Western Suffolk BOCES has issued Request for Proposal #25/26-47PI-MB for comprehensive network penetration and compromise assessment services targeting their IT infrastructure in Suffolk County, New York. The procurement seeks a qualified vendor to conduct a detailed security evaluation involving penetration testing on 10 external facing servers, 150 internal networked devices, and 5 wireless access devices. The comprehensive assessment requires vulnerability scanning across 1,550 endpoints, including 1,400 VDI clients, 100 servers, and 50 network devices, with the ultimate goal of identifying potential security vulnerabilities, network compromise evidence, and systemic security gaps. The proposal mandates delivering a detailed security report with recommended solutions, identifying potential distributed denial of service (DDoS) attack vulnerabilities, and providing 30 hours of professional service for system hardening and security remediation. Proposals are due on October 15, 2025, and will be evaluated across five key criteria: responsiveness (20%), experience (30%), implementation timeline (15%), cost proposal (25%), and references (10%). The contract will be awarded to the vendor best meeting Western Suffolk BOCES' needs, with the understanding that the lowest-cost proposal may not necessarily be selected. The RFP does not explicitly indicate specific set-aside designations or restrictions for disadvantaged enterprises. Vendors must complete several mandatory forms, including a W-9, insurance certification, references, and certifications related to sexual harassment prevention, Iranian energy sector divestment, and non-collusive bidding. While a specific budget range is not disclosed, the contract will be in effect from the date of award through project completion, not exceeding the prices submitted in the vendor's proposal. The cost summary sheet requires vendors to provide rates for multiple service components, including compromise assessment, penetration testing, phishing exercise and user awareness training, Microsoft 365 security assessment, wireless testing, best practices consultation, and hourly rates for additional project work outside the specified scope. Prospective vendors will need to demonstrate significant cybersecurity expertise, with professional certifications and proven experience in conducting comprehensive network security assessments likely being important qualitative factors in the evaluation process.
Name | Description | Size | Type (Click to sort descending) | Posted (Click to sort descending) |
|---|---|---|---|---|
Services for Network Penetration and Compromise Assessment RFP 25-26-47PI-MB.pdf | 789KB | 9/24/25 |