Procurement

Enhanced Security Operations Managed Service

  • STUDENT LOANS COMPANY

Procurement identifier (OCID): ocds-h6vhtk-06f556

Description

The Student Loans company (SLC) have an agreement for Enhanced Security Operations Managed Service expiring April 2028. In order to provision for a retender of the agreement SLC are undertaking pre-market engagement with regards to the provision of the following:

• Requirement A: Enhanced Security Operations Managed Service - MXDR Service (2026-TR-0109a)

• Requirement B: Enhanced Security Operations Managed Service - Vulnerability Management (VM) Service (2026-TR-0109b)

• Requirement C: Enhanced Security Operations Managed Service - Breach Attack Simulation (BAS) Service (2026-TR-0109c)

• Requirement D: Enhanced Security Operations Managed Service - Cyber Threat Intelligence (CTI) Service (2026-TR-0109d)

• Requirement E: Enhanced Security Operations Managed Service - Digital Forensics and Incident Response (DFIR) Retainer Service (2026-TR-0109e)

• Requirement F: Enhanced Security Operations Managed Service - Security Architecture and Engineering Support Services (2026-TR-0109f)

SLC is considering an approach to the market to give the suppliers an option to bid for one or ALL of the contractual requirements.

Requirement A

Enhanced Security Operations Managed Service - MXDR Service

The Supplier will provide a Managed Extended Detection and Response (MXDR) capability operating on a hybrid customer/supplier model.

MXDR Service

The Supplier will provide:

• 24x7x365 monitoring of SLC security telemetry.

• L1 and L2 Security Operations Centre capability (SLC retain L3).

• Incident identification, triage and investigation.

• Security use-case monitoring and tuning.

• Management of Microsoft Sentinel detections.

• SOAR playbook execution and optimisation.

• Escalation management.

• Alert enrichment.

• Threat hunting capability.

• Malicious activity investigation.

• Service governance and performance management.

• Security reporting at operational, tactical and strategic levels.

Security Engineering (Operational)

The Supplier shall provide:

• L3 Engineering support for Sentinel.

• Analytics rule development and tuning.

• SOAR playbook management.

• Connector maintenance and health monitoring.

• Logging optimisation.

• Onboarding and validation of agreed log sources.

• Detection engineering support.

• Detection gap analysis and monitoring coverage reviews.

• Security use case development and continuous improvement.

• Monitoring health checks.

• Monitoring and remediation of ingestion issues.

• Security platform optimisation.

• Proactive automation support and development.

• Threat intelligence-led detection improvements.

Data Loss Prevention (DLP) & Phishing

The Supplier shall:

• Monitoring, triage and investigation of DLP, phishing, business email compromise (BEC), malicious email, malicious attachment and malicious URL alerts.

• Investigation of suspected data loss, data exfiltration and policy breach events.

• Support for user reported phishing submissions.

• Escalation and coordination of confirmed incidents in accordance with agreed response procedures.

• Identification and analysis of phishing campaigns, attacker infrastructure, indicators of compromise and emerging attack trends.

• Recommendations for improvements to DLP policies, email security controls, detections and response processes.

• Monthly reporting, trend analysis and security improvement recommendations.

Reporting

The Supplier shall provide:

• Weekly operational reports.

• Monthly service reports.

• Quarterly service reviews.

• KPI and SLA reporting.

• Security metrics and trend analysis.

Requirement B

Enhanced Security Operations Managed Service - Vulnerability Management Service

The Supplier shall provide Vulnerability Management services Monday to Friday, UK Core Hours (09:00-17:00).

Vulnerability Management

The Supplier shall:

• Monitor vulnerability management queues.

• Investigate vulnerability notifications.

• Manage vulnerability triage.

• Validate vulnerability findings.

• Perform exploitability assessments.

• Provide remediation recommendations.

• Support exposure management activities.

• Support CTEM activities.

Stakeholder Engagement

The Supplier shall:

• Conduct monthly technical review meetings.

• Support resolver teams.

• Assist remediation planning.

• Review remediation performance.

• Provide vulnerability prioritisation guidance.

Dashboarding & Reporting

The Supplier shall:

• Maintain executive dashboards.

• Enhance Power BI reporting.

• Produce technical reports.

• Produce executive reports.

• Produce PCI compliance reports.

• Produce risk trending reports.

Tooling

The Supplier shall support:

• Microsoft Defender for Endpoint.

