All tenders
PublicOpen · deadline not publishedocds-h6vhtk-06f556United Kingdom· Tender

Enhanced Security Operations Managed Service

Sign in to view the buyer

The buyer and the original notice are hidden. Create a free account to unlock them.Create free account
Estimated value
Not disclosed
Earliest action required
Checking…
Bid closes
Submission method
Not stated at source

Uk Fts · published 09 Sept 2026 · last checked 09 Sept 2026 · no amendments recorded

Scope of works

The Student Loans company (SLC) have an agreement for Enhanced Security Operations Managed Service expiring April 2028. In order to provision for a retender of the agreement SLC are undertaking pre-market engagement with regards to the provision of the following: • Requirement A: Enhanced Security Operations Managed Service - MXDR Service (2026-TR-0109a) • Requirement B: Enhanced Security Operations Managed Service - Vulnerability Management (VM) Service (2026-TR-0109b) • Requirement C: Enhanced Security Operations Managed Service - Breach Attack Simulation (BAS) Service (2026-TR-0109c) • Requirement D: Enhanced Security Operations Managed Service - Cyber Threat Intelligence (CTI) Service (2026-TR-0109d) • Requirement E: Enhanced Security Operations Managed Service - Digital Forensics and Incident Response (DFIR) Retainer Service (2026-TR-0109e) • Requirement F: Enhanced Security Operations Managed Service - Security Architecture and Engineering Support Services (2026-TR-0109f) SLC is considering an approach to the market to give the suppliers an option to bid for one or ALL of the contractual requirements. Requirement A Enhanced Security Operations Managed Service - MXDR Service The Supplier will provide a Managed Extended Detection and Response (MXDR) capability operating on a hybrid customer/supplier model. MXDR Service The Supplier will provide: • 24x7x365 monitoring of SLC security telemetry. • L1 and L2 Security Operations Centre capability (SLC retain L3). • Incident identification, triage and investigation. • Security use-case monitoring and tuning. • Management of Microsoft Sentinel detections. • SOAR playbook execution and optimisation. • Escalation management. • Alert enrichment. • Threat hunting capability. • Malicious activity investigation. • Service governance and performance management. • Security reporting at operational, tactical and strategic levels. Security Engineering (Operational) The Supplier shall provide: • L3 Engineering support for Sentinel. • Analytics rule development and tuning. • SOAR playbook management. • Connector maintenance and health monitoring. • Logging optimisation. • Onboarding and validation of agreed log sources. • Detection engineering support. • Detection gap analysis and monitoring coverage reviews. • Security use case development and continuous improvement. • Monitoring health checks. • Monitoring and remediation of ingestion issues. • Security platform optimisation. • Proactive automation support and development. • Threat intelligence-led detection improvements. Data Loss Prevention (DLP) & Phishing The Supplier shall: • Monitoring, triage and investigation of DLP, phishing, business email compromise (BEC), malicious email, malicious attachment and malicious URL alerts. • Investigation of suspected data loss, data exfiltration and policy breach events. • Support for user reported phishing submissions. • Escalation and coordination of confirmed incidents in accordance with agreed response procedures. • Identification and analysis of phishing campaigns, attacker infrastructure, indicators of compromise and emerging attack trends. • Recommendations for improvements to DLP policies, email security controls, detections and response processes. • Monthly reporting, trend analysis and security improvement recommendations. Reporting The Supplier shall provide: • Weekly operational reports. • Monthly service reports. • Quarterly service reviews. • KPI and SLA reporting. • Security metrics and trend analysis. Requirement B Enhanced Security Operations Managed Service - Vulnerability Management Service The Supplier shall provide Vulnerability Management services Monday to Friday, UK Core Hours (09:00-17:00). Vulnerability Management The Supplier shall: • Monitor vulnerability management queues. • Investigate vulnerability notifications. • Manage vulnerability triage. • Validate vulnerability findings. • Perform exploitability assessments. • Provide remediation recommendations. • Support ex

Type
Invitation to bid / open tender
Tender
Sector
Healthcare & Medical
Procedure
Not published at source
Classification
Not published at source

Key dates

  1. Published at source09 Sept 2026
  2. Submission deadline