Cyber Security and Resilience in the Supply Chain
Details
- Value
- GBP 500,000
- Published
- 29 April 2021
- Submission
- 13 May 2021
- Source
- uk:digital_marketplace
Tender description
Summary of the work This project will examine and enhance the NDA Group’s capability to manage cyber risk and ensure resilience with its supply chain, in an increasingly complex ecosystem of 3rd party system and service delivery and operations. Expected Contract Length The contract length will be up to 12 months. Latest start date Wednesday 26 May 2021 Budget Range Up to £500k for the initial phase of work. Why the Work is Being Done The NDA is 3 years into a Cyber Security and Resilience Programme implementing change across 7 businesses. A key goal is to ensure a secure and resilient supply chain, therefore this project will examine and enhance the NDA Group’s capability to manage cyber risk and retain resilience within its supply chain, in an increasingly complex ecosystem of 3rd party system and service delivery and operations. Strengthening, harmonising and ideally standardising approaches across the group is key. There will be an initial one year’s work to create the strategy and approach, and potentially two additional years’ work to rollout the design. Problem to Be Solved Securing the supply chain effectively is hard because vulnerabilities can be inherent, or introduced and exploited at any point in the supply chain. Key stakeholders include security, commercial and supplier teams. A series of global, high profile, damaging attacks on organisations has demonstrated that attackers have both the intent and ability to exploit vulnerabilities in supply chain security. The NDA Group comprises various businesses increasingly coming together under a group approach, whilst still legally accountable to the Office of Nuclear Regulation (ONR). Therefore, an approach is needed that is risk-based, efficient, collaborative and addresses current and future threats. Who Are the Users As a CISO I need to be confident that our policies, processes and guidance for procurement and supply chain management are effective at highlighting any security concerns and ensuring that security risks are identified and mitigated accordingly as part of our secure-by-default approach and security culture. This will limit vulnerability to cyber threats and ensure readiness to handle any incidents that do occur. As a procurement manager I need clear policies, processes and guidance ensure compliance and allow effective management of all risks, including security risks, whilst still ensuring innovation and value for money. Work Already Done A CSRP operations plan for 2021-22 has drafted for this project to create a community of interest, to assess current level of capability, to facilitate a common strategy, to facilitate enhanced supply chain security measures and to create a supply chain mapping of dependency and risk. An initial strategy is needed by end of Q2. Outside of CSRP, but still within the NDA, there is also an active Contract Security Working Group, a Supply Chain Forum, a supply chain assurance function and a significant commercial project (‘Project Victory’) to enhance commercial IT systems and supply chain risk management. Existing Team The supplier will work as part of the CSRP team, which is made up of a combination of NDA staff, contractors and other suppliers that are responsible for CSRP related services. The supplier may encounter other suppliers as they engage with NDA businesses, who have their own support teams and security services in place. The supplier will work with the forums and working groups described above, as well as all the NDA businesses. Current Phase Discovery Skills & Experience • Capability to create/enhance a Community of Interest between all stakeholders in supply chain(SC) security and their initiatives to address SC cyber security, to facilitate an effective, holistic and coordinated approach. • Capability to assess the current level of capability/capacity and performance of cyber security/resilience in the SC, with links to the current Target Operating Model (NIST CSF) and Risk Assessment approaches/tooling. • Capability to facilitate a common SC security strategy and implementation plan, with interventions, recommendations to deliver ‘quick wins’ and highlight opportunities. This will enhance the group cyber security strategy. • Capability to facilitate, document and support the implementation of enhanced SC security policies and associated best practice measures consistent with the NDA ecosystem and the dynamic threat environment. • Capability to create a SC mapping of level of security dependency (or impact of breach) versus maturity of security measures in place, in order to provide a SC risk dashboard. • Capability to recommend appropriate digital solutions based on experience. • Experience in creating improved security and resilience through effective observation and control of security risks and management of security operations between companies and suppliers. • Experience delivering improved (measurable) effectiveness/efficiency through the implementation of a standardised approach to applying security requirements and operational arrangements in relevant contracts at the start of the procurement cycle (Service/Systems) • Experience creating improved relationships and communication between the companies and its supply chain through the sharing of transparent policies and procedures and educating stakeholders on supply chain threats. • Ability to deliver an Agile project, using relevant programme tools ( eg AgiliePgM personal ) Sy SFIA skills • Utilise inhouse personnel and not subcontracting the work out. Nice to Haves • Experience in NDA/ONR/MOD(DCPP)/other CNI environments • Reference library of relevant supplier security documentation Work Location Whitehaven, Cumbria. Some meetings may take place at various other NDA sites. Working Arrangments Whilst Covid restrictions limit contact in the near term, allowing the supplier to work remotely