CDW Limited

CDW Checkpoint Sandblast Mobile

SandBlast Mobile (previously MTP or Capsule) provides a powerful and continuous level of security across an organisations mobile device real-estate. The solution provides an always-on, up-to-date protection for smartphone and tablet users against known and unknown threats against both mobile devices and data before any damage can be caused.


  • Cloud Behavioural Risk Engine determines risk level and appropriate response
  • Advanced app analysis to check if installed Apps are malicious
  • DLP prevents sensitive data from leaking through your SaaS application
  • Supported on tablets and smartphones running both Android and iOS
  • Events logs available for online analysis, & SEIM integration
  • Cloud based management portal with detailed reporting
  • MDM integration for seamless deployments and management of compromised devices.


  • Deploy any iOS / Android device with confidence
  • Protect sensitive information on mobile devices from espionage
  • Integrates into existing mobility and security infrastructures (MDM, MAM, SIEM.)
  • Preserve UX and privacy, whilst meeting organizational or regulatory mandates
  • Constant real-time protection against the latest threats
  • No additional hardware or software installation required
  • Proactive device lock down when threats are detected


£3.20 per device per month

Service documents

G-Cloud 11


CDW Limited

Andy Wood

0161 837 7744

Service scope

Service scope
Software add-on or extension Yes, but can also be used as a standalone service
What software services is the service an extension to Airwatch By Vmware BlackBerry MaaS360 MobileIron Microsoft Intune Citrix XenMobile
Cloud deployment model Hybrid cloud
Service constraints Mobile phones and tablets (versions may be restricted to latest OS’)
System requirements
  • IOs Android
  • Internet connection required to reach the Cloud management portal.

User support

User support
Email or online ticketing support Email or online ticketing
Support response times Standard Support Customers have an SLA of 4 Hours for Severity 2,3,4 Questions and 30 Minutes for Severity 1 Questions.
Premium Support Customers have an SLA of 4 Hours for Severity 3,4 Questions, 2 Hours for Severity 2 and 30 Minutes for Severity 1 Questions.
Elite Support Customers have an SLA of 4 hours for Severity 3,4 Questions and 30 minutes for Severity 1,2 Questions .
User can manage status and priority of support tickets Yes
Online ticketing support accessibility None or don’t know
Phone support Yes
Phone support availability 24 hours, 7 days a week
Web chat support No
Onsite support Yes, at extra cost
Support levels Check Point Standard Support: SLA 9x5 Buisness Day. Response Time Severity 1: 30 Minutes, Severity 2,3,4 4 Hours. Latest hotfixes yes, Major Upgrades and Enhancements Yes. Check Point Premium Support: SLA 7 x 24 Every Day. Response Time Severity 1: 30 Minutes, Severity 2,2 Hours and Severity 3 & 4 4 Hours. Latest hotfixes yes, Major Upgrades and Enhancements Yes. Check Point Elite Support: SLA 7 x 24 Every Day. On Site Engineer for Critcal SRs Response Time Severity 1: 30 Minutes, Severity 2 30 minutes and Severity 3 & 4 4 Hours. Latest hotfixes yes, Major Upgrades and Enhancements Yes. Check Point Diamond Support: SLA 7 x 24 Every Day. Designated Diamond Engineer Response Time Severity 1: 30 Minutes, Severity 2,3,4 based on level of support(Standard, Premium or Elite. Latest hotfixes yes, Major Upgrades and Enhancements Yes.
Support available to third parties Yes

Onboarding and offboarding

Onboarding and offboarding
Getting started N/A
Service documentation Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction Users can export logs which contain information about each mobile protected by the service, such as information scanned for malware.
End-of-contract process N/A

Using the service

Using the service
Web browser interface Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
Application to install Yes
Compatible operating systems
  • Android
  • IOS
Designed for use on mobile devices Yes
Differences between the mobile and desktop service Mobile is the enforcement point Desktop is the management platform.
Service interface No
What users can and can't do using the API Check Point Sandblast Mobile API Enables users to call for certain information such as, Device Risk, Alert information, Device Status and Device Details.
Check Point SandBlast Mobile SDK allows organizations to embed its market-leading mobile security solution in their mobile apps.
API documentation Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment No
Customisation available Yes
Description of customisation Buyers can customise via the SDK.


