Managed Extended Detection and Response Services
Value
€870k
Deadline
12 Apr
12 Apr 2024
Value
€870k
Deadline
12 Apr
Provision of managed extended detection and response services for Mercy University Hospital
Provision of managed extended detection and response services for Mercy University Hospital
Bidder profile
Firms with experience in cybersecurity services and public sector tenders are encouraged to apply.
Risks & flags
- Cybersecurity risks
- Compliance requirements
- Two-step tender process
- Ambiguity in scoring criteria
Briefing
AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.
1. At a glance
| Field | Detail |
|---|---|
| Buyer | Mercy University Hospital |
| Title | Managed Extended Detection and Response Services |
| CPV / category | services |
| Estimated value | 870000.00 |
| Per-year (if multi-year) | not stated |
| Procedure type | not stated |
| Lots | not stated |
| Location | Ireland |
| Contract length | 12 months |
| Submission deadline | 2024-04-12T16:00:00+00:00 |
| Go-live / start | not stated |
2. Scope of Work
Mercy University Hospital ran this procurement for “Managed Extended Detection and Response Services” as an operational contract requiring implementation and sustained service execution. The extracted pack showed qualification-stage material with references to later ITT technical depth; practical activity therefore centred on building, integrating, and operating the specified service stack with compliant reporting and handover obligations where stated. Constituent activities and named work elements in the supplied extracts:
- Title: Managed Extended Detection and Response Services
- ority estimates that the expenditure on the Services to be covered by the proposed Services Contract may amount to some €1,000,000 (excl
- covered by the proposed Services Contract may amount to some €1,000,000 (excl
- apidly enhance the security operations and strengthen the cyber defence posture post the Incident, a number of security services were stood up on
- rer shall be required to supply its Tax Clearance Access Number and Tax Reference Number to facilitate online verification of their tax status by
- 3 The service must have ISO27001 security accreditation in place covering the support services
- st be delivered with a quality management system aligned to ISO9001
- Managed Extended Detection and Response Services
- Tenderers should note that prices may be increased or decreased only on the first anniversary of the Effective Date of the Services Contract (as defined in the Services Contract) and on subsequent anniversaries of the Effective Date thereafter, and then only by the percentage by which the price has increased or decreased in the edition of that index published by the price most recently prior to that anniversary.
- Tenderers must address each of the issues and requirements in this part of the RFT and submit a detailed description in each case which demonstrates how these issues and requirements will be dealt with / met and their approach to the proposed delivery of the Services. A mere affirmative statement by the Tenderer that it can/will do so or a reiteration of the tender requirements is NOT sufficient in this regard.
- Mercy University Hospital (MUH) invites tenders from suitable parties for the provision of Managed Extended Detection and Response Services. The award will be made based on the ability to provide all the services outlined below.
- On 14 May 2021, the HSE & MUH were subjected to a serious criminal cyberattack, through the infiltration of IT systems using Conti Ransomware. This cyberattack resulted in the IT infrastructure within HSE & MUH being significantly impacted leading to unavailability of key patient information and diagnostics. To rapidly enhance the security operations and strengthen the cyber defence posture post the Incident, a number of security services were stood up on an emergency basis. Non-binding monetary references in the source were treated as context only and were not used as qualification thresholds.
3. Background & buyer context
The buyer context reflected a formal Irish public-procurement route, with pre-qualification used to control entry into the tender stage.
- and waste disposal policy and procedure in compliance with ISO 14000 or equivalent
- 1.7 Contracting Authority policy
- 1.7 Contracting Authority policy seeks to encourage participation on a fair and equal basis by Small and Medium Enterprises (“SME”s) in this Competition. SMEs that believe the scope of this Competition is beyond their technical or business capacity are encouraged, subject to paragraph 2.5, to explore the possibilities of forming relationships with other SMEs or with larger enterprises. Through such relationships they can participate and contribute to the successful implementation of any Services Contract that may result from this Competition and therefore increase their social and economic benefits.
- A1.2.3 Integrates with broader cybersecurity risk management strategy.
4. Eligibility & selection criteria
- Turnover requirement — not specified for this tender
- Insurance — not specified for this tender
- Certifications — not specified for this tender
- Past experience — not specified for this tender
- Personnel — not specified for this tender
- Geographic / facility constraints — not specified for this tender
5. Award criteria & scoring
| Criterion | Weight (%) | Sub-criteria | Pass/fail threshold |
|---|---|---|---|
| Quality | not stated | Methodology / implementation detail not stated in extract | not stated |
| Price | not stated | Pricing basis not stated in extract | not stated |
| The documents indicated a staged process (qualification, then tender). Any explicit MEAT split is captured above where a numeric line was visible; otherwise it remained not specified in the provided text extract. |
6. Submission requirements
- Method statement / response document (template/page limits) — Appendix 1 questionnaire/PQQ response was required.
- CVs (page count, named roles) — not specified in extract.
- Pricing schedule (format/template) — expected at ITT stage.
- Case studies (number/value range) — client references/comparable project evidence was referenced.
