System operational · UK tenders
planned
ocds-h6vhtk-06f556 · planning

Enhanced Security Operations Managed Service

STUDENT LOANS COMPANY

Estimated Value

Not specified

Deadline

Not specified

Published

9 September 2026

Type

Not specified

North EastGB

Full Description

The Student Loans company (SLC) have an agreement for Enhanced Security Operations Managed Service expiring April 2028. In order to provision for a retender of the agreement SLC are undertaking pre-market engagement with regards to the provision of the following:

  • Requirement A: Enhanced Security Operations Managed Service - MXDR Service (2026-TR-0109a)
  • Requirement B: Enhanced Security Operations Managed Service - Vulnerability Management (VM) Service (2026-TR-0109b)
  • Requirement C: Enhanced Security Operations Managed Service - Breach Attack Simulation (BAS) Service (2026-TR-0109c)
  • Requirement D: Enhanced Security Operations Managed Service - Cyber Threat Intelligence (CTI) Service (2026-TR-0109d)
  • Requirement E: Enhanced Security Operations Managed Service - Digital Forensics and Incident Response (DFIR) Retainer Service (2026-TR-0109e)
  • Requirement F: Enhanced Security Operations Managed Service - Security Architecture and Engineering Support Services (2026-TR-0109f)

SLC is considering an approach to the market to give the suppliers an option to bid for one or ALL of the contractual requirements.

Requirement A

Enhanced Security Operations Managed Service - MXDR Service

The Supplier will provide a Managed Extended Detection and Response (MXDR) capability operating on a hybrid customer/supplier model.

MXDR Service

The Supplier will provide

  • 24x7x365 monitoring of SLC security telemetry.
  • L1 and L2 Security Operations Centre capability (SLC retain L3).
  • Incident identification, triage and investigation.
  • Security use-case monitoring and tuning.
  • Management of Microsoft Sentinel detections.
  • SOAR playbook execution and optimisation.
  • Escalation management.
  • Alert enrichment.
  • Threat hunting capability.
  • Malicious activity investigation.
  • Service governance and performance management.
  • Security reporting at operational, tactical and strategic levels.

Security Engineering (Operational)

The Supplier shall provide

  • L3 Engineering support for Sentinel.
  • Analytics rule development and tuning.
  • SOAR playbook management.
  • Connector maintenance and health monitoring.
  • Logging optimisation.
  • Onboarding and validation of agreed log sources.
  • Detection engineering support.
  • Detection gap analysis and monitoring coverage reviews.
  • Security use case development and continuous improvement.
  • Monitoring health checks.
  • Monitoring and remediation of ingestion issues.
  • Security platform optimisation.
  • Proactive automation support and development.
  • Threat intelligence-led detection improvements.

Data Loss Prevention (DLP) & Phishing

The Supplier shall

  • Monitoring, triage and investigation of DLP, phishing, business email compromise (BEC), malicious email, malicious attachment and malicious URL alerts.
  • Investigation of suspected data loss, data exfiltration and policy breach events.
  • Support for user reported phishing submissions.
  • Escalation and coordination of confirmed incidents in accordance with agreed response procedures.
  • Identification and analysis of phishing campaigns, attacker infrastructure, indicators of compromise and emerging attack trends.
  • Recommendations for improvements to DLP policies, email security controls, detections and response processes.
  • Monthly reporting, trend analysis and security improvement recommendations.

Reporting

The Supplier shall provide

  • Weekly operational reports.
  • Monthly service reports.
  • Quarterly service reviews.
  • KPI and SLA reporting.
  • Security metrics and trend analysis.

Requirement B

Enhanced Security Operations Managed Service - Vulnerability Management Service

The Supplier shall provide Vulnerability Management services Monday to Friday, UK Core Hours (09:00-17:00).

Vulnerability Management

The Supplier shall

  • Monitor vulnerability management queues.
  • Investigate vulnerability notifications.
  • Manage vulnerability triage.
  • Validate vulnerability findings.
  • Perform exploitability assessments.
  • Provide remediation recommendations.
  • Support exposure management activities.
  • Support CTEM activities.

Stakeholder Engagement

The Supplier shall

  • Conduct monthly technical review meetings.
  • Support resolver teams.
  • Assist remediation planning.
  • Review remediation performance.
  • Provide vulnerability prioritisation guidance.

Dashboarding & Reporting

The Supplier shall

  • Maintain executive dashboards.
  • Enhance Power BI reporting.
  • Produce technical reports.
  • Produce executive reports.
  • Produce PCI compliance reports.
  • Produce risk trending reports.

