Skip to main content

Help us improve the Digital Marketplace - send your feedback

BECHTLE LIMITED

Proofpoint Threat Protection Suite

Proofpoint Email Protection stops malware and non-malware threats, it also utilises granular filtering to control SPAM. Targeted Attack Protection detects and blocks advanced threats, including ransomware. We detect known threats and never-before-seen attacks that use malicious attachments and URLs.

Features

  • URLs Sandboxing time of click, time of delivery (predictive analysis).
  • Sandboxing of URLs found inside attachments.
  • Attachment Sandboxing
  • Owns all security technology in solution
  • Attachments delivered as-is (unaltered state)
  • Granular threat forensics (name, indicators of compromise, exploit environment)
  • Smart Search: Comprehensive message tracing across mail agents in seconds.
  • Dedicated threat research team keeping up with changing threat landscape
  • Dynamic Imposter email classifier rules adjust as attackers change tactics

Benefits

  • Protects people from malicious attachments in email
  • Protects people from malicious URL's in attachments and email
  • Respond to threats faster
  • Protects people from impersonation attacks
  • Deployment On-Prem or Cloud
  • Threat analysis through TAP Dashboard
  • Community based intelligence contains more than 800 billion data points

Pricing

£13.59 a licence

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at publicsector.uk@bechtle.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 14

Service ID

9 0 5 4 4 9 2 9 8 7 4 8 7 3 8

Contact

BECHTLE LIMITED Public Sector
Telephone: 01249 467900
Email: publicsector.uk@bechtle.com

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Extension to messaging platform services – eg On Premise Exchange, Office 365, Google Apps
Cloud deployment model
Community cloud
Service constraints
Refer to Service Level Agreement
System requirements
Existing mail server, eg; Exchange, o365, Zimbra, Lotus Notes

User support

Email or online ticketing support
Email or online ticketing
Support response times
Dependant on Service Level Purchased
Support Portal - All Levels
Telephone Support Business Hours
Telephone Support 365x24x7
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.1 AA or EN 301 549
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Self-Service, Platinum, Premium & Global

Self-Service: primary access via portal, phone support limited to business hours P1 issues, 2 authorised support contacts

Platinum: access via portal and phone, phone support for all priorities during business hours plus P1 issues 24x7, 4 authorised support contacts.

Premium: access via portal and phone, phone support for all priorities during business hours plus P1 issues 24x7, 6 authorised support contacts, assigned Technical Account Manager .

Global: available to Platinum and Premium only. phone access for all cases, all priorities 24x7x365, 12 authorised support contacts
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Installation and training / knowledge share available with dedicated engineer
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
Data extraction tools driven by customer.
End-of-contract process
Data extraction tools driven by customer.

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
  • Windows
  • Windows Phone
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
.
Service interface
Yes
User support accessibility
WCAG 2.1 AA or EN 301 549
Description of service interface
Utilisation of a reporting dashboard - eg Palo Alto
Accessibility standards
WCAG 2.1 AA or EN 301 549
Accessibility testing
Installation and training / knowledge share available with dedicated engineer
API
Yes
What users can and can't do using the API
Utilisation of a reporting dashboard - eg Palo Alto
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
No
Customisation available
No

Scaling

Independence of resources
All Proofpoint SaaS systems are actively monitored with local agents collecting hundreds of metrics specific to hardware, networking, and OS. All metrics are measured against a baseline compiled from historical data. Acceptable thresholds are defined based on a combination of optimal performance targets and historical baselines.

Analytics

Service usage metrics
Yes
Metrics types
Granular Reporting of message flow, deep analysis into threats
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Up to Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Other
Other data at rest protection approach
AES 256
Access to the Proofpoint production environment, where services are hosted, is granted based on role and occurs via a 2FA encrypted VPN.
Data sanitisation process
Yes
Data sanitisation type
  • Explicit overwriting of storage before reallocation
  • Deleted data can’t be directly accessed
Equipment disposal approach
In-house destruction process

Data importing and exporting

Data export approach
Data extraction tools driven by customer.
Data export formats
Other
Other data export formats
PDF
Data import formats
Other
Other data import formats
PDF

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
  • Other
Other protection between networks
Proofpoint has documented information security program consisting of policies, procedures and standards that aligns with the requirements of NIST 800-53 and ISO 27001. The program is owned by the Proofpoint Global Information Security group, and includes a continuous monitoring program consisting of monthly and quarterly evidence collection and review, and an annual SOC 2 Type II audit of the program.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Policies, procedures, and standards comprising the Proofpoint information security program are reviewed and updated annually by the Proofpoint Global Information Security group and approved by the Proofpoint CFO.