- Declarations (ESPD/Bona Fides/Tax/COI) — ESPD/declaration/statement-of-confirmation language was present.
- Mandatory site visit — not specified in extract.
- Submission portal and formatting — eTenders portal and PDF electronic copies were referenced. Submission-related source lines:
- Appendix 1: Requirements and Specifications
- Appendix 4: Declaration as to Personal Circumstances of Tenderer
- Appendix 6: Confidentiality Agreement
- Tenderers must address each of the issues and requirements in this part of the RFT and submit a detailed description in each case which demonstrates how these issues and requirements will be dealt with / met and their approach to the proposed delivery of the Services. A mere affirmative statement by the Tenderer that it can/will do so or a reiteration of the tender requirements is NOT sufficient in this regard.
- Please complete the pricing matrix below.
- Appendix 4 : Declaration as to Personal Circumstances of Tenderer
7. Key dates & process
| Milestone | Date |
|---|---|
| RFT issued | not specified |
| Clarification deadline | not specified |
| Mandatory site visit | not specified |
| Tender deadline (date + time) | 2024-04-12T16:00:00+00:00 |
| Expected award | not specified |
| Contract start | not specified |
| Go-live / mobilisation | not stated |
| Date surfaced in documents | 2024-04-12T16:00:00+00:00 |
| Date surfaced in documents | 14 May 2021 |
| Date surfaced in documents | 12 March 2001 |
| Date surfaced in documents | May 2021 |
8. Contract terms that matter
Contract duration in the extract: 12 months. Payment cycle, SLA/KPI schedule, and penalty regime were not fully disclosed in the snippets unless listed below.
- VERIFIED PHRASES (deterministic regex extract from the documents — treat as authoritative for numerical claims)
- ontinues for 10 calendar days either Party may terminate at 14 days notice If the Force Majeure Event con
- tinues for 10 calendar days either Party may terminate at 14 days notice
- breach(es) (if the breach(es) are capable of remedy) within 30 days after receipt of a request in writing f
- A For the Term and for a period of 12 months thereafter (and save in respect of publ
- Tenderers must address each of the issues and requirements in this part of the RFT and submit a detailed description in each case which demonstrates how these issues and requirements will be dealt with / met and their approach to the proposed delivery of the Services. A mere affirmative statement by the Tenderer that it can/will do so or a reiteration of the tender requirements is NOT sufficient in this regard.
- Schedule B: Detailed description of Services provided – The Specification.
- [Insert description of Lots and any rules / instructions in relation to Lots]
9. Risks, red flags & unusuals
- Numeric qualification gates were only partially visible, so eligibility certainty required full pack review.
- The two-step process (PQQ then ITT) shifted effort to compliance evidence early, with competitive scoring detail potentially deferred.
- Technical and contractual granularity appeared ITT-dependent, increasing ambiguity at qualification stage for non-incumbent bidders.
10. SME fit assessment
This competition looked most accessible to firms with established public-sector tender capability, documented financial capacity, and direct operational experience in the relevant service category.
- Credible bidder profile — specialist operator with compliant procurement governance and evidencable experience.
- Consortium / sub-contracting — allowed or addressed in the extracts (Appendix references and reliance provisions).
- Indicative bid-prep effort — 6 to 12 working days for evidence collation, form completion, and review cycles at PQQ level.
- Pwin signal — strongest for bidders with reusable qualification artefacts, comparable references, and low-friction mobilisation capability.
11. Where to dig deeper
- Source RFT/PQQ filenames: MUH RFT SIEMv2.docx, RFT SIEMv2.docx] Request for Tenders, Appendix 1: Requirements and Specifications.
- eTenders CFT / notice reference: not specified in extract.
- Clarification contact / portal: eTenders message portal (email not surfaced in extract).
- Key attachments to prioritise: Appendix 2: Pricing Schedule, Appendix 3: Tenderer’s Statement, Appendix 4: Declaration as to Personal Circumstances of Tenderer.
Can you bid?
Required certifications
- ISO 27001
- ISO 9001
Public liability insurance
€6,500,000
Named standards / methodologies
Scoring
Most Economically Advantageous Tender
Technical Merit
Price
Lots (1)
Provision of cybersecurity monitoring and response services for Mercy University Hospital.
Documents (5)
MUH RFT SIEMv2.docx
182.1 KB · RFT / Invitation to Tender
Appendix A. Company Information Form.doc
288.0 KB
Appendix A. Company Information Form.pdf
212.7 KB · Appendix / Annex
Appendix B. Article 57 of directive 2014.24.EU.doc
137.0 KB
Appendix B. Article 57 of directive 2014.24.EU.pdf
221.5 KB · Appendix / Annex
Original notice text
Mercy University Hospital seeks tenders for managed extended detection and response services to enhance cybersecurity operations following a significant cyberattack. The contract will require implementation and sustained service execution over 12 months.
AI analysis updated 4 months ago
Value
€870k
Deadline
12 Apr
Location
Ireland
Procedure
Open
Clarification
05 Apr 2024
eTenders ID
3206044
Ask AI
Knows this tender's documents
Example only — sign up to ask about this tender