Estimated Value
Not specified
Deadline
Not specified
Published
16 June 2026
Type
services
Overview
GSA require a Managed Detection and Response, Security service to mitigation of threats across the GSA's digital environment. The service includes Managed Detection and Response, Security Information and Event Management, Endpoint Detection and Response supported by Next Generation Anti‑Virus, identity monitoring, cyber threat intelligence, threat hunting, cyber maturity assessments, efficiency testing and full incident response readiness.
These capabilities collectively enable the proactive identification, investigation and mitigation of threats across the GSA's digital environment. Managed Detection and Response (MDR).
Enterprise data will be captured and analysed for indicators of attack or compromise, which, if discovered, shall initiate a first response. This response will be either automated or human, depending on the source of the detection.
Additional details
GSA require Level 1 and 2 support, and the first one hour of any Level 3 investigations. Support levels are defined below.
Level 1 The first line of security analysts who manage security tools and run regular reporting. At this level, alerts and alert urgency will be determined by the security team.
Decisions about escalation to Level 2 will also be undertaken at this level. Level 2 The second line of security analysts / engineers who have the expertise required to get to the root of a problem and assess which part of the enterprise may be compromised.
Remediation and repair of problems is expected and issues for additional investigation will be highlighted. Level 3 The third line of security engineers / incident responders, which consists of highly skilled technical resource.
If required, personnel will use advanced detection methods (threat hunting) to identify and neutralise the threat, providing remediation advice to the Client's IT team. Key deliverables: - Managed Detection and Response (MDR) Service o 24/7x365 Threat Detection & Response o Ongoing Detection Engineering o Ongoing Use Case Development o Cyber Threat Intelligence (CTI) o Threat Hunting o Cyber Maturity Assessment o Incident Response (first 1 hour of IR) o Dedicated Customer Success Manager - SIEM Licensing (Splunk) 100GB - CrowdStrike EDR Licensing with Falcon Mobile (1650 endpoints)
AI Analysis
Powered by AI — always verify against official documents
The GSA (likely a UK government agency) is looking for a managed cybersecurity service to monitor, detect, and respond to threats across their computer network 24 hours a day. The service includes threat detection software, security monitoring, staff analysis, and incident response support.
Requirements
- Provide 24/7/365 Managed Detection and Response (MDR) capability
- Supply and manage Splunk SIEM (Security Information and Event Management) with 100GB capacity
- Provide CrowdStrike EDR (Endpoint Detection and Response) Falcon Mobile licensing for 1,650 endpoints
- Deliver Level 1 and Level 2 security analyst support (first and second-line response teams)
- Provide first 1 hour of Level 3 incident response support (advanced investigation by senior engineers)
- Offer Next Generation Anti-Virus capabilities integrated with the service
- Conduct cyber threat intelligence and threat hunting investigations
- Perform cyber maturity assessments to evaluate security readiness
- Perform efficiency testing of security systems
- Provide full incident response readiness planning
- Assign a dedicated Customer Success Manager to the GSA
- Automated and human response capability for detected threats
- Daily reporting and alert management capabilities
Key Tasks & Deliverables
- Monitor GSA digital environment for security threats and attacks 24/7/365
- Analyse enterprise data and alert logs to identify indicators of compromise or attack
- Provide first-line (Level 1) security analyst team to triage alerts, assess urgency, and decide on escalation
- Provide second-line (Level 2) security analyst/engineer team to investigate root causes, assess compromise scope, and perform remediation
- Respond to the first hour of advanced (Level 3) incident investigations for highly complex threats
- Conduct threat hunting (proactive search for hidden threats in the network)
- Deliver Cyber Threat Intelligence reports and insights relevant to GSA
- Perform annual or periodic cyber maturity assessments (benchmarking GSA's security posture)
- Execute security efficiency testing and validation
- Provide incident response readiness planning and preparation
- Manage Splunk SIEM logging and reporting (100GB data capacity)
- Manage CrowdStrike EDR licensing and updates for 1,650 endpoints
- Maintain Next Generation Anti-Virus across the estate
How to Read This Tender
- 1Understand the three support levels: Level 1 handles initial alerts, Level 2 investigates and fixes problems, Level 3 is expert incident response (you only provide the first hour). This is a tiered support model — know which level your team can staff reliably.
