Enhanced Security Operations Managed Service
Issued by STUDENT LOANS COMPANY · via UK Find a Tender Service
- Published
- 9 Sept 2026
- Reference
- 2026-TR-0109
- Location
- United Kingdom
- Sector
- IT & Telecom
- Type
- services
Details
The Student Loans company (SLC) have an agreement for Enhanced Security Operations Managed Service expiring April 2028. In order to provision for a retender of the agreement SLC are undertaking pre-market engagement with regards to the provision of the following:
- Requirement A: Enhanced Security Operations Managed Service - MXDR Service (2026-TR-0109a)
- Requirement B: Enhanced Security Operations Managed Service - Vulnerability Management (VM) Service (2026-TR-0109b)
- Requirement C: Enhanced Security Operations Managed Service - Breach Attack Simulation (BAS) Service (2026-TR-0109c)
- Requirement D: Enhanced Security Operations Managed Service - Cyber Threat Intelligence (CTI) Service (2026-TR-0109d)
- Requirement E: Enhanced Security Operations Managed Service - Digital Forensics and Incident Response (DFIR) Retainer Service (2026-TR-0109e)
- Requirement F: Enhanced Security Operations Managed Service - Security Architecture and Engineering Support Services (2026-TR-0109f)
SLC is considering an approach to the market to give the suppliers an option to bid for one or ALL of the contractual requirements. Requirement A Enhanced Security Operations Managed Service - MXDR Service The Supplier will provide a Managed Extended Detection and Response (MXDR) capability operating on a hybrid customer/supplier model. MXDR Service
The Supplier will provide:
- 24x7x365 monitoring of SLC security telemetry.
- L1 and L2 Security Operations Centre capability (SLC retain L3).
- Incident identification, triage and investigation.
- Security use-case monitoring and tuning.
- Management of Microsoft Sentinel detections.
- SOAR playbook execution and optimisation.
- Escalation management.
- Alert enrichment.
- Threat hunting capability.
- Malicious activity investigation.
- Service governance and performance management.
- Security reporting at operational, tactical and strategic levels.
Security Engineering (Operational)
The Supplier shall provide:
- L3 Engineering support for Sentinel.
- Analytics rule development and tuning.
- SOAR playbook management.
- Connector maintenance and health monitoring.
- Logging optimisation.
- Onboarding and validation of agreed log sources.
- Detection engineering support.
- Detection gap analysis and monitoring coverage reviews.
- Security use case development and continuous improvement.
- Monitoring health checks.
- Monitoring and remediation of ingestion issues.
- Security platform optimisation.
- Proactive automation support and development.
- Threat intelligence-led detection improvements.
Data Loss Prevention (DLP) & Phishing
The Supplier shall:
- Monitoring, triage and investigation of DLP, phishing, business email compromise (BEC), malicious email, malicious attachment and malicious URL alerts.
- Investigation of suspected data loss, data exfiltration and policy breach events.
- Support for user reported phishing submissions.
- Escalation and coordination of confirmed incidents in accordance with agreed response procedures.
- Identification and analysis of phishing campaigns, attacker infrastructure, indicators of compromise and emerging attack trends.
- Recommendations for improvements to DLP policies, email security controls, detections and response processes.
- Monthly reporting, trend analysis and security improvement recommendations.
Reporting
The Supplier shall provide:
- Weekly operational reports.
- Monthly service reports.
- Quarterly service reviews.
- KPI and SLA reporting.
- Security metrics and trend analysis.
Requirement B Enhanced Security Operations Managed Service - Vulnerability Management Service The Supplier shall provide Vulnerability Management services Monday to Friday, UK Core Hours (09:00-17:00). Vulnerability Management
The Supplier shall:
- Monitor vulnerability management queues.
- Investigate vulnerability notifications.
- Manage vulnerability triage.
- Validate vulnerability findings.
- Perform exploitability assessments.
- Provide remediation recommendations.
- Support exposure management activities.
- Support CTEM activities.
Stakeholder Engagement
The Supplier shall:
- Conduct monthly technical review meetings.
- Support resolver teams.
- Assist remediation planning.
- Review remediation performance.
- Provide vulnerability prioritisation guidance.
Dashboarding & Reporting
The Supplier shall:
- Maintain executive dashboards.
- Enhance Power BI reporting.
- Produce technical reports.
- Produce executive reports.
- Produce PCI compliance reports.
- Produce risk trending reports.
Tooling
The Supplier shall support:
- Microsoft Defender for Endpoint.
- Rapid7.
- SLC PCI ASV Scanning tooling.
- Jira.
- Power BI.
Requirement C Enhanced Security Operations Managed Service - Breach Attack Simulation Service The Supplier shall provide a Breach Attack Simulation (BAS) capability, currently using AttackIQ or similar. BAS Service
The Supplier shall:
- Operate and maintain the BAS platform.
- Deploy and maintain BAS agents.
- Configure integrations.
- Execute scheduled simulations.
- Execute customer-specific simulations.
- Execute retests following remediation activities.
Adversary Simulation
Testing scenarios shall include:
- Initial Access.
- Execution.
- Persistence.
- Privilege Escalation.
- Credential Access.
- Lateral Movement.
- Command and Control.
- Exfiltration.
- Malware.
- Ransomware.
- Advanced Persistent Threat activity.
Security Validation
The Supplier shall assess:
- Security control effectiveness.
- Security monitoring effectiveness.
- Detection coverage.
