Notice Information
Notice Title
Threat Intelligence and Digital Risk
Notice Description
National Grid is looking to continue to deliver and enhance their Threat & Risk Management capabilities and ensure the external services utilised are still relevant, providing the most value and strategic partners. Operationally, it's key that National Grid achieve improved service delivery across the areas of security; including Security Operations, Threat Intelligence, Vulnerability Management, and Risk Management teams. It is critical that all services can flex to meet our future needs whilst insuring stability in the current operating environment. The required services, ranging from Threat Intelligence, Vulnerability Management, Digital Risk Management and Third Party Risk will be used to detect and respond to cyber threats and vulnerabilities outside the network perimeter and will enable protection, monitoring, and give early indication of security risks. This must be done according to regulated policies to maintain security of National Grid, its reputation, data, assets and to manage impact of security events affecting our third parties.
Lot Information
Threat Intelligence
A cyber threat intelligence feed including strategic and technical intelligence on threat actors and attack patterns. Intelligence should provide regular reporting to inform the Security team of changes to the threat landscape and new threats. The service must also enable integration with a Threat Intelligence Platform to enable automated actions.
Vulnerability ManagementAn external vulnerability management service that detects vulnerabilities to National Grids externally facing assets through continuous assessment of the digital footprint. Such a service will detect exposed services, open ports, and vulnerabilities. Tactical reporting will enable timely resolution, and the service will enable integration with centralised logging to allow for automated response.
Digital Risk ManagementA digital risk management service will scan open, deep, and dark web resources to identify risks to National Grid. Examples include potential phishing domains, data loss, or credentials. Tactical reporting will enable timely resolution, and the service will enable integration with centralised logging to allow for automated response.
Third Party RiskA focus on third party risk management; this service should provide insight into risks associated with third parties; such as security incidents or data breaches that may have an impact to the security of National Grid.
Notice Details
Publication & Lifecycle
- Open Contracting ID
- ocds-h6vhtk-030f98
- Publication Source
- Find A Tender Service
- Latest Notice
- https://www.find-tender.service.gov.uk/Notice/002303-2022
- Current Stage
- Planning
- All Stages
- Planning
Procurement Classification
- Notice Type
- Planning Notice
- Procurement Type
- Standard
- Procurement Category
- Services
- Procurement Method
- Not Specified
- Procurement Method Details
- Not specified
- Tender Suitability
- Not specified
- Awardee Scale
- Not specified
Common Procurement Vocabulary (CPV)
- CPV Divisions
72 - IT services: consulting, software development, Internet and support
-
- CPV Codes
72000000 - IT services: consulting, software development, Internet and support
Notice Value(s)
- Tender Value
- £1,950,000 £1M-£10M
- Lots Value
- Not specified
- Awards Value
- Not specified
- Contracts Value
- Not specified
Notice Dates
- Publication Date
- 26 Jan 20224 years ago
- Submission Deadline
- 28 Feb 2022Expired
- Future Notice Date
- 30 Mar 2023Expired
- Award Date
- Not specified
- Contract Period
- Not specified - Not specified
- Recurrence
- Not specified
Notice Status
- Tender Status
- Planned
- Lots Status
- Planned
- Awards Status
- Not Specified
- Contracts Status
- Not Specified
Buyer & Supplier
Contracting Authority (Buyer)
- Main Buyer
- NATIONAL GRID UK LIMITED
- Contact Name
- Clive Redington
- Contact Email
- clive.redington@nationalgrid.com
- Contact Phone
- Not specified
Buyer Location
- Locality
- WARWICK
- Postcode
- CV34 6DA
- Post Town
- Coventry
- Country
- England
-
- Major Region (ITL 1)
- TLG West Midlands (England)
- Basic Region (ITL 2)
- TLG1 Herefordshire, Worcestershire and Warwickshire
- Small Region (ITL 3)
- TLG13 Warwickshire CC
- Delivery Location
- Not specified
-
- Local Authority
- Warwick
- Electoral Ward
- Warwick Myton & Heathcote
- Westminster Constituency
- Warwick and Leamington
Further Information
Open Contracting Data Standard (OCDS)
View full OCDS Record for this contracting process
The Open Contracting Data Standard (OCDS) is a framework designed to increase transparency and access to public procurement data in the public sector. It is widely used by governments and organisations worldwide to report on procurement processes and contracts.
