Computacenter - Varonis SaaS Data Security Platform
Varonis is a leader in data security, fighting a different battle than conventional cybersecurity companies. Our cloud-native Data Security Platform continuously discovers and classifies critical data, removes exposures, and detects advanced threats with AI-powered automation.
Features
- Accurate data inventory: Find, classify, label, secure sensitive data
- Flexible policies: Library of hundreds of customizable classification rules
- Data access intelligence: Control net permissions, reduce exposure/compliance risk
- Policy automation: Automated remediation for exposures, unnecessary permissions, misconfigurations
- Cross-platform audit trail: Searchable data access and granular permissions
- Data-centric UEBA: Detect abnormal activity to stop data breaches
- MDDR: 24x7x365 incident response, threat hunting & forensics
- DSPM: Reports and dashboards show meaningful risk reduction
- Email security: Detect exposures, email-based attacks & insider threats
- Compliance: posture against GDPR, CAF, NHS DSPT, NIST, ISO27001
Benefits
- Improve your data security posture automatically
- Enable the safe rollout/use of generative AI/LLMs (e.g. Co-Pilot)
- Accurately discover, classify, and label sensitive data
- Monitor cloud data activity and prevent exfiltration
- Enforce least privilege, labels, and secure settings
- Detect abnormal activity from APTs and insider threats
- Fix critical SaaS misconfigurations and third-party app risk
- Automate compliance regulations and frameworks
- Lock down sensitive mailboxes and stop exfiltration
- Reduce risk and minimize cyber insurance claims
Pricing
£6.39 a licence
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
9 1 8 0 7 2 6 7 6 7 4 7 7 5 3
Contact
Computacenter (UK) Ltd
Karen Baldock
Telephone: +44 (0) 1707 631000
Email: government@computacenter.com
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
-
The Varonis Data Security Platform offers both SaaS and self-hosted
deployment options.
Our cloud-native Data Security Platform is hosted by Varonis and
delivered as software-as-a-service (SaaS). Our SaaS platform can
monitor and protect both cloud and on-premises data.
Our self-hosted Data Security Platform can be deployed either on
prem or in any private cloud that can run Windows servers (e.g., Azure,
AWS, Google, etc.). - System requirements
-
- Windows Server 2019/2022 Standard or Enterprise (x64) (Fully Patched)
- 8 Core, 2 GHz or better CPU
- 16 GB RAM minimum
- 250 GB Drive (required to be on C:\\)
- .NET Framework - 4.7.2 or 4.8
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
-
Varonis standard support is available Monday to Friday from 9am to
9pm Central European Time. 24/7 support can be accessed for an
additional cost. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.1 AAA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Onsite support
- Support levels
-
Tickets are opened through the Customer portal on help.varonis.com
and can be updated online or via email.
Varonis Support has 3 tiers of response- FLS (T1), Tier2, Tier 3. Most
cases that are open by SEs/Partners/customers will be received by
FLS, and escalated according to need. SLA is defined upon the level of Support Services the customer has purchased and the severity of the
case. For further details, please see "Varonis Support Principles"
document. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Training can be completed by leveraging Varonis Education Services
for standard training of the application and advanced/troubleshooting
classes that are offered. All training is done online. In addition,
Professional Services can provide online or on-site training that is
more customised based upon specific products and use
cases/business needs for the customer. Varonis also offers additional
learning resources (ex: how-to documents and videos) in the Customer
Community portal. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Users can create and extract Varonis reports from their environment
and data within the platform until the subscription expires. Varonis
only collects and stores metadata on the platform. No customer files
are stored on the platform. - End-of-contract process
-
After the subscription has expired Varonis metadata collection and
data processing will cease. The customer can then decommission
their collectors and disable relevant service accounts used by Varonis.
Retention of Subscriber Data - Our default retention policy is a sliding
window of 180 days during the subscription term (unless a longer
period was approved by Varonis, at its sole discretion, at the request of
the Client). Upon the end/termination of the subscription term,
Subscriber Data which is held by Varonis at such time shall be kept for
a period of up to 30 days after termination of the subscription.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Linux or Unix
- MacOS
- Windows
- Other
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- WCAG 2.1 AAA
- API
- Yes
- What users can and can't do using the API
-
Varonis has exposed APIs in its core SaaS, DatAdvantage,
DataPrivilege and DatAlert platforms. These APIs expose reports, file system change information, the capability to change permissions and group membership through the Varonis Commit Engine, and
Authorisation and Entitlement review workflows through SOAP and
REST APIs.
Varonis APIs can also be used to feed alerts to other security tools e.g. SIEM and SOAR solutions. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Reports can be customised, automation and policies can be
customised, Alerts and Rules can be customised.
