Application IT Health (ITHC) Check
Working with our partner Cyberfort's team we provide reliable independent assurance that applications, databases and associated infrastructure are protected from security threats. Using CREST and CHECK ITHC accredited methodologies, we perform state-of-the-art automated vulnerability scanning and carefully targeted manual testing to deliver an outstanding assessment across internal and external estates.
Features
- CREST and CHECK ITHC accredited Application Penetration Testing
- Methodology based on OWASP, OWASP ASVS, WAHH
- Comprehensive automated and manual Penetration Testing
- Clear communication of threats and risks in their business context
- Complete technical vulnerability reporting
- Actionable remediation advice and support
- Operational acceptance, source code and gold image build reviews
- Assurance of security controls across all deployment platforms
- Dedicated technical lead supported by cross discipline team
Benefits
- Correct scoping ensures best return on investment with no surprises
- Meet regulatory and internal compliance requirements
- Remove uncertainty and de-risk penetration testing
- Actionable prioritised resolution advice; save time and drive efficiency
- Clear benefit realisation against agreed performance indicators
- Penetration testing service aligned with your requirements
Pricing
£880 to £1,375 a transaction a day
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
9 5 0 2 1 0 0 0 1 2 3 6 6 2 6
Contact
Akhter Computers PLC
Latifa Hamdan
Telephone: 01279 821200
Email: ccsales@akhter.co.uk
Planning
- Planning service
- No
Training
- Training service provided
- Yes
- How the training service works
-
The Secure Coding Training/Workshop is a course aimed at software developers, software architects, security consultants and quality assurance engineers who want to understand how attackers uncover and exploit vulnerabilities in web applications, and what can be done by developers to prevent it.
The course covers a methodology used to assess the security of a web application and gives detailed guidance on secure development, relating to both the design and implementation of web applications.
The course is a mix of presentations and hands-on lab sessions where attendees will practice and experience how application vulnerabilities are detected and exploited by attackers, and how applications can successfully defend against these attacks. - Training is tied to specific services
- No
Setup and migration
- Setup or migration service available
- No
Quality assurance and performance testing
- Quality assurance and performance testing service
- No
Security testing
- Security services
- Yes
- Security services type
-
- Security strategy
- Security risk management
- Security design
- Cyber security consultancy
- Security testing
- Security incident management
- Security audit services
- Other
- Other security services
-
- Managed MDR
- Managed MXDR
- Managed Vulnerability Management
- Certified security testers
- Yes
- Security testing certifications
-
- CHECK
- CREST
- Cyber Scheme
- Other
- Other security testing certifications
-
- CompTIA Sec +
- CompTIA Net +
- CompTIA CySA +
- BSc (Hons) Cyber Security Management
- Cyber Scheme Team Leader
- Cyber Scheme Team Member
- CREST CCT Application / Cyber Scheme CSTL App
- CREST CCT Infrastructure / Cyber Scheme CSTL Inf
- CREST CRT / Cyber Scheme CSTM
- CREST CPSA
Ongoing support
- Ongoing support service
- No
Service scope
- Service constraints
- No constraints
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
-
The Service Desk operates 24/7/365 and is the primary point of contact, undertaking initial triaging of any service requests, incidents, or events directly with the client.
A ticket number is issued with an initial response within 15-minutes of logging a query.
Resolution time goals will be calculated in accordance with a priority matrix.
Please refer to our Service Definition, for more details on our service response times and commitments. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.1 AA or EN 301 549
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Support levels
- Support Desk operates 24 x 7 x 365.
Resellers
- Supplier type
- Reseller (no extras)
- Organisation whose services are being resold
- Cyberfort
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Developed Vetting (DV)
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- 17/04/2024
- What the ISO/IEC 27001 doesn’t cover
- Cyberfort was first registered to ISO27001 in August 2019. At our recertification audit in 2023, there were no nonconformities or observations. 2024 Continual assessment visit resulted in no nonconformities or observations.
