Phishing Simulation and User Awareness Platform for Enterprise Environment
Tender Overview
About this tender
Key problem/s National Library of Australia is seeking a phishing simulation solution to strengthen our cyber security awareness program. While we currently have a phishing simulation solution in operation, several gaps limit its effectiveness in preparing staff for real-world phishing threats. 1. Lack of Realistic Phishing Simulations Current solution relies on generic or predictable phishing emails, which do not adequately reflect modern, sophisticated attack techniques. We need the capability to deliver highly targeted, context-aware phishing campaigns that simulate real-world attack scenarios (e.g., spear phishing, business email compromise, credential harvesting etc.) 2. Limited Flexibility in Campaign Design Existing tools do not offer sufficient flexibility in crafting and managing campaigns e.g., limited phishing templates, no capability to distribute We require: Access to a comprehensive library of phishing templates Ability to easily customise templates to align with our organisational context. Support for multiple phishing payload variations within a single campaign. Capability to distribute different phishing email variants across user groups or individuals, rather than sending the same payload to all staff on the same day. Support for varying difficulty levels and attack types to better simulate real-world adversary tactics. Ability to select specific user or users of a branch in campaign design. 3. Predictable Campaign Execution The current solution does not randomise phishing simulation payloads across the user base, reducing the effectiveness of campaigns and potentially creating artificial user behaviour. We require: Randomised and staggered phishing delivery across users and time periods. Ability to simulate “always-on” threat conditions rather than point-in-time testing. 4. Limited Visibility into User Risk We lack detailed insight into how individuals and groups respond to phishing attempts. The solution should provide: Granular visibility at individual, team, and enterprise levels Tracking of user actions (click, credential submission, email reply, reporting, etc.) Clear identification of high-risk users and behavioural trends over time 5. Inability to Effectively Manage Repeat Offenders Repeat offenders present a higher organisational risk but are not currently systematically addressed. We require: Identification and flagging of repeat offenders. Ability to target high-risk users with more frequent or advanced simulations. Risk scoring to prioritise remediation efforts. 6. Need for Continuous Improvement and Metrics There is currently no strong feedback loop to measure program effectiveness. We require: Metrics such as phish-prone percentage, reporting rates, and resilience scores. Benchmarking and trend analysis over time Support for continuous improvement of the cyber awareness program The users and their needs 1. Executive and Operational Visibility We require: Intuitive dashboards for quick assessment of organisational risk posture Executive-level reporting with trends and key metrics Ability to export data for governance, audit, and reporting purposes. 2. Reporting Capability The solution should include: A “Phish Alert” button integrated into enterprise email clients so that employees can report phishing email. Capability to capture, analyse, and triage reported emails feedback loop to reinforce correct reporting behaviour. 3. Usability and Administrative Efficiency We require: A user-friendly administration interface Streamlined campaign creation, reporting, and user management. Minimal administrative overhead for ongoing operations
How to respond to this tender
A strong tender response is clear, compliant, and backed by evidence. These steps apply to most Australian and New Zealand public tenders.
Read the requirements in full
Open the official listing and download the full tender pack. Note the response schedules, evaluation criteria, mandatory conditions, and the exact closing time and lodgement method.
Confirm you are eligible and it is worth bidding
Check licences, insurances, certifications, and any conformance requirements before you commit. A quick bid or no-bid decision saves days of wasted effort on a tender you cannot win.
Answer every criterion with evidence
Respond to each evaluation criterion directly and back your claims with concrete examples, referees, and past performance. Address the buyer’s stated need, not a generic capability statement.
Lodge early through the official portal
Submit through the source portal well before the deadline. Late or incorrectly lodged bids are almost always rejected, so leave time for uploads, portal errors, and last-minute questions.
