Award of a contract without prior publication of a call for competition in the Official Journal of the European Union in the cases listed below
- Extreme urgency brought about by events unforeseeable for the contracting authority and in accordance with the strict conditions stated in the directive
Explanation
In the early hours of Friday 14th May 2021, the HSE became aware of a major cyber-attack which severely impacted ICT services across the HSE, voluntary hospitals and other organisations which rely on HSE infrastructure such as Tusla. The HSE’s ICT systems were impacted through the criminal infiltration of these systems using Conti Ransomware. As a result, all HSE ICT systems were shut down before 8am on Fri 14th May. This event was thought to be the most serious cyber-attack on the country’s critical infrastructure and a major incident response was triggered by HSE.
Healthcare services across the country were severely disrupted with real and immediate consequences for the thousands of people who require health services every day.
Given the seriousness of this attack and the impact it had on those people who are dependent on health services, the Board of the HSE immediately began work on putting in place an effective cyber-security incident-response team (CSIRT). Clear roles and responsibility were established which enabled internal coordination and fostered a united approach. The CSIRT acted as the recognised point for external coordination. The process was designed with a focus on damage-limitation to the HSE’s services, its data assets, its network, and its application infrastructure.
In the critical response to the Cyber attack, the OoCIO Head Security had an urgent requirement to seek assistance for provision of 24*365 managed service pertaining to the running of a Security Operations Centre to oversee the HSE’s endpoint security platform (McAfee)
This involved engagement by the CIO and the Security Operations team with existing HSE McAfee support partner to expand standard product support service out to a fully managed in-hours and out-of-hours monitoring/alerting/maintenance service.
HSE used the negotiated procedure without prior publication in accordance with Article 32(2)(c) of Directive 2014/24/EU to award this contract. The HSE is satisfied the tests permitting use of the negotiated procedure without prior publication (Article 32(2)(c)) were met, as set out below.
A. As far as is strictly necessary:
The contract awarded is proportionate to the HSE’s needs and is not a long-term supply arrangement.
B. There are genuine reasons for extreme urgency:
The Authority was responding to the Cyber-attack immediately because of public health risks presenting a genuine emergency.
C. The events that have led to the need for extreme urgency were unforeseeable:
The extent of the Conti Ransomware attack is thought to be the most serious cyber-attack on the country’s critical infrastructure. The level of impairment on hospitals, and other health institutions to provide treatment, could, certainly, not be foreseen and planned in advance, and thus constitute an unforeseeable event for the contracting authorities.
D. It was impossible to comply with the usual timescales in Directive 2014/24/EU:
It cannot be doubted that the immediate needs of the hospitals and health institutions to have their ICT systems effectively restored had to be met with all possible speed. It was judged to be a situation of extreme urgency making compliance with general deadlines impossible. Procurement following the usual timescales under Directive 2014/24/EU, including accelerated options, was impossible in this case as these timescales would not meet the public health needs and would put lives at risk.
E. The situation is not attributable to the contracting authority:
As documented above, the Conti Ransomware attack is the most serious cyber-attack on the country’s critical infrastructure and presented a serious risk to human life. The HSE acted proportionately and without delay in its response to this most serious cyber-attack.
The procurement is covered by the Government Procurement Agreement
: yes