← Back to search results

AwardedFind a Tender · award

Security Operations Centre Services

Buyer: Financial Ombudsman Service →

BuyerFinancial Ombudsman Service
StatusAwarded
DeadlineNot published
ValueValue not published
Published12 Dec 2024

What is being bought

Contract for the provision of a managed Security Operations Centre (SOC) service to provide the following: 1. Provision of a modern and fit-for-purpose SOC capability operating 24 hours a day, 7 days a week, 365 days a year (working in concert with the Financial Ombudsman Service’s cyber security team); 2. Undertake standard security operations functions including: a) Performing triage of security incidents, core security incident response, and escalation activities (we refer to these as level 1 and 2 activities); b) Tuning/configuration of the Security Information & Event Management (SIEM) solution and associated Security Orchestration, Automation & Response (SOAR) capabilities; c) Responding to threat intelligence and performing proactive threat hunting; d) Management, investigation, and resolution of critical/major security incidents including digital forensics as required; and e) Conducting process improvement activities to improve the effectiveness of the SOC. 3. Provision of cyber security resources on demand to augment the Financial Ombudsman Service's team on an ad-hoc basis. These resources maybe involved in project or business as usual activities.

Delivery location

UK

Categories

IT services: consulting, software development, Internet and support 72000000

Lot details

Lot 1

Contract for the provision of a managed Security Operations Centre (SOC) service to provide the following: 1. Support of the existing SOC team to enable a modern and fit-for-purpose SOC capability operating 24 hours a day, 7 days a week, 365 days a year. We are looking for a supplier that can provide a SOC capability that functions over a 24-hour period, 7 days a week, 365 days a year. 2. Undertake standard security operations functions including: a) Performing triage of security incidents, core security incident response, and escalation activities (we refer to these as level 1 and 2 activities); b) Tuning/configuration of the Security Information & Event Management (SIEM) solution and associated Security Orchestration, Automation & Response (SOAR) capabilities; and c) Responding to threat intelligence and performing proactive threat hunting. The SOC service will tune and configure our SIEM tool on an ongoing basis. We expect the supplier to maintain an up to date knowledge of industry best practices and threat intelligence sources to inform the tuning and configuration process. In addition to this, we require the SOC capability to monitor and respond to alerts from the SIEM solution and manage any related incidents, liaising with the Financial Ombudsman Service team where required. 3. Management, investigation, and resolution of critical/major security incidents, including digital forensics as required. If we suffer a major security incident, we may ask the supplier to assist with the management, investigation, and resolution of it. This may involve attending the Financial Ombudsman Service’s offices. 4. Conducting agreed ongoing process improvement activities that will strengthen and improve the SOC’s ability to effectively detect and respond to the changing landscape of threats faced by the Financial Ombudsman Service and the financial services industry. 5. Provision of cyber security resources on demand to augment the Financial Ombudsman Service's team on an ad-hoc basis. These resources maybe involved in project or business as usual activities. Provision of information security resources to augment our existing information security team, as called-off by us on an ad-hoc basis. These resources may be involved in project or business as usual activities in the Cyber Security area. 

Statuscancelled

Award criteria
SOC Services — 55
Implementation — 15
Critical Incident Support — 10
Security Services — 5
Knowledge Transfer — 5
Team and Structure — 5
Values and CSR — 5
price — 70% Quality - 30% Price

What is included

ItemCategoryQuantity
1Not publishedNot published

Comparable-procurement analytics

Benchmarked against retained Find a Tender procedures with CPV division 72. The category anchor is IT services: consulting, software development, Internet and support (72000000); this is a deliberately broad market comparator. The comparison is shown at several levels rather than pretending one company or region is always the best benchmark.

Comparison setProceduresReported bids per procedureNamed award suppliersPrice evidence
Market: CPV division 7210,5392 median · 15.4 average (4,161 of 10,539 with a bid count)2 average (5,053 of 10,539 with named award suppliers)Not published
Same buyer45 median · 5 average (2 of 4 with a bid count)1 average (4 of 4 with named award suppliers)Not published
Delivery region: UK3,3232 median · 33.9 average (1,171 of 3,323 with a bid count)2.8 average (1,501 of 3,323 with named award suppliers)Not published

“Reported bids” is an official aggregate, sometimes reported per lot; it is the closest available competition measure. “Named award suppliers” are winners, not all applicants.

