Scope of works
The UK’s public telecommunications networks are a critical national infrastructure (CNI) subsector, underpinning the functioning of every other CNI sector, the digital economy, and essential public services, for which the Department for Digital, Culture, Media and Sport (DCMS) is the lead government department. Their continued availability, integrity and confidentiality are fundamental to national security, economic resilience, and the everyday lives of UK citizens and businesses. Telecoms operators manage complex, large-scale, geographically distributed systems, including exchanges, data centres, transmission sites and access network assets , which are increasingly attractive targets for hostile state and state-aligned actors seeking to disrupt, degrade or exploit UK infrastructure. Physical compromise and insider threat are significant attack vectors that hostile actors could seek to exploit. Strengthening physical and personnel security across the sector is therefore a priority area of work for DCMS. DSIT is exploring options for obtaining specialist support to undertake a physical and personnel security assessment of UK public telecommunications networks and services. We are seeking engagement from accredited security consultancy firms to conduct a sector-level physical and personnel security assessment of UK public telecoms networks and services. This should include assessment of current vulnerabilities and potential threat vectors, and set out a prioritised list of recommended mitigations for operators to reduce the risk of security compromise stemming from physical and personnel security vulnerabilities. This list of prioritised mitigations should identify how existing NPSA guidance can be applied to address telecoms sector vulnerabilities. An estimated project commencement date is October 2026 , to conclude in February 2027, subject to a tender launch and agreed contract. Some of the core deliverables are listed below: A detailed report setting out: (i) current physical and personnel security vulnerabilities within the UK’s public telecoms networks and services, (ii) physical and personnel security threat vectors (i.e. how threat actors could exploit these vulnerabilities, not a threat assessment), and (iii) a prioritised list of mitigations for operators to take to reduce the identified physical and personnel security risks - this should include identification of how existing NPSA guidance can applied to address telecoms sector vulnerabilities.
- Type
- Contract award
- Contract Award
- Sector
- Marine & Ports
- Procedure
- Below threshold - limited competition
- Classification
- Not published at source
- Original notice
- Sign in to open the original notice