Availability and resilience

Guaranteed availability
Please refer to: https://www.proofpoint.com/sites/default/files/general_terms_hosted_services_sla_-_mar_2016.pdf
Approach to resilience
The services run in active/active mode between a pair of geographically-diverse co-location facilities.
Outage reporting
Please refer to:
https://www.proofpoint.com/sites/default/files/general_terms_hosted_services_sla_-_mar_2016.pdf

Identity and authentication

User authentication needed
Yes
User authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
All access to the Proofpoint production environment, where services are hosted, is via a 2FA encrypted VPN and granted based on role.
Access restriction testing frequency
At least once a year
Management access authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Description of management access authentication
All access to the Proofpoint production environment, where services are hosted, is via a 2FA encrypted VPN and granted based on role.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
Less than 1 month
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 1 month and 6 months

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber essentials plus
No
Other security certifications
Yes
Any other security certifications
SOC 2 Type II audit report, available here: https://go.proofpoint.com/soc2_report_request.html

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Governing Standard - NIST 800-53
The Proofpoint security program is led by the Proofpoint CSO. The program is based on identifying and mitigating risk to our personnel, the organization and the customer.
Information security policies and processes
Proofpoint's information security program is aligned with the requirements of NIST 800-53 and ISO 27001. However, we are not certified to the ISO 27001 standard.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Proofpoint has a documented change management policy that includes requirements around documented change tickets and review and approval by the Change Review Board.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Proofpoint performs internal and external vulnerability scanning and remediates applicable findings in line with the Proofpoint patch management policy.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Proofpoint has distributed monitoring in place for availability, performance, capacity and security. Alerts are directed to a 24x7 NOC or SOC for review, remediation and/or escalation.
Incident management type
Supplier-defined controls
Incident management approach
Proofpoint has a documented Incident Response Plan that includes procedures to detect, investigate, remediate and communicate security incidents. A trained IRT team is responsible for the maintenance of the program.

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Social Value

Social Value

Social Value

  • Fighting climate change
  • Covid-19 recovery
  • Tackling economic inequality
  • Equal opportunity
  • Wellbeing

Fighting climate change

Bechtle are actively taking steps to ensure that we operate our business with as little environmental impact as possible. As a group, we are Ecovadis Gold and ISO14001 certified, and are committed to becoming carbon net zero by 2030. We launched the Bechtle Sustainability Strategy 2030 to serve as a roadmap for how we will get there, identifying 4 areas of action as part of this strategy:

• Ethical business practices
• Environmental Approach
• People
• Sustainable digital future

Bechtle have established a database for recording Scope 1 and 2 (direct and indirect CO2 emissions) and Scope 3 (that of the Bechtle Group, such as purchased goods and services, transportation and distribution, business travel, and employee commuting) emissions. We are collecting data through group-wide sustainability software, WeSustain, and have used the data to produce a Carbon Reduction Plan (CRP) that is published on our website (Carbon-Reduction-Plan-BechtleUK-2022.pdf) and updated annually.

Supply chain management
We work closely with our vendor partners to broaden our portfolio of sustainable technologies, solutions, and services, and could help to minimise the future environmental impact.

Recycling/Asset disposal
Bechtle actively encourage our customers to make sustainable use of their resources, through secure asset disposal, refurbishment, and recycling of devices. Bechtle have recently helped facilitate a self-funding recycling program for a large local authority, who wanted to prevent their old laptops from going to landfill.

Green Logistics
Bechtle design our logistics processes around an ecological efficiency criteria, both in terms of transport and packaging.