Independence of resources We have an autoscaling Service which is hosted in the cloud also.


Service usage metrics Yes
Metrics types Provide how many licenses are being used.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request


Supplier type Reseller (no extras)
Organisation whose services are being resold Checkpoint

Staff security

Staff security
Staff security clearance Other security clearance
Government security clearance Up to Security Clearance (SC)

Asset protection

Asset protection
Knowledge of data storage and processing locations Yes
Data storage and processing locations European Economic Area (EEA)
User control over data storage and processing locations No
Datacentre security standards Supplier-defined controls
Penetration testing frequency At least once a year
Penetration testing approach Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with SSAE-16 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process Yes
Data sanitisation type Deleted data can’t be directly accessed
Equipment disposal approach In-house destruction process

Data importing and exporting

Data importing and exporting
Data export approach Users can export logs which contain information about each mobile protected by the service, such as information scanned for malware.
Data export formats CSV
Data import formats CSV

Data-in-transit protection

Data-in-transit protection
Data protection between buyer and supplier networks TLS (version 1.2 or above)
Data protection within supplier network TLS (version 1.2 or above)

Availability and resilience

Availability and resilience
Guaranteed availability The analysis is performed in the cloud to avoid impacting device performance, and since protection runs in the background, users are protected without having to learn anything new.
Approach to resilience Check Point Sandblast Mobile is a background running app, taking a small amount of battery usage. It can perform app anaylsis, monitor network activity, access device level (OS) vulnerabilities and scan SMS messages. Because it is light weight it takes little resource.
Outage reporting Sandblast Mobile will report back to the dashboard and report it back in log format.

Identity and authentication

Identity and authentication
User authentication needed Yes
User authentication
  • Username or password
  • Other
Other user authentication Users authenticate using Username and Password Via email. Email is sent to the correct using and then User either scans QR code or enters username and password for authentication.
Access restrictions in management interfaces and support channels N/A
Access restriction testing frequency At least once a year
Management access authentication Username or password

Audit information for users

Audit information for users
Access to user activity audit information Users have access to real-time audit information
How long user audit data is stored for User-defined
Access to supplier activity audit information No audit information available
How long system logs are stored for User-defined

Standards and certifications

Standards and certifications
ISO/IEC 27001 certification No
ISO 28000:2007 certification No
CSA STAR certification No
PCI certification No
Other security certifications No

Security governance

Security governance
Named board-level person responsible for service security Yes
Security governance certified Yes
Security governance standards ISO/IEC 27001
Information security policies and processes For our internal processes we strive to meet the same level as ISO 27001, however do not seek accreditation

Operational security

Operational security
Configuration and change management standard Supplier-defined controls
Configuration and change management approach Check Point has a change management process with Q&A development before technology changes.
Vulnerability management type Supplier-defined controls
Vulnerability management approach Check Point always responds back on any vulnerabilities found in its technology in a quick and timely manor. Within industry we are the fastest responding vendor.
Protective monitoring type Supplier-defined controls
Protective monitoring approach Check Point is constantly monitoring their process and striving for increased performance within all technologies.
Incident management type Supplier-defined controls
Incident management approach Check Point handles all incidents in a tiered support process. Biggest impact taking highest priority.

Secure development

Secure development
Approach to secure software development best practice Conforms to a recognised standard, but self-assessed

Public sector networks

Public sector networks
Connection to public sector networks No


Price £3.20 per device per month
Discount for educational organisations Yes
Free trial available Yes
Description of free trial 15 Day Evaluation license
Link to free trial

Service documents

pdf document: Pricing document pdf document: Service definition document pdf document: Terms and conditions pdf document: Modern Slavery statement
Service documents
Return to top ↑