- 2The two software components (Splunk SIEM and CrowdStrike EDR) are specified by name and version — check if you have partnerships or reseller agreements with these vendors, or if you'll need to negotiate licensing. This is a significant cost line.
- 3The 'Key Deliverables' section lists what you must provide. The service is 24/7/365, so factor in shift patterns, coverage, and on-call costs when pricing.
- 4Look for the full tender documents to find: pricing model (per endpoint? per month? per incident?), response time SLAs (how quickly must Level 1 respond to an alert?), and escalation criteria (when does Level 1 escalate to Level 2?).
- 5Watch for hidden complexity: managing 1,650 endpoints across a government network likely means security clearance requirements, audit trails, compliance reporting (ISO 27001, NIST, etc.), and strict change control processes. These aren't mentioned here but are almost certain in the full spec.
Tips for Small Businesses
- If you're a smaller security firm without CrowdStrike or Splunk relationships, consider forming a consortium or subcontracting to a larger managed security provider (MSSP) who holds these licenses. You could focus on Level 1 analyst staffing or threat hunting specialisation, with a larger partner handling licensing and Level 2/3.
- The 24/7/365 requirement is expensive. Consider whether you can staff this in-house or if you'll need to partner with offshore security operations centres (SOCs) to cover night shifts cost-effectively. Factor this into your bid early.
- Government contracts often require security clearances (SC or DV) for staff accessing GSA systems. Check the full tender to confirm, and budget time and cost for vetting your team before contract start.
Award Details
Cysiam Limited
Likely incumbents
Suppliers who won similar work from this buyer in the last 5 years.
- 1
Culture Amp
Culture Amp is the most likely incumbent based on recency and category match. To win, bidders typically need a clearly differentiated proposition or a price advantage.
Before you bid, buyers check
two years of filed accountsyour financial standingturnover vs contract valueyour Companies House recordcash flow for 30-day termscredit scores and ratios
Actions
Sign up freeto open noticeA free account takes a moment and unlocks the buyer’s own notice, tender documents, fit scoring and the Bid Writer. From 1 September 2026 opening these links becomes £2/month membership.
Open Bid WriterIndependent software, web & cloud studio. We design, build and grow digital products that quietly outlast their category.
How to Apply
Step-by-step submission guide
Submission Portal
Find a Tender
Open the original notice
Click the button below to view the full notice on Find a Tender Service (FTS)
Check the procedure type
The "Procedure" section tells you if it's Open (one stage) or Restricted (SQ then ITT). This changes how you apply
Access the eSourcing portal
FTS notices link to the buyer's eSourcing platform — register there to access documents
Complete the Selection Questionnaire
Higher-value contracts often require an SQ first — this pre-qualifies you before the full bid stage
Submit electronically
Upload your completed response through the eSourcing platform before the closing date and time
FTS contracts are above UK procurement thresholds. Late submissions are strictly rejected — submit at least 24 hours before the deadline to avoid portal issues.
Buyer Profile
GREENSQUAREACCORD LIMITEDKey Dates
Published
16 June 2026
Submission deadline
Not specified
Notice type
award
Source
find a tender
Related Contracts
T26-117ENV archaeology services for unlocking silent heritage (historic cemeteries enhancement) project peaceplus
Derry City and Strabane District Council invites quotations from suitably qualified and experienced commercial archaeologists and archaeological organisations to provide archaeolog
Tourism campaign 2027 - video agency tender
The contract is for a video and photography agency to create footage for the North York Moors National Park Tourism Campaign 2027, filming in September‑October and delivering the final assets by December 2027.
Passenger transport open framework
North Yorkshire Council is seeking tenders from interested organisations for the Passenger Transport Open Framework. The Authority is developing an Open Framework which will consis
National trust NI - lead consultant, carrick-a-rede capital works infrastructure project
The National Trust is seeking to appoint a Lead Consultant for the Carrick-a-Rede Visitor Infrastructure Project through a single-stage Request for Proposal (RFP1) process. Bidders