Tooling

The Supplier shall support

  • Microsoft Defender for Endpoint.
  • Rapid7.
  • SLC PCI ASV Scanning tooling.
  • Jira.
  • Power BI.

Requirement C

Enhanced Security Operations Managed Service - Breach Attack Simulation Service

The Supplier shall provide a Breach Attack Simulation (BAS) capability, currently using AttackIQ or similar.

BAS Service

The Supplier shall

  • Operate and maintain the BAS platform.
  • Deploy and maintain BAS agents.
  • Configure integrations.
  • Execute scheduled simulations.
  • Execute customer-specific simulations.
  • Execute retests following remediation activities.

Adversary Simulation

Testing scenarios shall include

  • Initial Access.
  • Execution.
  • Persistence.
  • Privilege Escalation.
  • Credential Access.
  • Lateral Movement.
  • Command and Control.
  • Exfiltration.
  • Malware.
  • Ransomware.
  • Advanced Persistent Threat activity.

Security Validation

The Supplier shall assess

  • Security control effectiveness.
  • Security monitoring effectiveness.
  • Detection coverage.
  • Response capability.
  • Incident handling.
  • Use-case effectiveness.

Reporting

The Supplier shall produce

  • Monthly BAS reports.
  • Executive summaries.
  • Technical findings.
  • Remediation recommendations.
  • Retest outcomes.

Requirement D

Enhanced Security Operations Managed Service - Cyber Threat Intelligence Service

The Supplier shall provide strategic, operational and tactical Cyber Threat Intelligence services.

Threat Intelligence Managed Service

The Supplier shall provide

  • Threat Intelligence reporting.
  • Integration into Microsoft Sentinel.
  • Indicator of Compromise feeds.
  • Threat actor intelligence.

Operational Intelligence

The Supplier shall provide

  • Threat alerts.
  • Vulnerability intelligence.
  • Emerging threat notifications.
  • Campaign tracking.
  • Industry specific intelligence.

Strategic Intelligence

The Supplier shall provide

  • Threat landscape assessments.
  • Quarterly threat reports.
  • Executive intelligence briefings.
  • Board level threat summaries.
  • Sector specific threat reporting.

Security Operations Support

The Supplier shall provide

  • Intelligence support during incidents.
  • Threat hunting support.
  • Intelligence driven use-case creation.
  • Intelligence enrichment services.

Requirement E

Enhanced Security Operations Managed Service - Digital Forensics & Incident Response Retainer Service

The Supplier shall provide a DFIR Retainer available 24x7x365.

Cyber Incident Response

The Supplier shall provide

  • Incident investigation.
  • Malware analysis.
  • Threat containment.
  • Threat eradication.
  • Recovery support.
  • Crisis management support.
  • Regulator support.
  • On-site support

Digital Forensics

The Supplier shall provide

  • Evidence acquisition.
  • Chain of custody management.
  • Endpoint forensics.
  • Server forensics.
  • Network forensics.
  • Cloud forensics.
  • Forensic reporting.

Readiness Services

The Supplier shall provide access to

  • Tabletop exercises.
  • Incident simulations.
  • Executive workshops.
  • CSIRT training.
  • Lessons learned reviews.

Retained Consultancy

The Supplier shall provide specialist support including

  • Security strategy input.
  • Audit support.
  • Major incident reviews.
  • Regulatory engagement support.
  • Ransomware negotiation services.

Requirement F

Enhanced Security Operations Managed Service - Security Architecture & Engineering Support Services

The Supplier shall provide specialist Security Architecture and Engineering services on a call-off basis.

Security Architecture

The Supplier shall provide

  • Security architecture reviews.
  • Security design authority support.
  • Secure by Design reviews.
  • Solution security reviews.
  • Threat modelling.
  • Architecture governance.
  • Security requirements definition.
  • Architectural risk assessments.

Security Engineering

The Supplier shall provide

  • Technical security engineering.
  • Security tool implementation.
  • Security configuration reviews.
  • Security hardening activities.
  • Technical control implementation.

Strategy & Transformation

The Supplier shall provide

  • Security roadmap development.
  • Target operating model development.
  • Control framework assessments.
  • Security maturity reviews.
  • Improvement planning.

Governance & Assurance

The Supplier shall provide

  • Security assessments.
  • Risk management support.
  • Audit support.
  • KPI development.
  • Board reporting support.
  • Security governance support.
  • Independent design and control assurance.
  • Security exception and risk acceptance reviews.
  • Third party and supplier security assessments.

