|
TO: |
Board of Trustees |
|
THROUGH: |
Jay Fox, Executive Director |
|
FROM: |
Alisha Garrett, Chief Enterprise Strategy Officer |
|
PRESENTER(S): |
Kyle Brimley, IT Director |
|
|
|
TITLE:

title
Contract: Managed Security Services and Incident Response (Optiv Security Inc.)
end

AGENDA ITEM TYPE:
Procurement Contract/Change Order

RECOMMENDATION:
Approve award and authorize Executive Director to execute the contract and associated disbursements with Optiv Security, Inc. in the amount of $1,181,127.23 over 5 years.

BACKGROUND:
Information Security and Cyber Security measures are critical to ensure UTA is in the best possible position to protect ourselves from potential risks and attacks. Over the last few years in order to increase UTA’s security posture, the Department of Information Technology has implemented edge firewalls, multi-factor authentication (MFA), cloud-based workstation and server endpoint security, AI-driven network threat detection and response, and other technologies. These systems generate thousands of events and event logs every second which are collected by a security information and event management system (SIEM) and need to be correlated to specific threats. Current staffing does not allow for continuous monitoring, which increases the risk of undetected threats. In the event of an incident, staff would need additional assistance in mitigating these threats.

DISCUSSION:
This managed security services contract and incident response retainer will augment the efforts of UTA IT staff by implementing a co-managed SIEM agreement where the contractor will assess and configure the SIEM to industry best practices which are tuned to the needs of UTA in a cooperative model. Once this has been accomplished, the contractor will take over 24/7/365 monitoring of the SIEM, correlating events to known and unknown activities, and performing threat hunting activities. Contractor will also perform break-fix, patching, upgrades, and work with the solution vendor when required. It is estimated 4 new FTEs would be required to provide the 24/7/365 monitoring, threat hunting, and response activities being offered under this contract.
The incident response retainer from contractor will augment IT staff in the event of a declared incident, providing industry expertise in dealing with cyber incidents, freeing IT staff to focus on disaster recovery and remediation efforts. If no incidents occur within the year from contract initiation, then UTA can utilize up to 72% of the yearly retainer amount for other proactive security services offered by the contractor.

CONTRACT SUMMARY:
|
Contractor Name: |
Optiv Security Inc. |
|
Contract Number: |
21-03463 |
|
Base Contract Effective Dates: |
5/1/2022-4/30/2025 |
|
Extended Contract Dates: |
Two 1-year option periods through 4/30/2027 |
|
Existing Contract Value: |
$0 |
|
Amendment Amount: |
N/A |
|
New/Total Contract Value: |
Year 1 $285,127.33, Year 2 $222,000, Year 3 $222,000, Year 4 (option) $225,000, Year 5 (option) $227,000. Total Value $1,181,127.33 |
|
Procurement Method: |
RFP |
|
Budget Authority: |
IT Operating Budget |
|
|
|
ALTERNATIVES:
The largest risk to UTA of not executing this contract would be the ability of current staff to provide the 24/7/365 security monitoring of the corporate network and systems. Providing this coverage would take an additional 4 FTEs.
For the IR Retainer portion of this contract, having experienced experts who have handled previous cyber incidents for other large organizations is critical for the ability to respond and recover in the shortest timeframe possible.

FISCAL IMPACT:
This service is budgeted in 5210 operational expense accounts.

ATTACHMENTS:
Contract