Physical and Personnel Security Assessment for UK Telecoms
Department for Science, Innovation & Technology · Radio, TV & telecoms equipment · United Kingdom
What the buyer wants
The UK’s public telecommunications networks are a critical national infrastructure (CNI) subsector, underpinning the functioning of every other CNI sector, the digital economy, and essential public services, for which the Department for Digital, Culture, Media and Sport (DCMS) is the lead government department. Their continued availability, integrity and confidentiality are fundamental to national security, economic resilience, and the everyday lives of UK citizens and businesses.
Telecoms operators manage complex, large-scale, geographically distributed systems, including exchanges, data centres, transmission sites and access network assets , which are increasingly attractive targets for hostile state and state-aligned actors seeking to disrupt, degrade or exploit UK infrastructure. Physical compromise and insider threat are significant attack vectors that hostile actors could seek to exploit. Strengthening physical and personnel security across the sector is therefore a priority area of work for DCMS.
This Request for Information (RFI) is issued solely for preliminary market engagement purposes and does not constitute a call for competition, tender or contract opportunity. The Authority is seeking information to better understand market capability, capacity, security accreditation requirements and delivery approaches. Participation in this RFI will not confer any advantage or disadvantage in any future procurement process.
DSIT is exploring options for obtaining specialist support to undertake a physical and personnel security assessment of UK public telecommunications networks and services. We are seeking engagement from accredited security consultancy firms to conduct a sector-level physical and personnel security assessment of UK public telecoms networks and services. This should include assessment of current vulnerabilities and potential threat vectors, and set out a prioritised list of recommended mitigations for operators to reduce the risk of security compromise stemming from physical and personnel security vulnerabilities. This list of prioritised mitigations should identify how existing NPSA guidance can be applied to address telecoms sector vulnerabilities.
An estimated project commencement date is October 2026 , to conclude in February 2027, subject to a tender launch and agreed contract.
Some of the core deliverables are listed below:
A detailed report setting out:
(i) current physical and personnel security vulnerabilities within the UK’s public telecoms networks and services,
(ii) physical and personnel security threat vectors (i.e. how threat actors could exploit these vulnerabilities, not a threat assessment), and
(iii) a prioritised list of mitigations for operators to take to reduce the identified physical and personnel security risks - this should include identification of how existing NPSA guidance can applied to address telecoms sector vulnerabilities.
Still open in this sector
Browse open tenders
Stop finding out when someone else wins
Tell us what your firm does and we'll email the tenders you could win, while there's still time to bid. Free, no card.
Watch this for me