Skip to main content

Help us improve the Digital Marketplace - send your feedback

I C S CONSULTING LIMITED

Asset Risk and Investment Decisions

ICS provide software and advisory services to asset intensive industries throughout the UK. We have spent the last 25 years helping organisations manage the risks and service impacts of their assets and make better investment decisions that balance customer service performance, affordability and sustainability to maximise stakeholder value.

Features

  • Asset Lifecycle Risk Management and Investment Decision Making
  • Asset Risk Assessment and Risk Prioritisation
  • Investment Project Definition, Costing, Assessment and Appraisal
  • Investment Plan Selection, Optimisation and Analysis
  • Delivery Portfolio Management, Review and Update
  • Risk and Investment Plan Monitoring and Reporting
  • Capital Investment Portfolio Optimisation and Allocation
  • Asset Investment Whole Life Costing and Business Cases
  • Investment Plan Balancing and Programme Business Cases
  • Risk and Service Value Economic Appraisal Framework

Benefits

  • Alignment of Investment Plan with Business and Stakeholder Outcomes
  • Transparent, Objective and Auditable Investment Decision Making
  • Efficient Investment Plan Development with Supporting Strategic and Economic Cases
  • Agile and Responsive Project Portfolio Delivery
  • Proactive Management of Risk and Visibility of Residuals
  • Risk and Value Based Investment and Delivery Decision Making
  • Inclusion of Sustainability and Resilience in the Investment Plan
  • Consistent and Comprehensive Project and Programme Value for Money Assessment

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@icsconsulting.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 4 5 8 8 7 1 7 4 8 4 1 2 2 8

Contact

I C S CONSULTING LIMITED Tim Young
Telephone: 07796951967
Email: tenders@icsconsulting.co.uk

About your service

Service categories

Applications

Enterprise resource management

  • Project and portfolio management
  • Asset life-cycle management
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
Service constraints
None.
System requirements
  • Microsoft Edge (Chromium)
  • Chrome
  • Firefox
  • Safari

User support

Email or online ticketing support
Yes
Support response times
The response times for each priority of question / incident are :
Priority 1 : 2 business hours;
Priority 2 : 8 business hours;
Priority 3 : 2 business days;
Priority 4 : 4 business days.

These response times are for normal business times : Monday to Friday 8.30am to 5.00pm. Responses outside these hours are next working day.
Enhanced support hours can be provided if required at extra cost.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
ICS provides a tiered support structure: where initial tier 1 support is provided by the client super users and administrators; tier 2 support provided by ICS and is for business use related or minor application issues; tier 3 is the highest level of support provided by ICS and is for the technical resolution of more detailed technical queries and issues.

For tier 2 and 3 support the target resolution times for each priority are : Priority 1 : One business day; Priority 2 : Two business days, Priority 3 : 5 business days, Priority 4 : 10 business days.

The costs for the support are included within the service pricing.

ICS provides an account manager for all clients, who work with the client to make that they gain maximum value from the use of our software. The account manager undertakes regular support calls with the client and co-ordinate with the rest of the ICS team as required. An annual on-site visit will also be co-ordinated by the account manager and provide the opportunity to undertake deep-dives into product features and usage as well as enable the client to understand shape the product roadmap.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Implementation support is provided at the start to ensure that the configuration of the service best supports the requirements and processes of the customer and enables maximum value to be gained from the use of the service. The activities typically included within implementation are:
Customer investment planning approach and process confirmation;
Service design and configuration;
Service mobilisation and acceptance;
User training and materials – face to face, remote, train the trainer;
Service embedment support.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
At end of contract, ICS will provide a complete copy of the data in a portable, usable format. This includes core business data such as the asset register (assets, hierarchies, attributes), reference data, locations, condition/performance inputs, intervention/options data, and any scenario or optimisation outputs produced within the service. Customer content held within the system, such as uploaded files/attachments, can also be included.

Given the large volumes of data, extraction is provided via a managed export undertaken by ICS. The export can be supplied as 'database dump' or in standard formats such as CSV and/or JSON, organised by logical data domains to support re-use in other systems. We would provide supporting schema information so customers can interpret relationships and field definitions.

Extraction is limited to the customer’s own data and does not include any platform source code, proprietary optimisation logic or database design. After an agreed post-contract retention period to support close-out, customer data is securely deleted in line with our retention and deletion policies and any legal or regulatory obligations.
End-of-contract process
At the end of the contract, access to the service is closed in line with the agreed end date, unless a renewal or extension is agreed. We work with the client to complete contract close-out activities, which typically include:

Data extraction will be undertaken as described in End-of-contract data extraction.

Transition support can be provided as described in End-of-contract data extraction.

All user accounts and system integrations are disabled to prevent further access.

