit Engine, and
Authorisation and Entitlement review workflows through SOAP and
REST APIs.
Varonis APIs can also be used to feed alerts to other security tools
e.g. SIEM and SOAR solutions. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Reports can be customised, automation and policies can be
customised, Alerts and Rules can be customised.
Scaling
- Independence of resources
-
Varonis is designed in high availability. The SaaS and DAC platform
are cloud native solutions which are scalable and elastic for users
onboarded.
The self-hosted platform components are scoped based on the
organisations size and we offer documentation to support the
increase system specification should there be a need to increase
resources for the platform.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Varonis can provide metrics on: platform run/uptime, system health,
event collection, past incidents, scan progress. - Reporting types
- Real-time dashboards
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Varonis
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Varonis can be implemented in your own cloud environment. You control who has access to your Varonis environment, and we do not have access to your data or facilities. All data processing is performed at the customer facility, under the control of customer staff.
- Data sanitisation process
- Yes
- Data sanitisation type
- Explicit overwriting of storage before reallocation
- Equipment disposal approach
- In-house destruction process
Data importing and exporting
- Data export approach
- Varonis has a number of reports and APIs which can be used to pull data from the system into various formats or feed the information into other tools.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- HTML
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- XML
- Syslog
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Varonis is designed in high availability. Our SaaS and DAC platforms are cloud native solutions with 99% availability over a rolling 90days. For self-hosted, the components can be made highly available, and we offer DR best practice documentation with our solution.
- Approach to resilience
- Our SaaS solution is hosted in a UK South region with resiliency provided by 3 availability zones. More information is available on request.
- Outage reporting
- Publicly available dashboard. With the option to subscribe to email updates.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- Varonis authentications via Active Directory. In cloud, using Microsoft Entra ID.
- Access restrictions in management interfaces and support channels
- Role Based Access Control and Resource Based Custodianship provides Separation of front end user roles and back end solution configuration roles, Segregate resource views by administrative region or resource type, Asia-Pac administrators only see Asia-Pac Servers, SharePoint administrators only see SharePoint resources , Content based access separation for lower level operational IT roles, Hide information like sensitive content locations from Help-Desk admins, Segregate resource views by administrative region/resource type, Asia-Pac administrators only see Asia-Pac Servers, SharePoint administrators only see SharePoint resources, Content based access separation for operational IT roles, Hide information like sensitive content locations from Help-Desk admins.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- 2-factor authentication
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
- Varonis authenticates all access, including management access, using active directory. In cloud, using Microsoft Entra ID.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- The Standards Institution of Israel
- ISO/IEC 27001 accreditation date
- 08/01/2021
- What the ISO/IEC 27001 doesn’t cover
- There are no exceptions, the certification covers - Development, Research, Software Delivery, Support, Professional Services, Delivery Cloud Based Software Solutions, Sales, Training, Project Management, Design and planning of risk assessment, protection of information systems, security of corporate and cloud networks.
- ISO 28000:2007 certification
- No
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- 01/11/2023
- CSA STAR certification level
- Level 1: CSA STAR Self-Assessment
- What the CSA STAR doesn’t cover
- The certificate covers relevant security controls in place for the services offered by Varonis.
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- 1 Cyber Valley
- PCI DSS accreditation date
- 30/11/2023
- What the PCI DSS doesn’t cover
- Varonis has completed an SAQ-D for Service Providers and Attestation of Compliance (AoC) which can be provided upon request. The Varonis Service has not been designed to store or process cardholder data. There is, however, a very low-level risk of card contamination within the file analysis process. To mitigate this risk, the requirements for card transmission and encryption were assessed as part of the assessment.
- Cyber essentials
- Yes
- Cyber essentials plus
- Yes
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 27017:2015
- ISO 27018:2019
- SOC2
- ISO/IEC 27701
- NIAP Common Criteria Certification
- HIPAA
- Data Privacy Framework
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
Varonis also complys with
ISO 27017:2015
ISO 27018:2019
CSA CCM version 4.0
SOC2
ISO/IEC 27701
NIAP Common Criteria Certification
HIPAA
Data Privacy Framework
CSA STAR certification
PCI-DSS - Information security policies and processes
-
Varonis CISO — Leads the global security teams and is responsible for internal infrastructure and cloud production security programs. The CISO also directs and oversees the development and review of information security policies, standards, and guidelines. The security standards that Varonis maintains are scoped for all our cloud solutions. Our compliance program constantly evolves to keep cloud infrastructure, policies, and standards updated with industry best practices. This compliance also includes regular independent external audits to ensure security, privacy, and compliance controls and procedures.
