Disclosure Log

Contracts for Firewall, Anti-virus, Microsoft Enterprise Agreement, and Power BI (FOI/5933)

Message from Nottinghamshire County Council - 13 June 2025


Dear *****

Freedom of Information Request – Ref: FOI/00005933

Thank you for your email of 4 June 2025 where you requested information about our contracts for our firewall, anti-virus, Microsoft Enterprise agreement and Power BI.

The information, which can be disclosed, is:
 

1. Standard Firewall (Network)

Firewall services that protect the organisation’s network from unauthorised access and other internet security threats.

2. Anti-virus Software Application

Programs designed to prevent, detect, and remove viruses, malware, trojans, adware, and related threats.

3. Microsoft Enterprise Agreement

A volume licensing agreement that may include:
  • Microsoft 365 (Office, Exchange, SharePoint, Teams)
    Windows Enterprise
    Enterprise Mobility + Security (EMS)
    Azure services (committed or pay-as-you-go)
    4. Microsoft Power BI
Or any alternative business intelligence platform used for data connectivity, dashboards, and reporting.

For each of the above areas, I kindly request the following:
  1. Who is the existing supplier for this contract – Withheld (see below)
     
  2. What is the annual spend for each contract – Withheld (see below)
     
  3. What is the description of the services provided – IT Services and Licencing including Cyber Security Protection
     
  4. Primary brand (where applicable) – Withheld (see below)
     
  5. What is the start date of the contract – Firewall and Network 01/10/2024, AV – 11/12/2021, IT licences – 01/09/2021
     
  6. What is the expiry date of the contract Firewall and Network 30/09/2027, AV – 11/12/2025, IT licences – 31/08/2025
     
  7. What is the total duration of the contract Firewall and Network 3 years, AV and IT licences – 4 years
     
  8. Who is the responsible contract officer – Lorraine Dennis, (0115) 977 2248, [email protected]
     • Please include at least their job title, and where possible, name, contact number, and direct email address

     
How many licences or users are included (where applicable) – Approx 10,000


Some the information that you requested above is exempt under section 31 (law enforcement) of the Freedom of Information Act 2000 and is therefore withheld.

S31(1) provides, “Information which is not exempt information by virtue of section 31 is exempt information if its disclosure under this Act would, or would be likely to, prejudice – (a) the prevention or detection of crime”.
 
Applicable interests
 
There is a prejudice which could affect the council’s interests in the prevention or detection of crime.  This is therefore an applicable interest identified and therefore relevant to this exemption which it is designed to protect.
 
Nature of the prejudice
 
Turning to the nature of the prejudice, by disclosing the details of our vendors, suppliers or contracts the council considers that there is a real risk that this could have a detrimental effect on the prevention or detection of crime.
 
If disclosed, the information could be used by hackers, scammers, and other malicious actors to compromise the Council’s ICT systems and cyber security should not be disclosed to external organisations, partners or members of the public.  Examples of information which could be used by malicious actors include:
 
  • Use of external cyber/online security contractors, firms; and 
  • Details of ICT and cyber security systems, procedures, policies and contracts particular to the Council 
 
This list is not exhaustive and there are likely to be other potential prejudice caused in relation to the specific information that you have requested.
 
Likelihood of prejudice
 
Considering the above, I will now consider the likelihood of prejudice.  S31(1) states that information can be exempt where disclosure, “would, or would be likely to” cause prejudice.  In considering where prejudice, “would” occur, I conclude that the above circumstances is more probable than not and that there is a real and significant risk of prejudice in releasing the information requested.
 
In considering where prejudice, “would be likely” to occur, I conclude that there is a real and significant risk of the prejudice occurring even though the probability of such may fall short of being more probable than not.
 
Cybercrime and criminal activities are regularly linked to poor ICT security.  Based on this cyber criminals are likely to use the information that you have requested to attack council ICT systems for illegal purposes which would lead to a significant prejudice to the council who has a duty to consider the safety and security of the ICT systems it operates to support the delivery of council services. It is a realistic possibility that the information requested would or would likely lead to prejudice to the council as outlined in s31(1).
 
Public Interest Test
 
Having considered the prejudice test, I now turn to the public interest test which I am obliged to consider in relying on the qualified exemption at s31(1) to determine whether or not the information should nevertheless be disclosed.
 
In considering the public interest test, the council pays attention to the need to demonstrate openness, transparency and accountability to show citizens how public funds are spent and how activities are carried out by the council on their behalf.  This would allow better scrutiny by taxpayers.  Furthermore, openness with future competitors may lead to more competition and therefore better value for money for citizens.
 
However, in favour of maintaining the exemption, a council must be allowed to act to prevent or detect criminal activities as well as protect our ICT systems residents from being exposed to such.  There is a clear public interest in protecting our ICT systems from the impact of cybercrime.  It is also appropriate to take account of the cost of recovering from cybercrime activities.  Furthermore, the council must consider the effect on day-to-day services disrupted in the event of cybercrime.
 
In considering your request, I have considered the legislation and the ICO guidance on that legislation.
 
Having considered the public interest, the Council’s decision is therefore to withhold the information.



Your privacy: we use your personal information such as name and address so that we can comply with our legal obligations to respond to FOI requests.  For further details about the use of information about you, please see the information handling privacy notice on our website at https://www.nottinghamshire.gov.uk/media/4323566/informationgovernanceandinformationrightsprivacynotice.pdf.

If you are dissatisfied with the handling of your request, you have the right to ask for an internal review.  Internal review requests should be submitted within 40 working days of the date of receipt of the response to your original request and should be addressed to: Complaints and Information – Team Manager, Nottinghamshire County Council, County Hall, Loughborough Road, West Bridgford, NOTTINGHAM, NG2 7QP or [email protected].

Please remember to quote the reference number above in any future communications. 

If you are not content with the outcome of the internal review, you have the right to apply directly to the Information Commissioner for a decision.  The Information Commissioner can be contacted at: Information Commissioner’s Office, Wycliffe House, Water Lane, WILMSLOW, SK9 5AF or https://ico.org.uk/make-a-complaint/foi-and-eir-complaints/.

Yours sincerely

Colin Sawers (He/Him)
Information Case Officer | Customers, Complaints and Information
Chief Executive"s Department | Nottinghamshire County Council
County Hall | Loughborough Road | West Bridgford | NOTTINGHAM | NG2 7QP

Tel: (0115) 977 3714