Price-outcome signal

Not enough comparable procedures currently publish both a GBP tender value and a usable lowest-valid-bid value to calculate a responsible price-reduction benchmark. Tenderline deliberately does not infer a saving from named award suppliers or from missing award values.

Procurement strategy & market signals

Framework agreementNot published
Dynamic purchasing systemNot published
Competitive procurementNot published
Recurring requirementNot published
Procurement method rationaleNot published
Rationale classificationsNot published
Special regimeNot published
Covered byNot published
Submission policyNot published
Selection criteriaNot published
Risk detailsNot published

Planning & early market engagement

BudgetNot published
No-engagement rationaleNot published
Planning documents0
Planning milestones0

No planning milestones published.

Related procurements

No linked framework, prior procurement or reprocurement published.

Awards

Contracts

Security Operations Centre

Statusactive
Value£1,146,500

Documents & submission route

No documents are published in the current source record.

Source data inventory

Diagnostic view. “Not published” means this current release does not provide a value.

OCIDocds-h6vhtk-041aea
Latest release ID040157-2024
Latest release timestampThu Dec 12 2024 16:31:36 GMT+0000 (Coordinated Universal Time)
Sourcefind-a-tender
Official notice URLNot published
Tender statuscomplete
Procurement methodselective
Procurement method detailsRestricted procedure
Main procurement categoryservices
Above thresholdNot published
Legal basis32014L0024
Tender period: startNot published
Tender period: endNot published
Expression of interest deadlineNot published
Enquiry deadlineNot published
Award period: startNot published
Award period: endNot published
Submission method detailsNot published
Submission languagesNot published
Electronic catalogue policyNot published
Total tender valueNot published
Tender lots in source1
Tender items in source1
Tender documents in source0
Awards in latest release1
Contracts in latest release1
Parties in latest release3

Notice history

DateEventReference
12 Dec 2024award, contract040157-2024
17 Nov 2023tender034127-2023

All source data

Unmodified official OCDS data retained by Tenderline for this procurement process.

