Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

County receives around 20 bids for cybersecurity risk-assessment contract; prices vary widely

2126309 · January 16, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Berkeley County opened bids for a cybersecurity risk-assessment contract advertised as a one-year service with options to renew for up to five years; county staff said about 20 firms submitted bids with 2025 prices ranging from roughly $21,320 to more than $1.2 million, and staff will review the submissions before recommending an award.

Berkeley County opened bids on a cybersecurity risk-assessment contract at the Jan. 14 commission meeting and reported unusually broad variation in price and bidder types.

County staff told commissioners the solicitation was widely advertised and that roughly 20 firms submitted proposals for a contract described as a one-year service with options to renew for up to five years. The bidding list included national professional-services firms, regional cybersecurity vendors and several smaller firms.

During the public readout, staff listed sample bids: some firms offered five-year lump-sum pricing in the low tens of thousands for the initial year (one firm’s listed 2025 price was $21,320), while other proposals — notably from some larger vendors — quoted six-figure or seven-figure annual fees (one large vendor’s 2025 figure exceeded $1.2 million in the readout). County staff said the wide spread reflects differing scopes and pricing models among bidders; some proposals included per-application testing fees in addition to base-year pricing.

County staff emphasized the assessment is intended to be an outside technical audit to identify vulnerabilities and recommend remediation steps. The county has performed limited internal work previously and said it now needs an external technical audit to align practices with peer jurisdictions.

No contract award was made at the meeting. Staff said they will complete a technical review and return to the commission with a recommendation. Commissioners and staff noted the need to match the county’s specific technical scope to any procurement recommendation so the county does not overpay for unnecessary services or underfund a comprehensive audit.

Why it matters: A cybersecurity risk assessment helps identify vulnerabilities in county networks, applications and systems; the selected vendor and scope will determine the depth of review and the county’s remediation roadmap.

Next steps: County staff will evaluate proposals for technical compliance, scope alignment and cost, then recommend an award at a future meeting.