Appointment of a Service Provider to Conduct a Red Team Assessment

053/2025/EWSS/RED/TEAM/RFB

2025-10-09 11:00

Tender Closed on: 2025-10-30 11:00

https://tenderbulletins.co.za/tender-award/tender-award-appointment-of-a-service-provider-to-conduct-a-red-team-assessment/

Information and Communications Technology, IT Security Services and Solutions

Centurion, Gauteng, Pretoria

Trans-Caledon Tunnel Authority

Scroll down for tender details and to access the tender documents

Trans-Caledon Tunnel Authority Tenders

Account Functions

You will need an account login to View Tender Documents, Create a Business Listing on the site or to add your details to show your interest in joining a Joint Venture or working as subcontractor for this tender


  • Sign Up
Or Login Using
Please wait. Signing you in...
Or Login Using
Please wait. Signing you in...
Lost your password? Please enter your username or email address. You will receive a link to create a new password via email.
Tender Number: 053/2025/EWSS/RED/TEAM/RFB
Department: Trans-Caledon Tunnel Authority
Tender Type: Request for Bid(Open-Tender)
Province: Gauteng
Closing Date: Thursday, 30 October 2025 - 11:00
Place where goods, works or services are required: 1st Floor, Building No. 9, Byls Bridge Office Park, 11 Byls Bridge Boulevard - Highveld Extension 73, Centurion - Pretoria - 0045
Special Conditions: N/A
ENQUIRIES:
Contact Person: The Receiving Officer
Email: [email protected]
Telephone number: 012-683-1200
FAX Number: N/A
BRIEFING SESSION:
Is there a briefing session?: Yes Is it compulsory? NO
Briefing Date and Time: Thursday, 09 October 2025 - 11:00
Briefing Venue: Online via MS Teams

This tender is also available from www.etenders.gov.za


Tender Summary

Objectives

The primary objective of this tender is to appoint a qualified and experienced service provider to conduct a comprehensive Red Team Assessment for TCTA. This assessment aims to identify, validate, and ethically exploit security vulnerabilities across TCTA’s internal and external ICT environments. The outcomes will inform executive decision-making, enhance cybersecurity resilience, and support compliance with frameworks such as NIST, ISO/IEC 27001, and statutory requirements like POPIA and PFMA.

Scope

The scope encompasses planning, executing, and reporting on a multi-phase Red Team Assessment that includes:

  • Simulating external adversary attacks on internet-facing systems and infrastructure.
  • Internal network testing to assess insider threats, privilege escalation, and lateral movement.
  • Web application security testing against OWASP Top 10 and business logic vulnerabilities.
  • Physical security assessment, including social engineering techniques to evaluate physical access controls.
  • Testing of human factors through phishing, pretexting, tailgating, and on-site access simulations.
  • Controlled exploitation of vulnerabilities, with prior approval, excluding DoS/DDoS attacks.
  • Post-assessment remediation validation through re-testing and validation reports.

Technical Requirements

The assessment must be structured into five independent phases:

  1. External Penetration Testing: Simulate black-box attacks on internet-facing systems.
  2. Internal Network Testing: Assess insider threats, privilege escalation, and lateral movement.
  3. Web Application Testing: Evaluate web apps for OWASP Top 10 vulnerabilities and business logic flaws.
  4. Physical & Social Engineering: Conduct social engineering, physical access attempts, and onsite security evaluations.
  5. Remediation & Re-Testing: Verify that vulnerabilities are addressed and attack paths are closed, including follow-up re-tests.

Key conditions include controlled exploitation, prior approval for social engineering, immediate notification of critical findings, source IP whitelisting, and adherence to a Mutual Non-Disclosure Agreement.

Skills Requirements

  • Company Experience: Minimum of three (3) verifiable client references for similar Red Team assessments within the past five (5) years, demonstrating experience with external/internal network assessments, web application testing, and social engineering.
  • Personnel Expertise: The service provider must assign a Technical Lead with at least two (2) recognized certifications such as OSCP, OSWE, CREST CCSAS/CCSAM, ECSA, CISSP, or equivalent.
  • Technical Lead Qualifications: Demonstrated experience in penetration testing, adversarial simulation, and physical/social engineering assessments, supported by references and past engagement summaries.
  • Additional Personnel: The team should have expertise in ethical hacking, vulnerability assessment, physical security, and social engineering.

Furthermore, the provider must be able to provide CVs, proof of certifications, project experience summaries, and client references for verification. Replacement personnel must meet the same vetting standards.

Summary

This tender seeks a capable and experienced cybersecurity service provider to deliver a comprehensive, multi-phase Red Team Assessment aligned with international standards and local statutory requirements. The scope covers technical, human, and physical security testing, with an emphasis on controlled exploitation, validation, and remediation validation. The skills requirement emphasizes proven experience, recognized certifications, and demonstrable expertise in adversarial security testing.

This summary is AI generated. Download the tender documents for all the information.

How to Submit a Response / Quote to this Tender

The information needed for submitting your quote is in the description of the tender and the Tender Documents. You will also need documents and templates supplied by the entity that issued the tender, in order to supply the correct business and quote information.

To get the Tender Documents, click on the “Download Tender Documents” button below. This will take you to the Download page for this specific tender. To download the documents, you will need to create a Free Download account and then Login to this account. There is a Registration and Login form on the Download page, or above the tender description on this page. There are also Register and Login links at the top of all pages of this website.

Once you have the Tender Documents, complete them with your details and the quote details and submit to the entity or organisation that issued the tender. The details and method to submit are in the tender description and the tender documents.

Joint Ventures, Consortia and Subcontracting:

Most large tenders are composed of tasks in a number of different fields, and it is not always possible for a single company to cater for all of them, and therefore Joint Ventures and Consortia are formed to then submit a tender together.

Government tenders are also requiring the subcontracting of a percentage of the tender work, and the trouble is then finding Subcontractors to comply with the tender requirements

To assist companies with finding tender partners and subcontractors, you can now submit your contact details and company information on this page, so other interested parties can contact you for purposes of forming Joint Ventures and subcontracting

You will need to supply your details on every tender you are interested in tendering for. For this you need an active Business Listing - Register and Login at My Account to create a Business Listing

NOTE: This is not a tender application form, it is meant to facilitate the meeting of partners to form a Joint Venture or Subcontractor relationship for this tender only


To submit your details for this tender, you will need to Register an account - see the Registration form on this page or go to My Account

If you already registered, please login at My Account

You will also need to create a Business Listing in order to show your information here

Potential Subcontractor and Joint Venture Partners

To view a list of Businesses that match the Categories of this tender,
please Subscribe to a Paid Notification Plan

(If you are already a Paid Subscriber - not Trial, please Login to view this information on this tender)

Why not let us send tenders to your inbox?

from R120 per month