Complete current OCDS release JSON
{
  "id": "040157-2024",
  "tag": [
    "award",
    "contract"
  ],
  "bids": {
    "statistics": [
      {
        "id": "1",
        "value": 4,
        "measure": "bids",
        "relatedLot": "1"
      },
      {
        "id": "2",
        "value": 1,
        "measure": "smeBids",
        "relatedLot": "1"
      },
      {
        "id": "3",
        "value": 4,
        "measure": "foreignBidsFromEU",
        "relatedLot": "1"
      },
      {
        "id": "4",
        "value": 4,
        "measure": "foreignBidsFromNonEU",
        "relatedLot": "1"
      },
      {
        "id": "5",
        "value": 4,
        "measure": "electronicBids",
        "relatedLot": "1"
      }
    ]
  },
  "date": "2024-12-12T16:31:36Z",
  "ocid": "ocds-h6vhtk-041aea",
  "buyer": {
    "id": "GB-FTS-21382",
    "name": "Financial Ombudsman Service"
  },
  "awards": [
    {
      "id": "040157-2024-1",
      "title": "Security Operations Centre",
      "status": "active",
      "suppliers": [
        {
          "id": "GB-FTS-132668",
          "name": "Littlefish (UK) Limited"
        }
      ],
      "relatedLots": [
        "1"
      ]
    }
  ],
  "tender": {
    "id": "ocds-h6vhtk-041aea",
    "lots": [
      {
        "id": "1",
        "status": "cancelled",
        "options": {
          "description": "Three year contract with three additional option years."
        },
        "hasOptions": true,
        "description": "Contract for the provision of a managed Security Operations Centre (SOC) service to provide the following:\n1. Support of the existing SOC team to enable a modern and fit-for-purpose SOC capability operating 24 hours a day, 7 days a week, 365 days a year.\nWe are looking for a supplier that can provide a SOC capability that functions over a 24-hour period, 7 days a week, 365 days a year.\n2. Undertake standard security operations functions including:\na) Performing triage of security incidents, core security incident response, and escalation activities (we refer to these as level 1 and 2 activities);\nb) Tuning/configuration of the Security Information & Event Management (SIEM) solution and associated Security Orchestration, Automation & Response (SOAR) capabilities; and\nc) Responding to threat intelligence and performing proactive threat hunting.\nThe SOC service will tune and configure our SIEM tool on an ongoing basis. We expect the supplier to maintain an up to date knowledge of industry best practices and threat intelligence sources to inform the tuning and configuration process.\nIn addition to this, we require the SOC capability to monitor and respond to alerts from the SIEM solution and manage any related incidents, liaising with the Financial Ombudsman Service team where required.\n3. Management, investigation, and resolution of critical/major security incidents, including digital forensics as required.\nIf we suffer a major security incident, we may ask the supplier to assist with the management, investigation, and resolution of it. This may involve attending the Financial Ombudsman Service’s offices.\n4. Conducting agreed ongoing process improvement activities that will strengthen and improve the SOC’s ability to effectively detect and respond to the changing landscape of threats faced by the Financial Ombudsman Service and the financial services industry.\n5. Provision of cyber security resources on demand to augment the Financial Ombudsman Service's team on an ad-hoc basis. These resources maybe involved in project or business as usual activities.\nProvision of information security resources to augment our existing information security team, as called-off by us on an ad-hoc basis. These resources may be involved in project or business as usual activities in the Cyber Security area. ",
        "awardCriteria": {
          "criteria": [
            {
              "name": "SOC Services",
              "type": "quality",
              "description": "55"
            },
            {
              "name": "Implementation",
              "type": "quality",
              "description": "15"
            },
            {
              "name": "Critical Incident Support",
              "type": "quality",
              "description": "10"
            },
            {
              "name": "Security Services",
              "type": "quality",
              "description": "5"
            },
            {
              "name": "Knowledge Transfer",
              "type": "quality",
              "description": "5"
            },
            {
              "name": "Team and Structure",
              "type": "quality",
              "description": "5"
            },
            {
              "name": "Values and CSR",
              "type": "quality",
              "description": "5"
            },
            {
              "type": "price",
              "description": "70% Quality - 30% Price"
            }
          ]
        }
      }
    ],
    "items": [
      {
        "id": "1",
        "relatedLot": "1",
        "deliveryAddresses": [
          {
            "region": "UK"
          }
        ]
      }
    ],
    "title": "Security Operations Centre Services",
    "status": "complete",
    "legalBasis": {
      "id": "32014L0024",
      "scheme": "CELEX"
    },
