Contract award notice

Information

Published

Date of dispatch of this notice: 29/06/2021

External Reference: 2021-214347

TED Reference: 2021/S 126-334288

Contract award notice

Contract award notice

Results of the procurement procedure

Directive 2014/24/EU

Section I: Contracting authority

I.1)

Name and addresses

Health Service Executive (HSE)
N/A
Head Office
Naas
Millennium Park
IE
Contact person: Aisling O Brien
Telephone: +353 0
NUTS code:  IE -  IRELAND
Internet address(es):
Main address: http://www.hse.ie

I.2)

Joint procurement

The contract is awarded by a central purchasing body
I.4)

Type of the contracting authority

Body governed by public law
I.5)

Main activity

Health

Section II: Object

II.1)

Scope of the procurement

II.1.1)

Title

Managed Security Monitoring & Incident Response Service
Reference number:  HSE 16957
II.1.2)

Main CPV code

71356300  -  Technical support services
II.1.3)

Type of contract

Services
II.1.4)

Short description

Managed Security Monitoring & Incident Response Service
II.1.6)

Information about lots

This contract is divided into lots: no
II.1.7)

Total value of the procurement

Value excluding VAT:  511680.00  EUR
II.2)

Description

II.2.2)

Additional CPV code(s)

48732000  -  Data security software package
72212732  -  Data security software development services
72250000  -  System and support services
72253200  -  Systems support services
72261000  -  Software support services
72315000  -  Data network management and support services
II.2.3)

Place of performance

NUTS code:  IE -  IRELAND
Main site or place of performance:  
IRELAND
II.2.4)

Description of the procurement

Managed Security Monitoring & Incident Response Service
II.2.5)

Award criteria

Criteria below
Price
II.2.11)

Information about options

Options: no
II.2.13)

Information about European Union funds

The procurement is related to a project and/or programme financed by European Union funds: no

Section IV: Procedure

IV.1)

Description

IV.1.1)

Type of procedure

Award of a contract without prior publication of a call for competition in the Official Journal of the European Union in the cases listed below
  • Extreme urgency brought about by events unforeseeable for the contracting authority and in accordance with the strict conditions stated in the directive
Explanation
In the early hours of Friday 14th May 2021, the HSE became aware of a major cyber-attack which severely impacted ICT services across the HSE, voluntary hospitals and other organisations which rely on HSE infrastructure such as Tusla. The HSE’s ICT systems were impacted through the criminal infiltration of these systems using Conti Ransomware. As a result, all HSE ICT systems were shut down before 8am on Fri 14th May. This event was thought to be the most serious cyber-attack on the country’s critical infrastructure and a major incident response was triggered by HSE.
Healthcare services across the country were severely disrupted with real and immediate consequences for the thousands of people who require health services every day.
Given the seriousness of this attack and the impact it had on those people who are dependent on health services, the Board of the HSE immediately began work on putting in place an effective cyber-security incident-response team (CSIRT). Clear roles and responsibility were established which enabled internal coordination and fostered a united approach. The CSIRT acted as the recognised point for external coordination. The process was designed with a focus on damage-limitation to the HSE’s services, its data assets, its network, and its application infrastructure.
In the critical response to the Cyber attack, the OoCIO Head Security had an urgent requirement to seek assistance for provision of 24*365 managed service pertaining to the running of a Security Operations Centre to oversee the HSE’s endpoint security platform (McAfee)
This involved engagement by the CIO and the Security Operations team with existing HSE McAfee support partner to expand standard product support service out to a fully managed in-hours and out-of-hours monitoring/alerting/maintenance service.
HSE used the negotiated procedure without prior publication in accordance with Article 32(2)(c) of Directive 2014/24/EU to award this contract. The HSE is satisfied the tests permitting use of the negotiated procedure without prior publication (Article 32(2)(c)) were met, as set out below.
A. As far as is strictly necessary:
The contract awarded is proportionate to the HSE’s needs and is not a long-term supply arrangement.
B. There are genuine reasons for extreme urgency:
The Authority was responding to the Cyber-attack immediately because of public health risks presenting a genuine emergency.
C. The events that have led to the need for extreme urgency were unforeseeable:
The extent of the Conti Ransomware attack is thought to be the most serious cyber-attack on the country’s critical infrastructure. The level of impairment on hospitals, and other health institutions to provide treatment, could, certainly, not be foreseen and planned in advance, and thus constitute an unforeseeable event for the contracting authorities.
D. It was impossible to comply with the usual timescales in Directive 2014/24/EU:
It cannot be doubted that the immediate needs of the hospitals and health institutions to have their ICT systems effectively restored had to be met with all possible speed. It was judged to be a situation of extreme urgency making compliance with general deadlines impossible. Procurement following the usual timescales under Directive 2014/24/EU, including accelerated options, was impossible in this case as these timescales would not meet the public health needs and would put lives at risk.
E. The situation is not attributable to the contracting authority:
As documented above, the Conti Ransomware attack is the most serious cyber-attack on the country’s critical infrastructure and presented a serious risk to human life. The HSE acted proportionately and without delay in its response to this most serious cyber-attack.
IV.1.8)

Information about the Government Procurement Agreement (GPA)

The procurement is covered by the Government Procurement Agreement : yes
IV.2)

Administrative information

Section V: Award of contract

Contract No: 1

Title: Managed Security Monitoring & Incident Response Service

A contract/lot is awarded: yes
V.2)

Award of contract

V.2.1)

Date of conclusion of the contract

28/06/2021
V.2.2)

Information about tenders

Number of tenders received:  1
The contract has been awarded to a group of economic operators :  no
V.2.3)

Name and address of the contractor

Caveo Information Systems Ltd
Ellis Quay
Dublin 7
D07 EV81
IE
NUTS code:  IE -  IRELAND

The contractor is an SME : no
V.2.4)

Information on value of the contract/lot (excluding VAT)

Initial estimated total value of the contract/lot:  511680.00  EUR
Total value of the contract/lot:  511680.00  EUR

Section VI: Complementary information

VI.4)

Procedures for review

VI.4.1)

Review body

High Court of Ireland
Four Courts
Inns Quay
Dublin 7
IE