Single Framework for the Provision of IT Support Services - Network Security Services
Value
€2.1m
Deadline
08 Sep
08 Sep 2026
Value
€2.1m
Deadline
08 Sep
Establish a single-party framework for IT support services focused on network security, including 24/7 MDR, firewall support, security consultancy, and penetration testing.
IT support services framework for network security, including MDR, firewall support, and consultancy
Bidder profile
Established IT security service providers with proven experience in MDR, firewall support, and security consultancy, holding specific ISO certifications and substantial insurance coverage.
Risks & flags
- Single-party framework
- No guarantee of purchase volume
- HRI may procure outside framework
- Unspecified award criteria details
- No amendments to templates
Briefing
AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.
1. At a glance
| Buyer | Horse Racing Ireland (HRI) |
|---|---|
| Title | Single Framework for the Provision of IT Support Services - Network Security Services |
| CPV / category | Not specified |
| Estimated value | €2,000,000.00 |
| Per-year (if multi-year) | Not specified |
| Procedure type | Open Procedure |
| Lots | Single Lot |
| Location | Ireland |
| Contract length | Maximum potential duration: 4 years (2 initial + 2 optional) |
| Submission deadline | 2026-09-08T12:00:00 |
| Go-live / start | Not specified |
2. Scope of Work
This tender seeks to establish a single-party framework agreement for the provision of IT support services focused on network security. The framework will cover a maximum potential duration of four years, commencing with an initial two-year period and an option for yearly extensions up to a total of four years. The services required are comprehensive and include 24/7 Managed Detection and Response (MDR), reactive support and annual health checks for existing HRI firewalls, security consultancy, penetration testing, and the potential supply of other security products and services.
The constituent activities and deliverables include:
-
24/7 Managed Detection and Response (MDR) Service:
-
24x7 SOC coverage.
-
Threat detection and analysis.
-
Threat hunting.
-
Incident response using pre-agreed actions.
-
Onboarding process and continuous integration of new systems and services.
-
Service covers the entire HRI organisation, including 250 Windows client devices, 70 servers, 45 network devices (switches, NAS, firewalls, appliances), Office 365 environment, Azure environment, and Cato environment.
-
Daily log volume is approximately 15GB, processed via Microsoft Sentinel SIEM.
-
Proactive threat hunting and development of threat content (correlation/alerting rules).
-
Incident Detection, Security Incident Analysis, Security Incident Response, Threat Intelligence, Threat Hunting, Real Time Dashboards, Security Advisory, and Continuous Improvement.
-
Development of specific use cases alongside HRI IT.
-
Reactive Support and Annual Health Checks of Existing HRI Firewalls:
-
3rd level reactive support for HRI IT staff.
-
Maintenance and support of IT infrastructure.
-
Annual health checks on each firewall component.
-
Consultation on changes or upgrades to supported infrastructure and advice on potential new projects.
-
Firewall supply, maintenance, and change support.
-
Supply of hardware, licenses, and manufacturer support contracts.
-
Support for changes and troubleshooting on firewall issues, including VPN creation, policy creation, IPS changes, and incident management, potentially involving on-site services.
-
On-site health checks with reports and recommendations.
-
Supply of Check Point and Fortigate firewalls when required.
-
Specific firewall infrastructure includes:
-
HRI Ballymany site: Clustered Check Point 9100 with separate management appliance.
-
HRI Disaster Recovery Site: Fortigate 40F.
-
6 Remote sites (Racecourses): Check Point Quantum Spark 1535 Appliance.
-
Other Racecourse: Clustered Fortigate 200E.
-
Support for Checkpoint Firewall hardware, license renewals, and additional licenses.
-
Response times for calls: Critical (2 hours), Medium (4 hours), Low (24 hours), Request (TBA). Approximate number of support calls per year is 6.
-
Security Consultancy and Advisory Services:
-
Complex changes/upgrades on firewalls.
-
Installation of new features.
-
End-user training, including security awareness training.
-
Audits of systems and processes.
-
Cyber security policy development.
-
Security Penetration Testing Services:
-
Penetration testing of at least 20 internet-facing IP addresses.
-
Application penetration testing of all HRI Group websites.
-
Supply of Other Security Products and Services (Optional):
-
Licenses for products such as Nessus Pro, Tenable IO, Cisco Email Security, Cato Networks.
-
Services such as Incident Response, Table top exercises, PCI compliance services, Security awareness training.