    "description": "Contract for the provision of a managed Security Operations Centre (SOC) service to provide the following:\n1. Provision of a modern and fit-for-purpose SOC capability operating 24 hours a day, 7 days a week, 365 days a year (working in concert with the Financial Ombudsman Service’s cyber security team);\n2. Undertake standard security operations functions including:\na) Performing triage of security incidents, core security incident response, and escalation activities (we refer to these as level 1 and 2 activities);\nb) Tuning/configuration of the Security Information & Event Management (SIEM) solution and associated Security Orchestration, Automation & Response (SOAR) capabilities;\nc) Responding to threat intelligence and performing proactive threat hunting;\nd) Management, investigation, and resolution of critical/major security incidents including digital forensics as required; and\ne) Conducting process improvement activities to improve the effectiveness of the SOC.\n3. Provision of cyber security resources on demand to augment the Financial Ombudsman Service's team on an ad-hoc basis. These resources maybe involved in project or business as usual activities.",
    "classification": {
      "id": "72000000",
      "scheme": "CPV",
      "description": "IT services: consulting, software development, Internet and support"
    },
    "procurementMethod": "selective",
    "mainProcurementCategory": "services",
    "procurementMethodDetails": "Restricted procedure"
  },
  "parties": [
    {
      "id": "GB-FTS-21382",
      "name": "Financial Ombudsman Service",
      "roles": [
        "buyer"
      ],
      "address": {
        "region": "UK",
        "locality": "London",
        "postalCode": "E14 9SR",
        "countryName": "United Kingdom",
        "streetAddress": "Exchange Tower, Harbour Exchange Square,"
      },
      "details": {
        "url": "http://www.financial-ombudsman.org.uk",
        "classifications": [
          {
            "id": "BODY_PUBLIC",
            "scheme": "TED_CA_TYPE",
            "description": "Body governed by public law"
          },
          {
            "id": "04",
            "scheme": "COFOG",
            "description": "Economic affairs"
          }
        ]
      },
      "identifier": {
        "legalName": "Financial Ombudsman Service"
      },
      "contactPoint": {
        "email": "procurement.enquiries@financial-ombudsman.org.uk",
        "telephone": "+44 02037169072"
      }
    },
    {
      "id": "GB-FTS-132668",
      "name": "Littlefish (UK) Limited",
      "roles": [
        "supplier"
      ],
      "address": {
        "region": "UK",
        "locality": "Nottingham",
        "postalCode": "NG1 1LS",
        "countryName": "United Kingdom",
        "streetAddress": "Price House, 37 Stoney Street"
      },
      "details": {
        "scale": "sme"
      },
      "identifier": {
        "legalName": "Littlefish (UK) Limited"
      }
    },
    {
      "id": "GB-FTS-132669",
      "name": "Financial Ombudsman Service",
      "roles": [
        "reviewBody"
      ],
      "address": {
        "locality": "London",
        "postalCode": "E14 9SR",
        "countryName": "United Kingdom",
        "streetAddress": "Exchange Tower"
      },
      "identifier": {
        "legalName": "Financial Ombudsman Service"
      }
    }
  ],
  "language": "en",
  "contracts": [
    {
      "id": "040157-2024-1",
      "title": "Security Operations Centre",
      "value": {
        "amount": 1146500,
        "currency": "GBP"
      },
      "status": "active",
      "awardID": "040157-2024-1",
      "dateSigned": "2024-12-06T00:00:00Z"
    }
  ],
  "initiationType": "tender"
}
Complete JSON history (2 releases)
12 Dec 2024 · 040157-2024 · award, contract
{
  "id": "040157-2024",
  "tag": [
    "award",
    "contract"
  ],
  "bids": {
    "statistics": [
      {
        "id": "1",
        "value": 4,
        "measure": "bids",
        "relatedLot": "1"
      },
      {
        "id": "2",
        "value": 1,
        "measure": "smeBids",
        "relatedLot": "1"
      },
      {
        "id": "3",
        "value": 4,
        "measure": "foreignBidsFromEU",
        "relatedLot": "1"
      },
      {
        "id": "4",
        "value": 4,
        "measure": "foreignBidsFromNonEU",
        "relatedLot": "1"
      },
      {
        "id": "5",
        "value": 4,
        "measure": "electronicBids",
        "relatedLot": "1"
      }
    ]
  },
  "date": "2024-12-12T16:31:36Z",
  "ocid": "ocds-h6vhtk-041aea",
  "buyer": {
    "id": "GB-FTS-21382",
    "name": "Financial Ombudsman Service"
  },
  "awards": [
    {
      "id": "040157-2024-1",
      "title": "Security Operations Centre",
      "status": "active",
      "suppliers": [
        {
          "id": "GB-FTS-132668",
          "name": "Littlefish (UK) Limited"
        }
      ],
      "relatedLots": [
        "1"
      ]
    }
  ],
  "tender": {
    "id": "ocds-h6vhtk-041aea",
    "lots": [
      {
        "id": "1",
        "status": "cancelled",
        "options": {
          "description": "Three year contract with three additional option years."
        },
        "hasOptions": true,
