This public procurement record has 1 release in its history.

Planning

09 Sep 2026 at 10:45

Summary of the contracting process

Student Loans Company is planning an enhanced security operations managed service for its UK activities. The proposed scope covers six connected requirements: hybrid managed extended detection and response with 24/7 monitoring, security operations, Microsoft Sentinel and SOAR support; weekday vulnerability management; breach attack simulation using AttackIQ or similar; strategic, operational and tactical cyber threat intelligence; a 24/7 digital forensics and incident response retainer; and call-off security architecture and engineering support. Services include incident investigation, threat hunting, detection and control improvement, vulnerability assessment, adversary simulation, forensic analysis, crisis and regulatory support, security design, governance, assurance and reporting. The procurement is for services, classified under IT consulting, software development, internet and support. Delivery is across the United Kingdom.

This procurement is at the planning stage and is not yet an invitation to tender. Student Loans Company is conducting pre-market engagement to inform a retender, with suppliers able to comment on one or all six requirements. The buyer expects a future notice on 7 May 2027. The current agreement is described as expiring in April 2028, and the planned contract period is 14 April 2028 to 30 April 2030, with a possible renewal extending to 30 April 2031. The opportunity is planned as one lot, with renewal rights under consideration. The buyer expects to allow bids for individual requirements or all requirements. The engagement questionnaire is expected to close on 22 October 2026 at 10:00am.

The work is suited to specialist cyber security providers, managed security service operators, incident response firms, threat intelligence specialists, vulnerability management teams, breach and adversary simulation providers, and security architecture consultancies. Relevant preparation includes demonstrating 24/7 security operations, monitoring and incident response capability, or weekday vulnerability services, together with expertise in Microsoft Sentinel, Microsoft Defender for Endpoint, Rapid7, Jira, Power BI and AttackIQ or comparable platforms. Suppliers with digital forensics capability should be able to acquire and preserve evidence and support endpoint, server, network and cloud investigations. Architecture and engineering specialists should cover threat modelling, secure-by-design reviews, control implementation, hardening, governance, risk, audit and third-party assurance. The planned structure may suit SMEs and suppliers wishing to offer a single specialist service or a broader integrated capability.

How relevant is this notice?