Services are to be provided within normal business hours (9 am to 6 pm Mon-Fri, excluding bank holidays), with out-of-hours service on a case-by-case basis.
3. Background & buyer context
Horse Racing Ireland (HRI) is procuring these IT support services to enhance its network security posture. The current IT infrastructure is managed by three permanent staff members and spans multiple sites, including the main HQ at Ballymany, The Curragh, Co. Kildare, six racecourses (Leopardstown, Fairyhouse, Navan, Tipperary, Curragh, Cork), one golf course, a Disaster Recovery site in West Dublin, and another Dublin data centre. The procurement is being conducted via an open procedure under EU regulations. HRI has adopted a framework agreement approach to leverage efficiencies and maximise cost savings over a four-year period. The existing MDR service uses Microsoft Sentinel SIEM. The framework agreement is intended to provide a single point of contact for a range of security services, ensuring consistent and effective management of HRI's network security.
4. Eligibility & selection criteria
To be eligible for consideration, bidders must meet the following minimum requirements:
- Turnover Requirement: Tenderers must provide evidence of having attained an average annual turnover of at least €2,000,000.00 in any one of the three preceding financial years.
- Insurance:
- Employer's Liability: €13m in any one occurrence.
- Public/Product Liability: €6.5m in any one occurrence.
- Cyber Insurance: €2m.
- Certifications: Applicants must confirm they hold the following accreditations:
- ISO 27001: Information Security Management.
- ISO 9001: Quality Management.
- ISO 20000-1: IT Service Management.
- Past Experience: Not specified for this tender.
- Personnel: Applicants must demonstrate access to at least the minimum numbers of skilled personnel stated. Specific roles and minimum experience levels are not detailed in the provided extract.
- Geographic / Facility Constraints: Not specified for this tender.
5. Award criteria & scoring
The evaluation process will first assess self-declaration forms for completeness. Tenderers meeting this requirement will then be assessed against award criteria to identify the most economically advantageous tender (MEAT). The MEAT tenderer will then be requested to submit evidence to validate against eligibility criteria. The specific award criteria, weightings, and scoring thresholds are not detailed in the provided extract. However, the tender states that the "lowest notional ultimate cost tender submission that also meets all minimum requirements" will be considered, implying cost is a significant factor.
| Criterion | Weight (%) | Sub-criteria | Pass/Fail Thresholds |
|---|---|---|---|
| Not specified | Not specified | Not specified | Not specified |
6. Submission requirements
Tenderers must submit a comprehensive tender response via the eTenders website. Key submission requirements include:
- Method Statement / Response Document: Not specified in terms of template or page limits, but must be comprehensive and comply with ITT instructions.
- CVs: Not specified.
- Pricing Schedule: Must use the provided template, and failure to do so may result in elimination. Pricing must be quoted exclusive of VAT.
- Case Studies: Not specified.
- Declarations:
- Form of Self Declaration (Appendix 3).
- Tenderer's Statement (Appendix 1 – Form of Tender), confirming acceptance of Framework Agreement Terms & Conditions.
- Tax Reference Number and Access Number for online verification, or a valid tax clearance certificate.
- Confirmation of insurance details.
- Disclosure of any conflicts of interest.
- Mandatory Site Visit: Not specified.
- Submission Portal: www.etenders.gov.ie.
- File Size Limits: Total upload of 500MB, with individual files up to 250MB.
- Format: Electronic submission only; hard copy submissions are not permitted. Tenderers are prohibited from amending text or content of provided forms, declarations, or templates.
7. Key dates & process
| Event | Date/Time |
|---|---|
| RFT issued | Not specified |
| Clarification deadline | 2026-09-01T12:00:00 |
| Mandatory site visit | Not specified |
| Tender deadline | 2026-09-08T12:00:00 |
| Expected award | Not specified |
| Contract start | Not specified |
| Go-live / mobilisation | Not specified |
8. Contract terms that matter
- Term: Initial period of two years, with an option to extend yearly up to a maximum of four years. Contracts awarded under the framework may extend beyond the framework expiry date.
- Payment Terms: Payments will be made in Euro (€) only. Invoices and payments will be in accordance with agreed terms. Payments under the Framework Agreement shall be payable within 30 days of receipt.
- Key SLAs/KPIs: Response times for support calls are defined (Critical: 2 hours, Medium: 4 hours, Low: 24 hours). Specific KPIs for MDR service are not detailed but include proactive threat hunting and continuous improvement.
- Liquidated Damages/Penalties: Not specified in the provided extract.
