BETAThis is a new independent transparency project, not an official government website. The data is sourced from public registers and may contain errors, so always verify against the official source. If you find a problem, please report it here.
Ofgem currently stores system administration usernames and passwords in a shared software product where everyone in each team can see all usernames and passwords with system administration rights. There is no protection around these files, so each user with rights may change, or even delete system admin credentials. In addition, most of those usernames are generic "Admin" users and not assigned to individuals making auditing specific privileged user activity nearly difficult.
Lastly, we have limited sys admin resources to create new server services, administrate existing one and collapse services identified for decommissioning.
We are looking for a technical solution supported by PAM professional services that helps resolve the risk associated with unmonitored, unlimited priviledged access to Ofgems infrastructure systems and gain control over the privileged accounts to the technical assets
For more information see attached document - 2020-008 Privileged Access Management (PAM) Tool ITT
| Supplier | Identifier | Award Value | Cross-References |
|---|---|---|---|
| Ncc Group Security Services Limited | 04474600 | £187,000 | - |
Government spending data: This supplier has received £34,266,294 in 741 payments (over £25k) from UK Health Security Agency, Home Office, Department for Work and Pensions, Department for Education, Department for Transport and 32 more public bodies (2012-10-25 to 2026-06-24). View full payment history →