-
-
FOI request (FOIR-720158049)
Contracts for Firewall, Anti-virus, Microsoft Enterprise Agreement, and Power BI
Requested Wed 04 June 2025
Responded Wed 11 June 2025I am conducting a research project into how public sector organisations procure cyber security services and enterprise software platforms. As part of this, I would be grateful if you could provide the most recent contract information you hold for the following areas:
1. Standard Firewall (Network)
Firewall services that protect the organisation’s network from unauthorised access and other internet security threats.
2. Anti-virus Software Application
Programs designed to prevent, detect, and remove viruses, malware, trojans, adware, and related threats.
3. Microsoft Enterprise Agreement
A volume licensing agreement that may include:
Microsoft 365 (Office, Exchange, SharePoint, Teams)
Windows Enterprise
Enterprise Mobility + Security (EMS)
Azure services (committed or pay-as-you-go)
4. Microsoft Power BI
Or any alternative business intelligence platform used for data connectivity, dashboards, and reporting.
For each of the above areas, I kindly request the following:
1. Who is the existing supplier for this contract?
2. What is the annual spend for each contract?
3. What is the description of the services provided?
4. Primary brand (where applicable)
5. What is the start date of the contract?
6. What is the expiry date of the contract?
7. What is the total duration of the contract?
8. Who is the responsible contract officer? Please include at least their job title, and where possible, name, contact number, and direct email address.
9. How many licences or users are included (where applicable)?
Important Notes
I do not request any technical specifications such as device models, serial numbers, IP ranges, or site-level infrastructure details that may pose a security or operational risk.
If full disclosure of named personnel is not possible under Section 40 of the FOI Act, I would still appreciate disclosure of job titles and generic contact information, such as a team inbox or switchboard extension.
If any commercial sensitivities under Section 43 apply, I respectfully request a clear explanation of the specific harm expected from disclosing aggregated annual spend or supplier names, especially where the contract has already been awarded.
This request is made in line with the principles of the Procurement Act 2023, which reinforces the importance of transparency and public access to contract information, particularly around supplier identity, contract value, and duration.
Response
Contract 1 - Standard Firewall (Network)
1. Who is the existing supplier for this contract? - REFUSED
2. What is the annual spend for each contract? - REFUSED
3. What is the description of the services provided? - REFUSED
4. Primary brand (where applicable) - REFUSED
5. What is the start date of the contract? - April 2025
6. What is the expiry date of the contract? - April 2030
7. What is the total duration of the contract? - 5 Years
8. Who is the responsible contract officer? - Head of Information Technology
9. How many licences or users are included (where applicable)? - Not Applicable
Contract 2 - Anti-virus Software Application
1. Who is the existing supplier for this contract? - REFUSED2. What is the annual spend for each contract? - REFUSED
3. What is the description of the services provided? - REFUSED
4. Primary brand (where applicable) - REFUSED
5. What is the start date of the contract? - January 2025
6. What is the expiry date of the contract? - January 2026
7. What is the total duration of the contract? - 1 Year
8. Who is the responsible contract officer? - Head of Information Technology
9. How many licences or users are included (where applicable)? - Not Applicable
Contract 3 - Microsoft Enterprise Agreement
1. Who is the existing supplier for this contract? - REFUSED
2. What is the annual spend for each contract? - REFUSED
3. What is the description of the services provided? - REFUSED
4. Primary brand (where applicable) - REFUSED
5. What is the start date of the contract? - July 2025
6. What is the expiry date of the contract? - June 2028
7. What is the total duration of the contract? - 3 Years
8. Who is the responsible contract officer? - Head of Information Technology
9. How many licences or users are included (where applicable)? - Not Applicable
Contract 4 - Microsoft Power BI
1. Who is the existing supplier for this contract? - Information Not Held
2. What is the annual spend for each contract? - Information Not Held
3. What is the description of the services provided? - Information Not Held
4. Primary brand (where applicable) - Information Not Held
5. What is the start date of the contract? - Information Not Held
6. What is the expiry date of the contract? - Information Not Held
7. What is the total duration of the contract? Information Not Held
8. Who is the responsible contract officer? - Information Not Held
9. How many licences or users are included (where applicable)? - Information Not Held
Notice of Refusal
Disclosure of information relating to ICT systems, infrastructure and security constitutes a security risk as it would leave the Council's computer assets more vulnerable to a malicious hacking attack. This means that disclosure would:
• Make the Council more vulnerable to crime (Section 31)
• Risk harming the systems on which the day-to-day business of the Council relies (Section 43)
Section 31 (Law Enforcement) Section 31(1)(a) states that information is exempt if its disclosure is likely to prejudice the prevention or detection of crime. ICO guidance states that this can be used to protect information on a public authority's systems which would make it more vulnerable to crime.
This exemption can be used by a public authority that has no law enforcement function:
• To protect the work of one that does
• To withhold information that would make anyone, including the public authority itself, more vulnerable to crime
The crime in question would be a malicious attack on the Council's computer systems. Since the disclosure of the withheld information would make the Council's systems more vulnerable to such crime, the exemption is engaged.
The exemption is subject to the public interest test.
There is an overwhelming public interest in keeping the Council's computer systems secure which would be served by non-disclosure.
This outweighs the public interest in accountability and transparency that would be served by disclosure.
Section 43 (Commercial Interests) Section 43(2) states that information is exempt if its disclosure would, or would be likely to, prejudice the commercial interests of any person (including the public authority holding it).
Disclosure of information relating to ICT systems, infrastructure and security puts the council at risk of a malicious hacking attack. This would compromise the Council's ability to provide its services and carry out 'business-as-usual' should our systems be compromised. Were our systems to be compromise, the cost of a system recovery would be detrimental to the Council's commercial interests.
The exemption is subject to the public interest test.
There is an overwhelming public interest in keeping the Council's computer systems secure which would be served by non-disclosure.
This outweighs the public interest in accountability and transparency that would be served by disclosure.
-
-
Freedom of Information
Contact
Contact us if you have a question about democratic services.
Comments
The content on this page is the responsibility of our Democratic Services team.
