Awarded contract

Cyber Risk Support

Details

Value
GBP 772,536
Published
12 December 2022

Tender description

Summary of the work The Cyber Resilience Programme, in support of Navy Digital and HMNBC require the delivery of outcomes to support 4 work-streams to baseline and reduce cyber risk at HMNBC. Expected Contract Length 6 Months Latest start date Monday 31 October 2022 Budget Range Budget range - Not to exceed £790,000 ex VAT (proposed costs are to include T&S allowance) Why the Work is Being Done The Cyber Resilience Programme (CRP) is investing in opportunities to reduce cyber risk across Defence. The delivery of these Secure@Reach (S@R) workstreams will reduce MOD’s cyber risk exposure by targeting of key areas at the site and implementing a series of high-impact improvement activities. RN Cyber Risk and HMNBC seek to support the existing programme of cyber security by delivering a number of outcomes across a range of areas of cyber security. Problem to Be Solved To provide and deliver outcomes against a portfolio of work-streams at the naval base in support of the management of cyber risk. The work-streams covered are listed below: a. Governance – Updating the governance structure in line with organisational changes to manage cross-cutting security risks relating to HMNBC. b. Foundations – Identify opportunities for improvements in data transfer on and off systems whilst maintain security outcomes. c. Military Automation & Controls Systems (MACS) – Mapping of the connected landscape at HMNBC and plan for consistent implementation of controls. d. Assess the cyber security risk of systems and if required identify and deliver mitigations to manage identified risks. e. Behaviours – Testing of adoption of cyber awareness at HMNBC and development of behavioural intervention plan. Who Are the Users The users are Royal Navy personnel, Royal Marines, civil servants and contractors across HMNBC. The users are required to use a range of ICT to access, process, store and generate information in support of their business function and objectives. The users need compliant, secure and assured services to provide information to undertake their business function. Early Market Engagement Not Applicable Work Already Done An existing programme of Cyber Security exists both at the site and across MOD. Existing Team The supplier will work with the existing HMNBC Cyber team and Navy Digital Cyber PM. Engagement with people from other teams is essential. Current Phase Discovery Skills & Experience • At least 5 years experience working in MOD or a similar organisation in Cyber defence/assurance roles. • Evidence of working with MOD or a similar organisation on CIS projects and knowledge of JSP440 and JSP604. • Evidence of understanding and experience of MOD or a similar organisation's accreditation and other processes. • Evidence of understandings and experience in Cyber projects and providing external guidance and SQEP support to improve governance, processes and practices. • Evidence of understanding and experience in mapping and assessing CIS and operation technology against relevant Cyber security frameworks. • Evidence of understanding and experience in assessing Cyber behaviours and implementing a Cyber behaviours improvement plan. • Ability to communicate effectively and justify findings with impartial / balanced recommendations using evidence-based arguments. • Demonstrate ability to analyse and interpret complex information and deliver complex problem solutions. Nice to Haves • Evidence of working collaboratively and taking responsibility for the tasks in hand to deliver service outcomes. • Evidence of understanding and experience in business analysis on MOD or similar organisation CIS projects. Work Location HMNB Clyde, Helensburgh, Argyll & Bute. Defence Digital (MOD Corsham). SDA (MOD Abbey Wood) as well as remotely using MOD provided IT. Working Arrangments The supplier is expected to work collaboratively with the existing HMNBC Cyber team attending face to face meetings as required. It is expected that the supplier will be able to work under own initiative once tasked and attend relevant MOD locations as required to deliver service outcomes. Security Clearance The majority of resources must have DV clearance. SC clearance will be considered if niche skills are only available with SC. Clearance must be held prior to the contract award date - evidence of validity is required. Additional T&Cs All expenses must be pre-agreed between the parties and must comply with the MOD Travel and Subsistence (T&S) Policy. Suppliers must use the Authority’s Purchase to Payment Tool CP&F or be prepared to sign up to the tool. In accordance with DEFCON 658 a Cyber risk assessment has been undertaken. Risk Assessment Ref: RAR-624023508 Cyber risk profile: Moderate Potential bidders are required to complete a Supplier Assurance Questionnaire (SAQ) against the security controls appropriate to the risk level. Tenderers should complete their SAQ using the form in the following link: https://forms.office.com/Pages/ResponsePage.aspx?id=7WB3vlNZS0iuldChbfoJ5Tv4OR9pb0BHial1Ag-WKXVUOFk3Sk9SS0JDQ0FRWjhYNDhTVldHUDJaNy4u No. of Suppliers to Evaluate 3 Proposal Criteria • Describe your approach to meet the requirement and user needs. How you’ll manage the work and maintain quality. Describe any innovations you would propose in delivery - 