Enhanced Security Operations Managed Service
key details
| Status | planning |
|---|---|
| Category (CPV) | 72000000 |
| SME suitable | Yes |
| OCID | ocds-h6vhtk-06f556 |
description
The Student Loans company (SLC) have an agreement for Enhanced Security Operations Managed Service expiring April 2028. In order to provision for a retender of the agreement SLC are undertaking pre-market engagement with regards to the provision of the following:
| • | Requirement A: Enhanced Security Operations Managed Service - MXDR Service (2026-TR-0109a) |
| • | Requirement B: Enhanced Security Operations Managed Service - Vulnerability Management (VM) Service (2026-TR-0109b) |
| • | Requirement C: Enhanced Security Operations Managed Service - Breach Attack Simulation (BAS) Service (2026-TR-0109c) |
| • | Requirement D: Enhanced Security Operations Managed Service - Cyber Threat Intelligence (CTI) Service (2026-TR-0109d) |
| • | Requirement E: Enhanced Security Operations Managed Service - Digital Forensics and Incident Response (DFIR) Retainer Service (2026-TR-0109e) |
| • | Requirement F: Enhanced Security Operations Managed Service - Security Architecture and Engineering Support Services (2026-TR-0109f) |
SLC is considering an approach to the market to give the suppliers an option to bid for one or ALL of the contractual requirements.
Requirement A
Enhanced Security Operations Managed Service - MXDR Service The Supplier will provide a Managed Extended Detection and Response (MXDR) capability operating on a hybrid customer/supplier model.
MXDR Service
The Supplier will provide:
| • | 24x7x365 monitoring of SLC security telemetry. |
| • | L1 and L2 Security Operations Centre capability (SLC retain L3). |
| • | Incident identification, triage and investigation. |
| • | Security use-case monitoring and tuning. |
| • | Management of Microsoft Sentinel detections. |
| • | SOAR playbook execution and optimisation. |
| • | Escalation management. |
| • | Alert enrichment. |
| • | Threat hunting capability. |
| • | Malicious activity investigation. |
| • | Service governance and performance management. |
| • | Security reporting at operational, tactical and strategic levels. |
Security Engineering (Operational)
The Supplier shall provide:
| • | L3 Engineering support for Sentinel. |
| • | Analytics rule development and tuning. |
| • | SOAR playbook management. |
| • | Connector maintenance and health monitoring. |
| • | Logging optimisation. |
| • | Onboarding and validation of agreed log sources. |
| • | Detection engineering support. |
| • | Detection gap analysis and monitoring coverage reviews. |
| • | Security use case development and continuous improvement. |
| • | Monitoring health checks. |
| • | Monitoring and remediation of ingestion issues. |
| • | Security platform optimisation. |
| • | Proactive automation support and development. |
| • | Threat intelligence-led detection improvements. |
Data Loss Prevention (DLP) & Phishing
The Supplier shall:
| • | Monitoring, triage and investigation of DLP, phishing, business email compromise (BEC), malicious email, malicious attachment and malicious URL alerts. |
| • | Investigation of suspected data loss, data exfiltration and policy breach events. |
| • | Support for user reported phishing submissions. |
| • | Escalation and coordination of confirmed incidents in accordance with agreed response procedures. |
| • | Identification and analysis of phishing campaigns, attacker infrastructure, indicators of compromise and emerging attack trends. |
| • | Recommendations for improvements to DLP policies, email security controls, detections and response processes. |
| • | Monthly reporting, trend analysis and security improvement recommendations. |
Reporting
The Supplier shall provide:
| • | Weekly operational reports. |
| • | Monthly service reports. |
| • | Quarterly service reviews. |
| • | KPI and SLA reporting. |
| • | Security metrics and trend analysis. |
Requirement B
Enhanced Security Operations Managed Service - Vulnerability Management Service The Supplier shall provide Vulnerability Management services Monday to Friday, UK Core Hours (09:00-17:00).
Vulnerability Management
The Supplier shall:
| • | Monitor vulnerability management queues. |
| • | Investigate vulnerability notifications. |
| • | Manage vulnerability triage. |
| • | Validate vulnerability findings. |
| • | Perform exploitability assessments. |
| • | Provide remediation recommendations. |
| • | Support exposure management activities. |
| • | Support CTEM activities. |
Stakeholder Engagement
The Supplier shall:
| • | Conduct monthly technical review meetings. |
| • | Support resolver teams. |
| • | Assist remediation planning. |
| • | Review remediation performance. |
| • | Provide vulnerability prioritisation guidance. |
Dashboarding & Reporting
The Supplier shall:
| • | Maintain executive dashboards. |
| • | Enhance Power BI reporting. |
| • | Produce technical reports. |
| • | Produce executive reports. |
| • | Produce PCI compliance reports. |
| • | Produce risk trending reports. |
Tooling
The Supplier shall support:
| • | Microsoft Defender for Endpoint. |
| • | Rapid7. |
| • | SLC PCI ASV Scanning tooling. |
| • | Jira. |
| • | Power BI. |
Requirement C
Enhanced Security Operations Managed Service - Breach Attack Simulation Service The Supplier shall provide a Breach Attack Simulation (BAS) capability, currently using AttackIQ or similar.