- Termination Clauses: The Framework Agreement may be terminated in accordance with the Framework Agreement Terms and Conditions (Appendix 4). If non-performance continues for 3 weeks, the unaffected party may terminate by giving 30 days' written notice. The Operator must promptly (within 7 days of termination/expiry) return all HRI documentation.
- IP Ownership: Not specified.
- Sub-contracting Rules: Where a group of undertakings submits a tender, a single nominated entity must be authorised to represent all members. The successful tenderer must designate a single entity (Prime Contractor) responsible for the Framework Agreement, irrespective of subcontractors.
- Parent Company Guarantee/Bond: Not specified.
9. Risks, red flags & unusuals
- Single-Party Framework: This is a single-party framework, meaning HRI is contracting with one successful bidder. However, HRI reserves the right to operate outside the framework if it offers greater value for money, which could impact guaranteed volumes.
- No Guarantee of Purchase: The framework agreement does not guarantee a specific quantity of services will be purchased.
- Tender Validity: A 12-month tender validity period is required, commencing from the submission deadline.
- No Amendments to Templates: Tenderers are prohibited from amending the text or content of provided forms, declarations, or templates, including pricing schedules. Failure to comply may lead to elimination.
- Potential for Outside Procurement: HRI explicitly states it may procure services outside the framework if it offers better value for money.
- Unspecified Award Criteria: While MEAT is mentioned, the specific weighting and details of the award criteria are not provided in the extract, making it difficult to fully assess the scoring mechanism.
10. SME fit assessment
This tender is likely best suited for established IT security service providers with a proven track record in managed detection and response, firewall support, and security consultancy. The requirement for specific ISO certifications (27001, 9001, 20000-1) and significant insurance levels (€13m EL, €6.5m PL/IL, €2m Cyber) suggests a need for a mature organisation. The turnover requirement of €2m average annual turnover further indicates that very small businesses may struggle to meet the eligibility criteria.
Consortium or subcontracting is permitted, provided a single nominated entity is designated as the Prime Contractor responsible for the overall framework. This allows smaller firms to potentially participate by partnering with larger entities or by specialising in specific service areas.
The bid preparation effort is likely to be substantial, requiring detailed responses on technical capabilities, service delivery models, personnel qualifications, and pricing. The absence of specific past experience criteria means that while new entrants might be considered if they meet all other gates, the complexity of the services and the scale of HRI's infrastructure suggest that bidders with demonstrable experience in similar environments will have an advantage. The "lowest notional ultimate cost" aspect of the award criteria suggests that price will be a critical differentiator, but only after meeting all technical and eligibility requirements.
11. Where to dig deeper
- Source RFT Filename: [Single Framework for the Provision of IT Support Services - Network Security Services.pdf]
- eTenders CFT ID: Not specified in the provided extract.
- Contact / Clarification Portal: Queries must be submitted via the eTenders website (www.etenders.gov.ie).
- Most Important Attachments:
- Appendix 1 – Form of Tender
- Appendix 3 – Form of Self Declaration
- Appendix 4 – Terms & Conditions of Framework Agreement
Can you bid?
Required certifications
- ISO 27001
- ISO 9001
- ISO 20000-1
Minimum turnover
€2,000,000
Public liability insurance
€6,500,000
Named standards / methodologies
Scoring
Cost Effectiveness
Lots (1)
Documents (2)
Editable Appendices.docx
55.3 KB
Single Framework for the Provision of IT Support Services - Network Security Services.pdf
822.2 KB
Original notice text
Horse Racing Ireland’s (HRI) IT Infrastructure spans several sites and is supported by three HRI permanent staff members. The main HQ is located in Ballymany, The Curragh, Co. Kildare. The majority of the users and IT infrastructure are located at this location. HRI’s remote sites include six racecourses and one golf course, located in Leopardstown (racecourse and golf course), Fairyhouse, Navan, Tipperary, Curragh and Cork. HRI also have a Disaster Recovery site in West Dublin and have IT infrastructure located in another Dublin data Centre.
AI analysis updated 1 week, 3 days ago
Value
€2.1m
Deadline
08 Sep
Location
Ireland, including HQ at Ballymany, Co. Kildare, six racecourses, one golf course, a Disaster Recovery site in West Dublin, and another Dublin data centre.
Procedure
Open
Clarification
01 Sep 2026
eTenders ID
8781382
Ask AI
Knows this tender's documents
Example only — sign up to ask about this tender