Enhanced Security Operations Managed Service
- STUDENT LOANS COMPANY
Procurement identifier (OCID): ocds-h6vhtk-06f556
Description
The Student Loans company (SLC) have an agreement for Enhanced Security Operations Managed Service expiring April 2028. In order to provision for a retender of the agreement SLC are undertaking pre-market engagement with regards to the provision of the following:
• Requirement A: Enhanced Security Operations Managed Service - MXDR Service (2026-TR-0109a)
• Requirement B: Enhanced Security Operations Managed Service - Vulnerability Management (VM) Service (2026-TR-0109b)
• Requirement C: Enhanced Security Operations Managed Service - Breach Attack Simulation (BAS) Service (2026-TR-0109c)
• Requirement D: Enhanced Security Operations Managed Service - Cyber Threat Intelligence (CTI) Service (2026-TR-0109d)
• Requirement E: Enhanced Security Operations Managed Service - Digital Forensics and Incident Response (DFIR) Retainer Service (2026-TR-0109e)
• Requirement F: Enhanced Security Operations Managed Service - Security Architecture and Engineering Support Services (2026-TR-0109f)
SLC is considering an approach to the market to give the suppliers an option to bid for one or ALL of the contractual requirements.
Requirement A
Enhanced Security Operations Managed Service - MXDR Service
The Supplier will provide a Managed Extended Detection and Response (MXDR) capability operating on a hybrid customer/supplier model.
MXDR Service
The Supplier will provide:
• 24x7x365 monitoring of SLC security telemetry.
• L1 and L2 Security Operations Centre capability (SLC retain L3).
• Incident identification, triage and investigation.
• Security use-case monitoring and tuning.
• Management of Microsoft Sentinel detections.
• SOAR playbook execution and optimisation.
• Escalation management.
• Alert enrichment.
• Threat hunting capability.
• Malicious activity investigation.
• Service governance and performance management.
• Security reporting at operational, tactical and strategic levels.
Security Engineering (Operational)
The Supplier shall provide:
• L3 Engineering support for Sentinel.
• Analytics rule development and tuning.
• SOAR playbook management.
• Connector maintenance and health monitoring.
• Logging optimisation.
• Onboarding and validation of agreed log sources.
• Detection engineering support.
• Detection gap analysis and monitoring coverage reviews.
• Security use case development and continuous improvement.
• Monitoring health checks.
• Monitoring and remediation of ingestion issues.
• Security platform optimisation.
• Proactive automation support and development.
• Threat intelligence-led detection improvements.
Data Loss Prevention (DLP) & Phishing
The Supplier shall:
• Monitoring, triage and investigation of DLP, phishing, business email compromise (BEC), malicious email, malicious attachment and malicious URL alerts.
• Investigation of suspected data loss, data exfiltration and policy breach events.
• Support for user reported phishing submissions.
• Escalation and coordination of confirmed incidents in accordance with agreed response procedures.
• Identification and analysis of phishing campaigns, attacker infrastructure, indicators of compromise and emerging attack trends.
• Recommendations for improvements to DLP policies, email security controls, detections and response processes.
• Monthly reporting, trend analysis and security improvement recommendations.
Reporting
The Supplier shall provide:
• Weekly operational reports.
• Monthly service reports.
• Quarterly service reviews.
• KPI and SLA reporting.
• Security metrics and trend analysis.
Requirement B
Enhanced Security Operations Managed Service - Vulnerability Management Service
The Supplier shall provide Vulnerability Management services Monday to Friday, UK Core Hours (09:00-17:00).
Vulnerability Management
The Supplier shall:
• Monitor vulnerability management queues.
• Investigate vulnerability notifications.
• Manage vulnerability triage.
• Validate vulnerability findings.
• Perform exploitability assessments.
• Provide remediation recommendations.
• Support exposure management activities.
• Support CTEM activities.
Stakeholder Engagement
The Supplier shall:
• Conduct monthly technical review meetings.
• Support resolver teams.
• Assist remediation planning.
• Review remediation performance.
• Provide vulnerability prioritisation guidance.
Dashboarding & Reporting
The Supplier shall:
• Maintain executive dashboards.
• Enhance Power BI reporting.
• Produce technical reports.
• Produce executive reports.
• Produce PCI compliance reports.
• Produce risk trending reports.
Tooling
The Supplier shall support:
• Microsoft Defender for Endpoint.