during early phases, the intent is for the Supply Chain project to be run from Whitehaven, Cumbria, with a mix of onsite and remote working. The supplier PM and key personnel will be expected to be routinely available with daily stand-ups by conference call. Online communication is inevitable given the geographic spread of NDA sites. Expenses will be as per the NDA policy and all travel will be authorised by the NDA point of contact. Security Clearance BPSS minimum (or equivalent) and personnel may need to go through additional NDA clearance checks. No. of Suppliers to Evaluate 3 Proposal Criteria • Ability to meet timeframe • Experience in creating and delivering other supplier and supply chain security projects and solutions • Approach to project and task management, including a risk-based approach given that the NDA Group uses >5000 suppliers directly a year and spends ~£1.9bn/yr through suppliers • Value for money (including transparency of costs) Cultural Fit Criteria • Demonstrate the ability to work within a wider cyber programme as demonstrated by previous case studies • Demonstrate the ability to focus on the outcome of the work, not the specifics of their technical capability • Demonstrate the ability to work collaboratively to co-develop approaches that get buy-in from stakeholders across the NDA Group • Demonstrate a willingness to share wider knowledge and experience • Demonstrate a willingness to take responsibility Payment Approach Capped time and materials Assessment Method • Case study • Presentation Evaluation Weighting Technical competence 60% Cultural fit 20% Price 20% Questions from Suppliers 1. Question 1As an SME, we regularly use trusted subcontractors to deliver specific requirements. Does your final essential point rule out this way of working? Question 1In order to meet the requirements of this project, speed of delivery and continuity of service will be crucial. As such, we require all bidders to manage the requirement without subcontracting any elements out. 2. Question 2Can the Authority please confirm whether there is an incumbent supplier? This is a new requirement and there is no incumbent in place. 3. Question 3Can the Authority please confirm whether this opportunity is assessed as inside or outside of IR35? We have not undertaken an IR35 assessment as this is a contract between the NDA & contracted organisation. It’s not normal practice to undertake assessments at our end for this type of procurement. We have not undertaken an IR35 assessment as this is a supplier contract between the NDA and the contracting organisation, therefore an IR35 assessment is not required as it would be as an agency supplied worker contract. 4. Question 4Can more information be provided on the amount of time (frequency and duration) that is expected to be spent on client site? At present we are following government guidelines and working remotely. In time, the business is looking to have a flexible resource model with limited expectation to be on site on a day to day basis. With this in mind, it's expected that the requirements will be able to be met with a blend of on site and remote, in line with NDA's expenses policy. 5. Question 5Would you accept a DBS security clearance for this role? No, we require BPSS minimum and SC for some activities. 6. Question 6Please can you clarify is the requirement “Utilise inhouse personnel and not subcontracting the work out.” Relates to the supplier not using sub-contractors, or an ask to demonstrate upskilling of client staff so to not need sub-contractors going forward? As per question 1, this relates to the supplier having their own dedicated suitably qualified experienced people to undertake the work. 7. Question 7The requirements state an initial strategy is required by the end of Q2. Can you please confirm what date this is? We are unable to confirm the exact date as progress will be dependant on variables such as SC clearances, operating company availability and the workshop planning which needs to be detailed. Please note that 'end of Q2' relates to financial year (September) 8. Question 8For opportunities such as these we would usually submit a joint proposal with a partner who has specialist experience in supply chain security. We would therefore like to submit a joint proposal, using inhouse personnel, without subcontracting outside of these two teams. Would this be compatible with your requirement to use inhouse personnel? We are looking to engage with a single specialist organisation with the requisit skills for this project. 9. Question 9How many of the >5000 suppliers would need to go through the process within the 12 month period? To be further detailed - will will adopt a risk based sample approach selecting suppliers of various different sizes, functions and risk profile reflective of risk to posed to the operating companies in the NDA Group (could be circa 50 suppliers). 10. Question 10What toolsets have been tried and rejected in the NDA’s previous attempts to resolve the issues? We have yet to trial any toolsets for this requirement. 11. Question 11What are the contractual obligations placed on the supplier currently regarding security, and/or are contracts expected to enforce the required behaviours? As an NDPB we reflect HMG & ONR's requirments for the managemt and handling of information including Sensitive Nuclear Information. Many suppliers hold cyber essentials or cyber essentials plus and there is a reqirement for suppliers to comply with security aspects letters. Sub contractors are routinely subject to security audits. 12. Question 12What current techniques are used to measure and document a supplier’s security status? Our assurance processes are in line with the office of nuclear regulation(ONR). 13. Question 13We’re an SME who uses trusted associates to help deliver some of our government projects. Are we precluded from this opportunity because of your requirement to use inhouse personnel? This would seem to prevent most SMEs from applying for this opportunity. No, no one is precluded. Our expectation however is that the supplier would have the capability and capacity available to deliver the requirements without the need to sub-contract to third parties. 