        "description": "Contract for the provision of a managed Security Operations Centre (SOC) service to provide the following:\n1. Support of the existing SOC team to enable a modern and fit-for-purpose SOC capability operating 24 hours a day, 7 days a week, 365 days a year.\nWe are looking for a supplier that can provide a SOC capability that functions over a 24-hour period, 7 days a week, 365 days a year.\n2. Undertake standard security operations functions including:\na) Performing triage of security incidents, core security incident response, and escalation activities (we refer to these as level 1 and 2 activities);\nb) Tuning/configuration of the Security Information & Event Management (SIEM) solution and associated Security Orchestration, Automation & Response (SOAR) capabilities; and\nc) Responding to threat intelligence and performing proactive threat hunting.\nThe SOC service will tune and configure our SIEM tool on an ongoing basis. We expect the supplier to maintain an up to date knowledge of industry best practices and threat intelligence sources to inform the tuning and configuration process.\nIn addition to this, we require the SOC capability to monitor and respond to alerts from the SIEM solution and manage any related incidents, liaising with the Financial Ombudsman Service team where required.\n3. Management, investigation, and resolution of critical/major security incidents, including digital forensics as required.\nIf we suffer a major security incident, we may ask the supplier to assist with the management, investigation, and resolution of it. This may involve attending the Financial Ombudsman Service’s offices.\n4. Conducting agreed ongoing process improvement activities that will strengthen and improve the SOC’s ability to effectively detect and respond to the changing landscape of threats faced by the Financial Ombudsman Service and the financial services industry.\n5. Provision of cyber security resources on demand to augment the Financial Ombudsman Service's team on an ad-hoc basis. These resources maybe involved in project or business as usual activities.\nProvision of information security resources to augment our existing information security team, as called-off by us on an ad-hoc basis. These resources may be involved in project or business as usual activities in the Cyber Security area. ",
        "awardCriteria": {
          "criteria": [
            {
              "name": "SOC Services",
              "type": "quality",
              "description": "55"
            },
            {
              "name": "Implementation",
              "type": "quality",
              "description": "15"
            },
            {
              "name": "Critical Incident Support",
              "type": "quality",
              "description": "10"
            },
            {
              "name": "Security Services",
              "type": "quality",
              "description": "5"
            },
            {
              "name": "Knowledge Transfer",
              "type": "quality",
              "description": "5"
            },
            {
              "name": "Team and Structure",
              "type": "quality",
              "description": "5"
            },
            {
              "name": "Values and CSR",
              "type": "quality",
              "description": "5"
            },
            {
              "type": "price",
              "description": "70% Quality - 30% Price"
            }
          ]
        }
      }
    ],
    "items": [
      {
        "id": "1",
        "relatedLot": "1",
        "deliveryAddresses": [
          {
            "region": "UK"
          }
        ]
      }
    ],
    "title": "Security Operations Centre Services",
    "status": "complete",
    "legalBasis": {
      "id": "32014L0024",
      "scheme": "CELEX"
    },
    "description": "Contract for the provision of a managed Security Operations Centre (SOC) service to provide the following:\n1. Provision of a modern and fit-for-purpose SOC capability operating 24 hours a day, 7 days a week, 365 days a year (working in concert with the Financial Ombudsman Service’s cyber security team);\n2. Undertake standard security operations functions including:\na) Performing triage of security incidents, core security incident response, and escalation activities (we refer to these as level 1 and 2 activities);\nb) Tuning/configuration of the Security Information & Event Management (SIEM) solution and associated Security Orchestration, Automation & Response (SOAR) capabilities;\nc) Responding to threat intelligence and performing proactive threat hunting;\nd) Management, investigation, and resolution of critical/major security incidents including digital forensics as required; and\ne) Conducting process improvement activities to improve the effectiveness of the SOC.\n3. Provision of cyber security resources on demand to augment the Financial Ombudsman Service's team on an ad-hoc basis. These resources maybe involved in project or business as usual activities.",
    "classification": {
      "id": "72000000",
      "scheme": "CPV",
      "description": "IT services: consulting, software development, Internet and support"
    },
    "procurementMethod": "selective",
    "mainProcurementCategory": "services",
    "procurementMethodDetails": "Restricted procedure"
  },
  "parties": [
    {
      "id": "GB-FTS-21382",
