Provision of Security Operations Centre (SOC) and SIEM Services
Deadline
29 Sep
29 Sep 2026
Deadline
29 Sep
An Post requires a Security Operations Centre (SOC) and SIEM service provider for continuous IT security monitoring, threat detection, incident response, and compliance assurance.
An Post seeks SOC and SIEM services for 24x7x365 IT security monitoring and incident response.
Bidder profile
This tender is suitable for established cybersecurity firms with significant experience in providing 24x7 SOC/SIEM services to large, regulated organisations, and the financial capacity to meet high insurance and turnover requirements.
Risks & flags
- Data residency requirements (EEA/Adequacy/EU-US DP)
- 24x7x365 service delivery
- High insurance requirements
- Negotiated procedure (limited bidders)
Briefing
AI-generated analysis of the documents. Check the official notice and any amendments for current submission details.
1. At a glance
Buyer Title CPV / category Estimated value Per-year Procedure type Lots Location Contract length Submission deadline Go-live / start | :------------ | :----------------------------------------------------------------- | :------------- | :-------------- | :------- | :------------------------------ | :--- | :------- | :-------------- | :------------------ | :------------------ | An Post Provision of Security Operations Centre (SOC) and SIEM Services 79713000-1 not disclosed not stated Negotiated Procedure with prior publication 1 Ireland 3 years (extendable to 8) 2026-09-29 11:00 not stated
2. Scope of Work
This tender seeks a Security Operations Centre (SOC) and Security Information and Event Management (SIEM) service provider for An Post. The selected partner will manage An Post's IT environment, providing continuous security monitoring, threat detection, incident response support, and compliance assurance. The service operates 24x7x365.
Key activities and components include:
- Continuous Security Monitoring and Event Management: 24x7x365 monitoring of An Post's IT environment.
- SIEM Platform Management: Operation, management, and enhancement of An Post's SIEM platform, primarily Microsoft Sentinel. The supplier must also support equivalent SIEM platforms and integrate with non-Microsoft security event sources.
- Incident Management: Detection, triage, investigation, and escalation of security incidents. This includes integration with customer support and ticketing processes, and providing incident response, containment, recovery, and forensic support.
- Security Orchestration, Automation, and Response (SOAR): Implementation of SOAR capabilities.
- Detection Engineering: Development of use cases and continuous service improvement for detection mechanisms.
- Threat Intelligence: Provision of threat intelligence, sector-relevant insights, and actionable advice, including proactive threat hunting.
- Service Governance and Reporting: Management of the service, including reporting and stakeholder engagement.
- Personnel Provision: Deployment of appropriately qualified and experienced cybersecurity personnel.
- Integration: Secure integration with An Post's existing tooling, specifically Microsoft Sentinel and Microsoft Defender.
- Security Posture Management: Maintaining and supporting An Post's information security policies, including areas such as Access Control, Remote Access, Vulnerability Management, Patch Management, User Access Management, Data Loss Prevention, Logging & Auditing, Incident Response and Management, and Encryption and Key Management.
- Data Protection and Compliance: Ensuring all services comply with GDPR and other applicable data protection legislation.
- Business Continuity: Maintaining and testing business continuity and operational resilience arrangements to ensure continuous service delivery.
- Exit and Transition Planning: Maintaining an up-to-date exit and transition plan for service transfer.
- Vetting: Implementing a vetting procedure for resources working on the contract.
The solution is expected to be delivered from within the EEA, a country with a European Commission Adequacy Decision, or the US under the EU-US Data Privacy Framework.
3. Background & buyer context
An Post operates a complex, highly regulated, business-critical IT environment supporting its core postal, money transmission, savings, and retail services. The organisation has a significant national presence with 879 post offices and 102 Delivery Service Units. In 2024, the An Post Group generated revenues of €1.051 billion, handling approximately 2.5 million delivery points daily, with everyday banking contributing nearly €3 billion. The Group also operates subsidiary businesses like Post Insurance and Air Business. This procurement is driven by An Post's requirement for a qualified Security Partner to deliver robust SOC and SIEM capabilities, ensuring continuous security monitoring, threat detection, and incident response across its IT estate to meet its security, resilience, governance, and regulatory obligations.
