MOBILE APPLICATIONS THREAT ASSESSMENT SOLUTIONS
key details
| Value | £160,000 |
|---|---|
| Status | complete |
| Category (CPV) | 72000000 |
| Region | North West |
| Deadline | 17 Dec 2018 |
| Contract start | 17 Dec 2018 |
| Contract end | 16 Dec 2020 |
| Procedure | selective |
| SME suitable | Yes |
| OCID | ocds-b5fd17-86fe7d8a-a67b-4473-8a58-270788cea149 |
Award
| Supplier | Value | Date | Status |
|---|---|---|---|
| KRYPTOWIRE LLC | £160,000 | 17 Feb 2018 | active |
description
Delivering Apps to Smartphones is a key element of transforming the digital workplace and providing colleagues with modern solutions which enable them to be more efficient and effective. To date the delivery of Apps to the DWP store has been slow and/or resulted in apps being declined due to primarily to security concerns and lack of the right tools and internal capability to be able to assess and understand app behaviour.
In a global landscape where we have new vulnerabilities continuously emerging, we have the opportunity to secure an 'App Threat Assessment' from a third party.
Options Considered The desired outcome is:
New apps added to the DWP App store in volume and at pace. User experience enhanced and colleagues have a wider range of apps to improve productivity
Security risks reduced
Two options have been considered and tested:
Internal Service: A test rig was developed which identified which IP addresses each app accessed. Whilst this provided some helpful information, it did not provide an assessment of
| If/what data is being transferred/leaked out of DWP; | |
| Which phone services are being used by the app e.g. blue tooth, location services etc. | |
| any underlying and/or unexpected behaviours being performed by the app |
This resulted in a considerable amount of residual product and security team effort which in a number of cases failed to determine the associated risk due to a lack of visibility of app behaviour.
External, expert service: In 2017, as a proof of concept 3 apps were sent for review by 4 suppliers, specialising in threat assessments. Each supplier provided a comprehensive threat assessment which will enable DWP to make an informed assessment of each app within 24 hours of request. The security community as well as the product team were impressed with the granularity of detail provided.
Doing nothing would expose the department to security risks or lost data. Therefore external procurement is recommended.
notice history
1 notice published against this procurement.
| Published | Type | Regime | Notice |
|---|---|---|---|
| 20 May 2021 | Award update (awardUpdate) | · | 80ef4e61-8da2-4f96-896f-24cc45d85ce6-437924 |
more from Department for Work and Pensions
- SSL Certificates 2026 · £670,000 · 27 Jul 2026
- Digital Payment Services - Payments as a Service - Bacs Payment Fulfilment · £7,843,000 · 23 Jul 2026
- WorkWell (Expansion) NST (National Support Team) · £6,600,000 · 23 Jul 2026
- WorkWell (Expansion) NST · 21 Jul 2026
- Functional Assessment Services (FAS) 2023 – Lot 5 · £2,796,800,000 · 17 Jul 2026
- OpenText Exstream Extended Support 2026 · £115,889 · 1 Jul 2026
- Crown Hosting Service · £11,900,886 · 30 Jun 2026
- Public Cloud Services (G-Cloud 14) · 30 Jun 2026
all contracts from this buyer →
similar contracts awarded
Other awarded contracts in the same category. Useful for seeing who normally wins this kind of work, and at what value.
- SSL Certificates 2026 · Department for Work and Pensions · £670,000
- Support for Agile Technology Project Delivery · Financial Conduct Authority · £300,000
- Ivanti Neurons ITSM & ITAM Named & Concurrent Analyst Cloud Subscription · MCA - Maritime and Coastguard Agency · £44,574
- GMCA 1569 EA - Cisco Agreement · Greater Manchester Combined Authority
- FCA Handbook Static Website · Financial Conduct Authority · £95,000
- Core Tech Resource Request - March 2026 · FCA · £1,238,533
- Govtech webCAPTURE and eCAPTURE · Leeds City Council · £1,442,500
- Records Management SMEs 26+ · FCA · £8,993,623
source
Published on Contracts Finder. Contact details for named individuals are not reproduced on this site.