Scaling
- Independence of resources
-
Varonis is designed in high availability. Our SaaS and DAC platforms
are cloud native solutions which are scalable and elastic for users
onboarded.
Our selfhosted platform components are scoped based on the
organisations size and we offer documentation to support the increase
system specification should there be a need to increase resources for
the platform.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Varonis can provide metrics on: platform run/uptime, system health,
event collection, past incidents, scan progress. - Reporting types
- Real-time dashboards
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Varonis
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Up to Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
-
Varonis can be implemented in your own cloud environment. You
control who has access to your Varonis environment, and we do not
have access to your data or facilities. All data processing is performed
at the customer facility, under the control of customer staff. - Data sanitisation process
- Yes
- Data sanitisation type
- Explicit overwriting of storage before reallocation
- Equipment disposal approach
- In-house destruction process
Data importing and exporting
- Data export approach
-
Users can export Varonis reports of their environment and data in CSV,
PDF, Excel, HTML formats. Varonis only collects and stores metadata
on the platform. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- HTML
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- XML
- Syslog
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Varonis is designed in high-availability. SaaS and DAC platforms are
cloud native with 99% availability over a rolling 90 days. For
selfhosted, the components can be made highly available, and we
offer disaster recovery best practice documentation. Varonis will use commercially reasonable efforts to assure that
Subscriber is able to access the Varonis’ web application of the
Subscription Services at least 99% of the time, as measured by
Varonis over the course of twelve months period(s) (Availability). If
Varonis does not meet the Availability commitment, Subscriber will be
eligible to receive Service Credit as described in Varonis SaaS Support
Policies. - Approach to resilience
-
Available on request.
Our SaaS solution is hosted in a UK South region with resiliency
provided by 3 availability zones. - Outage reporting
-
Publicly available dashboard. With the option to subscribe to email
updates.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
-
Varonis authenticates via Active Directory. In cloud, using Microsoft
Entra ID. - Access restrictions in management interfaces and support channels
-
Varonis has application Role Based Access Control and resource
based custodianship. There are currently 28 different roles. RBAC and
Custodianship provides:
• Separation of front-end user roles and back-end solution
configuration roles
• Segregate resource views by administrative region or resource
type
• Asia-Pac administrators can only see Asia-Pac Servers
• SharePoint administrators can only see SharePoint resources
• Content based access separation for lower level operational IT
roles.
• Hide information views such as sensitive content locations
from Help-Desk admins. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- 2-factor authentication
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
-
Varonis authenticates all access, including management access, using
active directory. In cloud, using Microsoft Entra ID.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- 28/04/2022
- What the ISO/IEC 27001 doesn’t cover
- Our ISO/IEC 27001 certification relates to the information security management system and not the products or services of the certified organisation.
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Gemserv Ltd
- PCI DSS accreditation date
- 22/09/2021
- What the PCI DSS doesn’t cover
- As per section 2a of the PCI-DSS certificate, there are no areas that were marked as ‘Not Included’. We therefore confirm we are compliant across all relevant requirements for our services as a Hosting Provider, Managed Services and Payment Processing.
- Cyber essentials
- Yes
- Cyber essentials plus
- Yes
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
• ISO 27017:2015
• ISO 27018:2019
• CSA CCM version 4.0
• SOC2
• ISO/IEC 27701
• NIAP Common Criteria Certification
• HIPAA
• Data Privacy Framework
• CSA STAR certification
• PCI-DSS - Information security policies and processes
-
Varonis is a pioneer in data security and analytics specialising in data
protection, threat detection and response, and compliance. Varonis
adopts a risk-based approach for its information security management
system (ISMS). This approach requires identifying, assessing, and
appropriately mitigating vulnerabilities and threats to information
assets. Deploying an ISMS reduces the risk of unauthorized,
accidental, or intentional information disclosure, modification, or
destruction.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Varonis provides customers with maintenance and upgrade releases
periodically. We ensure that customers are notified of new versions via
email and or the Varonis customer portal. When implemented within
the customer's cloud environment configuration and change
management processes are the responsibility of the customer.
Varonis maintains an inventory of our components to ensure they are
monitored and tracked.
Changes within all our environments are subject to a structured
change-management procedure. They undergo design and impact
analysis and are continuously monitored. As with all our processes,
the procedure is subject to annual external audits (SOC 2 and ISO/IEC
27000 series). - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Varonis has a Vulnerability and Threat Management Policy. Varonis
systems are scanned and results are reviewed by the CISO and IT
departments. Security vulnerabilities are remediated within the
timeline defined within the policy which includes procedures decided
by the CISO for zero-day and other urgent patches.
