The Provision of a Managed SIEM and SOC solution
Deadline
23 Oct
23 Oct 2024
Deadline
23 Oct
Managed SIEM and SOC solution for the Irish Blood Transfusion Service
Managed SIEM and SOC solution for the Irish Blood Transfusion Service
Bidder profile
Firms with experience in managed cybersecurity services, particularly in SIEM and SOC solutions, are encouraged to apply.
Risks & flags
- High insurance coverage requirements
- Potential barriers for smaller firms
- Significant contract value commitment
Briefing
AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.
1. At a glance
| Buyer | Irish Blood Transfusion Service |
|---|---|
| Title | The Provision of a Managed SIEM and SOC solution |
| CPV / category | IT & Software / Services |
| Estimated value | not disclosed |
| Per-year (if multi-year) | not stated |
| Procedure type | Open procedure |
| Lots | not stated |
| Location | not stated |
| Contract length | Three (3) Years, with possible extensions |
| Submission deadline | 2024-10-23 11:00:00 |
| Go-live / start | not stated |
2. Scope of Work
The contract involves the provision of a Managed Security Information and Event Management (SIEM) and Security Operations Centre (SOC) solution for the Irish Blood Transfusion Service (IBTS). The contractor will be responsible for monitoring, detecting, and responding to security incidents across IBTS's IT infrastructure. The estimated expenditure for the services is approximately €600,000 over the contract term, although this figure is subject to change based on actual usage.
Key activities include:
- Security Monitoring: Continuous monitoring of security events and incidents across the IBTS network.
- Incident Response: Providing a structured response to security incidents, including investigation and remediation.
- Log Management: Ensuring that logs from various systems are collected and stored for a minimum of 12 months for compliance and investigation purposes.
- Reporting: Regular reporting on security incidents, trends, and compliance with security policies.
- Integration: Integration with existing IT systems and infrastructure, including DNS, email, and internet services, which require a minimum bandwidth of 20mb at each site, with the headquarters currently operating at 100mb.
- Collaboration: Working with IBTS staff to ensure that security policies and procedures are adhered to and that staff are trained in security awareness.
The contractor will also be required to maintain compliance with ISO 27001 or equivalent standards throughout the contract duration.
3. Background & buyer context
The procurement of this managed SIEM and SOC solution aligns with the IBTS's strategic objective to enhance its cybersecurity posture. The decision to issue this tender is driven by the increasing need for robust security measures in response to evolving cyber threats. The IBTS has historically managed its IT security internally but recognizes the need for specialized expertise and resources to effectively monitor and respond to security incidents. This initiative is part of a broader government policy aimed at improving cybersecurity across public sector organizations.
4. Eligibility & selection criteria
Bidders must meet the following eligibility and selection criteria to be considered for evaluation:
- Turnover requirement: Not specified for this tender.
- Insurance:
- Employer’s Liability: €12.7 million for any one claim or series of claims arising out of a single occurrence.
- Public Liability: €6.5 million for any one claim or series of claims arising out of a single occurrence.
- Professional Indemnity: €1 million in the aggregate per insurance year.
- Cyber Security Indemnity: €1 million in the aggregate per insurance year.
- Product Liability: Not specified for this tender.
- Certifications: Tenderers must hold ISO 27001 or equivalent certification and provide evidence of this certification.
- Past experience: Evidence of at least three previous relevant contracts demonstrating technical and professional ability.
- Personnel: Not specified for this tender.
- Geographic / facility constraints: Not specified for this tender.
5. Award criteria & scoring
Bids will be evaluated based on the following criteria:
| Criterion | Weight (%) | Sub-criteria |
|---|---|---|
| SIEM & SOC Proposal | 60 | Product features & functionality, SOC proposal, incident management proposal, implementation approach, relevant experience |
| Service Delivery | 10 | Ongoing service management, methodologies, tools, account management proposals, reporting |
| Cost | 30 | Total costs, including ongoing service charges, implementation costs, additional hardware and software costs |
The evaluation will follow a Most Economically Advantageous Tender (MEAT) approach, with a minimum score required for each qualitative criterion to pass to the next evaluation stage.
