Services for Network Penetration and Compromise Assessment

Solicitation # 252647PIMB
Posted 9/24/25, 12:00 AM
No Updates
Due 10/15/25, 3:00 PM
Source
View
Similar Opportunities
The Western Suffolk Board of Cooperative Educational Services (BOCES), located in Suffolk County, New York, is seeking a comprehensive Video Management Software (VMS) solution through RFP #25/26-40P-SIE5-CP. The procurement involves a turn-key installation of an integrated video surveillance system with advanced analytics and AI capabilities across multiple educational facilities including Brennan, WTDH, JEA ES, JEA Jr/Sr HS, Manor Plains, Taukomas, WT Republic, and WT Northport. The required...
Wake County Public School System (WCPSS) Technology Services Department has issued Request for Proposal #251-26-167 for external and internal network penetration testing services, seeking qualified vendors to conduct comprehensive network security assessments across their enterprise networks. The procurement targets a vendor capable of testing up to 100 hosts in mixed technology environments, including Windows, Linux, UNIX, legacy SCADA systems, and IoT devices, with the primary goal of...
The State University of New York (SUNY) has issued a Request for Proposal (RFP 25/26-034MC) seeking qualified internet service providers to establish a robust 10 Gbps internet connectivity and Distributed Denial-of-Service (DDoS) mitigation service for Stony Brook University. The procurement aims to enhance internet redundancy, performance, and security through a new Internet Service Provider (ISP) connection located in Syracuse, NY, which will provide geographic and carrier diversity. Key...
The New York Board of Elections has initiated a state contract opportunity for Managed Security Services, seeking a comprehensive cybersecurity solution to be delivered through a vendor's Pro Offering. The primary objectives include establishing 24x7x365 monitoring of the entire technological environment, enabling near real-time threat detection and response, and improving cyber resilience through AI-driven security operations center (SOC) automation. The procurement specifically targets...
The Suffolk County Water Authority (SCWA) has issued a Request for Proposal (RFP No. 1667) seeking consulting advisory services for a comprehensive Human Capital Management (HCM) Technology Assessment. This procurement opportunity is specifically targeting professional consulting services to evaluate and potentially enhance the organization's human resources technology infrastructure. The RFP requires interested bidders to submit comprehensive proposals electronically through...

Western Suffolk BOCES has issued Request for Proposal #25/26-47PI-MB for comprehensive network penetration and compromise assessment services targeting their IT infrastructure in Suffolk County, New York. The procurement seeks a qualified vendor to conduct a detailed security evaluation involving penetration testing on 10 external facing servers, 150 internal networked devices, and 5 wireless access devices. The comprehensive assessment requires vulnerability scanning across 1,550 endpoints, including 1,400 VDI clients, 100 servers, and 50 network devices, with the ultimate goal of identifying potential security vulnerabilities, network compromise evidence, and systemic security gaps. The proposal mandates delivering a detailed security report with recommended solutions, identifying potential distributed denial of service (DDoS) attack vulnerabilities, and providing 30 hours of professional service for system hardening and security remediation. Proposals are due on October 15, 2025, and will be evaluated across five key criteria: responsiveness (20%), experience (30%), implementation timeline (15%), cost proposal (25%), and references (10%). The contract will be awarded to the vendor best meeting Western Suffolk BOCES' needs, with the understanding that the lowest-cost proposal may not necessarily be selected.

The RFP does not explicitly indicate specific set-aside designations or restrictions for disadvantaged enterprises. Vendors must complete several mandatory forms, including a W-9, insurance certification, references, and certifications related to sexual harassment prevention, Iranian energy sector divestment, and non-collusive bidding. While a specific budget range is not disclosed, the contract will be in effect from the date of award through project completion, not exceeding the prices submitted in the vendor's proposal. The cost summary sheet requires vendors to provide rates for multiple service components, including compromise assessment, penetration testing, phishing exercise and user awareness training, Microsoft 365 security assessment, wireless testing, best practices consultation, and hourly rates for additional project work outside the specified scope. Prospective vendors will need to demonstrate significant cybersecurity expertise, with professional certifications and proven experience in conducting comprehensive network security assessments likely being important qualitative factors in the evaluation process.

Generated 9/24/25, 6:38 PM