Industry engagement for a penetration testing framework for the civil nuclear sector (NBEST)
Details
- Buyer
- Department for Business Energy and Industrial Strategy (BEIS)
- Supplier(s)
- Frazer-Nash Consultancy Limited
- Value
- GBP 40,000
- Published
- 1 December 2017
- Source
- uk:digital_marketplace
Tender description
Summary of the work To deliver a written framework for carrying out advanced cyber assessments for the civil nuclear sector. In doing so, the contracted party will facilitate up to six workshops with industry representatives from the civil nuclear sector, threat intelligence and penetration testing providers over a three month period. Expected Contract Length 3 months, following sign off of the framework. Latest start date Monday 30 October 2017 Budget Range The target budget for the 3 months of work is for approximately £40,000 exclusive of VAT. Contractors should provide a full and detailed breakdown of costs (including options where appropriate). This should include staff (and day rate) allocated to specific tasks. Why the Work is Being Done The civil nuclear sector has invested in a broad range of cyber security and resilience measures in order to protect against, and mitigate the impacts of, cyber attacks. An advanced cyber assessment will examine how effectively the protective cyber security and resilience measures have been implemented by the company/site, and whether or not they increase the capability to deter, detect, and defend against risk scenarios developed by the Department of Business, Energy and Industrial Strategy (BEIS), the Office for Nuclear Regulation (ONR), the National Cyber Security Centre (NCSC), and industry. Problem to Be Solved To deliver a technical written framework for carrying out advanced cyber assessments for the nuclear sector. In doing so, the contracted party will facilitate up to six workshops with industry representatives from the civil nuclear sector, threat intelligence and penetration testing providers over a three month period. The engagement with industry will determine the appetite for, and viability of, carrying out penetration tests on nuclear sites. It will also look to establish any ‘red lines’ for the tests. Who Are the Users If the industry engagement proves successful and determines penetration testing is possible on nuclear sites, all civil nuclear licenced sites and the supply chain will be potential users of the framework. It will be used as part of a suite of tools to provide assurance to themselves, the regulator and government on the efficacy of their cyber security arrangements, and that vulnerabilities are being properly assessed and mitigated. Work Already Done Similar frameworks have been developed for the finance and telecoms sectors with support from the Bank of England (CBEST) and the Department for Digital, Culture, Media and Sport. This work should build on the existing frameworks, and benefit from the lessons learned. The ONR has recently appointed a contractor to carry out a similar but distinct piece of work on conducting evaluations of cyber arragements at nuclear facilities, including a process to determine the readiness of sites to undergo an advanced penetration test. This is complementary to and will build on the work advertised here, but is separate from it. Existing Team The supplier will be working with the civil nuclear cyber security team in BEIS who will manage the contract. The supplier will also need to work with teams in the National Cyber Security Centre, the Office for Nuclear Regulation, the Nuclear Decommissioning Authority and wider industry. Current Phase Discovery Skills & Experience • Have an aptitude for successfully carrying out and facilitating stakeholder engagement to achieve project objectives. • Have an understanding of the risks and benefits of penetration testing live systems. Nice to Haves Demonstrate a familiarity with the nuclear sector Work Location Work will take place at BEIS offices (central London) and the supplier site as required. Work may also need to be carried out at sites in the North of England to allow participation by the greatest number of industry members. Working Arrangments Actual arrangements will be agreed at the outset of Discovery. Users and stakeholders are nationwide so we anticipate a requirement to engage users from different regional areas. Security Clearance Baseline Personnel Security Standard (BPSS) No. of Suppliers to Evaluate 6 Proposal Criteria • How the approach or solution meets your organisation’s policy or goal • Approach and methodology • How they’ve identified risks and dependencies and offered approaches to manage them • Value for money • Team structure (with roles and responsibilities) Cultural Fit Criteria • Work as a team with our organisation and other organisations • Take a collaborative and sharing approach, actively seeking input from colleagues and stakeholders. • Challenge the status quo Payment Approach Capped time and materials Evaluation Weighting Technical competence 50% Cultural fit 20% Price 30% Questions from Suppliers 1. Can you please confirm that DV clearance is not required for this work? We do not require suppliers to hold DV clearance for this work, only Baseline Personnel Security Standard (BPSS) level security clearance. 2. Can you please confirm if travel expenses be available in addition to the daily rate for this work? The budget for this work is £40,000 excluding VAT. Travel expenses need to be covered in your tender for the work within that budget. 3. Will the supplier who is selected to develop the NBEST framework be prohibited from providing or restricted in providing NBEST assessment services after the framework is developed? Furthermore, would there be similar independence restrictions applied for providing other “BEST” framework assessments (e.g. CBEST, TBEST, etc) as a result of developing the NBEST framework? No restrictions will be placed on the successful supplier with regards to future ‘BEST’ work.
Timeline
- Completed: Award published1 December 2017Current notice
- Completed: Award date1 December 2017
About the buyer
Department for Business Energy and Industrial Strategy (BEIS) is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@department-for-business-energy-and-industrial-strategy-beis.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@department-for-business-energy-and-industrial-strategy-beis.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@department-for-business-energy-and-industrial-strategy-beis.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@department-for-business-energy-and-industrial-strategy-beis.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@department-for-business-energy-and-industrial-strategy-beis.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@department-for-business-energy-and-industrial-strategy-beis.gov |
Related topics
Topics related to Industry engagement for a penetration testing framework for the civil nuclear sector (NBEST), ranked by notice volume.
- 5,183£735.8bn
- 11,175£1.0tn
- 26,969£1.7tn
- 1,417£20.1bn
- 4,088£269.5bn
Related buyers
Buyers similar to Department for Business Energy and Industrial Strategy (BEIS).
- 1,531£58.3bn
- 750£1.3bn
- 692£133.2bn
- 641£160.0bn
- 458£8.1bn
- 338£7.4bn
- 326£1.3bn
- 280£1.1bn
- 263£902.6m
- 228£550.1m
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
