Enhanced Security Operations Managed Service
PlanningHighlights
- Deadline
- —
- Estimated value
- —
- Location
- UK
Details
- Published
- 9 Sept 2026
- Deadline
- —
- Value
- —
- Location
- UK
- Source
- Find a Tender
- Source notice ID
- 085261-2026
- OCID
- ocds-h6vhtk-06f556
- CPV codes
- 72000000
Description
The Student Loans company (SLC) have an agreement for Enhanced Security Operations Managed Service expiring April 2028. In order to provision for a retender of the agreement SLC are undertaking pre-market engagement with regards to the provision of the following:
- Requirement A: Enhanced Security Operations Managed Service - MXDR Service (2026-TR-0109a)
- Requirement B: Enhanced Security Operations Managed Service - Vulnerability Management (VM) Service (2026-TR-0109b)
- Requirement C: Enhanced Security Operations Managed Service - Breach Attack Simulation (BAS) Service (2026-TR-0109c)
- Requirement D: Enhanced Security Operations Managed Service - Cyber Threat Intelligence (CTI) Service (2026-TR-0109d)
- Requirement E: Enhanced Security Operations Managed Service - Digital Forensics and Incident Response (DFIR) Retainer Service (2026-TR-0109e)
- Requirement F: Enhanced Security Operations Managed Service - Security Architecture and Engineering Support Services (2026-TR-0109f)
SLC is considering an approach to the market to give the suppliers an option to bid for one or ALL of the contractual requirements.
Requirement A
Enhanced Security Operations Managed Service - MXDR Service
The Supplier will provide a Managed Extended Detection and Response (MXDR) capability operating on a hybrid customer/supplier model.
MXDR Service
The Supplier will provide:
- 24x7x365 monitoring of SLC security telemetry.
- L1 and L2 Security Operations Centre capability (SLC retain L3).
- Incident identification, triage and investigation.
- Security use-case monitoring and tuning.
- Management of Microsoft Sentinel detections.
- SOAR playbook execution and optimisation.
- Escalation management.
- Alert enrichment.
- Threat hunting capability.
- Malicious activity investigation.
- Service governance and performance management.
- Security reporting at operational, tactical and strategic levels.
Security Engineering (Operational)
The Supplier shall provide:
- L3 Engineering support for Sentinel.
- Analytics rule development and tuning.
- SOAR playbook management.
- Connector maintenance and health monitoring.
- Logging optimisation.
- Onboarding and validation of agreed log sources.
- Detection engineering support.
- Detection gap analysis and monitoring coverage reviews.
- Security use case development and continuous improvement.
- Monitoring health checks.
- Monitoring and remediation of ingestion issues.
- Security platform optimisation.
- Proactive automation support and development.
- Threat intelligence-led detection improvements.
Data Loss Prevention (DLP) & Phishing
The Supplier shall:
- Monitoring, triage and investigation of DLP, phishing, business email compromise (BEC), malicious email, malicious attachment and malicious URL alerts.
- Investigation of suspected data loss, data exfiltration and policy breach events.
- Support for user reported phishing submissions.
- Escalation and coordination of confirmed incidents in accordance with agreed response procedures.
- Identification and analysis of phishing campaigns, attacker infrastructure, indicators of compromise and emerging attack trends.
- Recommendations for improvements to DLP policies, email security controls, detections and response processes.
- Monthly reporting, trend analysis and security improvement recommendations.
Reporting
The Supplier shall provide:
- Weekly operational reports.
- Monthly service reports.
- Quarterly service reviews.
- KPI and SLA reporting.
- Security metrics and trend analysis.
Requirement B
Enhanced Security Operations Managed Service - Vulnerability Management Service
The Supplier shall provide Vulnerability Management services Monday to Friday, UK Core Hours (09:00-17:00).
Vulnerability Management
The Supplier shall:
- Monitor vulnerability management queues.
- Investigate vulnerability notifications.
- Manage vulnerability triage.
- Validate vulnerability findings.
- Perform exploitability assessments.
- Provide remediation recommendations.
- Support exposure management activities.
- Support CTEM activities.
Stakeholder Engagement
The Supplier shall:
- Conduct monthly technical review meetings.
- Support resolver teams.
- Assist remediation planning.
- Review remediation performance.
- Provide vulnerability prioritisation guidance.
Dashboarding & Reporting
The Supplier shall:
- Maintain executive dashboards.
- Enhance Power BI reporting.
- Produce technical reports.
- Produce executive reports.
- Produce PCI compliance reports.
- Produce risk trending reports.
Tooling
The Supplier shall support:
- Microsoft Defender for Endpoint.
- Rapid7.
- SLC PCI ASV Scanning tooling.
- Jira.
- Power BI.
Requirement C
Enhanced Security Operations Managed Service - Breach Attack Simulation Service
The Supplier shall provide a Breach Attack Simulation (BAS) capability, currently using AttackIQ or similar.