Notice Title

Enhanced Security Operations Managed Service

Notice Description

The Student Loans company (SLC) have an agreement for Enhanced Security Operations Managed Service expiring April 2028. In order to provision for a retender of the agreement SLC are undertaking pre-market engagement with regards to the provision of the following: * Requirement A: Enhanced Security Operations Managed Service - MXDR Service (2026-TR-0109a) * Requirement B: Enhanced Security Operations Managed Service - Vulnerability Management (VM) Service (2026-TR-0109b) * Requirement C: Enhanced Security Operations Managed Service - Breach Attack Simulation (BAS) Service (2026-TR-0109c) * Requirement D: Enhanced Security Operations Managed Service - Cyber Threat Intelligence (CTI) Service (2026-TR-0109d) * Requirement E: Enhanced Security Operations Managed Service - Digital Forensics and Incident Response (DFIR) Retainer Service (2026-TR-0109e) * Requirement F: Enhanced Security Operations Managed Service - Security Architecture and Engineering Support Services (2026-TR-0109f) SLC is considering an approach to the market to give the suppliers an option to bid for one or ALL of the contractual requirements. Requirement A Enhanced Security Operations Managed Service - MXDR Service The Supplier will provide a Managed Extended Detection and Response (MXDR) capability operating on a hybrid customer/supplier model. MXDR Service The Supplier will provide: * 24x7x365 monitoring of SLC security telemetry. * L1 and L2 Security Operations Centre capability (SLC retain L3). * Incident identification, triage and investigation. * Security use-case monitoring and tuning. * Management of Microsoft Sentinel detections. * SOAR playbook execution and optimisation. * Escalation management. * Alert enrichment. * Threat hunting capability. * Malicious activity investigation. * Service governance and performance management. * Security reporting at operational, tactical and strategic levels. Security Engineering (Operational) The Supplier shall provide: * L3 Engineering support for Sentinel. * Analytics rule development and tuning. * SOAR playbook management. * Connector maintenance and health monitoring. * Logging optimisation. * Onboarding and validation of agreed log sources. * Detection engineering support. * Detection gap analysis and monitoring coverage reviews. * Security use case development and continuous improvement. * Monitoring health checks. * Monitoring and remediation of ingestion issues. * Security platform optimisation. * Proactive automation support and development. * Threat intelligence-led detection improvements. Data Loss Prevention (DLP) & Phishing The Supplier shall: * Monitoring, triage and investigation of DLP, phishing, business email compromise (BEC), malicious email, malicious attachment and malicious URL alerts. * Investigation of suspected data loss, data exfiltration and policy breach events. * Support for user reported phishing submissions. * Escalation and coordination of confirmed incidents in accordance with agreed response procedures. * Identification and analysis of phishing campaigns, attacker infrastructure, indicators of compromise and emerging attack trends. * Recommendations for improvements to DLP policies, email security controls, detections and response processes. * Monthly reporting, trend analysis and security improvement recommendations. Reporting The Supplier shall provide: * Weekly operational reports. * Monthly service reports. * Quarterly service reviews. * KPI and SLA reporting. * Security metrics and trend analysis. Requirement B Enhanced Security Operations Managed Service - Vulnerability Management Service The Supplier shall provide Vulnerability Management services Monday to Friday, UK Core Hours (09:00-17:00). Vulnerability Management The Supplier shall: * Monitor vulnerability management queues. * Investigate vulnerability notifications. * Manage vulnerability triage. * Validate vulnerability findings. * Perform exploitability assessments. * Provide remediation recommendations. * Support exposure management activities. * Support CTEM activities. Stakeholder Engagement The Supplier shall: * Conduct monthly technical review meetings. * Support resolver teams. * Assist remediation planning. * Review remediation performance. * Provide vulnerability prioritisation guidance. Dashboarding & Reporting The Supplier shall: * Maintain executive dashboards. * Enhance Power BI reporting. * Produce technical reports. * Produce executive reports. * Produce PCI compliance reports. * Produce risk trending reports. Tooling The Supplier shall support: * Microsoft Defender for Endpoint. * Rapid7. * SLC PCI ASV Scanning tooling. * Jira. * Power BI. Requirement C Enhanced Security Operations Managed Service - Breach Attack Simulation Service The Supplier shall provide a Breach Attack Simulation (BAS) capability, currently using AttackIQ or similar. BAS Service The Supplier shall: * Operate and maintain the BAS platform. * Deploy and maintain BAS agents. * Configure integrations. * Execute scheduled simulations. * Execute customer-specific simulations. * Execute retests following remediation activities. Adversary Simulation Testing scenarios shall include: * Initial Access. * Execution. * Persistence. * Privilege Escalation. * Credential Access. * Lateral Movement. * Command and Control. * Exfiltration. * Malware. * Ransomware. * Advanced Persistent Threat activity. Security Validation The Supplier shall assess: * Security control effectiveness. * Security monitoring effectiveness. * Detection coverage. * Response capability. * Incident handling. * Use-case effectiveness. Reporting The Supplier shall produce: * Monthly BAS reports. * Executive summaries. * Technical findings. * Remediation recommendations. * Retest outcomes. Requirement D Enhanced Security Operations Managed Service - Cyber Threat Intelligence Service The Supplier shall provide strategic, operational and tactical Cyber Threat Intelligence services. Threat Intelligence Managed Service The Supplier shall provide: * Threat Intelligence reporting. * Integration into Microsoft Sentinel. * Indicator of Compromise feeds. * Threat actor intelligence. Operational Intelligence The Supplier shall provide: * Threat alerts. * Vulnerability intelligence. * Emerging threat notifications. * Campaign tracking. * Industry specific intelligence. Strategic Intelligence The Supplier shall provide: * Threat landscape assessments. * Quarterly threat reports. * Executive intelligence briefings. * Board level threat summaries. * Sector specific threat reporting. Security Operations Support The Supplier shall provide: * Intelligence support during incidents. * Threat hunting support. * Intelligence driven use-case creation. * Intelligence enrichment services. Requirement E Enhanced Security Operations Managed Service - Digital Forensics & Incident Response Retainer Service The Supplier shall provide a DFIR Retainer available 24x7x365. Cyber Incident Response The Supplier shall provide: * Incident investigation. * Malware analysis. * Threat containment. * Threat eradication. * Recovery support. * Crisis management support. * Regulator support. * On-site support Digital Forensics The Supplier shall provide: * Evidence acquisition. * Chain of custody management. * Endpoint forensics. * Server forensics. * Network forensics. * Cloud forensics. * Forensic reporting. Readiness Services The Supplier shall provide access to: * Tabletop exercises. * Incident simulations. * Executive workshops. * CSIRT training. * Lessons learned reviews. Retained Consultancy The Supplier shall provide specialist support including: * Security strategy input. * Audit support. * Major incident reviews. * Regulatory engagement support. * Ransomware negotiation services. Requirement F Enhanced Security Operations Managed Service - Security Architecture & Engineering Support Services The Supplier shall provide specialist Security Architecture and Engineering services on a call-off basis. Security Architecture The Supplier shall provide: * Security architecture reviews. * Security design authority support. * Secure by Design reviews. * Solution security reviews. * Threat modelling. * Architecture governance. * Security requirements definition. * Architectural risk assessments. Security Engineering The Supplier shall provide: * Technical security engineering. * Security tool implementation. * Security configuration reviews. * Security hardening activities. * Technical control implementation. Strategy & Transformation The Supplier shall provide: * Security roadmap development. * Target operating model development. * Control framework assessments. * Security maturity reviews. * Improvement planning. Governance & Assurance The Supplier shall provide: * Security assessments. * Risk management support. * Audit support. * KPI development. * Board reporting support. * Security governance support. * Independent design and control assurance. * Security exception and risk acceptance reviews. * Third party and supplier security assessments.