Customer data will be retained only for an agreed post-contract retention period to support extraction and reconciliation, after which it is securely deleted from live systems in accordance with our retention/deletion policy and any legal or regulatory obligations.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Onboarding and off-boarding documentation is available on request from ICS.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
There is no functional difference when accessing the system via a mobile (iPad) or desktop. The service is delivered as a SaaS web application, the main differences are related to usability rather than capability:

File handling: exports/downloads work on both, but depend on the device’s browser and local app support (eg. opening large spreadsheets).

Data entry: on smaller screens bulk-edit editing is less efficient; we expect users to perform intensive data management tasks on desktops.

Performance: mobile performance will be influenced by device specifications.

Security and access controls are consistent across devices using the same authentication, RBAC/permissions and audit logging.
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
Our API is designed to let customers integrate and transfer data between our service and client system. We provide APIs for key elements of the application based on SOAP and REST standards to enable integration with other systems.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
There are two levels of customisation that are available within the service.

The first level is during the mobilisation phase where ICS work together with the client to make the service fully suitable for the client specific assets, risk assessment criteria, service performance, investment decisions and business processes.

The second level is during the use of the service where administrators and advanced users can customise key elements of the service to solve the specific investment decisions that they are making. This includes key financial parameters, whole life cost and benefit methodologies, investment planning logistics and constraints.

Scaling

Independence of resources
We minimise the impact through a combination of capacity management and protective limits, so one customer’s peak usage does not materially degrade the experience for others. For customers with higher assurance, performance, or segregation requirements, we can provide a dedicated client environment to provide predictable performance.

We also employ workload separation, where user activity is kept separate from heavy/background processing such as optimisation runs. Long-running tasks run as asynchronous jobs so they don’t impact normal UI responsiveness.

Analytics

Service usage metrics
Yes
Metrics types
The service provides usage and operational metrics presented via dashboards and audit/activity views in the application.

Typical metrics include:

User activity: active users over time, login/activity trends, and usage by role/team.

Feature usage: volumes of key actions (eg. asset records viewed/edited, workflows completed, scenarios created/run).

Data volumes: counts of assets/records, data storage usage/availability.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
NCSC approved service provider
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export their data using self-service export functions within the application.

Authorised users can download datasets directly from relevant screens, reports, and data views (eg. asset register, hierarchies, reference data, inputs, and results/outputs where applicable).

Exports are provided in common formats such as CSV and/or XLSX, so they can be reused in spreadsheets, BI tools, or other systems.

Since the optimised datasets are very large we provide access to optimisation outputs through our data Warehouse. This data can be replicated as a background task to be available BI tools for further analysis.
Data export formats
  • CSV
  • Other
Other data export formats
  • Excel
  • PDF
  • JPEG/PNG
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Our SLA is measured on a monthly basis and expressed as a percentage uptime for the production service. Our standard commitment is 99.8% monthly uptime for the production application, excluding any agreed planned maintenance windows.

Planned maintenance is scheduled outside peak hours where possible, communicated in advance, and excluded from the uptime calculation where this is defined in the contract. The SLA also excludes unavailability caused by factors outside our control, such as customer network issues, misconfigured customer devices or browsers, or customer-managed integrations.

We operate severity-based incident response and restore targets with regular progress updates during incidents, and if availability falls below the SLA, service credits or other contractual remedies apply as defined in the agreement. Where a customer requires higher assurance and isolation, we can provide a dedicated client environment with availability targets aligned to the customer’s requirements.
Approach to resilience
Our service is designed for resilience across platform architecture, data protection, and operational processes to ensure continuity of service and rapid recovery from incidents. We host the service within a dedicated, professionally managed UK data centre environment with resilient facilities controls, including redundant power arrangements (UPS and generator-backed supply), environmental monitoring, and fire detection/suppression.

At the platform layer, the service is engineered to remove single points of failure wherever practical. Core components are deployed in a way that supports failover and recovery, and we separate key service tiers (for example, web/application and database) to prevent faults in one area propagating across the full stack. Capacity is managed to maintain headroom and ensure stable performance during peak demand, maintenance activities, or partial component failure.

Data resilience is provided through robust backup and recovery controls. We perform regular backups, protect backups from accidental deletion or corruption, and test restoration processes to validate that data can be recovered within agreed recovery objectives.

Operationally, resilience is supported by proactive monitoring and alerting, documented incident response procedures, and routine maintenance of the underlying infrastructure. This ensures issues are detected quickly, response is coordinated, and service is restored efficiently while maintaining data integrity and security.
Outage reporting
We continuously monitor the service for availability, performance, and underlying infrastructure health. If an outage or performance issue is detected, we log an incident and notify the customer as soon as possible via the agreed communications route, typically an email to nominated contacts, or alternative channels if required.