Varonis has nearly 30 security policies in place, covering various security domains in our documentation and aligns policies with various ISO/IEC standards (27001, 27017, 27018, and 27701), NIST 800-53, AICPA (American Institute of Certified Public Accountants), and other privacy regulations such as GDPR. Varonis certifications are available here: https://www.varonis.com/trust.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Varonis provides customers with maintenance and upgrade releases periodically. We ensure that customers are notified of new versions via email and or the Varonis customer portal. When implemented within the customer's cloud environment configuration and change management processes are the responsibility of the customer.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Varonis has a Vulnerability and Threat Management Policy. Varonis systems are scanned and results are reviewed by the CISO and IT departments. Security vulnerabilities are remediated within the timeline defined within the policy which includes procedures decided by the CISO for zero-day and other urgent patches. We deploy patches according to Varonis internal policy which aligns with industry standards and best practices. Our patch management policy requires security updates be installed promptly. Our SOC teams constantly monitor sources to ensure they are informed of new threats and vulnerabilities.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Varonis' Security Operations Centre, which comprise information
security personnel are responsible for the review and/or monitoring of
information security incidents or events. Our SOC and Cloud
operations teams constantly monitor our environments to ensure they
are aware of any threats or security incidents. We have processes and
playbooks in place to respond to threats and incidents. Varonis responds to incidents according to our internal incident management policy and processes which align with industry standards and best practices. The Incident Response Team analyses and validates each incident, following a pre-defined process and documenting each step taken according to Varonis internal policy. - Incident management type
- Supplier-defined controls
- Incident management approach
- Varonis has an Incident Response Policy that includes notification to the relevant stakeholders (including customers) as needed. Varonis will notify customers with all relevant information and cooperate with reasonable requests for information. This policy is aligned with industry best practices and included preparartion, identification, reporting, containment, discovery, eradication, recovery, and post incident report. We test our response plans periodically with a red team and a blue team. As highly qualified and experienced security professionals and forensic experts, our IR team is trained to detect and respond quickly to any security incident.
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
As an organisation that works closely with the public sector, Somerford is keen to demonstrate our commitment to supporting the achievement of the Net Zero target of greenhouse gas emissions by 2050.
Management and staff at Somerford have been conscious of our impact upon the environment even before the Climate Change Act was introduced, and we’ve adopted environmentally friendly practices as the business has grown. Consequently, Somerford ‘s business already has a reasonably low carbon footprint, and will continue to strive for further reductions wherever possible because this is beneficial for our business, our stakeholders and the environment.
We will use our influence as a value added reseller of leading edge software products and supporting professional services to select supplier-partners whose own carbon reduction philosophy and plans are aligned with ours, and who can show commitment to the Net Zero target. In practical terms, this means we participate in a carbon-net-zero supply chain in the delivery of the solutions from our supplier-partners to our customers.
For further details, please see our Carbon Reduction Plan online at https://www.somerfordassociates.com/carbon-reduction-policy-and-plan/ As an organisation that works closely with the public sector.Covid-19 recovery
During the Covid-19 pandemic, our robust business continuity measures, prudent fiscal policy, and the benefits of a highly flexible team, meant we were well prepared for the difficulties ahead.
Staff wellbeing has been at the forefront of our Covid-19 recovery plans, taking care of their physical and mental health, including;
* home working to avoid unnecessary exposure to the virus
* providing safe office space where staff personal circumstances dictated
* regular contact, albeit remotely, to prevent isolation
* organised e-based social events to maintain interaction;
As a result we have been able to:
* give uninterrupted service to our customers
* move our staff to home working
* avoid compulsory redundancies and minimised furlough
* in 2020, gain an 11% increase in revenues
* continue to grow the workforce by over 10% in the same year
* take on new partners to enhance our solutions portfolio
* invest in staff education to meet future customer needs.
Changes in business practices due to Covid-19 have shown that flexible work patterns can be very effective, and we’re unlikely to fully return to our previous style of working.
Our solutions have also helped customers to cope with their changing work patterns too - supporting their Covid recovery by providing the infrastructure, tooling and monitoring to support their own remote, flexible and sustainable ways of working.Tackling economic inequality
Somerford is a healthily growing business, and actively strives to create employment opportunities that are inclusive of all socio-economic groups. For example:
* 47% of our staff joined us as junior.
* 17 of our team have joined us as apprentices or graduated from our in house technical academy
* We actively participate in the Armed Forces Covenant Scheme and help to redeploy and re-skill leavers from the Armed Forces. So far, 18 staff have joined us in this way;
Strong technical skills are key to the delivery of services to our customers, so we’ve invested heavily in staff training, as is demonstrated by 47% of our staff starting with us as juniors.Equal opportunity
Somerford is an equal opportunities employer and does not discriminate on the grounds of gender, sexual orientation, marital or civil partner status, pregnancy or maternity, gender reassignment, race, colour, nationality, ethnic or national origin, religion or belief or age.
We do not discriminate on the grounds of disability. We take particular care to respect the rights of those with disabilities, throughout all stages of recruitment and employment. We make reasonable adjustments to ensure those with disabilities are not disadvantaged in the workplace, eg. adjusting working hours or providing special equipment to help to do their job.Wellbeing
Somerford is committed to promoting and supporting the wellbeing of all of its staff. We aim to create a culture which focuses on prevention of issues in the workplace that can adversely affect staff health and wellbeing, and where issues are identified, they are managed promptly before they can have a detrimental impact.
This includes:
* providing staff with clarity and purpose regarding their job role;
* ensuring staff have the capability, training, support and encouragement to conduct their role confidently and effectively;
* providing a physical working environment that is suitable for the work to be carried out effectively;
* encouraging staff to maintain a sensible work-life balance;
* minimising the stressful impacts of work;
* ensuring bullying and harassment have no place in the working environment;
* managing sickness and absence effectively;
* considering requests for career breaks and sabbaticals;
* providing medical assistance to staff;
* encouraging employee fitness;
* promoting dignity at work.
Pricing
- Price
- £221 a user a year
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
Varonis offers free Data Risk Assessments, designed specifically for the outcome you are looking for. e.g. Cyber-Resiliency Assessment, Cloud Application assessment, Compliance Assessment, Office365 Assessment, Co-pilot readiness assessment.
You'll receive a report highlighting your at-risk sensitive data, flags access control issues, any weaknesses across your data stores and recommends improvements. - Link to free trial
- https://www.somerfordassociates.com/varonis-dra-resource-page/