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Sec Consulting
- PCI DSS accreditation date
- 09/10/2023
- What the PCI DSS doesn’t cover
- Requirement 3 Requirement 4 Appendix A1 Appendix A2
- Cyber essentials
- Yes
- Cyber essentials plus
- Yes
- Other security certifications
- Yes
- Any other security certifications
-
- NHS Data Security and Protection Toolkit
- NCSC IT Health CHECK Service - CHECK Service Provider
- CREST Certificate Membership Cyber Incident Response, Vulnerability Assessment and PenTest
- NCSC Assured Cyber Security Consultancy Risk Assessment, Management, Audit Review
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
Cyberfort support and act on fighting climate change through our Environmental Management System (EMS) which meets the requirements of our ISO:14001 certification. We have initiated programs designed to increase the energy efficiency of our operations, reduce waste, and protect the environment in communities where we work. Our environmental goals and achievements are published in our Carbon Reduction Plan (CRP), which is aligned to the requirements of CCS PPN 06/21.
Our social value strategy addresses MAC 4.1 & 4.2 with the following commitments:
Effective stewardship of the environment
We are committed to become a net-zero and environmentally conscious company by conserving energy, minimising consumption, reducing, and preferring low pollution materials, maximising environmental efficiency, whilst ensuring waste is managed and controlled.
We support our environmental targets with the following initiatives:
• Continue to reduce our carbon emissions, including 100% renewable energy, power saving modes, light replacement programmes, hybrid/remote working and cycle to work incentives.
• Reduce water consumption, including water filter systems off the mains instead of using water providers, consider Water Butts around site as an alternative for gardening, and detection of increased water consumption to identify any leaks in facilities.
• Adopt strategies to promote, reuse, recycle, recover energy and disposal of waste sent to landfill, including initiatives to reduce our plastic waste and targets for recycling of waste.
• Deliver initiatives to support our environments, ensuring that we are protecting and encouraging native plants and wildlife. We’ve already introduced a small flock of sheep to our Ash site to help make our site more environmentally friendly, and at our Newbury site we limit operations to specific times to ensure protection of nightjars which is a protected wildlife species.
• Consider who we purchase goods and services from ensuring providers are targeting net-zero initiatives and offer sustainable product and servicesCovid-19 recovery
Cyberfort support and act on Covid-19 recovery by encompassing initiatives that force for positive change. We have aligned the activities of our business by considering sustainability through the decisions we make as a business, including the way we operate, employ staff, engage with communities, and procure products and services, allowing us to cultivate a more sustainable, resilient, and inclusive society.
Our social value strategy addresses MAC 1.1, 1.3, 1.4 & 1.5 with the following commitments:
Help local communities to manage and recover from the impact of COVID-19
We support Covid-19 recovery with the following initiatives:
• Throughout the pandemic and to date we’ve maintained a recruitment drive, often offering positions to individuals affected by the impacts of Covid-19 in the industry.
• We upskill people new to Cyber via supporting Apprenticeship schemes.
• We remove any barriers for disadvantaged groups by adjusting our recruitment and selection processes and excluding bias.
• We promote health and wellbeing in the workplace, ensuring all our people have healthy lifestyles, thrive, and that they feel supported with the tools they need from us to be at their best. Including Mental Health First Aiders, confidential, and free-of-charge, support and benefits to all, including counselling and Private Medical Insurance.
• Since the pandemic we recruit fully remote or hybrid working roles, which allows us to tap into wider talent pools and therefore ensure we are accessing the best candidates without any locational barriers.
• We are committed to working with small, diverse, high-quality business to procure goods and services, structuring our supply chain selection process in a way that ensures fairness and encourages participation by new and growing businesses.Tackling economic inequality
Cyberfort support and act on tackle economic inequality, through supporting new businesses, new employment opportunities and development of new skills.
Our social value strategy addresses MAC 2.2 & 2.3 with the following commitments:
Create new businesses, new jobs and new skills
We are committed to ensuring that everyone is given the opportunity to develop in accordance with their ability, ambition and opportunities available, providing recruitment, training, development and progression opportunities to encourage everyone to reach their fullest potential.
