Awarded contract

Software package and information systems

Details

Value
GBP 295,966
Topic
Software package and information systems
Published
16 March 2018

Tender description

The Council has multiple lines of defence when it comes to security, a number of services have been pulled together to create a Cyber Security Suite which includes Endpoint antivirus, Email Protection, Password Solutions, Policy Management, Vulnerability Scanning, Phishing Simulation and Consultancy. There are newly introduced Government standards that the Council would like to comply with going forward, these are based around email security and encryption, specifically DMARC and SPF, there is a requirement that the encryption used should be a minimum of TLS 1.2. Guidance on Government secure emails can be found here. We would like to utilise the solution to replace the current encrypted email solution and GCSX (Government Secure Intranet) secure email solution that we have in place for secure email exchange between both government partners and external non-government parties. Additionally, the council has a non-core requirement for replacement of a hosted secure email solution that is used to generate invoices and mail these securely to customers. If an API or similar integration method is offered for the encrypted e-mail solution then this could also be used to replace this system in addition. In addition to signature based end point security, we would like to incorporate the use of behavioural based threat protection, which will involve consistently monitoring for abnormal behaviour patterns across our entire corporate network, but primarily on the endpoint devices. The Council are looking to be able to rapidly distribute policy changes, updates and news to users across our corporate estate. This is to enable better policy understanding and compliance across the organisation. The Council would be looking for an easy to use and understand management interface that would allow us to audit policy, and target updates or tests at specific user groups. The Council are aiming to complete proactive scanning throughout the year on a regular cycle and make changes to secure any issues that have been identified. The Council view this as taking a proactive approach to security by blocking loopholes before they are exploited by the new generation of ransomware. The Council are looking for a regularly updated tool that will be able to scan end user devices as well as servers, switches and firewalls for known vulnerability in Hardware and Software including both Operating Systems and applications. This will allow us to patch and take appropriate controls to secure our entire estate. The Council currently have a phishing simulation tool that we have used across the Authority with some relative degree of success. The Council currently complete most of our education of phishing manually and would like to move towards to more automated solution. We'd like to build education and training into the core of our phishing simulation, with the ability to run campaigns targeted amongst individual groups of users, or levels of management etc. The Council has a requirement to carry out annual an IT Health check for our PSN membership, and are looking toward gaining Cyber Essentials Plus and PCI DSS compliance. The Council is looking for a partner to be able to carry out the above certifications / audits as required and also assist us with gaining the accreditations. The accreditation requirements for ITHC. Cyber Essentials and PCI DSS are not a strict requirement within the first year, but we would like to be able to plan our work towards these, with support from a consultancy provider. The support could be in multiple forms for example a number of days over the duration or the Agreement or a set number of days per year, these could be weighted around timescales to help us achieve compliance. We are open to new ideas and creativity in this area, in terms of how the consultancy could be delivered to suit the Council and provider. The Council is looking to increase the security of the password policies whilst looking to make the process easier for the end user. The Council would expect to see features like blocking of dictionary passwords, blocks on reuse of similar passwords, self-reset and some kind of password strength tool to show users how secure / insecure a password is. The password solution will need to work with Active Directory as this is our one source for Single Sign On within various products used across the corporate estate. We would like to implement a password reward system, whereby users who use stronger passwords are rewarded with a longer expiry period, if this is possible.

Timeline

  1. Completed: Award date13 February 2018
  2. Completed: Award published16 March 2018
    Current notice

About the buyer

Barnsley Metropolitan Borough Council is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.

Relevant CPV codes

  • 48000000 · Software package and information systems
  • 72000000 · IT services: consulting, software development, Internet and support

AI insights

  • Is there a preferred supplier?
  • What are the buyers pain points?
  • What has the buyer previously procured?
  • What are the key requirements?
Sign-up to enrich

Decision makers

Connect with the people behind this procurement.

Contact nameJob titlePhone numberWork email
Head of Procurement+44 •••• ••••••
Commercial Director+44 •••• ••••••
Procurement Manager+44 •••• ••••••
Category Lead+44 •••• ••••••
Senior Buyer+44 •••• ••••••
Contracts Manager+44 •••• ••••••

68 similar open tenders

See more open tenders related to Software package and information systems.

Explore all open tenders

Related buyers

Buyers similar to Barnsley Metropolitan Borough Council.

View all buyers

Win more public sector contracts

Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.