BAS Service
The Supplier shall:
| • | Operate and maintain the BAS platform. |
| • | Deploy and maintain BAS agents. |
| • | Configure integrations. |
| • | Execute scheduled simulations. |
| • | Execute customer-specific simulations. |
| • | Execute retests following remediation activities. |
Adversary Simulation
Testing scenarios shall include:
| • | Initial Access. |
| • | Execution. |
| • | Persistence. |
| • | Privilege Escalation. |
| • | Credential Access. |
| • | Lateral Movement. |
| • | Command and Control. |
| • | Exfiltration. |
| • | Malware. |
| • | Ransomware. |
| • | Advanced Persistent Threat activity. |
Security Validation
The Supplier shall assess:
| • | Security control effectiveness. |
| • | Security monitoring effectiveness. |
| • | Detection coverage. |
| • | Response capability. |
| • | Incident handling. |
| • | Use-case effectiveness. |
Reporting
The Supplier shall produce:
| • | Monthly BAS reports. |
| • | Executive summaries. |
| • | Technical findings. |
| • | Remediation recommendations. |
| • | Retest outcomes. |
Requirement D
Enhanced Security Operations Managed Service - Cyber Threat Intelligence Service The Supplier shall provide strategic, operational and tactical Cyber Threat Intelligence services.
Threat Intelligence Managed Service
The Supplier shall provide:
| • | Threat Intelligence reporting. |
| • | Integration into Microsoft Sentinel. |
| • | Indicator of Compromise feeds. |
| • | Threat actor intelligence. |
Operational Intelligence
The Supplier shall provide:
| • | Threat alerts. |
| • | Vulnerability intelligence. |
| • | Emerging threat notifications. |
| • | Campaign tracking. |
| • | Industry specific intelligence. |
Strategic Intelligence
The Supplier shall provide:
| • | Threat landscape assessments. |
| • | Quarterly threat reports. |
| • | Executive intelligence briefings. |
| • | Board level threat summaries. |
| • | Sector specific threat reporting. |
Security Operations Support
The Supplier shall provide:
| • | Intelligence support during incidents. |
| • | Threat hunting support. |
| • | Intelligence driven use-case creation. |
| • | Intelligence enrichment services. |
Requirement E
Enhanced Security Operations Managed Service - Digital Forensics & Incident Response Retainer Service The Supplier shall provide a DFIR Retainer available 24x7x365.
Cyber Incident Response
The Supplier shall provide:
| • | Incident investigation. |
| • | Malware analysis. |
| • | Threat containment. |
| • | Threat eradication. |
| • | Recovery support. |
| • | Crisis management support. |
| • | Regulator support. |
| • | On-site support |
Digital Forensics
The Supplier shall provide:
| • | Evidence acquisition. |
| • | Chain of custody management. |
| • | Endpoint forensics. |
| • | Server forensics. |
| • | Network forensics. |
| • | Cloud forensics. |
| • | Forensic reporting. |
Readiness Services
The Supplier shall provide access to:
| • | Tabletop exercises. |
| • | Incident simulations. |
| • | Executive workshops. |
| • | CSIRT training. |
| • | Lessons learned reviews. |
Retained Consultancy
The Supplier shall provide specialist support including:
| • | Security strategy input. |
| • | Audit support. |
| • | Major incident reviews. |
| • | Regulatory engagement support. |
| • | Ransomware negotiation services. |
Requirement F
Enhanced Security Operations Managed Service - Security Architecture & Engineering Support Services The Supplier shall provide specialist Security Architecture and Engineering services on a call-off basis.
Security Architecture
The Supplier shall provide:
| • | Security architecture reviews. |
| • | Security design authority support. |
| • | Secure by Design reviews. |
| • | Solution security reviews. |
| • | Threat modelling. |
| • | Architecture governance. |
| • | Security requirements definition. |
| • | Architectural risk assessments. |
Security Engineering
The Supplier shall provide:
| • | Technical security engineering. |
| • | Security tool implementation. |
| • | Security configuration reviews. |
| • | Security hardening activities. |
| • | Technical control implementation. |
Strategy & Transformation
The Supplier shall provide:
| • | Security roadmap development. |
| • | Target operating model development. |
| • | Control framework assessments. |
| • | Security maturity reviews. |
| • | Improvement planning. |
Governance & Assurance
The Supplier shall provide:
| • | Security assessments. |
| • | Risk management support. |
| • | Audit support. |
| • | KPI development. |
| • | Board reporting support. |
| • | Security governance support. |
| • | Independent design and control assurance. |
| • | Security exception and risk acceptance reviews. |
| • | Third party and supplier security assessments. |
notice history
1 notice published against this procurement.
| Published | Type | Regime | Notice |
|---|---|---|---|
| 9 Sept 2026 | Preliminary market engagement (UK2) | Procurement Act 2023 | 085261-2026 |
more from STUDENT LOANS COMPANY
- Vmware ELA Subscription and Support · £2,700,000 · 7 Sept 2026
- SolarWinds Suite · 2 Jul 2026
- Repayment Unverified Customers · £2,790,000 · 10 Jun 2026
- Data Driven Innovation: Data Design, Implementation and Migration Partner · 13 May 2026
- Leadership Development - All leaders · 11 May 2026
- Data Solution Delivery Partner · £5,140,000 · 5 May 2026
- Forescout Renewal · 8 Apr 2026
- The Student room · 23 Mar 2026
all contracts from this buyer →
similar contracts awarded
Other awarded contracts in the same category. Useful for seeing who normally wins this kind of work, and at what value.
- OGVA Cloud Hosting Software Support Services · DVSA - Driver and Vehicle Standards Agency · £8,960,000
- Accessibility Testing - Call-Off Contract · MCA - Maritime and Coastguard Agency · £31,500
- Building compliance solution · London Borough of Camden · £99,000
- Tenant Satisfaction Survey · London Borough of Camden
- Maintain and optimise the Automated Regression Pack · BANK OF ENGLAND · £820,002
- Microsoft ESA - Leeds City Council · Leeds City Council · £13,000,000
- Synertec Software Developer · The Christie NHS Foundation Trust · £79,920
- Strategic Security Partner · MET OFFICE · £1,850,000
source
Published on Find a Tender. Contact details for named individuals are not reproduced on this site.