Southern Water has gone to market for a single supplier to run a combined Managed Detection and Response (MDR) service across both its Corporate/IT and Operational Technology environments — 24/7/365 monitoring of the systems that actually run pumps, valves and treatment works, not just the office network. It's a small contract by AMP8 standards, but it's a meaningful signal: OT cyber security is now being procured in its own right, not folded into a wider IT framework as an afterthought.
Southern Water has published a Find a Tender notice for a Managed Detection and Response (MDR) service — a single supplier providing continuous monitoring, threat detection and triage across the company's Corporate/IT estate and its Operational Technology (OT) environment. The estimated contract value is £10m. Submissions close at 4:00pm on 21 September 2026, with an estimated award decision date of 27 November 2026. The contract itself doesn't start until 1 July 2027, running to 30 June 2030, with two further extension options that could take it through to 30 June 2032.
What makes this tender worth flagging isn't the value — £10m is modest next to the multi-hundred-million capital delivery frameworks that usually lead AMP8 tender news. It's the scope. Southern Water is explicitly asking for a service that covers OT — the industrial control systems, SCADA platforms and instrumentation that run pumps, valves, treatment processes and network telemetry — with the same rigour as its office IT. That's a distinct and still relatively rare procurement category in the water sector, where OT security has historically been bundled into broader IT services contracts, addressed piecemeal by individual system vendors, or left under-resourced altogether.
The scope is a 24/7/365 MDR service spanning both environments — meaning the successful supplier needs genuine OT security expertise, not just a general SOC (Security Operations Centre) capability retrofitted to cover industrial systems. Southern Water already runs an existing security tooling estate, including Nozomi Networks and Cisco Cyber Vision for OT visibility, and CrowdStrike for endpoint detection on the IT side. The MDR provider is expected to consume and integrate telemetry from this existing stack rather than replace it by default — though the notice does allow tenderers to propose solutions for any material gaps they identify in the current tooling.
This is an important detail for bidders. Southern Water isn't asking suppliers to build a security stack from scratch — it's asking them to operate and extend one that already exists. Suppliers who can demonstrate native integration with Nozomi Networks, Cisco Cyber Vision and CrowdStrike, rather than proposing to swap them out, are likely to be viewed more favourably on cost and disruption grounds. Firms tied to a single vendor ecosystem that doesn't play well with this stack should factor that into their bid strategy early.
Water and wastewater treatment works are critical national infrastructure, and the operational technology running them — pumps, valves, dosing systems, SCADA — has a very different risk profile to a standard corporate network. An IT breach might mean stolen data; an OT breach at a treatment works can mean a genuine public health or environmental incident. Regulatory and government attention on OT resilience across critical infrastructure has been building steadily, and procurement like this is one of the clearest practical signals that water companies are starting to treat OT security as a distinct discipline requiring its own specification, its own budget line and its own supplier relationship — rather than a checkbox inside a general IT services framework.
For context, this sits alongside a broader pattern in AMP8 IT and digital procurement: Northern Ireland Water is currently running a separate £10–12m tender for a Leakage Management System managed service (submissions close 22 September 2026), and multiple water companies have been building out AI, data and digital delivery frameworks through 2026. Cyber and digital infrastructure procurement is becoming a genuine, recurring category of AMP8 spend in its own right — not an occasional line item.
This tender is worth bidding on its own merits, but its real value to firms not currently pursuing it directly is as a signal. If Southern Water is treating OT MDR as its own procurement category, other water and wastewater companies are very likely assessing the same gap internally. Firms with genuine OT security credentials — ICS/SCADA-specific threat detection experience, familiarity with the Nozomi/Cisco Cyber Vision/CrowdStrike ecosystem or equivalents, and 24/7 SOC capability — should treat this as the leading edge of a wider trend, not an isolated procurement. Start building relationships with security and IT leads at other water companies now, well before their own tenders appear.
Be realistic about fit. Southern Water's notice makes clear it wants demonstrable OT capability, not a corporate SOC extended to cover industrial systems as an afterthought. Bidding without genuine ICS/OT security credentials — or without a credible subcontracting partner who has them — is unlikely to succeed and risks wasting bid resource that would be better spent building the right capability or partnership first.
Nozomi Networks, Cisco Cyber Vision and similar OT visibility platforms are name-checked directly in the tender as Southern Water's existing estate. That's a reminder that platform vendors and their integration partners have a route into these contracts even without bidding as the prime MDR supplier — the successful bidder will need strong relationships with, or accreditation from, these tooling vendors regardless of who wins.
Water Industry Hub tracks live procurement notices — including IT, digital and cyber security tenders — across every UK water and wastewater company, so you're not relying on a general search to find the opportunities that fit your specialism.
View Membership Options Talk to Us First