BAS Service
The Supplier shall:
- Operate and maintain the BAS platform.
- Deploy and maintain BAS agents.
- Configure integrations.
- Execute scheduled simulations.
- Execute customer-specific simulations.
- Execute retests following remediation activities.
Adversary Simulation
Testing scenarios shall include:
- Initial Access.
- Execution.
- Persistence.
- Privilege Escalation.
- Credential Access.
- Lateral Movement.
- Command and Control.
- Exfiltration.
- Malware.
- Ransomware.
- Advanced Persistent Threat activity.
Security Validation
The Supplier shall assess:
- Security control effectiveness.
- Security monitoring effectiveness.
- Detection coverage.
- Response capability.
- Incident handling.
- Use-case effectiveness.
Reporting
The Supplier shall produce:
- Monthly BAS reports.
- Executive summaries.
- Technical findings.
- Remediation recommendations.
- Retest outcomes.
Requirement D
Enhanced Security Operations Managed Service - Cyber Threat Intelligence Service
The Supplier shall provide strategic, operational and tactical Cyber Threat Intelligence services.
Threat Intelligence Managed Service
The Supplier shall provide:
- Threat Intelligence reporting.
- Integration into Microsoft Sentinel.
- Indicator of Compromise feeds.
- Threat actor intelligence.
Operational Intelligence
The Supplier shall provide:
- Threat alerts.
- Vulnerability intelligence.
- Emerging threat notifications.
- Campaign tracking.
- Industry specific intelligence.
Strategic Intelligence
The Supplier shall provide:
- Threat landscape assessments.
- Quarterly threat reports.
- Executive intelligence briefings.
- Board level threat summaries.
- Sector specific threat reporting.
Security Operations Support
The Supplier shall provide:
- Intelligence support during incidents.
- Threat hunting support.
- Intelligence driven use-case creation.
- Intelligence enrichment services.
Requirement E
Enhanced Security Operations Managed Service - Digital Forensics & Incident Response Retainer Service
The Supplier shall provide a DFIR Retainer available 24x7x365.
Cyber Incident Response
The Supplier shall provide:
- Incident investigation.
- Malware analysis.
- Threat containment.
- Threat eradication.
- Recovery support.
- Crisis management support.
- Regulator support.
- On-site support
Digital Forensics
The Supplier shall provide:
- Evidence acquisition.
- Chain of custody management.
- Endpoint forensics.
- Server forensics.
- Network forensics.
- Cloud forensics.
- Forensic reporting.
Readiness Services
The Supplier shall provide access to:
- Tabletop exercises.
- Incident simulations.
- Executive workshops.
- CSIRT training.
- Lessons learned reviews.
Retained Consultancy
The Supplier shall provide specialist support including:
- Security strategy input.
- Audit support.
- Major incident reviews.
- Regulatory engagement support.
- Ransomware negotiation services.
Requirement F
Enhanced Security Operations Managed Service - Security Architecture & Engineering Support Services
The Supplier shall provide specialist Security Architecture and Engineering services on a call-off basis.
Security Architecture
The Supplier shall provide:
- Security architecture reviews.
- Security design authority support.
- Secure by Design reviews.
- Solution security reviews.
- Threat modelling.
- Architecture governance.
- Security requirements definition.
- Architectural risk assessments.
Security Engineering
The Supplier shall provide:
- Technical security engineering.
- Security tool implementation.
- Security configuration reviews.
- Security hardening activities.
- Technical control implementation.
Strategy & Transformation
The Supplier shall provide:
- Security roadmap development.
- Target operating model development.
- Control framework assessments.
- Security maturity reviews.
- Improvement planning.
Governance & Assurance
The Supplier shall provide:
- Security assessments.
- Risk management support.
- Audit support.
- KPI development.
- Board reporting support.
- Security governance support.
- Independent design and control assurance.
- Security exception and risk acceptance reviews.
- Third party and supplier security assessments.
Similar opportunities
- Provision of a new college websiteTenderCardiff and Vale College£220,000
- SAS SupportTenderQualifications ScotlandCloses 12 Oct 2026
- SONI089 – Software Licensing & Buying ServicesTenderSONI Ltd£68,557,055
- Dedicated Housing Tenant WebsiteTenderCardiff CouncilCloses 16 Oct 2026
- Land Observations Networks Modems and Sims - Re-tenderTenderMet OfficeCloses 5 Oct 2026
More from Student Loans Company
View all- Professional Services - EstatesAwardStudent Loans CompanyAwarded £2,050,000
- Vmware ELA Subscription and SupportPipelineStudent Loans Company£2,700,000
- Overseas Debt CollectionExpiredStudent Loans CompanyClosed 31 Mar 2019
- Childcare Grant Payment ServicesExpiredStudent Loans CompanyClosed 31 May 2018
- Overseas Debt CollectionAwardStudent Loans CompanyAwarded
Lots (1)
| Lot | Title | Value |
|---|---|---|
| 1 | Lot 1 | — |