10% • Describe How your approach and methodology to the requirement align with the essential skills and experience criteria - 10% • Provide the team structure, a list of their roles and responsibilities and how they’ll work together and with others - 10% • Provide CV's for the proposed team and their relevant qualifications - 0% • Describe how you will provide your understanding and experience in mapping and assessing CIS and operation technology against relevant Cyber security frameworks to support the requirement - 10% • Describe how you will provide your understanding and experience in assessing Cyber behaviours to implement a Cyber behaviours improvement plan for the requirement - 10% • Describe how you intend to provide external guidance and SQEP support to improve governance, processes and practices for the requirement - 10% Cultural Fit Criteria • Able to communicate effectively with staff, technical SMEs and senior management to identify pragmatic solutions to problems - 2.5% • Suppliers must demonstrate an ability and willingness to work collaboratively within a multi stakeholder environment to achieve outcomes - 2.5 • Recent proven experience of an open, transparent, and collaborative working relationship at all levels with excellent communication skills - 2.5% • Take responsibility for their work and outcomes - 2.5% • Social Value - Demonstrate the companies’ approach to Support educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications - 5% • Social Value - Demonstrate the companies’ approach to delivering additional environmental benefits in the performance of the contract, including working towards net zero greenhouse gas emissions - 2.5% • Social Value - Demonstrate action to identify and tackle inequality in employment, skills and pay in the contract workforce - 2.5% Payment Approach Fixed price Evaluation Weighting Technical competence 60% Cultural fit 20% Price 20% Questions from Suppliers 1. Is there a current incumbent? There is no incumbent supplier for the service. 2. Is the existing team, an external contractor, or is this a new task on which no one else has worked? The existing team support are internal staff from the HMNBC Cyber team, Navy Digital Cyber PM and internal MOD teams. The requirement covers a new service which has no incumbent supplier support. 3. Is there a current incumbent for this requirement? There is no incumbent supplier for the service. 4. Will the work take place at all 3 locations and if so how often will workers have to be on each site? The primary location for delivery of the work will be HMNB Clyde. Delivery will be outcome based where potential visits to the other sites may be necessary to achieve completion. 5. Is there really 0% for the following question?‘Provide CV’s for the proposed team and their relevant qualifications – 0%’ The submission of CV's will form part of the stage 2 evaluation evidence. 0% is correct, as the information will be used for reference purposes and will not form part of the weighted evaluation score. Skills and experience are covered in other parts of the marking criteria. 6. 07/09/22: Is there any guidance as to the amount of work which can be completed remotely and how much physical presence will be needed (given as a percentage) between:ScotlandAbbeywoodCorsham The work is to be delivered as determined by the expertise of the successful contractor. There are some principles which may help to determine the balance of remote vs onsite working. - Planning and write up activities could be undertaken remotely although consideration to classification should be considered. Use of MOD systems for write up could be accessed from other sites. - Establishing relationships and interaction of systems are activities most likely to require on-site presence this would be predominantly HMNB Clyde. 7. Can any information be provided regarding the contracting terms of the opportunity and which framework will be used? The contract will be produced through the Digital Outcomes and Specialists 5 (DOS5) terms and conditions. Details on the T&C's and framework can be accessed through the following site - https://www.gov.uk/guidance/digital-outcomes-and-specialists-5-legal-documents 8. The DOS5 Framework, do the terms and conditions for the framework contain any reference to who would own the IP for any creative material, such as Detection Rules and UC / Playbooks. Does the customer have a preference? Details covering the Authorities rights in the creation of new IPR through the course of contract delivery are covered under the DOS5 call off schedules (Schedule 6).

Timeline

  1. Completed: Award published12 December 2022
    Current notice
  2. Completed: Award date12 December 2022

About the buyer

Ministry of Defence is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.

AI insights

  • Is there a preferred supplier?
  • What are the buyers pain points?
  • What has the buyer previously procured?
  • What are the key requirements?
Sign-up to enrich

Decision makers

Connect with the people behind this procurement.

Contact nameJob titlePhone numberWork email
Head of Procurement+44 •••• ••••••
Commercial Director+44 •••• ••••••
Procurement Manager+44 •••• ••••••
Category Lead+44 •••• ••••••
Senior Buyer+44 •••• ••••••
Contracts Manager+44 •••• ••••••

Win more public sector contracts

Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.