We deploy patches according to Varonis internal policy which aligns
with industry standards and best practices. Our patch management
policy requires security updates be installed promptly.
Our SOC teams constantly monitor sources to ensure they are
informed of new threats and vulnerabilities. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Varonis' Security Operations Centre, which comprise information
security personnel are responsible for the review and/or monitoring of
information security incidents or events. Our SOC and Cloud
operations teams constantly monitor our environments to ensure they
are aware of any threats or security incidents. We have processes and
playbooks in place to respond to threats and incidents.
Varonis responds to incidents according to our internal incident
management policy and processes which align with industry standards
and best practices. The Incident Response Team analyses and
validates each incident, following a pre-defined process and
documenting each step taken according to Varonis internal policy. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Varonis has an Incident Response Policy that includes notification to
the relevant stakeholders (including customers) as needed. Varonis
will notify customers with all relevant information and cooperate with
reasonable requests for information. This policy is aligned with
industry best practices and included preparation, identification,
reporting, containment, discovery, eradication, recovery, and post
incident report.
We test our response plans periodically with a red team and a blue
team. As highly qualified and experienced security professionals and
forensic experts, our IR team is trained to detect and respond quickly
to any security incident.
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
Computacenter ensures that our business practices deliver effective stewardship of the environment in line with the Social Value Model. Computacenter's science-based emissions reductions targets are approved with the SBTi. Our Net Zero Journey Group Emissions is now just 16% of 2015 levels as outlined in our carbon reduction plan to achieve ‘Net Zero’ carbon emissions by 2040.
Business travel is necessary, both for our customer requirements and for our staff. We have materially reduced business travel, ensuring all business trips are necessary, helping reduce carbon emissions. We are investing in technology to allow greater use of existing communication platforms as part of our ‘hybrid working’ strategy. One of the key benefits we believe this will help us realise is reducing emissions from business travel by 35 per cent by 2025 (compared to 2019). For G-Cloud services this means that we will drive the use of virtual, technology-enabled meetings as much as possible for all internal and external sessions, including those with our wider supply chain.
Further to this we can provide customer advisory services which include guidance and recommendations on how to improve their sustainability performance to help inform customer decision making whilst achieving the desired commercial and technical outcomes through the services being provided.
Computacenter has introduced incentives to encourage the replacement of the existing Fleet with Ultra Low Emission Vehicles. We have 44 electric charging points across 2 of our locations to encourage the adoption of electric and hybrid vehicles, either through our company car scheme or privately. For this framework specifically, this means that our consultants, project managers and engineering resource will have access to a ULEV vehicle via our company car scheme and the ability to charge a vehicle at Computacenter office locations.Covid-19 recovery
Throughout the pandemic we have closely followed and implemented government guidance relating to the workplace and COVID-19. We created a COVID-19 risk assessment to enable us to understand the improvements that need to be made to our workplace conditions in line with the Government COVID-19 secure workplace guidelines and the business advice that is now current. It looks at the risks of COVID-19 in the workplace, such as hygiene, & cleaning and then states what we must put in place to mitigate these risks.
As we enter the recovery phase of the pandemic, we have introduced hybrid working for our employees. This will allow most employees including those delivering G-Cloud services increased flexibility in how and where they work ensuring that we still deliver the best service to our customers whilst looking after our people.
Our COVID-19 steering committee is there to identify activities that will improve workplace conditions then plan, build and regularly monitor various programmes focused on supporting the COVID-19 recovery effort. At these meetings, chaired by our Chief People Officer (‘CPO’) Sarah Long, our CIO John Gibbs and Services operations, the steering committee discuss changes that need to be implemented, identify areas of improvement, and review our roadmap of new activities.
Throughout the life of the contract, we will use our existing activities (as well as those that are in development in due course) to continue to improve workplace conditions in support of the COVID-19 recovery effort.
Questions relating to travel were included in the COVID-19 surveys that were issued through the pandemic. The assessment highlighted concerns people had about public transport. To help all employees; managers were coached and given guidance about being flexible with start/finish times. We continue to adapt our approach based on feedback received through the steering committee and employee surveys.Tackling economic inequality
As a diverse and inclusive organisation with a strong focus on equality and driving in-work progression, our approach to recruitment and employment is aligned to recognised industry best practices such as the 5 principles of quality work as set out in the Good Work Plan.
Our Employee Impact Groups for disadvantaged or minority groups provide representation, support, and community engagement, feeding into our People Panel ensuring all voices are heard, underpinning our wider ambition of building a sustainable business for the long term.