We support tackling economic inequality with the following initiatives:
• Attract, recruit, develop and retain the very best people at all levels.
• Upskill people new to Cyber via supporting Apprenticeship schemes.
• Actively support educational attainment across our workforce, including training to address skills gaps resulting in recognised qualifications.
• Support young people in the development of their passion for technology, introducing them to cybersecurity, and providing initiatives that support schools and colleges.
Our social value strategy addresses MAC 3.1, 3.4 & 3.5 with the following commitments:
Increase supply chain resilience and capacity
We are committed to work fairly and responsibly with our supply chain and ensure that we manage and identify cyber security risks.
We support tackling economic inequality with the following initiatives:
• Collaborating throughout the supply chain to adopt a fair and responsible approach to working with suppliers and partners.
• Supply chain selection process identifies opportunities to sub-contract with a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, and VCSEs.
• We have measures within supply chain selection process to mitigate and manage cyber security risks within our supply chain, e.g. including NCSC cyber risk regime and Cyber Essentials/Plus certifications.Equal opportunity
Cyberfort support and act on equal opportunities, fostering an inclusive culture that values people as individuals with diverse opinions, cultures, lifestyles and circumstances. All employees are covered by our Equality, Diversity & Inclusion Policy, which applies to all areas of employment including recruitment, selection, training, deployment, career development, and promotion.
Our social value strategy addresses MAC 5.1 & 5.2 with the following commitments:
Reduce the disability employment gap
We support the disability employment gap with the following initiatives:
• We are signatories of the Armed Forces Covenant.
• We are a Disability Confident Employer and founding members of Neurodiversity in Business.
• Our recruitment practices ensure we are disarming any barriers people with disabilities may face in the hiring process.
• Developing and supporting people with disabilities in gaining the skills they need to succeed.
Our social value strategy addresses MAC 6.1, 6.2 & 6.3 with the following commitments:
Tackle workforce inequality
We support the tackling workforce inequality with the following initiatives:
• Take reasonable and appropriate steps to encourage job applications from as diverse a range of people as possible and recruiting people with an impairment or disability.
• Decisions made relating to a person's promotion or career development must be free from discrimination.
• We provide training, development and progression opportunities to all staff supporting career aspirations.
• Our Employee Resource Groups include Women’s Network, Inclusion Committee and Neurodivergent Community Group, providing forums for people who have a passion for, or a connection with, a particular aspect of equality, diversity and inclusion.
• Whilst not required under the Modern Slavery Act 2015 to have a policy, we have a zero–tolerance approach and have implemented a modern slavery policy.Wellbeing
Cyberfort support and act on health and wellbeing through our Occupational Health and Safety (OH&S) policy in alignment with our ISO:45001 certification. We actively work on initiatives to promote health and wellbeing in the workplace, ensuring all our people have healthy lifestyles, thrive, and that they feel supported with the tools they need from us to be at their best.
Our social value strategy addresses MAC 7.1 & 7.2 with the following commitments:
Ensuring positive physical and mental health in the workforce, ensuring our people have healthy lifestyles.
We support our workforce with the following initiatives:
• Mental Health First Aiders – We have 9 fully trained Mental Health First Aiders within our workforce.
• Wellbeing Benefits – we provide confidential, and free-of-charge, support and benefits to all, including confidential counselling and support service available 24/7, 365 days a year and Private Medical Insurance with extra to cover employees for Mental Health support.
• Our Wellbeing Hub (on the Cyberfort SharePoint) provides various resources, self-help tools and guides to help individuals stay well and includes any previous recordings from workshops that have been run.
Our future goals include:
• Certified to ISO:45003 standard in 2024, which focuses on the “mental health” and “wellbeing” aspects of health and safety.
• Strengthening our commitments through 6 standards of the Mental Health at Work Commitment in 2024, to ensure that we continue to provide the right support as and when needed.
Pricing
- Price
- £880 to £1,375 a transaction a day
- Discount for educational organisations
- No