• Rapid7.

• SLC PCI ASV Scanning tooling.

• Jira.

• Power BI.

Requirement C

Enhanced Security Operations Managed Service - Breach Attack Simulation Service

The Supplier shall provide a Breach Attack Simulation (BAS) capability, currently using AttackIQ or similar.

BAS Service

The Supplier shall:

• Operate and maintain the BAS platform.

• Deploy and maintain BAS agents.

• Configure integrations.

• Execute scheduled simulations.

• Execute customer-specific simulations.

• Execute retests following remediation activities.

Adversary Simulation

Testing scenarios shall include:

• Initial Access.

• Execution.

• Persistence.

• Privilege Escalation.

• Credential Access.

• Lateral Movement.

• Command and Control.

• Exfiltration.

• Malware.

• Ransomware.

• Advanced Persistent Threat activity.

Security Validation

The Supplier shall assess:

• Security control effectiveness.

• Security monitoring effectiveness.

• Detection coverage.

• Response capability.

• Incident handling.

• Use-case effectiveness.

Reporting

The Supplier shall produce:

• Monthly BAS reports.

• Executive summaries.

• Technical findings.

• Remediation recommendations.

• Retest outcomes.

Requirement D

Enhanced Security Operations Managed Service - Cyber Threat Intelligence Service

The Supplier shall provide strategic, operational and tactical Cyber Threat Intelligence services.

Threat Intelligence Managed Service

The Supplier shall provide:

• Threat Intelligence reporting.

• Integration into Microsoft Sentinel.

• Indicator of Compromise feeds.

• Threat actor intelligence.

Operational Intelligence

The Supplier shall provide:

• Threat alerts.

• Vulnerability intelligence.

• Emerging threat notifications.

• Campaign tracking.

• Industry specific intelligence.

Strategic Intelligence

The Supplier shall provide:

• Threat landscape assessments.

• Quarterly threat reports.

• Executive intelligence briefings.

• Board level threat summaries.

• Sector specific threat reporting.

Security Operations Support

The Supplier shall provide:

• Intelligence support during incidents.

• Threat hunting support.

• Intelligence driven use-case creation.

• Intelligence enrichment services.

Requirement E

Enhanced Security Operations Managed Service - Digital Forensics & Incident Response Retainer Service

The Supplier shall provide a DFIR Retainer available 24x7x365.

Cyber Incident Response

The Supplier shall provide:

• Incident investigation.

• Malware analysis.

• Threat containment.

• Threat eradication.

• Recovery support.

• Crisis management support.

• Regulator support.

• On-site support

Digital Forensics

The Supplier shall provide:

• Evidence acquisition.

• Chain of custody management.

• Endpoint forensics.

• Server forensics.

• Network forensics.

• Cloud forensics.

• Forensic reporting.

Readiness Services

The Supplier shall provide access to:

• Tabletop exercises.

• Incident simulations.

• Executive workshops.

• CSIRT training.

• Lessons learned reviews.

Retained Consultancy

The Supplier shall provide specialist support including:

• Security strategy input.

• Audit support.

• Major incident reviews.

• Regulatory engagement support.

• Ransomware negotiation services.

Requirement F

Enhanced Security Operations Managed Service - Security Architecture & Engineering Support Services

The Supplier shall provide specialist Security Architecture and Engineering services on a call-off basis.

Security Architecture

The Supplier shall provide:

• Security architecture reviews.

• Security design authority support.

• Secure by Design reviews.

• Solution security reviews.

• Threat modelling.

• Architecture governance.

• Security requirements definition.

• Architectural risk assessments.

Security Engineering

The Supplier shall provide:

• Technical security engineering.

• Security tool implementation.

• Security configuration reviews.

• Security hardening activities.

• Technical control implementation.

Strategy & Transformation

The Supplier shall provide:

• Security roadmap development.

• Target operating model development.

• Control framework assessments.

• Security maturity reviews.

• Improvement planning.

Governance & Assurance

The Supplier shall provide:

• Security assessments.

• Risk management support.

• Audit support.

• KPI development.

• Board reporting support.

• Security governance support.

• Independent design and control assurance.

• Security exception and risk acceptance reviews.

• Third party and supplier security assessments.

Notices

UK2: Preliminary market engagement notice

Notice identifier
2026/S 000-085261
Published
9 September 2026, 10:45am