This opportunity has closed

The submission deadline was July 10, 2026. This page is kept for reference purposes.

Ransomware Tabletop Exercise

Office of the Superintendent of Financial Institutions (OSFI)
canadabuys Posted: June 16, 2026

PROCUREMENT OVERVIEW The Office of the Superintendent of Financial Institutions (OSFI) is seeking solutions-based informatics professional services (SBIPS) to conduct a Ransomware Tabletop Exercise. The primary objective is to validate the operational readiness of OSFI's updated Corporate Incident M...

Read full summary
Due Date
July 10, 2026
(Overdue)
Solicitation #
20260158

Actions

Create a free account to analyze this opportunity, get daily notifications, and win more bids with Narwin.ai

Description

NOTICE OF PROPOSED PROCUREMENT (NPP) For Solutions-based informatics professional services (SBIPS) Requirement Details Tendering Procedure: Selective Tendering This requirement is open only to those SBIPS Supply Arrangement Holders who qualified under Tier 1 for services in the National Capital Region under the Domain of expertise of Security management. The following SA Holders have been invited to submit a proposal: 1) Accenture Inc. 2) CGI Information Systems and Management Consultants Inc. Systems and Management Consultants Inc. 3) CIMA+ S.E.N.C. 4) Compusult Limited 5) Deloitte Inc. 6) DONNA CONA INC., IBM CANADA LIMITED IN JOINT VENTURE 7) DXC TECHNOLOGY CANADA CO. 8) Ernst & Young LLP 9) Gartner Canada Co. 10) IBISKA Telecom Inc. 11) IBM Canada Limited/IBM Canada Limitée Limitée 12) IPSS INC. 13) IT/Net - Ottawa Inc. 14) IT/NET OTTAWA INC, KPMG LLP, in joint venture 15) KPMG LLP 16) Malarsoft Technology Corporation 17) MDOS CONSULTING INC. 18) Open Text Corporation 19) OPTIV CANADA FEDERAL INC. 20) Pricewaterhouse Coopers LLP 21) S.I. SYSTEMS ULC 22) T-REX SOLUTIONS LLC 23) Tata Consultancy Services Canada Inc. 24) TEKsystems Global Services Corp. 25) The Bell Telephone Company of Canada or Bell Canada/La Compagnie de Téléphone Bell duCanada ou Bell Canada 26) TPG Technology Consulting Ltd. 27) TRM Technologies Inc. 28) Wiz Management Inc Description of Work: OSFI is maturing its Business Continuity Management function and has updated its Corporate Incident Management capability that incorporates Incident Command System (ICS) incident management principles, and closely integrates actions associated with the transition from emergency and incident response to the continuance and/or recovery of business operations. OSFI has identified a requirement to validate the operational readiness of all layers of the revised corporate incident management capability by conducting a corporate incident response exercise with a scenario focused on a ransomware event. Security Requirement: See Request for Proposal Minimum Corporate Security Required: Secret Minimum Resource Security Required: Secret Contract Authority Name: Craig Kenny, Lead Senior Contracting Officer Email Address: [email protected] Inquiries Inquiries regarding this RFP requirement must be submitted to the Contracting Authority named above. Request for Proposal (RFP) documents will be e-mailed directly from the Contracting Authority to the Qualified Supply Arrangement Holders who are being invited to bid on this requirement. BIDDERS ARE ADVISED THAT “BUYANDSELL.GC.CA” IS NOT RESPONSIBLE FOR THE DISTRIBUTION OF SOLICITATION DOCUMENTS. The Crown retains the right to negotiate with any supplier on any procurement. Documents may be submitted in either official language. NOTE: For Solutions-based informatics professional services (SBIPS)Method of Supply is refreshed three (3) times per year. If you wish to find out how you can be a “Qualified SA Holder”, please contact [email protected]

Additional Information

Amendment Number

001

Contact Info Email

Contact Info Name

Craig Kenny

Contracting Entity Name

Office of the Superintendent of Financial Institutions (OSFI)

