Telefonica UK Limited

Proofpoint Security from O2

Proofpoint provides security with the following; CASB, Threat protection suite with continuity, Email Fraud Defence; Email Security Essentials, Meta Networks (SASE), Security Awareness Training (PSAT)

Features

  • Smart Search: Comprehensive message tracing across mail agents in seconds
  • URLs Sandboxing time of click, time of delivery (predictive analysis)
  • Sandboxing of URLs found inside attachments
  • Attachment Sandboxing
  • Attachments delivered as-is (unaltered state)
  • Dedicated threat research team keeping up with changing threat landscape
  • Dynamic Imposter email classifier rules adjust as attackers change tactics
  • Business Continuity ensuring email flow during outage
  • Enterprise Archiving
  • CASB +Security Awareness Training +Secure Service Access Edge

Benefits

  • Protects people from malicious URL's in attachments and email
  • Respond to threats faster
  • Protects people from impersonation attacks
  • Continue to send/receive email during outages, e.g Office 365 outage
  • Threat analysis through TAP Dashboard
  • Community based intelligence contains more than 800 billion data points
  • Deployment On-Prem or Cloud
  • Archiving utilized for search antime - anywhere
  • Easy to enforce retention policies.

Pricing

£12.83 a user a year

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at g-cloud_framework@o2.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 12

Service ID

7 8 9 4 2 0 8 8 5 6 5 9 0 3 7

Contact

Telefonica UK Limited Steve Smith
Telephone: 07834 571216
Email: g-cloud_framework@o2.com

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Please contact O2 for additional details.
Cloud deployment model
Community cloud
Service constraints
Please refer to Proofpoint Service Level Agreement (SLA)
System requirements
Existing mail server, eg; Exchange, O365, Zimbra, Lotus Notes

User support

Email or online ticketing support
Email or online ticketing
Support response times
Dependent on Service Level Purchased
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Please refer to Proofpoint Service Level Agreement (SLA)
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Installation and training / knowledge share available with dedicated engineer
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Data extraction tools driven by customer.
End-of-contract process
Services cease to function.

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari 9+
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Not applicable
Service interface
No
API
Yes
What users can and can't do using the API
Utilization of a reporting dashboard
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
No
Customisation available
No

Scaling

Independence of resources
Historical baselines

Analytics

Service usage metrics
Yes
Metrics types
Granular Reporting of message flow, deep analysis into threats
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request

Resellers

Supplier type
Reseller (no extras)
Organisation whose services are being resold
Proofpoint

Staff security

Staff security clearance
Other security clearance
Government security clearance
Up to Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • European Economic Area (EEA)
  • EU-US Privacy Shield agreement locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
Never
Protecting data at rest
Other
Other data at rest protection approach
Please contact O2 for additional information.
Data sanitisation process
Yes
Data sanitisation type
  • Explicit overwriting of storage before reallocation
  • Deleted data can’t be directly accessed
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data export approach
Data extraction tools driven by customer.
Data export formats
Other
Other data export formats
Not applicable
Data import formats
Other
Other data import formats
Not applicable

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
  • Other
Other protection between networks
Aligns with the requirements of NIST 800-53 and ISO 27001. Annual SOC 2 Type II audit of the program.
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
https://www.proofpoint.com/sites/default/files/general_terms_hosted_services_sla_-_mar_2016.pdf
Approach to resilience
https://www.proofpoint.com/sites/default/files/general_terms_hosted_services_sla_-_mar_2016.pdf
Outage reporting
https://www.proofpoint.com/sites/default/files/general_terms_hosted_services_sla_-_mar_2016.pdf

Identity and authentication

User authentication needed
Yes
User authentication
Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
All access to the Proofpoint production environment, where services are hosted, is via a 2FA encrypted VPN and granted based on role.
Access restriction testing frequency
At least once a year
Management access authentication
2-factor authentication

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 6 months and 12 months
How long system logs are stored for
Between 6 months and 12 months

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Other security certifications
Yes
Any other security certifications
SOC 2 Type II audit report, available here: https://go.proofpoint.com/soc2_report_request.html

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
NIST 800-53
Information security policies and processes
The Proofpoint security program is led by the Proofpoint CSO. The program is based on identifying and mitigating risk to our personnel, the organization and the customer.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Proofpoint has a documented change management policy that includes requirements around documented change tickets and review and approval by the Change Review Board.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Proofpoint performs internal and external vulnerability scanning and remediates applicable findings in line with the Proofpoint patch management policy.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Proofpoint has distributed monitoring in place for availability, performance, capacity and security. Alerts are directed to a 24x7 NOC or SOC for review, remediation and/or escalation.
Incident management type
Supplier-defined controls
Incident management approach
Proofpoint has a documented Incident Response Plan that includes procedures to detect, investigate, remediate and communicate security incidents. A trained IRT team is responsible for the maintenance of the program.

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Price
£12.83 a user a year
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Full service offering as a Proof of Concept for 2 weeks as standard at customers request.
Link to free trial
Provided by a Proofpoint Engineer once requirements are confirmed.

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at g-cloud_framework@o2.com. Tell them what format you need. It will help if you say what assistive technology you use.