REOI - Cybersecurity Awareness Services
UNICC
REOI - Cybersecurity Awareness Services
Request for EOI
Reference:
UNICC/REOI/2026/00257
Beneficiary countries or territories:
Multiple destinations (see the Countries or territories tab)
Published on:
26-May-2026
Deadline on:
12-Jun-2026 18:00 (GMT 2.00)
Description
Deadline for submission of Expression of Interests is 12 June 2026. Responses must be submitted via InTend. Do not submit your responses via email.
In your response, please submit a completed Annex A and B.
----
Overview
The United Nations International Computing Center (UNICC) invites vendors to submit an Expression of Interest (EOI) for the provision of a Security Awareness and Human Risk Management Solution.
UNICC seeks to engage a vendor capable of delivering a comprehensive, SaaS-based security awareness platform to multiple United Nations Agencies through a centrally managed multi-tenant architecture. The solution is expected to support global, diverse environments and contribute to strengthening organizational security culture and reducing human cyber risk.
The envisaged solution shall enable UNICC and its partner agencies to move beyond compliance-based training towards a risk-driven, intelligence-led approach aligned with international best practices, including the SANS Security Awareness & Culture Maturity Model.
Key Functional Requirements
Vendors are expected to demonstrate capabilities in the following areas:
• Multi-Tenant Platform: A centralized environment enabling management of multiple agencies (tenants) with strict logical separation of data, configurations, and reporting, while providing global administrative oversight. The solution must be scalable to support additional organizations.
• Human Risk Intelligence: A centralized capability to aggregate and analyze behavioral data, phishing exposure, and user risk indicators, providing actionable insights and trends across the organization.
• Threat-Informed Content: Continuous delivery of up-to-date training content and phishing simulations based on real-world threats, attacker techniques, and social engineering campaigns.
• Campaign Management: Advanced capabilities to design, schedule, execute, and monitor awareness campaigns and phishing simulations across different user groups and organizational units.
• Reporting and Analytics: Multi-level reporting (operational, tactical, strategic) including user engagement, behavioral trends, risk reduction, and program maturity metrics. Export capabilities in standard formats (e.g., PDF, CSV).
• Risk-Based Training: Adaptive and targeted training programs based on user behavior and risk scoring, including automated remediation actions.
• Integration Capabilities: Support for integration with enterprise systems (e.g., identity providers such as Microsoft Entra ID and Google Workspace), including SSO, SCIM provisioning, and secure APIs for data exchange.
• Phishing Reporting: Native mechanisms enabling end users to report suspicious emails directly from their email clients.
• Multilingual Support: Availability of training content and simulations in multiple languages, including the six official United Nations languages.
• Content Management: Modular, role-based training content with embedded assessments, scoring, certification tracking, and continuous updates aligned with emerging threats.
• AI-Assisted Capabilities: Support for AI-driven creation and customization of awareness content and simulations.
• Service Delivery and Support: 24/7 platform availability and technical support, including SLA-driven incident handling and lifecycle support.
• Security and Compliance: Implementation of appropriate data protection and security controls, including encryption, access control, and audit logging.
UNICC intends to invite selected vendors to participate in a formal solicitation, via a Request for Proposals (RFP), at a later stage, for the above requirements. Complete details of the requirements will be included in the solicitation documents.
Email address:
procurement@unicc.org
First name:
Sara
Surname:
MASSARO
Telephone country code:
Switzerland (+41)
Telephone number:
41229291411
43233201
-
Authentication server software
43233203
-
Network security or virtual private network VPN management software
43233204
-
Network security and virtual private network VPN equipment software
43233205
-
Transaction security and virus protection software
80101507
-
Information technology consultation services
81111801
-
Computer or network or internet security
81112208
-
Security and protection software maintenance
81161501
-
Software application administration service
81161502
-
Network Account Administration Service
81161503
-
Network folder administration service
81161601
-
Instant Messaging Administration Service
81161701
-
Fax Administration Service
81161702
-
Fax Support Service
81161703
-
Mobile Telephone Administration Service
81161704
-
Mobile Telephone Support Service
81161705
-
Pager Administration Service
81161706
-
Pager Support Service
81161707
-
Telephone Administration Service
81161708
-
Telephone Support Service
81161709
-
Voice Mail Administration Service
81161710
-
Voice Mail Support Service
81161711
-
Videoconferencing service
81161712
-
Network voice service
81161713
-
Aeronautical Information Services
81161714
-
Aeronautical Fixed Telecommunication Network/Aeronautical Telecommunications Network Services (AFTN and ATN)
81161801
-
Data communication equipment or platform rental or leasing service
81162100
-
Cloud-based platform as a service
81162202
-
Cloud storage as a service