The Public GalleryToronto

General Government and Licensing Committee · 2020-07-07 · 2020.GL14.20

The filed record

Non-Competitive Contract for the Provision of Ransomware Resilience Framework and Governance with KPMG LLP

The Public Gallery wrote no story on this item. What follows is the city’s own record of what happened to it, as filed: nothing on this page is summarised or scored by us.

The decision

2020-07-28 · Toronto City Council · adopted

As filed

City Council on July 28 and 29, 2020, adopted the following: 1. City Council authorize the Chief Information Security Officer to negotiate and enter into a non-competitive agreement with KPMG for a period of an eight (8) month term in the amount of $1,978,007 net of Harmonized Sales Tax ($2,012,820, net of Harmonized Sales Tax recoveries) to develop an effective ransomware resilience framework and governance, on terms and conditions satisfactory to the Chief Information Security Officer and in a form satisfactory to the City Solicitor.

Show the rest of As filed, 911 more characters as filed

2. City Council direct Confidential Attachment 1 to the report (June 22, 2020) from the Chief Information Security Officer and the Chief Purchasing Officer be publicly released when the ransomware risks have been remediated and at the discretion of the Chief Information Security Officer and the City Solicitor. Confidential Attachment 1 to the report (June 22, 2020) from the Chief Information Security Officer and the Chief Purchasing Officer remains confidential at this time in accordance with the provisions of the City of Toronto Act, 2006, as it pertains to the security of property belonging to the City of Toronto. Confidential Attachment 1 to the report (June 22, 2020) from the Chief Information Security Officer and the Chief Purchasing Officer will be made public when the ransomware risks have been remediated and at the discretion of the Chief Information Security Officer and the City Solicitor.

On the agenda

As the city filed it

The purpose of this report is to seek City Council authority for the Chief Information Security Officer to negotiate and enter into a non-competitive agreement with KPMG LLP (KPMG) for professional services for an eight (8) month term. The Services are required immediately to enhance the City's ransomware resilience in order to minimize the impact attackers could cause if they managed to penetrate the City's technology defenses.

Show the rest of As the city filed it, 1,008 more characters as filed

It is essential to build an effective ransomware resilience framework and governance to enhance the City's capacity to sustain operations and deliver services to its citizens through a cyberattack while minimizing both disruption and reputational harm. Due to time constraints of having these services begin immediately, a competitive call process cannot be done. The total cost of the agreement with KPMG to build the ransomware resilience framework and governance is $1,978,007 net of Harmonized Sales Tax ($2,012,820, net of Harmonized Sales Tax recoveries). City Council approval is required in accordance with Municipal Code Chapter 195- Purchasing, where the current request exceeds the Chief Purchasing Official's authority of the cumulative five year commitment for each vendor, under Article 7, Section 195-7.3 (D) of the Purchasing By-Law or exceeds the threshold of $500,000 net of HST allowed under staff authority as per the Toronto Municipal Code, Chapter 71- Financial Control, Section 71-11A.

Staff recommended

The Chief Information Security Officer and the Chief Purchasing Officer recommend that: 1. City Council grant authority to the Chief Information Security Officer to negotiate and enter into a non-competitive agreement with KPMG for a period of an eight (8) month term in the amount of $1,978,007 net of Harmonized Sales Tax ($2,012,820, net of Harmonized Sales Tax recoveries) to develop an effective ransomware resilience framework and governance, on terms and conditions satisfactory to the Chief Information Security Officer and in a form satisfactory to the City Solicitor.

Show the rest of Staff recommended, 221 more characters as filed

2. City Council direct that the information in the confidential attachment be released when the ransomware risks have been remediated and as the discretion of the Chief Information Security Officer and the City Solicitor.

Considered

  • 2020-07-07 · General Government and Licensing Committee · adopted

    Decision as filed

    The General Government and Licensing Committee recommends that: 1. City Council grant authority to the Chief Information Security Officer to negotiate and enter into a non-competitive agreement with KPMG for a period of an eight (8) month term in the amount of $1,978,007 net of Harmonized Sales Tax ($2,012,820, net of Harmonized Sales Tax recoveries) to develop an effective ransomware resilience framework and governance, on terms and conditions satisfactory to the Chief Information Security Officer and in a form satisfactory to the City Solicitor.

    Show the rest of Decision as filed, 328 more characters as filed

    2. City Council direct that the information in the confidential attachment to the report (June 22, 2020) from the Chief Information Security Officer and the Chief Purchasing Officer be released when the ransomware risks have been remediated and as the discretion of the Chief Information Security Officer and the City Solicitor.

  • 2020-07-28 · Toronto City Council · adopted

On the record

The item as the City filed it

More from this meeting

The whole meeting