{
"tag": [
"compiled"
],
"id": "ocds-h6vhtk-030f98-2022-01-26T13:35:51Z",
"date": "2022-01-26T13:35:51Z",
"ocid": "ocds-h6vhtk-030f98",
"description": "We use the Achilles Utilities Vendor Database (UVDB) when compiling lists of potential suppliers for our goods and services requirements. For the majority of our purchases, it is a condition of supplying to National Grid that suppliers are registered on the UVDB. For more information please visit: https://www.nationalgrid.com/suppliers/new-suppliers",
"initiationType": "tender",
"tender": {
"id": "ocds-h6vhtk-030f98",
"legalBasis": {
"id": "32014L0025",
"scheme": "CELEX"
},
"title": "Threat Intelligence and Digital Risk",
"status": "planned",
"classification": {
"scheme": "CPV",
"id": "72000000",
"description": "IT services: consulting, software development, Internet and support"
},
"mainProcurementCategory": "services",
"description": "National Grid is looking to continue to deliver and enhance their Threat & Risk Management capabilities and ensure the external services utilised are still relevant, providing the most value and strategic partners. Operationally, it's key that National Grid achieve improved service delivery across the areas of security; including Security Operations, Threat Intelligence, Vulnerability Management, and Risk Management teams. It is critical that all services can flex to meet our future needs whilst insuring stability in the current operating environment. The required services, ranging from Threat Intelligence, Vulnerability Management, Digital Risk Management and Third Party Risk will be used to detect and respond to cyber threats and vulnerabilities outside the network perimeter and will enable protection, monitoring, and give early indication of security risks. This must be done according to regulated policies to maintain security of National Grid, its reputation, data, assets and to manage impact of security events affecting our third parties.",
"value": {
"amount": 1950000,
"currency": "GBP"
},
"lotDetails": {
"awardCriteriaDetails": "1. Threat Intelligence 2. Vulnerability Management 3. Digital Risk Management 4. Third Party Risk"
},
"lots": [
{
"id": "1",
"title": "Threat Intelligence",
"description": "A cyber threat intelligence feed including strategic and technical intelligence on threat actors and attack patterns. Intelligence should provide regular reporting to inform the Security team of changes to the threat landscape and new threats. The service must also enable integration with a Threat Intelligence Platform to enable automated actions.",
"status": "planned"
},
{
"id": "2",
"title": "Vulnerability Management",
"description": "An external vulnerability management service that detects vulnerabilities to National Grids externally facing assets through continuous assessment of the digital footprint. Such a service will detect exposed services, open ports, and vulnerabilities. Tactical reporting will enable timely resolution, and the service will enable integration with centralised logging to allow for automated response.",
"status": "planned"
},
{
"id": "3",
"title": "Digital Risk Management",
"description": "A digital risk management service will scan open, deep, and dark web resources to identify risks to National Grid. Examples include potential phishing domains, data loss, or credentials. Tactical reporting will enable timely resolution, and the service will enable integration with centralised logging to allow for automated response.",
"status": "planned"
},
{
"id": "4",
"title": "Third Party Risk",
"description": "A focus on third party risk management; this service should provide insight into risks associated with third parties; such as security incidents or data breaches that may have an impact to the security of National Grid.",
"status": "planned"
}
],
"items": [
{
"id": "1",
"additionalClassifications": [
{
"scheme": "CPV",
"id": "72000000",
"description": "IT services: consulting, software development, Internet and support"
}
],
"deliveryAddresses": [
{
"region": "UK"
},
{
"region": "US"
}
],
"relatedLot": "1"
},
{
"id": "2",
"additionalClassifications": [
{
"scheme": "CPV",
"id": "72000000",
"description": "IT services: consulting, software development, Internet and support"
}
],
"deliveryAddresses": [
{
"region": "UK"
},
{
"region": "US"
}
],
"relatedLot": "2"
},
{
"id": "3",
"additionalClassifications": [
{
"scheme": "CPV",
"id": "72000000",
"description": "IT services: consulting, software development, Internet and support"
}
],
"deliveryAddresses": [
{
"region": "UK"
},
{
"region": "US"
}
],
"relatedLot": "3"
},
{
"id": "4",
"additionalClassifications": [
{
"scheme": "CPV",
"id": "72000000",
"description": "IT services: consulting, software development, Internet and support"
}
],
"deliveryAddresses": [
{
"region": "UK"
},
{
"region": "US"
}
],
"relatedLot": "4"
}
],
"communication": {
"futureNoticeDate": "2023-03-31T00:00:00+01:00"
},
"tenderPeriod": {
"endDate": "2022-02-28"
},
"submissionTerms": {
"languages": [
"en"
]
}
},
"parties": [
{
"id": "GB-FTS-42072",
"name": "NATIONAL GRID UK LIMITED",
"identifier": {
"legalName": "NATIONAL GRID UK LIMITED"
},
"address": {
"streetAddress": "National Grid House, Warwick Technology Park",
"locality": "Warwick",
"region": "UK",
"postalCode": "CV34 6DA",
"countryName": "United Kingdom"
},
"contactPoint": {
"name": "Clive Redington",
"email": "Clive.Redington@nationalgrid.com"
},
"roles": [
"buyer"
],
"details": {
"url": "http://www.nationalgrid.com",
"classifications": [
{
"scheme": "TED_CE_ACTIVITY",
"id": "ELECTRICITY",
"description": "Electricity"
}
]
}
}
],
"buyer": {
"id": "GB-FTS-42072",
"name": "NATIONAL GRID UK LIMITED"
},
"language": "en"
}