PS.
PublicSupply
account_balanceBuyersbusinessSuppliersdescriptionNotices

Procurement notices · Find a Tender + Contracts Finder

Notices

Every UK public-sector procurement notice in one board — open opportunities, closed tenders, awards, and pre-market signals. Filter by deadline, value or CPV, and save your search as an alert.

FiltersReset all
Quick views
  • All open noticesLive opportunities
  • Closing today / tomorrow
  • Closing this week
  • Newly published (24h)
  • High value (£10m+)
  • Awards · last 7 daysMarket signal
  • Pre-market signalsFuture procurements
  • Recently closedAwaiting outcome
  • All noticesEvery PA23 type
Type
  • All
  • Services
  • Supplies
  • Works
Deadline
  • Any
  • Closing in 24 hours
  • Closing this week
  • Closing this month
  • Closing in 90 days
Value
  • Any
  • £100k+
  • £1m+
  • £10m+
  • £100m+
Published
  • Any
  • Last 24 hours
  • Last 7 days
  • Last 30 days
Category
  • All categories
  • IT services
  • Software packages
  • Business services
  • Health & social
  • Construction work
  • Medical equipment
  • Architecture & engineering
  • Repair & maintenance
  • Financial services
  • Education & training
ActiveCategory: IT services×Value: £100m+×Clear all
verified_userData sourced from Contracts Finder, Find a Tender, and Companies House.
Contracts Finder ↗Find a Tender ↗Procurement Act 2023 ↗
Closing 24h
4
Open notices
Closing this week
5
Don’t miss
Open · all
74,930
Live opportunities
Posted · 24h
1
New notices
Posted · 30d
6,289
All notice types
Awarded · 7d
19
Market signal

Notice peek

×
FT
TenderFTS · 069b2e

First Cyber Security Tooling & Managed Services Tender

FIRST TRENITALIA WEST COAST RAIL LIMITED
Closes in
11d
17 Jun 2026
Estimated
£3.4m
Supplies
Published
18 May 2026

Key facts

Notice ID
ocds-h6vhtk-069b2e
CPV code
48730000 · Software packages
Contract type
Supplies
Source
Find a Tender

