Procurement of IT Health Check and vulnerability scanning services
October 22, 2025 Joint Assistant Director: Communications and Customer Services (Officer) Approved View on council websiteFull council record
Content
Procurement of an IT Health Check (ITHC)
in-line with Public Sector Network (PSN) compliance requirements
and a non-exclusive arrangement to support IT web service
vulnerability scans in the following 12-months (capped by
value).
Reasons for the decision
It is good practice for all organisations to
perform IT security health checks (including "penetration tests")
on a regular basis to test existing security mechanisms and
identify vulnerabilities. The Council is specifically required to
seek such a test on an annual basis as part of the compliance
standards of being connected to the Public Sector Network
(PSN).
In addition, it is good practice for organisations to perform
targeted security checks ("vulnerability scans") following some
internet-facing web service changes.
This agreement will ensure the Council can align with good security
practices and meet the compliance standards of the Public Sector
Network, as well as providing the ability for the Council to
promptly conduct any internet-facing web service vulnerability
scans that may become necessary in the year. This helps the Council
protect both Council and resident data by identifying security
risks so they can be mitigated promptly.
Alternative options considered
Four companies listed on the National Cyber
Security Centre website as suppliers of CHECK Penetration Testing
services were offered the opportunity to quote for these
services.
Two companies responded to the request. Of these, NTA Monitor Ltd
(trading as Intertek NTA) provided the lowest price for a
PSN-aligned IT Health Check, and also provided the lowest day rate.
The highest price was within the price range received in the 2024
IT Health Check market evaluation, and the lowest day rate matched
the 2024 lowest day rate. It was therefore assumed that the market
price for the service has not changed much in the last year, and
that the lowest price option represented a competitive offer. NTA
Monitor Ltd was therefore recommended for award.
Details
| Outcome | Recommendations Approved |
| Decision date | 22 Oct 2025 |