14. Question 14Regarding the written proposal submission: Please detail how, when, and in what format you want the proposal to be submitted. Please also detail any limitations or key requirements we need to be aware of when creating or submitting the proposal. Finally, please confirm our assumption that the case study and presentation will only be required upon selection to proceed to the next phase. We require a written proposal (of a maximum of 10 pages). The proposal should meet the requirements stated in the Operating Plan 2021/2022 document. Bidders may also provide case studies (maximum 3 pages per case study) to demonstrate capability. The final down selection will then be based upon a presentation/technical demonstration. 15. Question 15Can you confirm the number of team members you are expecting? No, we would like the successful bidder to determine the team to meet the requirements. 16. Question 16Will expenses be allowable, in addition to the £500k budget? Expenses would be in addition to the £500k budget and would be in line with the NDA expenses policy. 17. Question 17Can you confirm the initial 12 months of the contract is just for writing and producing policies and procedures or will there also be a requirement to discover what is currently being followed and to audit the supply chain compliancy to security controls? As per question 9. 18. Question 18Can you please advise how many supplier staff you expect to be working on-site in Cumbria? As per question 4. 19. Question 19From reading your guidance we assume that this opportunity is for the initial 12 month project focused on strategy and approach. Please could you confirm if this is correct. Yes this requirement predominantly focusses on strategy and approach but also the demonstration of the methodology. Future phases of work sit outside of the existing scope and will be subject to a further procurement. 20. Question 20Does this initial project also require the Supplier to help NDA to ‘build’ its future state capability (i.e. select and configure technology solution(s) and train team members for agreed roles)? Or is the initial phase focused entirely on the design with build / implement being picked up as part of a future phase (beyond the initial 12 months)? This project includes the training of team members for agreed roles (pilot likely to start in NDA Corporate Centre for circa 10 people). 21. Question 21One of the essential skills and experience is: “Capability to create a SC mapping of level of security dependency (or impact of breach) versus maturity of security measures in place, in order to provide a SC risk dashboard.” Can we confirm that you are looking for evidence of capability as opposed to requiring this activity to be performed during the initial 12 month phase, which we currently understand to be more about strategy and approach as opposed to execution? We can confirm we are looking for evidence of the capability - evidence should be demonstrated through execution/piloting of activity. 22. Question 22Can you confirm whether NDA requires the supplier to support in establishing visibility into the NDA supply chain as part of this initial phase of work, or whether this is something the NDA has already done, or whether the actual illumination of NDA’s supply chain would be part of a future phase of work? We can confirm the NDA requires the supplier to establish visibility into the supply chain as part of this project. 23. Question 23Can you confirm whether you are looking for an Engagement Team to work collaboratively with the CSRP team to deliver specific outcomes to NDA, or whether you are looking for a specific individual (or individuals) to embed themselves within the CSRP team and use their experience to contribute to CSRP team objectives under the direction of the CSRP team leadership? We are looking for an engagement team to deliver specific outcomes in line with the project requirements. However it should be noted CSRP is a complex programme delivered in an agile way and therefore the resources will need to take direction from the CSRP team. The resources will not be able to operate in isolation as they will need to align with the CSRP master schedule and those of the Operating Companies within the Group. 24. Question 24You mention that as part of the CSRP operations plan 2021-22, an initial strategy is needed by the end of Q2. Can you confirm the specific date that Q2 ends (i.e. is it 30 Jun 2021) and how this milestone relates to the broader 12 month objective for this initial phase of work? As per question 7. Q2 is financial year. 25. Question 25Does this initial phase of work require the supplier to perform a current state assessment of existing capability, or will this be done separately by the CSRP and provided as an input to the supplier? Yes we would expect the current state assessment of existing capability to be carried out during the initial phase of the project. 26. Question 26Are there any programme related milestones that the supplier would need to be aware of and build into the programme plan? Yes there are, these will be provided to the successful bidder to finalise the project schedule upon contract award. 27. Question 27How many of the following outcomes drafted in the CSRP Operations plan for 2021-2022 are you looking to achieve in this initial phase? 1. To create a community of interest to assess current level of capability, 2. To facilitate a common strategy, 3. To facilitate enhanced supply chain security measures; and 4.To create a supply chain mapping of dependency and risk. We are looking to achieve each of these outcomes in this initial phase. 28. Question 28Are there any other specific deliverables you are looking to get out of this initial phase of work (12 months)? As well as the outcomes found in question 27 we would also require a project implementation plan, an activity schedule, a risks assumptions risks dependencies log, workshop schedule and other standard project management documents. 