Our notifications include the time the issue was identified, the known or suspected scope/impact (for example, complete outage vs degraded performance), and the immediate actions being taken. We provide follow-up updates at appropriate intervals until service is restored, then issue a closure message confirming resolution. For significant incidents, we can also provide a post-incident summary on request.

Identity and authentication

User authentication needed
Yes
User authentication
Multi-Factor Authentication (MFA)
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted using role-based access control (RBAC) and least-privilege principles. Administrative access is limited to authorised personnel only, protected with strong authentication including MFA where available, and granted through controlled joiner/mover/leaver processes with periodic access reviews.

Management interfaces are separated from customer access, protected by network controls via IP allow-listing and VPN. Support channels are restricted to verified customer contacts, and we use agreed identity checks before discussing account-specific information or performing sensitive actions, which includes password resets, data exports, or configuration changes.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Our security governance and software delivery processes are aligned to the UK Software Security Code of Practice and its recommendations for establishing a baseline of software security and resilience across the lifecycle (design, build, deploy, maintain, and customer communications).

These controls include defined security ownership and governance, secure-by-design and secure-by-default engineering, review and security testing prior to release, access control and audit logging, dependency/third-party component management, secure configuration and hardening in production.
Information security policies and processes
We operate documented information security policies and processes aligned to recognised good practice and underpinned by independent assurance. We are Cyber Essentials certified, and our data centre/hosted environment is ISO27001 certified, providing a robust baseline of technical and organisational controls.

Information security is governed by senior management, with an appointed security lead responsible for maintaining the security framework (policies, risk register, control monitoring), coordinating incident management, and reporting security performance and issues to leadership. Service and technical owners are accountable for implementing controls in their areas, and all staff are required to comply with policies as part of their roles.

We embed compliance through mandatory staff training, role-based procedures, and technical enforcement (for example MFA, controlled access, secure configuration baselines, and audit logging). Ongoing adherence is checked through routine access reviews.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We operate controlled configuration and change management to ensure service stability, security and traceability across application, database and infrastructure components.

Service components are tracked throughout their lifecycle, including application modules and versions, databases/schemas, infrastructure elements, key configurations, and third-party dependencies. Each is managed through version control and release management. Code and configuration are maintained in source control with tagged releases and deployment records. Administrative actions and configuration updates are protected by role-based access control and captured through audit logging.

All changes are assessed for security impact proportionate to risk. The assessment considers data handling and permissions, authentication and access controls.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We operate a risk-based vulnerability management process covering identification, remediation, verification and communication. Potential threats are assessed using severity, exploitability and active exploitation, exposure (internet-facing vs internal) and potential impact to confidentiality, integrity and availability.

Patches are deployed according to risk. Critical or actively exploited issues follow an expedited change route and are applied as soon as practicable after validation, often within days and faster where feasible. Lower are severities handled via planned maintenance. Threat intelligence comes from vendor advisories, CVE/NVD feeds, UK NCSC guidance, CISA KEV, security mailing lists, scanning and penetration testing.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We use protective monitoring to detect suspicious activity and potential compromise across the service and hosting environment. We identify issues through centralised logging and alerting from key sources, including authentication and privileged access events, system and application logs, with correlation for anomalies such as repeated failed logins, unusual access patterns.

When a potential compromise is detected we contain the issue, for example, disabling accounts, isolating affected components, and blocking malicious traffic. We preserve relevant evidence and remove/disable the cause to restore services safely. We respond to security incidents as soon as practicable, with expedited response for high-severity events.
Incident management type
Undisclosed
Incident management approach
We operate a documented incident management process with scenarios for common events (for example service outages, suspected security incidents, access issues and data/restoration requests). Incidents can be reported by users via our support email and/or agreed service desk channel, with clear escalation routes for urgent issues. Each incident is logged, prioritised by impact and urgency, and managed through assessment, containment/mitigation, recovery, and closure, with time-stamped communications to nominated contacts where appropriate. Following resolution, we can provide an incident report on request, including a timeline, customer impact, root cause, corrective actions taken, and preventative measures to reduce recurrence.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
ICS provide a free trial of the service for a period of one month. This free trial provides access to a preconfigured application with a varied number of asset types. The trial allows the user to explore the full features of the application albeit on a limited set of data.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
7.5%
Between £2,500,001 and £5,000,000
7.5%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
BSI Group
ISO 9001 accreditation date
Monday 25 March 2024
What the ISO 9001 doesn’t cover
Our ISO 9001 certification excludes "Monitoring and Measuring Equipment" as this is not relevant to the services that we provide.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
7abcd0b1-7c53-4466-85bb-188d96206366
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@icsconsulting.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.