The filed record
Non-Competitive Award of Contracts for IT and Cybersecurity Audits
The Public Gallery wrote no story on this item. What follows is the city’s own record of what happened to it, as filed: nothing on this page is summarised or scored by us.
The decision
2020-10-27 · Toronto City Council · adopted
As filed
City Council on October 27, 28 and 30, 2020, adopted the following: 1. City Council authorize the Auditor General to award new non-competitive contracts through her pre-qualified roster for IT and cybersecurity audit work, with the aggregate total amount of projects to exceed $500,000 if it is to conduct critical systems cybersecurity work.
On the agenda
As the city filed it
The City of Toronto, is increasingly conducting business and key operations using innovative technology solutions. This makes operations more efficient and enhances the delivery of City services to citizens and businesses. However, this comes with increased risk of cyberattacks and data breaches as threat actors are becoming more sophisticated with their attacks. The Auditor General recognizing the increased risks of cyberattacks has been proactive in performing cybersecurity audits at the City.
Show the rest of As the city filed it, 2,191 more characters as filed
Performing Information Technology (IT) penetration testing (Pen Testing) and vulnerability assessments (VA) is complex and requires highly trained IT security experts and specialized testing tools and software. Each tester must have a police security clearance to perform assessments on critical technology systems. In 2019, the Auditor General presented her report "Cyber Safety: A Robust Cybersecurity Program Needed to Mitigate Current and Emerging Threats" at the City Council meeting on October 29 and 30, 2019. At the meeting the recommendation "City Council request the City Manager, in consultation with the Auditor General, to report by the December 17 and 18, 2019 meeting of City Council on mechanisms required that would enable the Auditor General to conduct risk assessments or investigate cyber security for City Agencies and Corporations not currently within the Auditor General's purview" was adopted. To mitigate emerging cybersecurity threats the Auditor General increased the number of cybersecurity audits on her workplan. The Auditor General has now sole sourced several work assignments to the Firm that won a competitive bid in 2019 for a cybersecurity audit. We selected this Firm because the only other proponent that bid has since performed consulting work for the City, so there is an independence issue. The selected Firm has the expertise in cybersecurity and provided very competitive rates. The selected Firm is familiar with the current state of City system architecture and this knowledge is key. As most of the pre-qualified Firms have expressed little interest on bidding for these assignments, the Auditor General expects to continue to sole source such projects to the Firm. The Auditor General intends to revisit the sole source arrangement during latter half of 2021 to evaluate and determine other procurement choices. The Auditor General expects that the aggregate value of all contracts for various technology and cybersecurity audits at the City and its Agencies and Corporations may exceed $500,000 in total. Therefore, the purpose of this report is to keep Audit Committee and Council apprised of the non-competitive nature of these procurements.
Staff recommended
The Auditor General recommends that: 1. City Council authorize the Auditor General to award new non-competitive contracts through her pre-qualified roster for IT and cybersecurity audit work. The aggregate total amount of projects may exceed $500,000 if it is to conduct critical systems cybersecurity work.
Considered
2020-10-23 · Audit Committee · adopted
Decision as filed
The Audit Committee recommends that: 1. City Council authorize the Auditor General to award new non-competitive contracts through her pre-qualified roster for IT and cybersecurity audit work, with the aggregate total amount of projects to exceed $500,000 if it is to conduct critical systems cybersecurity work.
2020-10-27 · Toronto City Council · adopted
Clerk’s note
During the review of the Order Paper on October 27, 2020, City Council adopted a procedural motion to remove this Item from the Audit Committee and bring it forward to City Council for consideration.
On the record
More from this meeting
- Employee Health Benefits Fraud Involving a Medical SpaFiled record
- Audit of Winter Road Maintenance Program - Phase One: Leveraging Technology and Improving Design and Management of Contracts to Achieve Service Level OutcomesFiled record
- Strengthening Accountability and Outcomes for Affordable Housing: Understanding the Impact of the Affordable Home Ownership ProgramFiled record
- Continuous Controls Monitoring Program: Opportunities to Reduce Cost of Dental BenefitsFiled record
- Auditor General's Follow-Up of the Outstanding Recommendations - New Improved Automated ProcessFiled record
- Status of the Auditor General's Risk and Opportunity Assessment of the City and its Major Agencies and CorporationsFiled record