Created

June 18, 2026

Is Public

true

Organization Address City

Ottawa

Organization Country

Canada

Organization Address Line

255 Albert St

Organization Address Postal Code

K1A0H2

Organization Address Province

Ontario

Procurement Category

*SRV

Procurement Method

Competitive - Selective tendering

Reference Number

cb-553-91017696

Regions Of Delivery

*Canada

Regions Of Opportunity

*National Capital Region (NCR)

Selection Criteria

Highest Combined Rating of Technical Merit and Price

Source

canadabuys

Source Record ID

cb-553-91017696_001

Source System

canadabuys

Status

closed

Status En

closed

Summary Updated At

June 18, 2026

Tender Closing Date

July 10, 2026

Last Updated

July 10, 2026

Frequently Asked Questions

When is the proposal submission deadline?

The proposal submission deadline is July 10, 2026 (Overdue).

Note: This opportunity has already closed. See similar active opportunities above.

AI Summary

PROCUREMENT OVERVIEW

The Office of the Superintendent of Financial Institutions (OSFI) is seeking solutions-based informatics professional services (SBIPS) to conduct a Ransomware Tabletop Exercise. The primary objective is to validate the operational readiness of OSFI's updated Corporate Incident Management capability, which incorporates Incident Command System (ICS) principles. The exercise will focus on a ransomware scenario to ensure effective transition from incident response to business continuity and recovery.

ISSUING ORGANIZATION

The issuing organization is the Office of the Superintendent of Financial Institutions (OSFI), located in Ottawa, Ontario, Canada. The primary contact for this procurement is Craig Kenny, Lead Senior Contracting Officer, reachable at [email protected].

KEY DATES

  • Posted Date: June 16, 2026
  • Proposal Due Date: July 10, 2026
  • Anticipated Award Date: Not specified
  • Performance Period: Not specified

CONTRACT DETAILS

The procurement is structured as a selective tendering process, open only to Tier 1 SBIPS Supply Arrangement Holders within the National Capital Region. The contract type is not explicitly mentioned, and there is no estimated contract value provided.

MANDATORY REQUIREMENTS

Bidders must meet the following mandatory requirements:

  • Security Clearances: Minimum Corporate Security Required: Secret; Minimum Resource Security Required: Secret.
  • Eligibility: Open only to qualified SBIPS Supply Arrangement Holders listed in the opportunity.
  • Geographic Restrictions: Services must be provided within the National Capital Region (NCR).

TECHNICAL CAPABILITIES

Bidders should demonstrate expertise in:

  • Business Continuity Management
  • Incident Command System (ICS) principles
  • Cybersecurity, specifically related to ransomware scenarios
  • Experience in conducting corporate incident response exercises

DELIVERABLES AND PERFORMANCE STANDARDS

Key deliverables include:

  • A comprehensive tabletop exercise focused on a ransomware event.
  • Validation reports on operational readiness and incident management capability.
  • Recommendations for improvements based on exercise outcomes.

EVALUATION CRITERIA

Proposals will be evaluated based on a combined highest score for technical merit and price. Specific weighting is not provided, but technical approach and past performance are likely to be significant factors.

PREFERRED QUALIFICATIONS

While not mandatory, preferred qualifications that may enhance a bidder's competitiveness include:

  • Proven experience in conducting similar tabletop exercises for financial institutions or governmental organizations.
  • Relevant certifications in cybersecurity or business continuity (e.g., CISSP, CISM, CBCP).
  • Familiarity with OSFI regulations and standards.

This summary provides a comprehensive overview of the RFP for the Ransomware Tabletop Exercise, outlining the essential criteria and expectations for potential bidders.

Narwin.ai is a great way to find government contracts and opportunities. Disclaimer: This bid/tender/opportunity information is presented as is and may be incorrect at times. Please read the tender documents carefully before finalizing bids. We do not accept any responsibility and cannot be held legally liable for any inaccuracies.