See More RFPs

Security Awareness Learning and User Education Platform

Overview


Cybersecurity & Data Privacy
Redwood City, California, United StatesPosted 20 days agoDeadline: May 14th, 2026

Fit Score


Settle Intelligence

Settle helps teams find, evaluate, and respond to public RFPs. We continuously surface new opportunities, score them against your company strengths, and draft proposal responses so you can focus on the work that wins business.

SUMMARY


The county aims to implement a multimedia platform for security awareness training, user education, and realistic phishing simulations for personnel.

KEY REQUIREMENTS


BUDGET

Estimate

$150,000 – $500,000

CONTRACT DURATION


60 months

TIMELINE


RFP Released: April 17th, 2026

Pre-proposal meeting: April 27th, 2026

Deadline for questions: April 30th, 2026

Proposal due date: May 14th, 2026

QUESTION DEADLINE


April 30th, 2026

Issuing Agency


County Of San Mateo

Organization overview and procurement intelligence available on paid plans.

DESCRIPTION


The county seeks a vendor to provide a comprehensive security awareness learning and user education platform able to deliver robust training and education on cybersecurity topics to personnel countywide. The platform must utilize diverse multimedia modalities, including posters, videos, and configurable email-based tips, to effectively engage users across multiple departments.

The solution should feature real-world examples and testing of personnel on common security awareness subjects, such as phishing, business email compromise (BEC), and other relevant threats. Vendors must enable the creation and integration of custom multimedia content, facilitating a tailored educational approach. Realistic phishing and social engineering attack simulations are required, with the ability to randomize campaigns within date ranges and across departments, divisions, or work teams as defined in Active Directory.

Broad variations and realistic training on a wide menu of security threat subjects must be available, including denial of service (DDOS), man-in-the-middle (MIM) attacks, BEC recognition, dark web monitoring, fraudulent source emails, spoofing, social engineering, account takeovers, impersonation, password security, and electronic fraud. The platform should offer informative definitions and context for security terms and attacks.

Source attribution

This Settle analysis is based on the issuing organization’s public RFP listing.

Similar RFPs