Planning Information

All communication regarding this questionnaire shall take place via Delta E Sourcing and must state the appropriate contract reference number (2026-TR-0109) in all instances. Your sole contact for the purposes of this questionnaire is: Contact: Kenneth McKay Title: Commercial Manager Email: Kenneth_mckay@slc.co.uk Responses to this questionnaire must be submitted via Delta Esourcing Access Code: 96G7G98ZY3 End date: 22/10/2026 10:00am.

Publication & Lifecycle

Open Contracting ID
ocds-h6vhtk-06f556
Publication Source
Find A Tender Service
Latest Notice
https://www.find-tender.service.gov.uk/Notice/085261-2026
Current Stage
Planning
All Stages
Planning

Procurement Classification

Notice Type
UK2 - Preliminary Market Engagement Notice
Procurement Type
Standard
Procurement Category
Services
Procurement Method
Not Specified
Procurement Method Details
Not specified
Tender Suitability
SME
Awardee Scale
Not specified

Common Procurement Vocabulary (CPV)

CPV Divisions

72 - IT services: consulting, software development, Internet and support


CPV Codes

72000000 - IT services: consulting, software development, Internet and support

Notice Value(s)

Tender Value
Not specified
Lots Value
Not specified
Awards Value
Not specified
Contracts Value
Not specified

Notice Dates

Publication Date
9 Sep 20261 weeks ago
Submission Deadline
Not specified
Future Notice Date
7 May 20278 months to go
Award Date
Not specified
Contract Period
14 Apr 2028 - 30 Apr 2030 2-3 years
Recurrence
Not specified

Notice Status

Tender Status
Planning
Lots Status
Planning
Awards Status
Not Specified
Contracts Status
Not Specified

Contracting Authority (Buyer)

Main Buyer
Student Loans Company
Contact Name
Available with D3 Tenders Premium →
Contact Email
Available with D3 Tenders Premium →
Contact Phone
Available with D3 Tenders Premium →

Buyer Location

Locality
DARLINGTON
Postcode
DL1 1RW
Postcode Area
Darlington
Country
England

Major Region (ITL 1)
TLC North East (England)
Basic Region (ITL 2)
TLC3 Tees Valley
Small Region (ITL 3)
TLC33 Darlington
Delivery Location
Not specified

Local Authority
Darlington
Electoral Ward
Red Hall & Lingfield
Westminster Constituency
Darlington

Further Information

Notice Documents

Open Contracting Data Standard (OCDS)

View full OCDS Record for this contracting process

JSON Markdown

The Open Contracting Data Standard (OCDS) is a framework designed to increase transparency and access to public procurement data in the public sector. It is widely used by governments and organisations worldwide to report on procurement processes and contracts.

Loading OCDS record...