FOI release

Cybersecurity services for Herefordshire council

Some or all of the information requested was not provided because we didn't hold it.

Case reference FOI2026/02175

Received 10 September 2026

Published 28 September 2026

Request

I am writing to request information under the Freedom of Information Act 2000 regarding the Council's procurement and use of cyber security services. Where available, please provide details for the current contract(s), supplier(s) and procurement arrangements relating to the following services.

1. Procurement Routes

1. Which procurement platform(s) does the Council use for IT and cyber security procurements (for example Contracts Finder, Proactis, YORtender, Chest, Delta eSourcing or similar)?

2. Which framework agreements does the Council typically use for cyber security services (for example G-Cloud, DOS, CCS frameworks, Bloom or equivalent)?

2. Penetration Testing and Security Testing Please provide:

* Current supplier name(s)

* Contract start date

* Contract expiry date

* Contract value or annual spend

* Procurement route or framework used

* Whether services include infrastructure, web application, mobile, cloud, CHECK, IT Health Check or other penetration testing services

3. Cyber Essentials and Cyber Essentials Plus Please provide:

* Current supplier name

* Contract value or annual spend

* Contract start date

* Contract expiry date

* Procurement route or framework used

4. ISO 27001 Please provide details of any external supplier used for:

* ISO 27001 consultancy

* ISO 27001 implementation support

* ISO 27001 internal audit

* ISO 27001 certification preparation Including:

* Supplier name

* Contract value or annual spend

* Contract expiry date

* Procurement route used

5. PCI DSS Please provide details of any external supplier used for:

* PCI DSS consultancy

* PCI DSS QSA services

* PCI DSS penetration testing

* PCI DSS compliance support Including:

* Supplier name

* Contract value or annual spend

* Contract expiry date

* Procurement route used

6. Incident Response and Digital Forensics Please provide details of any external supplier used for:

* Incident response retainers

* Digital forensics retainers

* DFIR services

* Cyber breach response services Including:

* Supplier name

* Contract value or annual spend

* Contract expiry date

* Procurement route used

7. Future Procurement Activity Where known, please provide:

* The expected renewal or re-procurement date for each service

* Whether the Council currently expects to re-tender, extend or recompete the contract 8. Relevant Departments Please provide the name of the department or team responsible for:

* Cyber Security / Information Security

* ICT / IT Services

* Procurement and Commercial Management

I am not requesting personal information. Generic team names or departmental contact details are sufficient. Where information is already publicly available, please provide links to the relevant contract award notice, procurement record or contract register entry. Electronic response by email would be appreciated.

Response

I am writing to request information under the Freedom of Information Act 2000 regarding the Council's procurement and use of cyber security services.

Where available, please provide details for the current contract(s), supplier(s) and procurement arrangements relating to the following services.

1. Procurement Routes

  1.  Which procurement platform(s) does the Council use for IT and cyber security procurements (for example Contracts Finder, Proactis, YORtender, Chest, Delta eSourcing or similar)?

  2.  Which framework agreements does the Council typically use for cyber security services (for example G-Cloud, DOS, CCS frameworks, Bloom or equivalent)?

2. Penetration Testing and Security Testing

Please provide:

     Current supplier name(s)
     Contract start date
     Contract expiry date
     Contract value or annual spend
     Procurement route or framework used
     Whether services include infrastructure, web application, mobile, cloud, CHECK, IT Health Check or other penetration testing services

3. Cyber Essentials and Cyber Essentials Plus

Please provide:

     Current supplier name
     Contract value or annual spend
     Contract start date
     Contract expiry date
     Procurement route or framework used

4. ISO 27001

Please provide details of any external supplier used for:

     ISO 27001 consultancy
     ISO 27001 implementation support
     ISO 27001 internal audit
     ISO 27001 certification preparation

Including:

     Supplier name
     Contract value or annual spend
     Contract expiry date
     Procurement route used

5. PCI DSS

Please provide details of any external supplier used for:

     PCI DSS consultancy
     PCI DSS QSA services
     PCI DSS penetration testing
     PCI DSS compliance support

Including:

     Supplier name
     Contract value or annual spend
     Contract expiry date
     Procurement route used

6. Incident Response and Digital Forensics

Please provide details of any external supplier used for:

     Incident response retainers
     Digital forensics retainers
     DFIR services
     Cyber breach response services

Including:

     Supplier name
     Contract value or annual spend
     Contract expiry date
     Procurement route used

7. Future Procurement Activity

Where known, please provide:

     The expected renewal or re-procurement date for each service
     Whether the Council currently expects to re-tender, extend or recompete the contract

8. Relevant Departments

Please provide the name of the department or team responsible for:

     Cyber Security / Information Security
     ICT / IT Services
     Procurement and Commercial Management

I am not requesting personal information. Generic team names or departmental contact details are sufficient.

Where information is already publicly available, please provide links to the relevant contract award notice, procurement record or contract register entry.

Electronic response by email would be appreciated.

 

Answer: This Information is Not Held.

All the cyber security services referred to in this request are provided by Hoople under the SLA and are therefore not council contracts.

The SLA between Herefordshire Council and Hoople is detailed on the Herefordshire Council contracts register but it is not broken down by service.

Please see the contracts register linked below for more information:

Council contracts register and future opportunities - Herefordshire Council , please see Contract ID 000115.

For further information please contact the below email address:

enquiries@hoopleltd.co.uk

Documents

There are no documents for this release.

This is Herefordshire Council's response to a freedom of information (FOI) or environmental information regulations (EIR) request.

You can browse our other responses or make a new FOI request.