Issue a common brief
Give each bidder the same inventory, operating needs and outcomes. Explain your team, suppliers and products. State whether the work is new provision, co-managed support, a review or a transition. Include unknowns rather than letting each provider silently choose its own assumptions.
Compare operating models
- Platforms, populations, sources and hours.
- Named roles, subcontractors and escalation.
- Authority to make changes and contain incidents.
- Licences, retention, data location and export.
- Onboarding, continuity, reviews and exit.
Separate the commercial components
Identify assessment and onboarding, implementation, recurring fees, retained incident capacity and out-of-scope rates separately. Request assumptions about users, devices, accounts, event volumes and dependencies. No catalogue figure substitutes for an agreed proposal.
Check the evidence behind promises
Evaluate the named team, experience, insurance, delivery model and protections. Ask about partner delivery. A logo, tool licence or service title does not establish an operating team’s actual coverage.
Build your services RFP to match your platforms and support needs, or send an enquiry with your NDA or RFP.
Prepare a brief before the scoping call
Describe the technology you use, your existing security support and the outcomes you want. Review relevant service options, clarify operating responsibilities, then send the RFP with your NDA.
Use the free managed cybersecurity services brief builder to record objectives, assessment areas, constraints and NDA preferences. Review the proposed scope, then send it directly to Atlant Security through the contact form.