We put specific measures in place to provide opportunities to under-represented groups or those who face barriers to employment, including comprehensive outreach programmes for schools and universities, as well as partnerships with non-profit organisations within our communities. We continue focus on reaching harder to reach groups and people who are underrepresented in our sector by working with charities and schools in the local community to offer career talks and work experience opportunities. Our school outreach programme has over 130 volunteers dedicating over 2,600 hours running activities for employability and life skills in schools, colleges, and universities.
Computacenter is one of the 9 founding members of ‘Technology Community for Racial Equality’ (‘TC4RE’), a group set up to drive racial equality throughout the technology industry, with which we are delivering a half-day virtual event on ‘Enabling Ethnic Diversity’ featuring a series of expert keynotes, live panel discussions and interactive workshops with representation from across the UK technology community.
Furthermore, Computacenter are a silver level partner in the Armed Forces Covenant and has introduced a programme that provides the opportunity to attain a degree and ServiceNow certification whilst receiving full salary for armed forces leavers. This programme is the first of many programmes we intend on running to help ex-forces personal transition back into the workplace and the IT industry.Equal opportunity
Computacenter is committed to providing equal opportunities to all through fair recruitment practices and employment conditions across our organisation.
We are a Disability Confident ‘Committed’ employer, committed to making lasting changes to our business creating a diverse talent pool. We work with partners through our community outreach, who are specialists in disability. An example is our work with Knightsfield School in Welwyn Garden City, a specialist school for deaf children. We run at least 3 ‘get work ready’ events with them, as well as offer up to 4 work experience opportunities and onsite visits every year.
For this contract, we will use existing initiatives (as well as others that are in development) to provide career opportunities for individuals from under-represented groups to address requirements for specific skills or roles with a focus on increasing skillsets through the life of the contract. This will include apprenticeships aligned to security and cloud/infrastructure departments, as well as industrial placements and graduate schemes for our ServiceNow Centre of Excellence, with specific focus on delivering cloud-based services to our customers.
Our workforce for services delivered under this framework will have access to existing initiatives aimed at supporting in-work progression and development for those from disadvantaged/minority groups. For example, our gender diversity initiatives include our Growing Together programme, which over 150 women have been through so far, of which over one-third have been promoted or taken a new role within a year following the mentoring and coaching provided.
We are also committed to driving racial equality across our business and the wider technology industry. We are a founding member of ‘Technology Community for Racial Equality’ which recently delivered a half-day virtual event on ‘Enabling Ethnic Diversity’ featuring a series of expert keynotes, live panel discussions and interactive workshops with representation from across the UK technology community.Wellbeing
We understand how important employee Wellbeing is for a sustainable business model, therefore we are committed to creating a sustainable supply chain. Ensuring the wellbeing of our employees are looked after will positively affect productivity, recruitment, and retention rates.
In November 2021, a designated UK wellbeing manager was appointed and has since launched our wellbeing strategy, which aligns with the Social Value Model and the 6 standards of the Mental Health at Work Commitment, signed in July 2021. We are actively implementing the enhanced mental health standards as recommended through the ‘Thriving at Work’ review, and NICE mental health at work guidelines, as part of our Wellbeing strategy. The strategy encompasses four pillars of wellbeing, mental, physical, financial, and social. We are a Menopause friendly organisation and have created a support network for those in need.
We have 109 Mental Health First Aid (MHFA) accredited staff in the UK, trained by Mind, who act as Wellbeing Champions providing mental health first aid support and promoting our wellbeing services which those delivering G-Cloud service provisions will have access to. These champions are from every business area and from different seniority. We hold events throughout the year organised by our UK wellbeing manager and Champions, which have included celebrating World Mental Health days, Menopause awareness, financial wellbeing webinars and sponsored events to raise money for our mental health charity partners.
2021 also saw the launch of our new groupwide app-based programme ‘Be Well’ which gives our people access to over 3,000 fitness, nutrition, health and wellbeing courses through Humanoo. Through this app we have launched an extremely popular groupwide step challenge and has encouraged our people to be more active, with over 35% of our workforce now using the app and covering over 1.8bn steps so far.
Pricing
- Price
- £6.39 a licence
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
Varonis offers a free Data Risk Assessment - designed specifically for
your organisation’s needs and desired outcomes/controls These
include:
Cyber Resiliency Assessment,
Insider Threat Risk Assessment,
Compliance Risk Assessment (e.g. GDPR),
Ransomware Readiness Assessment,
Data Security Posture Management (DSPM) Assessment,
3rd-party app risk assessment,
M365 Risk Assessment,
Co-pilot readiness assessment. - Link to free trial
- https://info.varonis.com/en/data-risk-assessment