Tender Details
Expression of Interest for Operational Technology (OT) Vulnerability Management
Business Name
Seqwater
VP Reference #
VP460858
Buyers Reference #
06191
Opens
Thursday 22 May 2025 (E. Australia Standard Time)
Closes
Friday 13 June 2025 02:00 PM (E. Australia Standard Time) CLOSED
Supplier query cut-off
Friday 13 June 2025 02:00 PM (E. Australia Standard Time)
Expected decision
Tuesday 23 September 2025 (E. Australia Standard Time)
Buyer Details
Business Name
Seqwater
Location
117 Brisbane St
Ipswich, Queensland 4305
Australia
WebSite:
https://www.seqwater.com.au/
Business Info
Water is essential for life.

Seqwater is the Queensland Bulk Water Supply Authority responsible for delivering safe, secure and cost-effective bulk water supply for more than three million people across South East Queensland. We also:

* provide essential flood mitigation services
* manage catchment health and offer community recreation facilities
* provide water for irrigation to about 1,200 farmers across seven water supply schemes.

Seqwater is one of the largest water businesses with the most geographically spread and diverse asset base of any capital city water authority. Our operations extend from the New South Wales border to the base of the Toowoomba ranges.
Contact Details
The buyer has elected to have their personal and contact details hidden. These details will be revealed at the buyers discretion.
What the buyer is requesting
Details
Seqwater wishes to engage a suitably experienced and resourced Supplier who can provide vulnerability management solutions to report on vulnerabilities across the environment for Seqwater’s operating system within its Operational Technology (OT) Control systems.

Implementing a vulnerability management program provides a valuable opportunity to enhance cybersecurity, improve operational efficiency, and achieve a Maturity Level of 3.2 under the National Institute of Standards and Technology (NIST) Cybersecurity Framework 2.0. An alignment with the International Electrotechnical Commission (IEC) 62443 standards is highly desirable.
Background information / Compatibility requirements
Details
Refer to “06191 – Operational Technology (OT) Vulnerability Management - Expression of Interest Part 1 of 2" Section C - Scope of Works for further information
Desired Outcomes ('Nice to haves', Conditions & Warranties, SLA's, Project benefits)
Details
Refer to “06191 – Operational Technology (OT) Vulnerability Management - Expression of Interest Part 1 of 2" Section C - Scope of Works for further information
Supplier lists selected
Lists
  • IT & Telecomms
Categories selected
Categories
  • IT & Telecomms
    1: Hardware - Infrastructure
    2: Hardware - Networking Products
    3: Services - Architecture & Design
    4: Services - Cloud Services
    5: Services - Consultants
    6: Services - Internet of Things (IOT)
    7: Services - Maintenance Agreements
    8: Services - Security Management
    9: Services - Support
    10: Software - SaaS
Regions of Service
Locations
  • Queensland
    1: Brisbane

All Regions of Service locations are within Australia.
Information requested by others
23/May/2025 11:12 AM
Question:
Hi

Could you share any insights and differences( if any), on going to market with a second request for EoI on OT VM

The May EoI issue appears same as April issue apart from some minor differences.



thank you.

Answered on 23/May/2025 11:26 AM:


Good morning,

Seqwater advises that there were minor updates to all three documents released to market (between 06184 April and 06191 May). We therefore advise respondents to thoroughly review the amended documentation prior to submitting a response to the EOI.

Kind regards
23/May/2025 03:25 PM
Question:
If possible, could you specify the list of OT devices for which you want to perform vulnerability management? so that we can bid on this tender accordingly.

Answered on 26/May/2025 09:10 AM:


Seqwater will not define the list of OT devices at this stage. As per 06191 EOI Part 1, Section C Scope and Specification:

“A network detection and response (NDR) method will be used for detection. Scanning and assessment should be non-intrusive for OT devices.”
26/May/2025 09:54 AM
Question:
n the Protocol sheet of the Excel spreadsheet, there are several entries that appear to be brand or vendor-specific DCS/PLC solutions rather than actual communication protocols. Could you please clarify the protocol requirements. Thanks

Answered on 26/May/2025 01:53 PM:


Network Detection and Response (NDR) solutions must be capable of recognising and analysing protocols that are specifically used in Industrial Control Systems (ICS). This capability is essential for adapting to the evolving landscape of technology and ensuring that products remain relevant and effective in the future. By effectively identifying these specialised protocols, organisations can enhance their security posture, mitigate risks associated with industrial environments, and ensure ongoing compliance with emerging industry standards.
26/May/2025 02:40 PM
Question:
Hi

Will SEQ Water accept EoI responses from organisations that are currently undergoing ISO27001 assessment and can provide written evidence along with an expected certification date from the certifying organisation.

regards

Answered on 27/May/2025 12:06 PM:


In relation to 06191 EOI Part 2, Section 10. Strength of Cyber Security and Quality Management Systems and/ or Internal Quality Assurance Processes, the Respondent is to demonstrate the strength of their cybersecurity (via assurance framework, standards, or certification) with one (1) of the listed cyber security activities.

• SOC2 Type2 (Service Organization Control 2)

• IRAP ((Information Security Registered Assessors Program – Australia))

• ISO27001 and Statement of applicability (SOA)

• NIST (National Institute of Standards and Technology) CSF Self-Assessment

• International Electrotechnical Commission (IEC) 62443 certificate.

Where a Respondent is undergoing certification, written evidence should be provided to demonstrate that the Respondent’s policies, procedures, and practices align with the requirements of the relevant standard/certification.
26/May/2025 11:34 PM
Question:
To ensure compatibility and to better scope our solution, could you please confirm the operating systems installed on the OT (Operational Technology) devices mentioned in the tender? Specifically, if the OT devices run on Windows or Linux-based systems, we would be able to support this requirement effectively and proceed accordingly with our proposal.

Answered on 27/May/2025 12:07 PM:


Seqwater will not define the list of O/S. As per 06191 EOI Part 1, Section C Scope of Works and Specification:

“A network detection and response (NDR) method will be used for detection. Scanning and assessment should be non-intrusive for OT devices.”
27/May/2025 10:22 AM
Question:
Hi


Are you able to advise the no. of OT devices or an estimate as opposed to a list of devices ?

regards

Answered on 27/May/2025 12:08 PM:


Seqwater will not define the list of devices. As per 06191 EOI Part 1, Section C Scope of Works and Specification:

“A network detection and response (NDR) method will be used for detection. Scanning and assessment should be non-intrusive for OT devices.”
Updates made to this Request
02/Jun/2025 03:14 PM
In relation to Section 8 ‘Timetable’ the following amendment shall occur:

Delete: 2:00PM AEST on Friday 6 June 2025

Replace with: 2:00PM AEST Friday 13 June 2025

Summary of change: The EOI closing date and time has been extended for one (1) week.

02/Jun/2025 03:15 PM
Please note: The following addendum has been recently added.

1. Added: (Addendum) 06191 - Addendum 01.pdf

Please consider this addendum when responding.