29. Question 29Who will be responsible for the sign off of project deliverables between the CSRP team, contract Security Working Group, Supply Chain Forum, supply chain assurance function and Commercial? Head of CSRP programme is responsible for sign off - demonstration of successful stakeholder engagement will be required prior to approval. 30. Question 30Are you able to expand on scope of stakeholders for this programme/CoI – presuming this is NDA Group and each operating companies? The stakeholders for this project are multiple however the main focus will be the NDA CSRP team and each of the operating companies within the Group. 31. Question 31Do NDA and each OpCo currently have SC security policies and processes in place? If so, are you able to define their current maturity? Yes there are existing policies and processes in place with varying levels of maturity (these can't be shared at this stage), one of the desired outcomes will be to standardise these documents aligning all Operating Companies to a minimum level of good practice. 32. Question 32Is there any expectation for practices to be defined at Group level only? The practices will need to be defined at the Group level and then implemented within each of the operating companies. 33. Question 33To be clear on digital solutions, is this referring to TPRM solutions? Does NDA utilise any GRC-based platforms at the moment also? NDA will be rolling out a GRC tooling capability during this FY scheduled to commence in July. 34. Question 34Please can you explain further expectations for this response – ‘Reference library of relevant supplier security documentation’? Alignment with such things as the NCSC's CAF, and the ONR's SYAPS and good industry practice 35. Question 35Do you have an technical-solution to support this? Please name it? If not, would you include solution in initial phase? There isn't currently a solution in place but there is the potential to use the GRC tooling solution that is being implemented as part of the CSRP programme. 36. Question 36Do you have a team structure defined for this work, could you outline/share? No, this is to be defined by the bidder. 37. Question 37Have you established a prioritisation approach for your suppliers. Please describe? No, establishing the prioritisation is part of the requirements for this project - note it should be risk based. 38. Question 38Have you categorised suppliers in any way already? Please describe Not specifically. However, we recognise different suppliers pose different risk eg suppliers that have to process sensitive nuclear information potentially have a higher risk and therefore would be expected to have a higher level of security capability. 39. Question 39Have you established milestones/targets for the first phase? Please outline? We have an indicative plan which is detailed in the operations plan, however it is not in line with current timescales. 40. Question 40Would you expect the project team on-site in Cumbria? 2 days/week or 5 days/week typically? As per question 4. 41. Question 41The current phase is ‘discovery’, can you confirm if this is the phase of required work, or the stage of procurement? We can confirm that this is the required phase of work. 42. Question 42What do you see the digital solution providing in the context of the programme objectives? For example, is it to manage the third party lifecycle (planning, due diligence and control assessments, contracting and onboarding, ongoing monitoring and termination), provide dashboarding and reporting, host third party inventory; Or Specifically cyber security related – utilising external cyber security ratings providers? We are looking for the organisation that we contract with to advise us on the digital solution. It is likely to be be either the implementation of a COTS system (customised to a limited extent) or a bespoke digital solution for the NDA and the operating companies in the group to use. We are not looking to outsource the third party lifecycle however we expect to be able to train the commercial teams and security teams in the use of the tool & subsequently advise on supply chain risk and report on maturity throughout a product or service lifecycle. 43. Question 43Is there a preference on the format of our RFP response – PowerPoint, word or another? As per question 14. 44. Question 44Will clarification questions from all applications be shared to all bidding parties? Yes, as per DOS guidelines. 45. Question 45When will bidders be made aware whether they have been shortlisted? This will be dependent on the number of bids we receive, as an estimate you should receive feedback within 3 weeks of the submission deadline. 46. Question 46Will you accept sub-contractors as part of the submission? As per question 1. 47. Question 47Do all the team need to be located in the UK or can we use some of our European colleagues to support the programme? The support required will have to meet security criteria rather than location criteria, it should be noted overseas residence has additional security complexities to negotiate and the issue of NDA equipment that maybe required to undertake tasks can also be problematic. The NDA will take a risk based approach in assessing suitability.
Timeline
- Completed: Tender published29 April 2021Current notice
- Completed: Submission date13 May 2021
About the buyer
Nuclear Decommissioning Authority (NDA) is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov |
Related topics
Topics related to Cyber Security and Resilience in the Supply Chain, ranked by notice volume.
- 5,186£736.1bn
- 1,745£636.1bn
- 11,175£1.0tn
- 26,970£1.7tn
- 4,088£269.5bn
Related buyers
Buyers similar to Nuclear Decommissioning Authority (NDA).
- 1,661£204.4bn
- 441£232.8m
- 358£99.4m
- 349£15.0bn
- 288£2.8bn
- 255£16.6bn
- 240£507.0m
- 201£1.0bn
- 113£59.4m
- 96£936.8m
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