Timeline

  1. Published
    18 May 2026
  2. Submission deadline
    17 Jun 2026 · 11 days from now

Description

Lot - 1: FRH Cyber Security Tooling & Managed Services for GWR & AWC AI-powered managed cybersecurity is essential to counter a threat landscape marked by short attack timelines and sophisticated automated attacks. To address this, the organisation will procure a single integrated 24/7 managed security service covering Email Security, Network Detection and Response (NDR), Endpoint Detection and Response (EDR), and Security Information and Event Management (SIEM). The solution uses AI-driven automation, machine learning, and a managed SOC model to deliver real-time detection, triage, containment, and recovery across the estate. Automated detection and response reduce alert fatigue, cut mean time to respond (MTTR) and eliminate workflow bottlenecks that inhibit manual or traditional SOC operations. AI-powered response enables machine-speed containment for threats detected anywhere across the network, endpoint, email, and cloud services, while ensuring seamless integration of new and existing tooling. *- Strategic Objectives Enhance Threat Detection and Response Capabilities: Use AI-powered analysis and automation across email, endpoints, networks, and cloud environments for real-time detection and disruption of evolving threats, including zero-day attacks and business email compromise. The service provides real-time, data-driven insights and analytics, ensuring high-fidelity detection and response across all monitored domains. Reduce Dwell Time: AI automation enables rapid correlation and response, reducing dwell time from days to minutes in managed environments by minimising manual analysis lags and increasing accuracy through automated playbooks for containment actions. Ensure Regulatory Compliance: Continuous monitoring, automated reporting, and audit-grade response documentation support compliance mandates (e.g., GDPR, NIS2) and provide ready evidence for regulatory investigations. Ensure alignment and certification to industry best practices CSO/IEC 42001 (Artificial Intelligence Management System), ISO/IEC 27001 (Information Security Management System), ISO 22301 (Business Continuity Management System (BCMS)), Cyber Essentials, and Cyber Essentials Plus. Enable Proactive Defence: The solution supports automated threat hunting and anomaly detection to intervene early in the attack lifecycle, rather than relying solely on alert-based or reactive workflows. Optimise Resource Allocation: Automated detection and response to significantly reduce time spent dealing with email-based threats, allowing staff to focus on higher-value work. *- Scope of Services The organisation seeks a 24/7 fully managed security service covering: AI-driven Email Security, integrating threat intelligence and auto-remediation (using technologies such as Mimecast and Microsoft Defender). AI-driven NDR with behaviour analytics, automated response, and cloud app coverage (including M365, leveraging DarkTrace). AI-driven EDR integrated with SIEM, delivering automated detection, triage, and containment. AI-driven SIEM with unified log collection, AI-powered correlation, and enrichment from endpoint, network, and email telemetry. Wide compatibility and integration with common enterprise IaaS, PaaS and SaaS providers. Automated response and proactive threat hunting are built into the service. AI tunes out false positives in real time. NDR, EDR, and Email Security are orchestrated via SIEM, providing a centralised view and seamless handoff between detection, investigation, and response. *- Key Benefits Value for Money: Competitive tendering for integrated AI-driven managed services enables benchmarking, cost optimisation, and elimination of margin losses from operational inefficiency. Strengthening Security Capability and Outcomes: The solution delivers 24/7 managed detection and response with proven incident investigation, escalation, and rapid containment. Automated triage addresses >90% of alerts, moving human analysts to exception management and threat hunting. Reducing Operational and Delivery Risk: Relying on automated incident response closes the talent gap, addresses analyst burnout, and places delivery risk with suppliers that maintain AI-enhanced SOC capabilities. SLA-driven performance and machine-speed automated actions are formally contracted. Improving Governance, Auditability, and Transparency: Automated, AI-driven audit trails ensure end-to-end traceability of every incident, action, and management decision, enabling regulatory reporting and internal audit compliance. Enabling Scalability and Future Flexibility: AI-driven architecture processes thousands more alerts per day without proportional increases in headcount, supporting scale as business needs and threat volumes evolve. Supporting Compliance and Regulatory Obligations: The managed SOC operates within recognised frameworks (e.g., ISO 27001, ISO 42001, ISO 22301, Cyber Essentials and UK NIS and GDPR) and supplies compliance reporting and rapid incident response evidence proactively. Lot - 2 *- Strengthening Security Capability and Outcomes The scope of this procurement includes the replacement or renewal of several core cybersecurity capabilities, including: - Internet Security Gateway (ISG): Advanced inspection and protection of web traffic to mitigate malicious and high-risk internet activity - Zero Trust Network Access (ZTNA): Secure, identity- and context-based remote access, reducing reliance on legacy VPN solutions - Privileged Access Management (PAM): Control, monitoring, and auditing of privileged identities and access pathways (applicable to Group, Bus and Rail) - AI Governance and Control: Enforcement of policies governing access to internet-based AI services, SaaS platforms, and APIs to prevent unauthorised usage, data leakage, and compliance breaches - CASB and Data Loss Prevention (DLP): Protection of sensitive data across sanctioned and unsanctioned SaaS applications (applicable to Avanti West Coast) The solution must integrate seamlessly with FirstGroup's existing technology and security ecosystem, leveraging artificial intelligence and threat intelligence to enable continuous monitoring, automated policy enforcement, and proactive detection of emerging threats. *- Reducing Operational and Delivery Risk FirstGroup requires autonomous response and intelligent technical policy controls to reduce the operational burden on internal IT and security teams and address skills constraints within the organisation. Suppliers must demonstrate: - Mature and effective security governance frameworks - Robust operational controls and service management processes - Proven capabilities in incident management, access control, and service continuity Given the critical nature of the systems and data involved, cybersecurity is considered a material enterprise risk, and solutions must be resilient, secure, and aligned with best practices. *- Improving Governance, Auditability, and Transparency To ensure consistent assurance across all bidders, shortlisted suppliers will be required to complete the FirstGroup Supplier Information Security Assessment via the RiskXChange platform. This assessment evaluates supplier maturity across key domains, including: - SOC assurance and security operations - IT service management - Secure software development - Business continuity and disaster recovery - Identity and access management - Data protection and privacy - DDoS protection and cloud security governance This approach ensures a high standard of auditability, comparability, and transparency throughout the procurement process. *- Enabling Scalability and Future Flexibility The proposed solution must be scalable, adaptable, and future-ready, capable of supporting: - Evolving business requirements - Hybrid and distributed working models - Increasing adoption of cloud services and AI technologies Automation and AI-driven controls are expected to support a transition from reactive security operations to proactive and preventative security management, including dynamic policy enforcement across web, cloud, and AI service usage. *- Supporting Compliance and Regulatory Obligations Suppliers must provide certification with recognised industry standards, including: - ISO/IEC 27001 (Information Security Management) - ISO 22301 (Business Continuity Management) - ISO/IEC 42001 (Artificial Intelligence Management Systems) - UK NCSC-backed schemes Cyber Essentials and Cyber Essentials Plus In addition, the solution must support compliance with applicable UK regulations, including: - UK GDPR and the Data Protection Act, ensuring lawful, secure, and transparent processing of personal data - UK Network and Information Systems (NIS) Regulations, where applicable, including measures for risk management and incident reporting. *- Strategic Alignment of Tooling This procurement supports the delivery of Cyber Security Tooling for First Rail Holdings, including FirstGroup, FirstBus, FirstBus London, London Cable Car, Hull Trains, Lumo Trains, FirstRailLondon, Trams Operations Ltd (TOL), Air Coach, Avanti West Coast, Great Western Railway. The selected supplier will be responsible for delivering and managing an integrated, end-to-end security capability encompassing: - Internet access security - Cloud and AI governance - Privileged access management - Zero Trust connectivity This will improve overall security effectiveness, operational efficiency, organisational resilience, and regulatory compliance across participating operating companies.

