Managed Detection and Response (MDR)
Denmark · Ballerup · how to bid here →
Your path to submission
- Deadline: 30 November at 13:00 — 58 days left.
- The submission point is stated in the notice (link on the right).
- Offer and evidence in: DAN.
- Collect your evidence — use the eligibility analysis above: it lists the requirements and, for known certificates, how to get them.
Foreign bidders
In Denmark · Business services, 41 contracts went to foreign companies over the last 3 years (of 492 recorded awards) — mostly from Germany, Italy, Ireland.
Typical field: median 5 (from 451 awards).
What the buyer is looking for
In order to protect the State's IT (Order) against current and future cyber threats, the Order uses a number of security technologies, including an Extended Detection and Response (XDR) platform. The XDR platform supports the collection, correlation and analysis of security-related incidents across the Customer's IT environment in order to protect systems, services and data as well as ensure the confidentiality, integrity and availability of data. In view of this, the Contracting Party offers a contract whose purpose is to support and strengthen the Contracting Party's own operational IT security through the provision of a Managed Detection and Response (MDR) service from a Security Operations Center (SOC). The MDR service shall use and complement the Client's XDR platform with 24/7 monitoring, analysis, detection, validation, escalation and management of security incidents. The service…
Show full description
… shall be provided 24 hours a day, 365 days a year, and shall contribute to the rapid identification, assessment and management of cyber threats and security incidents. The services constitute an essential element of the contracting entity’s continued cybersecurity maturation and development process, focusing on technology, processes, competencies and collaboration across internal and external stakeholders. With the tender, the Contracting Authority wishes to have access to a professional MDR service that can meet the Contracting Authority's high requirements for quality, robustness and efficiency, as well as a supplier that can continuously engage in dialogue with the Contracting Authority on developments in cybersecurity, including the threat landscape, technological opportunities, automation, competence development and continuous improvement of the security level. The supplier must implement a technical, organisational and procedural Transition Ind that ensures that the ongoing MDR services can be provided from the transition to the operational phase. The Contracting Authority points out that the Contracting Authority has entered into a contract with two (2) suppliers for the performance of the Contracting Authority's existing XDR platform, with which the supplier must cooperate in connection with Transition Ind. As part of this, the Supplier shall establish and configure the necessary integrations between the Contracting Entity’s XDR platform and other relevant security sources, as well as the Supplier’s tools and platforms used for the performance of the Contract. The Supplier shall provide Continuous MDR Services; including continuous monitoring, analysis, correlation, validation and detection of alarms and security incidents. The supplier shall triage and qualify alarms to identify real security incidents, as well as ensure timely escalation and alerting in accordance with agreed processes and service levels. These ongoing MDR services include: • Continuous SOC monitoring of security-related incidents and alarms. • Analysis, correlation and qualification of events across relevant data sources. • Identification, detection and validation of security incidents. • Preparation, implementation and continuous optimization of detection rules, use cases and analysis models. • Use of relevant Threat Intelligence to support detection and analysis work. • Continuous assessment of the threat landscape and its relevance to the contracting entity’s environment. • Proactive identification of potential security incidents and security risks, including through Threat Hunting activities. • Escalation, notification and reporting of security incidents according to agreed processes and service levels. • Maintenance of existing integrations and establishment of new integrations as needed. • Optimization and further development of the Client’s XDR platform and other security solutions. • Advice on the development and maturation of the Contracting Authority’s security organisation, security processes and governance. • Conducting targeted Threat Hunting courses and analysis of suspicious activities. • Incident Response assistance for security incidents upon requisition from the Client, including analysis, scoping, handling, disposing of
What you must prove — eligibility criteria
Ansøger skal i Bilag A indarbejde en liste over de fire (4) betydeligste sammenlignelige leverancer, jf. punkt 2.1.4 i udbudsbekendtgørelsen, som ansøger har udført i løbet af de sidste fem (5) år inden ansøgningsfristen. Hver reference må ikke indeholde mere … ▸▾
Contract
Who has won here before
| Company | Awards | Period |
|---|---|---|
| BT Global Services Belgium | 1 | 2026 |
| Bravida Danmark A/S | 1 | 2025 |