Closed tender

Cyber Security Project Delivery Partner

Details

Value
GBP 2,500,000
Published
27 February 2019
Submission
13 March 2019

Tender description

Why the Work is Being Done The National Cyber Security Strategy details the UK government’s investment in to cyber security, with the vision for 2021 that the UK will be secure and resilient to cyber threats while prosperous and confident in the digital world. To achieve this, it is required to: • Continue projects across the Cyber Security Programme that demonstrate cyber risk reduction • Investigate, research and apply cyber security best practices from across government departments and industry partners • Plan, build and implement a strategy for the delivery and pilot launch of the capabilities Problem to Be Solved A supplier is required by the customer to complete the next phase of threat hunting, digital risk and intelligence, cloud Single sign on (SSO) projects and additional planned cyber projects. Deliverables include but are not limited to: • Delivery plans to launch each capability • Production of a target operating model • Build and implementation of a strategy for each area • Regular updates on progress and share of outcomes • Pilot launches with a subset of users or functions Who Are the Users As an internal user, I want to use one set of authentication details for my work station so that I can access all authorised applications without needing to enter further credentials. As a security manager, I want to introduce the threat hunting activity, so that I can understand and remediate how existing internal security controls can be evaded across the organisation. As a cyber-risk owner, I want to understand any potential threats in the public domain so that I can minimise cyber risk to the organisation. Early Market Engagement None Work Already Done The initial discovery phase has resulted in:- • Key recommendations and early suggestions made for capability adoption across the organisation • Initial capability maturity models created • Priority research areas identified • White paper reports • Recommendations paper on implementation of SaaS SSO across government including product offering • Initial delivery plans for piloting capabilities The on- boarded supplier will receive full details on the existing work and access to documentation. Existing Team The selected supplier will be working as part of the Cyber Security Programme (CSP) alongside existing suppliers. Key stakeholders from the Cabinet Office and National Cyber Security Centre, in addition to the Customer, will be involved in delivery acceptance and approvals. Current Phase Discovery Work Location The team will work as part of the CSP, located in Croydon and Central London. Close collaboration with CSOC teams in Manchester will be required and potentially travel to other Departmental locations in the UK on occasion. Working Arrangments The supplier’s team will be required to be located on site for five days (40 hours) per week, whether alongside the programme team in Croydon, or at a Departmental location around the UK. Occasional travel to regional sites may be required. Day rates will be inclusive of travel and subsistence expenses within M25/Greater London. Travel and subsistence expenses incurred from travel outside of the M25/Greater London will be subject to Home Office Travel and Subsistence Policy. Security Clearance Individuals in the supplier’s team will require Home Office SC clearance, or be willing to undergo Home Office SC clearance checks. The clearance needs to have been achieved before work can commence. Additional T&Cs Standard DOS framework and call-off terms and conditions will apply. This contract will consist of multiple phases and a statement of work will be created for each phase. Skills & Experience Experience in successful delivery of digital cyber strategy and security models. Experience in writing white papers advising central government departments on cyber security. Experience in successful pilots and implementations (including testing, deployment and transition to live) of cyber security solutions in medium to large organisations. Experience of providing single sign on (SSO) to cloud applications in medium to large sized organisations. Experience of Access Management and SSO technologies and offerings including Ping Identity, Okta and Microsoft AAD. Experience of mobilising an experienced team with required skills within short timescales and to manage their performance over the duration of the contract. Experience of digital cyber security tools and frameworks for threat intelligence and digital risk, specifically open source scraping services and open source tooling, as well as strategies and best practices. Experience of implementing and standardising new working processes and providing a full knowledge transfer to the end customer. Nice to Haves Experience of working in delivery of a cyber programme consisting of multiple suppliers. Experience of options for Network Access Control (NAC) implementation and associated costs. Experience of current endpoint protection tools and solutions. Experience of containerised services, infrastructure and security best practices. Experience of security best practices and vulnerability assessments for third party code adoption. Experience in use of SOC tooling including SIEM and open source scraping tools. No. of Suppliers to Evaluate 5 Proposal Criteria Proposed technical solution and implementation plan. Proposed implementation team structure, with CVs outlining relevant experience of each team member. Implementation approach of SSO for cloud applications. Supplier solution, including key considerations, for developing threat hunting and digital risk and intelligence capability. Proposed quality measures and standards on supplier’s deliverables and outputs including testing approach and information on how supplier will implement checks and reviews of their outputs. Recommended solution for transitioning from functional pilot to organisational launch. Proposed KPIs and service levels to measure success Proposed approach to mobilisation of the on-boarded team. Approach to ensuring value for money. Cultural Fit Criteria Ability to have effective communication and collaborate within a large programme with multiple suppliers and multiple customers. Work as a team with CSP suppliers, demonstrating a willingness to co-operate/collaborate, with practical mechanisms suggested to achieve this. Approach to issue management, problem resolution and improving ways of working. Approach to commercial and contract management. Ability to use the existing knowledge, experience and lessons learnt from previous similar engagements. Payment Approach Capped time and materials Assessment Method Written proposal Evaluation Weighting Technical competence 55% Cultural fit 10% Price 35% Questions from Suppliers Budget range up to £2.5m for the contract (the initial phase of projects will be for up to £830k exclusive of vat)

Timeline

  1. Completed: Tender published27 February 2019
    Current notice
  2. Completed: Submission date13 March 2019

About the buyer

Home Office is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.

AI insights

  • Is there a preferred supplier?
  • What are the buyers pain points?
  • What has the buyer previously procured?
  • What are the key requirements?
Sign-up to enrich

Decision makers

Connect with the people behind this procurement.

Contact nameJob titlePhone numberWork email
Head of Procurement+44 •••• ••••••
Commercial Director+44 •••• ••••••
Procurement Manager+44 •••• ••••••
Category Lead+44 •••• ••••••
Senior Buyer+44 •••• ••••••
Contracts Manager+44 •••• ••••••

Related topics

Topics related to Cyber Security Project Delivery Partner, ranked by notice volume.

View all topics

Win more public sector contracts

Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.