You might also see

  • All FIRST TRENITALIA WEST COAST RAIL LIMITED notices →
  • All Software packages notices →
Open full notice ↗View in this tab
1 noticeopen · sorted by deadline ascending
Page 1
Time to close
Value
Type
Buyer
Notice
Closing in the next 30 days3 notices
16d
22 Jun
£2.0bn
Estimated
Tender
FTS · Services
HR
HM Revenue & Customs
HMRC Customer Relationship Management
Software packages· Published 27 May
17d
23 Jun
£750.0m
Estimated
Tender
FTS · Supplies
NS
NHS SHARED BUSINESS SERVICES LIMITED
Healthcare AI Solutions
Medical equipment· Published 11 May
27d
03 Jul
£4.0bn
Estimated
Tender
FTS · Works
SP
Scape Procure Scotland Ltd
SCAPE Scotland Construction Works and Services Framework
Construction work· Published 14 May
Beyond 30 days17 notices
31d
07 Jul
£750.0m
Estimated
Tender
FTS · Supplies
NS
NHS Shared Business Services Limited
Healthcare AI Solutions
Medical equipment· Published 28 May
34d
10 Jul
£1.0bn
Estimated
Tender
FTS · Services
YP
Yorkshire Purchasing Organisation
Software Application Solutions 2
Software packages· Published 18 May
151d
04 Nov
£200.0m
Estimated
Tender
FTS · Services
TM
The Minister for the Cabinet Office acting through Crown Commercial Service
Extension of existing Dynamic Purchasing System for Artificial Intelligence DPS
IT services· Published 17 Jul
162d
15 Nov
£10.0bn
Estimated
Tender
FTS · Services
TM
The Minister for the Cabinet Office acting through Crown Commercial Service
Extension of existing Dynamic Purchasing System for Automation Marketplace DPS
IT services· Published 17 Jul
168d
22 Nov
£100.0m
Estimated
Tender
FTS · Services
CG
CADENT GAS LIMITED
Cadent Gas IT Consultancy & IT Technical Capability Dynamic Purchasing System
IT services· Published 22 Nov
173d
27 Nov
£800.0m
Estimated
Tender
FTS · Services
CC
Crown Commercial Service
Demand Management and Renewables
Petroleum & fuel· Published 27 Sept
237d
29 Jan
£127.2m
Estimated
Tender
FTS · Services
UU
UNITED UTILITIES WATER LIMITED
Continuous Water Quality Monitoring (CWQM)
Architecture & engineering· Published 02 Feb
248d
09 Feb
£500.0m
Estimated
Tender
FTS · Services
TM
The Minister for the Cabinet Office acting through Crown Commercial Service
Facilities Management and Workplace Services DPS
Transport equipment· Published 14 Dec
252d
13 Feb
£800.0m
Estimated
Tender
FTS · Services
TM
The Minister for the Cabinet Office acting through Crown Commercial Service
Cyber Security Services 3 Extension Notice
IT services· Published 14 Nov
454d
03 Sept
£500.0m
Estimated
Tender
FTS · Services
GA
Guy's and St Thomas' NHS Foundation Trust
Immersive, Simulation and Related Technologies Dynamic Purchasing System
Education & training· Published 17 Aug
454d
04 Sept
£260.0m
Estimated
Tender
FTS · Services
TM
The Minister for the Cabinet Office acting through Crown Commercial Service
Communications Marketplace DPS
Printed matter· Published 12 Jan
478d
27 Sept
£150.0m
Estimated
Tender
FTS · Services
TM
The Minister for the Cabinet Office acting through Crown Commercial Service
Construction Professional Services DPS
Repair & maintenance· Published 29 Sept
699d
05 May
£500.0m
Estimated
Tender
CF
BW
BISHOP WILKINSON CATHOLIC EDUCATION TRUST
A DPS for sustainable and ethically sourced goods and services, delivering social value in local communities
Mining & minerals· Published 09 May
701d
08 May
£500.0m
Estimated
Tender
FTS · Services
BW
BISHOP WILKINSON CATHOLIC EDUCATION TRUST
A DPS for sustainable and ethically sourced goods and services, delivering social value in local communities
Mining & minerals· Published 09 May
701d
08 May
£500.0m
Estimated
Tender
FTS · Services
BW
BISHOP WILKINSON CATHOLIC EDUCATION TRUST
A DPS for sustainable and ethically sourced goods and services, delivering social value in local communities'
Mining & minerals· Published 09 May
853d
06 Oct
£400.0m
Estimated
Tender
FTS · Services
WG
Welsh Government
Rural Support Dynamic Purchasing System (DPS)
Agriculture & forestry· Published 28 Oct
980d
10 Feb
£216.0m
Estimated
Tender
FTS · Services
TM
The Minister for the Cabinet Office acting through Crown Commercial Service
Space Enabled and Geospatial Services Extension Notice
Radio & TV equipment· Published 19 May