Requirements

The Supplier shall provide

The Supplier shall

The Supplier shall provide

The Supplier shall provide Vulnerability Management services Monday to Friday, UK Core Hours (09:00-17:00).

The Supplier shall

The Supplier shall

The Supplier shall

The Supplier shall support

The Supplier shall provide a Breach Attack Simulation (BAS) capability, currently using AttackIQ or similar.

The Supplier shall

Testing scenarios shall include

The Supplier shall assess

The Supplier shall produce

The Supplier shall provide strategic, operational and tactical Cyber Threat Intelligence services.

The Supplier shall provide

The Supplier shall provide

The Supplier shall provide

The Supplier shall provide

The Supplier shall provide a DFIR Retainer available 24x7x365.

The Supplier shall provide

The Supplier shall provide

The Supplier shall provide access to

The Supplier shall provide specialist support including

The Supplier shall provide specialist Security Architecture and Engineering services on a call-off basis.

The Supplier shall provide

The Supplier shall provide

The Supplier shall provide

The Supplier shall provide

AI AnalysisMembers

Requirements, key tasks and tips for reading this tender — included with Tendarix membership.

Create free account

£4.99/month after a 7-day free trial. Cancel anytime before it ends and you pay nothing.

Likely incumbents

Suppliers who won similar work from this buyer in the last 5 years.

5 found
  1. 1

    SOFTCAT PLC

    3 contracts wonlatest 9 Jan 2026ends 23 Feb 2028CH 02174990

    £155,446

    total awarded

  2. 2

    KAINOS WORKSMART LIMITED

    2 contracts wonlatest 5 Oct 2026ends 30 Nov 2029

    £2m

    total awarded

  3. 3

    Computacenter UK Ltd

    2 contracts wonlatest 10 Jun 2026ends 26 Jul 2028

    £210,727

    total awarded

  4. 4

    FRANKLIN COVEY EUROPE LIMITED

    2 contracts wonlatest 8 May 2026ends 27 May 2029CH 03282374

    £474,950

    total awarded

  5. 5

    COMPUTACENTER PLC

    2 contracts wonlatest 8 Apr 2026ends 14 Jun 2027CH 03110569

    £263,231

    total awarded

SOFTCAT PLC is the most likely incumbent based on recency and category match. To win, bidders typically need a clearly differentiated proposition or a price advantage.

Search for tenders
SponsoredEst. 2010
Gladstone & Co AccountantsTax advisers · East Ham, London

Before you bid, buyers check

two years of filed accountsyour financial standingturnover vs contract valueyour Companies House recordcash flow for 30-day termscredit scores and ratios

Annual accountsCash-flow forecastsManagement accountsCorporation taxVAT & MTDPayroll & RTIBookkeepingCompany formationSelf-assessmentVirtual FDHMRC enquiriesAuto-enrolmentProperty & landlord taxCharity SORP accounts
Get bid-ready — free 30-min call

Actions

Start free trialto open notice

Create an account and start a 7-day free trial to open the buyer’s own notice and tender documents, plus fit scoring and the Bid Writer. Then £4.99/month — cancel anytime.

Open Bid Writer
Built by · Digital studioEst. 2022
Unique
Evolution®

Independent software, web & cloud studio. We design, build and grow digital products that quietly outlast their category.

Web DesignSoftware DevelopmentSEO ServicesPromotion
Visit Unique Evolution

How to Apply

Step-by-step submission guide

Submission Portal

Find a Tender

Visit
1

Open the original notice

Click the button below to view the full notice on Find a Tender Service (FTS)

2

Check the procedure type

The "Procedure" section tells you if it's Open (one stage) or Restricted (SQ then ITT). This changes how you apply

3

Access the eSourcing portal

FTS notices link to the buyer's eSourcing platform — register there to access documents

4

Complete the Selection Questionnaire

Higher-value contracts often require an SQ first — this pre-qualifies you before the full bid stage

5

Submit electronically

Upload your completed response through the eSourcing platform before the closing date and time

FTS contracts are above UK procurement thresholds. Late submissions are strictly rejected — submit at least 24 hours before the deadline to avoid portal issues.

Buyer Profile

Student Loans Company
Typepublic body
RegionScotland
Total tenders94
Total spend£1,114,612,830
View buyer profile

Key Dates

Published

9 September 2026

Submission deadline

Not specified

Notice type

planning

Source

find a tender

Similar

Related Tenders