Closed tender

Cyber Security - Delivery Partner

Details

Value
GBP 300,000
Published
6 June 2019
Submission
20 June 2019

Tender description

Why the Work is Being Done In HM Land Registry’s Business Strategy 2017-2022, we committed to continually strengthen and mature our security defences to address increasingly sophisticated threats. HM Land Registry are investing in a Cyber project to transform our cyber capabilities and the Cyber Partner will assist in shaping and delivering workstreams within this project. Problem to Be Solved A partner is required to support the following: • Manage an IT Security Team. • Review current team practices and provide suggestions for improvement. • Provide cyber security strategy and delivery. • Provide technical resource to help in the delivery of cyber security projects and work packages. • Provide Security Architecture resource assisting in the development of security patterns and assurance of services. • Share knowledge and develop security standards for emerging technologies / techniques. • Perform detailed due diligence verification activities on specific third party suppliers managing or holding key information assets. Who Are the Users N/A Early Market Engagement Work Already Done Business as usual activity is currently performed by HM Land Registry’s core security teams. As a partner you will be continually involved in the security of HM Land Registry’s infrastructure and services. A gap analysis exercise has been completed, this has resulted in the creation of a Cyber project under which 9 workstreams will be delivered to increase security capabilities. - SIEM - Password Policy - 2FA - Threat Intelligence - DMARC - Endpoint Protection - PAM / PAW - Code scanning - Application whitelisting Existing Team The selected supplier will be working as part of the Cyber project alongside internal teams including IT Security, Security Operations and Security Architecture. Current Phase Not applicable Work Location HM Land Registry’s security teams are based in Plymouth, UK and this is where the work will take place. Working Arrangments This will be a 5 day per week (Monday to Friday) commitment and, although there may be some scope for remote working, our focus is to build co-located and integrated teams at our offices in Plymouth. Detailed working arrangements, including team location, size and make-up, will be contained within each statement of work. The Cyber Security Partner must follow HM Land Registry's IT and security procedures and policies in relation to access, data and equipment use Security Clearance HM Land Registry requires all supplier staff to have baseline personnel security standard clearance. There may be a requirement for some of the work to require security clearance checks. This will be detailed in the statement of work. Additional T&Cs The standard terms and conditions of a DOS framework agreement call-off contract apply. T&S will not be paid for travel to the "home" office which will usually be Plymouth and specified in the SOW. Skills & Experience • Experience in successful delivery of digital cyber strategy and security models • Experience of providing roles and team structures to meet customer deliverables and as defined in the Statement of Works • Experience in integrating roles and teams’ interplay with the customer and/or other suppliers’ resources, as a single delivery team • Experience of working with customers that are part of Central Government. • Experience of working with customers that run Critical 24x7 secure services. • Technical capability to design, implement and support new security infrastructures. • Proven ability to assist in setting the strategic direction for Cyber Security projects. • Capability to support and assist the Security Architecture team in the assessment and risk identifying, against new services. • Knowledge of a range of security standards including but not limited to ISO27000, SOC 2, CIS & NIST. • Knowledge and Experience of widely used IaaS/PaaS/SaaS environments and the ability to provide ongoing advice on how HM Land Registry secure their existing platforms. • Knowledge and experience of best practice regarding implementing least privilege security models and approaches within cloud and on-premise environments • Ability to provide guidance on appropriate separation of roles across the various operation planes (management, control & data), within cloud and on-premise environments. • Knowledge and experience of best practices to implement scalable and secure methods of storing sensitive data, such as service credentials within cloud and on-premise environments. • Experience of implementing Service based authentication within service and on-premise environments. • Experience of designing and implementing the use of modern device-based authentication methods e.g. Windows Hello and other MFA tools. • Experience of a range of security infrastructures and technologies including but not limited to, LDAP, Modern Authentication tools, End-Point Protection Technologies, Application Whitelisting Technologies. • Experienced in implementing Customer Identity Strategies Nice to Haves No. of Suppliers to Evaluate 4 Proposal Criteria • Written response to draft Statement of Work to be shared with shortlisted suppliers. – 20% • Proposed implementation team structure, with CV’s outlining relevant experience of each team member – 10% • Resources – depth and flexibility providing the ability to scale – 10% • Service quality management, including approach to issue management, problem resolution and improving ways of working and commercial and contract management. – 10% Cultural Fit Criteria • Establish good working relationships and generate team spirit – 2% • Work collaboratively with permanent staff and other suppliers – 2% • Share knowledge and participate in skills transfer – 2% • Ability to use existing knowledge, experience and lessons learnt – 2% • Adapt to meet changing priorities and take responsibility – 2% Payment Approach Capped time and materials Assessment Method Written proposal Case study Work history Reference Presentation Evaluation Weighting Technical competence 60% Cultural fit 10% Price 30% Questions from Suppliers Budget range anticipated value up to £300,000

Timeline

  1. Completed: Tender published6 June 2019
    Current notice
  2. Completed: Submission date20 June 2019

About the buyer

HM Land Registry (HMLR) is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.

AI insights

  • Is there a preferred supplier?
  • What are the buyers pain points?
  • What has the buyer previously procured?
  • What are the key requirements?
Sign-up to enrich

Decision makers

Connect with the people behind this procurement.

Contact nameJob titlePhone numberWork email
Head of Procurement+44 •••• ••••••
Commercial Director+44 •••• ••••••
Procurement Manager+44 •••• ••••••
Category Lead+44 •••• ••••••
Senior Buyer+44 •••• ••••••
Contracts Manager+44 •••• ••••••

Related topics

Topics related to Cyber Security - Delivery Partner, ranked by notice volume.

View all topics
TopicCountValue
  1. 1,485
    £14.9bn
  2. 5,186
    £736.1bn
  3. 1,745
    £636.1bn
  4. 4,088
    £269.5bn

Win more public sector contracts

Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.