Internal Sustainability team
We have a dedicated sustainability team, who’s aim is to improve and promote sustainability within three areas: social, personal, and business. The team have defined and actioned sustainable methods, changes in practice and greener alternatives across the whole of Bechtle UK and help to drive our sustainable

Covid-19 recovery

Many organisations have had to change their operating models and ways of working following the COVID-19 pandemic. IT also became clear to a number of our customers that their infrastructure that supported old ways of working, no longer supported new hybrid or remote working models. Through a thorough infrastructure review we can not only advise our customer on what best suits their current operating models but we can also help them to be future-ready. We can help them improve productivity, utilisation and adoption, getting maximum productivity out of their investment, whilst saving costs and limiting environmental impact through cloud/ hybrid adoption.

Tackling economic inequality

Bechtle’s equal opportunities policy applies across the whole company and includes recruitment, selection, training, career development and promotion. No employee or applicant will be treated less favourably on the grounds of colour, race, religion, nationality, ethnic or national origin, gender (including gender reassignment), sex, sexual orientation, age, marital status, disability, or be disadvantaged by conditions or requirements that cannot be shown to be relevant to the job in hand.

Specifically the Company is committed to:
1. Preventing any form of direct or indirect discrimination or victimisation.
2. Promoting equal opportunities for men and women.
3. Promoting equal opportunities for people with disabilities.
4. Promoting equal opportunities for ethnic minorities.
5. Promoting a good harmonious working environment where all employees are treated with respect and dignity and in which no form of intimidation or harassment will be tolerated.
6. Fulfilling all legal obligations under relevant legislation and associated codes of practice.
7. Taking all necessary permitted positive action including setting of goals and timetables.

Breaches of the Equal Opportunities Policy will be regarded as misconduct and could lead to dismissal in certain cases.

Equality and Diversity policy is available upon request

Equal opportunity

Bechtle’s equal opportunities policy applies across the whole company and includes recruitment, selection, training, career development and promotion. No employee or applicant will be treated less favourably on the grounds of colour, race, religion, nationality, ethnic or national origin, gender (including gender reassignment), sex, sexual orientation, age, marital status, disability, or be disadvantaged by conditions or requirements that cannot be shown to be relevant to the job in hand.

Specifically the Company is committed to:
1. Preventing any form of direct or indirect discrimination or victimisation.
2. Promoting equal opportunities for men and women.
3. Promoting equal opportunities for people with disabilities.
4. Promoting equal opportunities for ethnic minorities.
5. Promoting a good harmonious working environment where all employees are treated with respect and dignity and in which no form of intimidation or harassment will be tolerated.
6. Fulfilling all legal obligations under relevant legislation and associated codes of practice.
7. Taking all necessary permitted positive action including setting of goals and timetables.

Breaches of the Equal Opportunities Policy will be regarded as misconduct and could lead to dismissal in certain cases.

Equality and Diversity policy is available upon request

Wellbeing

Bechtle believe Health & Safety and wellbeing of employees contributes to a good working environment which is key to a business.

Throughout the year Bechtle hold different events, this gives everyone a chance to meet one another from different office branches which lends itself to a healthy work environment, some of these events are “Summer Festival (BBQ, Music, Dancing), Christmas Party, New Year kick off, Games events” to name a few. Each branch also have a relaxing area where employees can congregate and take time out in a chilled environment.

Bechtle have also introduced initiatives to promote social and economic wellbeing, such as:

• Competitive salary, which is well above the National Minimum Wage
• Cycle to work scheme
• Hybrid working model, where employees can work from home 2 days a week to reduce commuting time
• My Bechtle Benefits discount portal, offering employees discounts via numerous retailers
• Employee Assistance Programme, providing employees with mental health and wellbeing support
• WPA Health Cash Plan
• Enhanced pension contribution
• Reduced health and gym memberships
• Paid for professional training
• Piloting an electric vehicle salary sacrifice scheme, which is being rolled out to the wider company.

Pricing

Price
£13.59 a licence
Discount for educational organisations
No
Free trial available
No

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at publicsector.uk@bechtle.com. Tell them what format you need. It will help if you say what assistive technology you use.