4. Eligibility & selection criteria
Bidders must meet minimum requirements to be considered for this tender.
- Turnover requirement: A minimum average annual turnover of €1,000,000.00 (exclusive of VAT) for any two of the last three financial year ends. If relying on a parent company, their details must also be provided.
- Insurance: The successful tenderer must hold the following insurances for the contract term:
- Employer’s Liability: €13,000,000
- Public and Products Liability: €6,500,000
- Professional Indemnity: €2,600,000
- Cyber Insurance: €3,000,000
- Certifications:
- Information Security Policy aligned with or certified to ISO27001 standard (or equivalent).
- Quality Management System certified as compliant with EN ISO 9001 (or an equivalent recognised standard).
- ISO 14001 certification is noted as achieved by An Post, suggesting a preference for environmental management.
- Past experience: Demonstrated experience in delivering similar services for organisations of comparable scale and complexity. Specific project numbers or values are not stated at this PQQ stage.
- Personnel: Not specified at this PQQ stage, beyond the general requirement for suitably qualified and experienced cybersecurity personnel.
- Geographic / facility constraints: It is strongly preferred that the proposed solution, including all hosting, support, operational, monitoring, maintenance, and data processing activities, is located and delivered from within the EEA, a country subject to a European Commission Adequacy Decision, or the US under the EU-US Data Privacy Framework. This preference extends to all processing of An Post personal data, including sub-processing, the SOC location, supporting infrastructure, delivery personnel, and support teams.
5. Award criteria & scoring
The tender process involves a pre-qualification stage followed by a tender stage. While specific scoring for the tender stage is not detailed in the PQQ, the pre-qualification stage uses selection criteria. For the tender stage, the award will be based on the Most Economically Advantageous Tender (MEAT). The PQQ indicates that for the pre-qualification stage, specific criteria will be evaluated, with minimum scores required:
Criterion Weight (%) Sub-criteria
Can you bid?
Required certifications
- ISO27001
- EN ISO 9001
- ISO 14001
Minimum turnover
€1,000,000
Public liability insurance
€6,500,000
Professional indemnity insurance
€2,600,000
Named standards / methodologies
Scoring
Most Economically Advantageous Tender
Documents (2)
0055 - SOC and SIEM - PQQ.docx
793.3 KB
0055 - SOC and SIEM - PQQ.pdf
10.4 MB
Original notice text
An Post requires a suitably qualified Security Partner to deliver a managed Security Operations Centre (SOC) and Security Information and Event Management (SIEM) service across its technology estate. The successful Supplier will be responsible for providing a resilient, secure, and professionally managed cybersecurity capability that supports continuous security monitoring, threat detection, incident analysis, alert triage, incident response, escalation management, compliance assurance, service reporting, and ongoing service improvement. The Supplier will work collaboratively with An Post personnel and relevant third-party providers to ensure comprehensive monitoring coverage, effective management of security incidents, and alignment with An Post's security, resilience, governance, and regulatory requirements. The service will include the provision, operation, management, and continuous enhancement of security monitoring and incident management capabilities, including support for Microsoft Sentinel as An Post's current SIEM platform. The Supplier must also be capable of supporting alternative SIEM technologies should An Post's security architecture evolve during the contract term. In addition, the Supplier must be able to monitor and manage security event sources across both Microsoft and non-Microsoft technologies, including platforms that do not natively integrate with Microsoft Sentinel. The scope of the service is expected to include, but is not limited to, managed cybersecurity operations, threat detection and analysis, incident management and response, security platform support, threat intelligence, governance and reporting, and the provision of suitably qualified cybersecurity personnel to support service delivery.
AI analysis updated 14 hours, 17 minutes ago
Deadline
29 Sep
Buyer
An PostLocation
Services to be delivered from within the EEA, a country with a European Commission Adequacy Decision, or the US under the EU-US Data Privacy Framework.
Procedure
Negotiated
eTenders ID
8927838
Ask AI
Knows this tender's documents
Example only — sign up to ask about this tender