      "name": "Financial Ombudsman Service",
      "roles": [
        "buyer"
      ],
      "address": {
        "region": "UK",
        "locality": "London",
        "postalCode": "E14 9SR",
        "countryName": "United Kingdom",
        "streetAddress": "Exchange Tower, Harbour Exchange Square,"
      },
      "details": {
        "url": "http://www.financial-ombudsman.org.uk",
        "classifications": [
          {
            "id": "BODY_PUBLIC",
            "scheme": "TED_CA_TYPE",
            "description": "Body governed by public law"
          },
          {
            "id": "04",
            "scheme": "COFOG",
            "description": "Economic affairs"
          }
        ]
      },
      "identifier": {
        "legalName": "Financial Ombudsman Service"
      },
      "contactPoint": {
        "email": "procurement.enquiries@financial-ombudsman.org.uk",
        "telephone": "+44 02037169072"
      }
    },
    {
      "id": "GB-FTS-132668",
      "name": "Littlefish (UK) Limited",
      "roles": [
        "supplier"
      ],
      "address": {
        "region": "UK",
        "locality": "Nottingham",
        "postalCode": "NG1 1LS",
        "countryName": "United Kingdom",
        "streetAddress": "Price House, 37 Stoney Street"
      },
      "details": {
        "scale": "sme"
      },
      "identifier": {
        "legalName": "Littlefish (UK) Limited"
      }
    },
    {
      "id": "GB-FTS-132669",
      "name": "Financial Ombudsman Service",
      "roles": [
        "reviewBody"
      ],
      "address": {
        "locality": "London",
        "postalCode": "E14 9SR",
        "countryName": "United Kingdom",
        "streetAddress": "Exchange Tower"
      },
      "identifier": {
        "legalName": "Financial Ombudsman Service"
      }
    }
  ],
  "language": "en",
  "contracts": [
    {
      "id": "040157-2024-1",
      "title": "Security Operations Centre",
      "value": {
        "amount": 1146500,
        "currency": "GBP"
      },
      "status": "active",
      "awardID": "040157-2024-1",
      "dateSigned": "2024-12-06T00:00:00Z"
    }
  ],
  "initiationType": "tender"
}
17 Nov 2023 · 034127-2023 · tender
{
  "id": "034127-2023",
  "tag": [
    "tender"
  ],
  "date": "2023-11-17T15:15:28Z",
  "ocid": "ocds-h6vhtk-041aea",
  "buyer": {
    "id": "GB-FTS-98690",
    "name": "The Financial Ombudsman Service Limited"
  },
  "tender": {
    "id": "ocds-h6vhtk-041aea",
    "lots": [
      {
        "id": "1",
        "value": {
          "amount": 900000,
          "currency": "GBP"
        },
        "status": "active",
        "renewal": {
          "description": "A 3 year contract with the option to extend for a further 3 years in annual increments."
        },
        "hasOptions": false,
        "hasRenewal": true,
        "description": "The Financial Ombudsman Service intends to place a contract for the provision of a managed Security Operations Centre (SOC) service to provide the following: \n\n          \n1.\tSupport of the existing SOC team to enable a modern and fit-for-purpose SOC capability operating 24 hours a day, 7 days a week, 365 days a year.  \n\n          \nWe are looking for a supplier that can provide a SOC capability that functions over a 24-hour period, 7 days a week, 365 days a year. \n\n          \n2.\tUndertake standard security operations functions including: \na)\tPerforming triage of security incidents, core security incident response, and escalation activities (we refer to these as level 1 and 2 activities); \nb)\tTuning/configuration of the Security Information & Event Management (SIEM) solution and associated Security Orchestration, Automation & Response (SOAR) capabilities; and \nc)\tResponding to threat intelligence and performing proactive threat hunting. \nThe SOC service will tune and configure our SIEM tool on an ongoing basis. We expect the supplier to maintain an up to date knowledge of industry best practices and threat intelligence sources to inform the tuning and configuration process. \nIn addition to this, we require the SOC capability to monitor and respond to alerts from the SIEM solution and manage any related incidents, liaising with the Financial Ombudsman Service team where required. \n\n          \n3.\tManagement, investigation, and resolution of critical/major security incidents, including digital forensics as required. \nIf we suffer a major security incident, we may ask the supplier to assist with the management, investigation, and resolution of it. This may involve attending the Financial Ombudsman Service’s offices. \n\n          \n4.\tConducting agreed ongoing process improvement activities that will strengthen and improve the SOC’s ability to effectively detect and respond to the changing landscape of threats faced by the Financial Ombudsman Service and the financial services industry. \n5.\tProvision of cyber security resources on demand to augment the Financial Ombudsman Service's team on an ad-hoc basis.  These resources maybe involved in project or business as usual activities.\nProvision of information security resources to augment our existing information security team, as called-off by us on an ad-hoc basis. These resources may be involved in project or business as usual activities in the Cyber Security area. ",
        "secondStage": {