6. Submission requirements
Bidders must submit the following documents:
- Method statement / response document: A detailed response following the provided template, with no specified page limit.
- CVs: CVs of key personnel involved in the project, with no specified page count.
- Pricing schedule: Completed using the specified template.
- Case studies: Evidence of three relevant projects, including value ranges.
- Declarations: Including ESPD, Bona Fides, Tax clearance, and Conflict of Interest declarations.
- Mandatory site visit: Not applicable for this tender.
- Submission portal: Tenders must be submitted via the electronic postbox on www.etenders.gov.ie, adhering to specified format rules.
7. Key dates & process
| Key Date | Description |
|---|---|
| 2024-09-05 | RFT issued |
| 2024-09-18 | Clarification deadline |
| 2024-10-14 | Tender deadline (12:00) |
| 2024-10-23 | Expected award |
| 2024-11-01 | Contract start |
| 2024-11-15 | Go-live / mobilisation |
8. Contract terms that matter
Key contract terms include:
- Term: The contract will be for three years, with the option to extend for up to two additional 12-month periods.
- Payment terms: Payments will be made in accordance with the Services Contract, with all prices quoted being all-inclusive and exclusive of VAT.
- Key SLAs/KPIs: Specific service level agreements (SLAs) and key performance indicators (KPIs) will be established to monitor service delivery.
- Termination clauses: Either party may terminate the contract with 14 days' notice if breaches are not remedied within 30 days.
- IP ownership: Not specified for this tender.
- Sub-contracting rules: Subcontractors must be disclosed, and the prime contractor will retain overall responsibility for the contract.
9. Risks, red flags & unusuals
Potential risks and concerns specific to this tender include:
- The requirement for a high level of insurance coverage may limit participation to larger firms with established insurance policies.
- The lack of specified turnover requirements could indicate a preference for established firms, potentially disadvantaging smaller bidders.
- The contract's estimated value of €600,000 over three years suggests a significant commitment, which may deter smaller firms from bidding.
- The absence of a mandatory site visit may limit bidders' understanding of the IBTS's specific needs and infrastructure.
10. SME fit assessment
This tender appears to be open to small and medium-sized enterprises (SMEs) with relevant experience in cybersecurity services. Viable bidders should possess:
- Experience in providing managed SIEM and SOC solutions.
- ISO 27001 or equivalent certification.
- The capacity to handle contracts of significant value, although the absence of a specified turnover requirement may allow for some flexibility.
Consortium arrangements are permitted, allowing smaller firms to collaborate with larger enterprises to meet the tender requirements. The indicative bid preparation effort is estimated at several days, depending on the complexity of the proposal. The presence of established firms in the sector may signal a competitive bidding environment.
11. Where to dig deeper
- Source RFT filename: IBTS_SIEM_SOC RFT and Sample contract..docx
- eTenders CFT ID: not specified
- Contact email: Queries must be directed via the messaging facility on www.etenders.gov.ie.
- Important attachments:
- Appendix 1 — Requirements and Specifications
- Appendix 2 — Pricing Schedule
- Appendix 3 — Tenderer’s Statement
This tender has been awarded
- Ekco Security Limited · 01 May 2025
- Ekco Security Limited · 04 Mar 2025
Can you bid?
Required certifications
- ISO 27001
Public liability insurance
€6,500,000
Professional indemnity insurance
€1,000,000
Scoring
Most Economically Advantageous Tender
Documents (4)
NIS2.docx
170.3 KB · Specification
IBTS_SIEM_SOC RFT and Sample contract..docx
185.8 KB · RFT / Invitation to Tender
IBTSSIEMSOCServices2024Pricing Schedule.xlsx
39.8 KB · Pricing / BOQ / Schedule of Rates
Tender Response Document.xlsx
9.7 KB · Tender Response Template
Original notice text
Provision of a Managed Security Information and Event Management (SIEM) and Security Operations Centre (SOC) solution for the Irish Blood Transfusion Service, focusing on monitoring, incident response, and compliance.
AI analysis updated 4 months ago
Deadline
23 Oct
Location
Not specified
Procedure
Open
Clarification
18 Sep 2024
eTenders ID
4248790
Ask AI
Knows this tender's documents
Example only — sign up to ask about this tender