FOI release

Procurement and cyber security

Case reference FOI2026/01497

Received 10 September 2026

Published 15 September 2026

Request

I am writing to request information under the Freedom of Information Act 2000 regarding the Council's procurement and use of cyber security services. Where available, please provide details for the current contract(s), supplier(s) and procurement arrangements relating to the following services. 1. Procurement Routes 1. Which procurement platform(s) does the Council use for IT and cyber security procurements (for example Contracts Finder, Proactis, YORtender, Chest, Delta eSourcing or similar)? 2. Which framework agreements does the Council typically use for cyber security services (for example G-Cloud, DOS, CCS frameworks, Bloom or equivalent)? 2. Penetration Testing and Security Testing Please provide: * Current supplier name(s) * Contract start date * Contract expiry date * Contract value or annual spend * Procurement route or framework used * Whether services include infrastructure, web application, mobile, cloud, CHECK, IT Health Check or other penetration testing services 3. Cyber Essentials and Cyber Essentials Plus Please provide: * Current supplier name * Contract value or annual spend * Contract start date * Contract expiry date * Procurement route or framework used 4. ISO 27001 Please provide details of any external supplier used for: * ISO 27001 consultancy * ISO 27001 implementation support * ISO 27001 internal audit * ISO 27001 certification preparation Including: * Supplier name * Contract value or annual spend * Contract expiry date * Procurement route used 5. PCI DSS Please provide details of any external supplier used for: * PCI DSS consultancy * PCI DSS QSA services * PCI DSS penetration testing * PCI DSS compliance support Including: * Supplier name * Contract value or annual spend * Contract expiry date * Procurement route used 6. Incident Response and Digital Forensics Please provide details of any external supplier used for: * Incident response retainers * Digital forensics retainers * DFIR services * Cyber breach response services Including: * Supplier name * Contract value or annual spend * Contract expiry date * Procurement route used 7. Future Procurement Activity Where known, please provide: * The expected renewal or re-procurement date for each service * Whether the Council currently expects to re-tender, extend or recompete the contract 8. Relevant Departments Please provide the name of the department or team responsible for: * Cyber Security / Information Security * ICT / IT Services * Procurement and Commercial Management

Response

1. Procurement Routes

  1.  Which procurement platform(s) does the Council use for IT and cyber security procurements (for example Contracts Finder, Proactis, YORtender, Chest, Delta eSourcing or similar)?

FTS and Delta if procuring from the open market


  2.  Which framework agreements does the Council typically use for cyber security services (for example G-Cloud, DOS, CCS frameworks, Bloom or equivalent)?
There is no 'typical' framework we use. We assess on a case-by-case basis.


2. Penetration Testing and Security Testing

Please provide:

     Current supplier name(s)
NTA Monitor
 
   Contract start date
Information not held as there is no contract. It’s a one-off service.
     Contract expiry
date Information not held as there is no contract. It’s a one-off service.
     Contract value or annual spend £8,100.00
     Procurement route or framework used
Direct award
 
   Whether services include infrastructure, web application, mobile, cloud, CHECK, IT Health Check or other penetration testing services
IT Health Check

3. Cyber Essentials and Cyber Essentials Plus

Please provide:

     Current supplier name
Information not held
 
   Contract value or annual spend
Information not held
     Contract start date
Information not held
 
   Contract expiry date
Information not held
     Procurement route or framework used
Information not held

4. ISO 27001

Please provide details of any external supplier used for:

 
   ISO 27001 consultancy
Information not held
     ISO 27001 implementation support
Information not held
 
   ISO 27001 internal audit
Information not held
     ISO 27001 certification preparation
Information not held

Including:

 
   Supplier name
Information not held
     Contract value or annual spend
Information not held
 
   Contract expiry date
Information not held
     Procurement route used
Information not held

5. PCI DSS

Please provide details of any external supplier used for:

 
   PCI DSS consultancy
     PCI DSS QSA services
 
   PCI DSS penetration testing
  *   PCI DSS compliance support
We do not purchase any external support for PCI DSS services


Including:

     Supplier name 
 
   Contract value or annual spend
     Contract expiry date
 
   Procurement route used

6. Incident Response and Digital Forensics

Please provide details of any external supplier used for:

     Incident response retainers
Information not held
 
   Digital forensics retainers
Information not held
     DFIR services
Information not held
 
   Cyber breach response services
Information not held

Including:

     Supplier name
Information not held
 
   Contract value or annual spend
Information not held
     Contract expiry date
Information not held
 
   Procurement route used
Information not held

7. Future Procurement Activity

Where known, please provide:

  *   The expected renewal or re-procurement date for each service

The decision on re-procurement would be taken around 6 months before the contract ends. This would also include the decision to extend if there are extensions available in the contract.
  *   Whether the Council currently expects to re-tender, extend or recompete the contract
As above


8. Relevant Departments

Please provide the name of the department or team responsible for:

     Cyber Security / Information Security
Mid Kent ICT
 
   ICT / IT Services
Mid Kent ICT
  *   Procurement and Commercial Management
Procurement

Documents

There are no documents for this release.

This is Tunbridge Wells Borough Council's response to a freedom of information (FOI) or environmental information regulations (EIR) request.