          "maximumCandidates": 5,
          "minimumCandidates": 5
        },
        "contractPeriod": {
          "durationInDays": 1080
        },
        "submissionTerms": {
          "variantPolicy": "notAllowed"
        },
        "selectionCriteria": {
          "description": "See procurement documents."
        }
      }
    ],
    "items": [
      {
        "id": "1",
        "relatedLot": "1",
        "deliveryAddresses": [
          {
            "region": "UKI"
          }
        ],
        "additionalClassifications": [
          {
            "id": "72400000",
            "scheme": "CPV",
            "description": "Internet services"
          },
          {
            "id": "72500000",
            "scheme": "CPV",
            "description": "Computer-related services"
          },
          {
            "id": "72600000",
            "scheme": "CPV",
            "description": "Computer support and consultancy services"
          }
        ]
      }
    ],
    "title": "Security Operations Centre (SOC)",
    "value": {
      "amount": 900000,
      "currency": "GBP"
    },
    "status": "active",
    "documents": [
      {
        "id": "economic",
        "documentType": "economicSelectionCriteria"
      },
      {
        "id": "technical",
        "documentType": "technicalSelectionCriteria"
      }
    ],
    "legalBasis": {
      "id": "32014L0024",
      "scheme": "CELEX"
    },
    "description": "The Financial Ombudsman Service intends to place a contract for the provision of a managed Security Operations Centre (SOC) service to provide the following: \n1. Provision of a modern and fit-for-purpose SOC capability operating 24 hours a day, 7 days a week, 365 days a year (working in concert with the Financial Ombudsman Service’s cyber security team); \n2. Undertake standard security operations functions including: \na) Performing triage of security incidents, core security incident response, and escalation activities (we refer to these as level 1 and 2 activities); \nb) Tuning/configuration of the Security Information & Event Management (SIEM) solution and associated Security Orchestration, Automation & Response (SOAR) capabilities; \nc) Responding to threat intelligence and performing proactive threat hunting; \nd) Management, investigation, and resolution of critical/major security incidents including digital forensics as required; and \ne) Conducting process improvement activities to improve the effectiveness of the SOC. \n3. Provision of cyber security resources on demand to augment the Financial Ombudsman Service's team on an ad-hoc basis.  These resources maybe involved in project or business as usual activities.",
    "secondStage": {
      "invitationDate": "2024-01-22T00:00:00Z"
    },
    "tenderPeriod": {
      "endDate": "2023-12-18T17:00:00Z"
    },
    "contractTerms": {
      "performanceTerms": "As stated within the draft Terms and Conditions as issued with the tender documents.",
      "hasElectronicPayment": true,
      "electronicInvoicingPolicy": "allowed"
    },
    "hasRecurrence": false,
    "classification": {
      "id": "72000000",
      "scheme": "CPV",
      "description": "IT services: consulting, software development, Internet and support"
    },
    "submissionTerms": {
      "languages": [
        "en"
      ],
      "bidValidityPeriod": {
        "durationInDays": 180
      }
    },
    "submissionMethod": [
      "electronicSubmission",
      "written"
    ],
    "procurementMethod": "selective",
    "mainProcurementCategory": "services",
    "submissionMethodDetails": "https://procurement.financial-ombudsman.org.uk/web/login.html",
    "procurementMethodDetails": "Restricted procedure"
  },
  "parties": [
    {
      "id": "GB-FTS-98690",
      "name": "The Financial Ombudsman Service Limited",
      "roles": [
        "buyer"
      ],
      "address": {
        "region": "UKI",
        "locality": "London",
        "postalCode": "E14 9SR",
        "countryName": "United Kingdom",
        "streetAddress": "Exchange Tower, Harbour Exchange Square,"
      },
      "details": {
        "url": "https://www.financial-ombudsman.org.uk",
        "classifications": [
          {
            "id": "BODY_PUBLIC",
            "scheme": "TED_CA_TYPE",
            "description": "Body governed by public law"
          },
          {
            "id": "04",
            "scheme": "COFOG",
            "description": "Economic affairs"
          }
        ]
      },
      "identifier": {
        "legalName": "The Financial Ombudsman Service Limited"
      },
      "contactPoint": {
        "url": "https://procurement.financial-ombudsman.org.uk/web/login.html",
        "email": "procurement.enquiries@financial-ombudsman.org.uk",
        "telephone": "+44 2037169072"
      }
    },
    {
      "id": "GB-FTS-21383",
      "name": "Financial Ombudsman Service",
      "roles": [
        "reviewBody"
      ],
      "address": {
        "locality": "London",
        "postalCode": "E14 9GE",
        "countryName": "United Kingdom"
      },
      "identifier": {
        "legalName": "Financial Ombudsman Service"
      },
      "contactPoint": {
        "email": "procurement.enquiries@financial-ombudsman.org.uk"
      }
    }
  ],
  "language": "en",
  "initiationType": "tender"
}