• Rapid7.
• SLC PCI ASV Scanning tooling.
• Jira.
• Power BI.
Requirement C
Enhanced Security Operations Managed Service - Breach Attack Simulation Service
The Supplier shall provide a Breach Attack Simulation (BAS) capability, currently using AttackIQ or similar.
BAS Service
The Supplier shall:
• Operate and maintain the BAS platform.
• Deploy and maintain BAS agents.
• Configure integrations.
• Execute scheduled simulations.
• Execute customer-specific simulations.
• Execute retests following remediation activities.
Adversary Simulation
Testing scenarios shall include:
• Initial Access.
• Execution.
• Persistence.
• Privilege Escalation.
• Credential Access.
• Lateral Movement.
• Command and Control.
• Exfiltration.
• Malware.
• Ransomware.
• Advanced Persistent Threat activity.
Security Validation
The Supplier shall assess:
• Security control effectiveness.
• Security monitoring effectiveness.
• Detection coverage.
• Response capability.
• Incident handling.
• Use-case effectiveness.
Reporting
The Supplier shall produce:
• Monthly BAS reports.
• Executive summaries.
• Technical findings.
• Remediation recommendations.
• Retest outcomes.
Requirement D
Enhanced Security Operations Managed Service - Cyber Threat Intelligence Service
The Supplier shall provide strategic, operational and tactical Cyber Threat Intelligence services.
Threat Intelligence Managed Service
The Supplier shall provide:
• Threat Intelligence reporting.
• Integration into Microsoft Sentinel.
• Indicator of Compromise feeds.
• Threat actor intelligence.
Operational Intelligence
The Supplier shall provide:
• Threat alerts.
• Vulnerability intelligence.
• Emerging threat notifications.
• Campaign tracking.
• Industry specific intelligence.
Strategic Intelligence
The Supplier shall provide:
• Threat landscape assessments.
• Quarterly threat reports.
• Executive intelligence briefings.
• Board level threat summaries.
• Sector specific threat reporting.
Security Operations Support
The Supplier shall provide:
• Intelligence support during incidents.
• Threat hunting support.
• Intelligence driven use-case creation.
• Intelligence enrichment services.
Requirement E
Enhanced Security Operations Managed Service - Digital Forensics & Incident Response Retainer Service
The Supplier shall provide a DFIR Retainer available 24x7x365.
Cyber Incident Response
The Supplier shall provide:
• Incident investigation.
• Malware analysis.
• Threat containment.
• Threat eradication.
• Recovery support.
• Crisis management support.
• Regulator support.
• On-site support
Digital Forensics
The Supplier shall provide:
• Evidence acquisition.
• Chain of custody management.
• Endpoint forensics.
• Server forensics.
• Network forensics.
• Cloud forensics.
• Forensic reporting.
Readiness Services
The Supplier shall provide access to:
• Tabletop exercises.
• Incident simulations.
• Executive workshops.
• CSIRT training.
• Lessons learned reviews.
Retained Consultancy
The Supplier shall provide specialist support including:
• Security strategy input.
• Audit support.
• Major incident reviews.
• Regulatory engagement support.
• Ransomware negotiation services.
Requirement F
Enhanced Security Operations Managed Service - Security Architecture & Engineering Support Services
The Supplier shall provide specialist Security Architecture and Engineering services on a call-off basis.
Security Architecture
The Supplier shall provide:
• Security architecture reviews.
• Security design authority support.
• Secure by Design reviews.
• Solution security reviews.
• Threat modelling.
• Architecture governance.
• Security requirements definition.
• Architectural risk assessments.
Security Engineering
The Supplier shall provide:
• Technical security engineering.
• Security tool implementation.
• Security configuration reviews.
• Security hardening activities.
• Technical control implementation.
Strategy & Transformation
The Supplier shall provide:
• Security roadmap development.
• Target operating model development.
• Control framework assessments.
• Security maturity reviews.
• Improvement planning.
Governance & Assurance
The Supplier shall provide:
• Security assessments.
• Risk management support.
• Audit support.
• KPI development.
• Board reporting support.
• Security governance support.
• Independent design and control assurance.
• Security exception and risk acceptance reviews.
• Third party and supplier security assessments.
Notices
UK2: Preliminary market engagement notice
- Notice identifier
- 2026/S 000-085261
- Published
- 9 September 2026, 10:45am