- Response capability.
- Incident handling.
- Use-case effectiveness.
Reporting
The Supplier shall produce:
- Monthly BAS reports.
- Executive summaries.
- Technical findings.
- Remediation recommendations.
- Retest outcomes.
Requirement D Enhanced Security Operations Managed Service - Cyber Threat Intelligence Service The Supplier shall provide strategic, operational and tactical Cyber Threat Intelligence services. Threat Intelligence Managed Service
The Supplier shall provide:
- Threat Intelligence reporting.
- Integration into Microsoft Sentinel.
- Indicator of Compromise feeds.
- Threat actor intelligence.
Operational Intelligence
The Supplier shall provide:
- Threat alerts.
- Vulnerability intelligence.
- Emerging threat notifications.
- Campaign tracking.
- Industry specific intelligence.
Strategic Intelligence
The Supplier shall provide:
- Threat landscape assessments.
- Quarterly threat reports.
- Executive intelligence briefings.
- Board level threat summaries.
- Sector specific threat reporting.
Security Operations Support
The Supplier shall provide:
- Intelligence support during incidents.
- Threat hunting support.
- Intelligence driven use-case creation.
- Intelligence enrichment services.
Requirement E Enhanced Security Operations Managed Service - Digital Forensics & Incident Response Retainer Service The Supplier shall provide a DFIR Retainer available 24x7x365. Cyber Incident Response
The Supplier shall provide:
- Incident investigation.
- Malware analysis.
- Threat containment.
- Threat eradication.
- Recovery support.
- Crisis management support.
- Regulator support.
- On-site support
Digital Forensics
The Supplier shall provide:
- Evidence acquisition.
- Chain of custody management.
- Endpoint forensics.
- Server forensics.
- Network forensics.
- Cloud forensics.
- Forensic reporting.
Readiness Services
The Supplier shall provide access to:
- Tabletop exercises.
- Incident simulations.
- Executive workshops.
- CSIRT training.
- Lessons learned reviews.
Retained Consultancy The Supplier shall provide specialist support including:
- Security strategy input.
- Audit support.
- Major incident reviews.
- Regulatory engagement support.
- Ransomware negotiation services.
Requirement F Enhanced Security Operations Managed Service - Security Architecture & Engineering Support Services The Supplier shall provide specialist Security Architecture and Engineering services on a call-off basis. Security Architecture
The Supplier shall provide:
- Security architecture reviews.
- Security design authority support.
- Secure by Design reviews.
- Solution security reviews.
- Threat modelling.
- Architecture governance.
- Security requirements definition.
- Architectural risk assessments.
Security Engineering
The Supplier shall provide:
- Technical security engineering.
- Security tool implementation.
- Security configuration reviews.
- Security hardening activities.
- Technical control implementation.
Strategy & Transformation
The Supplier shall provide:
- Security roadmap development.
- Target operating model development.
- Control framework assessments.
- Security maturity reviews.
- Improvement planning.
Governance & Assurance
The Supplier shall provide:
- Security assessments.
- Risk management support.
- Audit support.
- KPI development.
- Board reporting support.
- Security governance support.
- Independent design and control assurance.
- Security exception and risk acceptance reviews.
- Third party and supplier security assessments.
This notice has closed — what to do next
We hold 3 notices from STUDENT LOANS COMPANY, going back to August 2026 — 2 of them still open. They buy mostly in IT & Telecom and Education & Training. There are 118 open IT & Telecom tenders in United Kingdom.
Open now from this buyer
Open IT & Telecom tenders in United Kingdom
- 390_27 Document Management Solutions· closes 12 Oct
- UKRI Integration of AI/HPC with Quantum Computing (UK)· closes 4 Nov
- CA18426 - Paradigm Trust - provision of HR & MIS system & Payroll Services· closes 5 Oct
- Agenda for Change Job Evaluation Digital System· closes 5 Oct
- Yate Washdown Canopy· closes 19 Oct
Before you bid on this tender
A quick checklist to help you decide whether to bid and prepare a compliant submission for this it & telecom opportunity. Always verify the details on the official source.
- Confirm the closing date and submission window on the official portal before you start preparing your bid.
- Read the full notice and every attached document, including the scope, specifications and any bill of quantities or terms of reference.
- Check the eligibility criteria — prior similar experience, annual turnover, certifications and registrations — and make sure you qualify before investing effort.
- Prepare any earnest-money deposit (EMD) or bid security and the required formats early; missing or wrongly-formatted documents are a common cause of rejection.
- Note how bids must be submitted (online or physical), in what format, and whether a digital signature or portal registration is required.
- Watch for corrigenda and clarifications right up to the deadline — requirements and dates can change.
More IT & Telecom tenders
- Proposed Construction of ICT HUB at Chepsigot ASS.Chiefs OfficeKeiyo South constituency · Kenya
- Provision of Internet Service over Fiber Optic Infrastructure for UNMISS in Juba, South SudanUnited Nations Procurement Division · South Sudan
- Supply and Delivery of LED Lights to MONUSCO Entebbe Support Base, UgandaUnited Nations Procurement Division · Uganda
- Consulting for the strengthening of the system of physical and financial monitoring of public investment in HondurasInter-American Development Bank (IDB) · Honduras
- Antarctic and Southern Ocean Data Stewardship RFPNew Zealand Government · New Zealand
FreeTender mirrors this notice for reference. Verify the details and bid on the official portal.
Verify & apply on the official portal →