Asset Risk and Investment Decisions
ICS provide software and advisory services to asset intensive industries throughout the UK. We have spent the last 25 years helping organisations manage the risks and service impacts of their assets and make better investment decisions that balance customer service performance, affordability and sustainability to maximise stakeholder value.
Features
- Asset Lifecycle Risk Management and Investment Decision Making
- Asset Risk Assessment and Risk Prioritisation
- Investment Project Definition, Costing, Assessment and Appraisal
- Investment Plan Selection, Optimisation and Analysis
- Delivery Portfolio Management, Review and Update
- Risk and Investment Plan Monitoring and Reporting
- Capital Investment Portfolio Optimisation and Allocation
- Asset Investment Whole Life Costing and Business Cases
- Investment Plan Balancing and Programme Business Cases
- Risk and Service Value Economic Appraisal Framework
Benefits
- Alignment of Investment Plan with Business and Stakeholder Outcomes
- Transparent, Objective and Auditable Investment Decision Making
- Efficient Investment Plan Development with Supporting Strategic and Economic Cases
- Agile and Responsive Project Portfolio Delivery
- Proactive Management of Risk and Visibility of Residuals
- Risk and Value Based Investment and Delivery Decision Making
- Inclusion of Sustainability and Resilience in the Investment Plan
- Consistent and Comprehensive Project and Programme Value for Money Assessment
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 4 5 8 8 7 1 7 4 8 4 1 2 2 8
Contact
I C S CONSULTING LIMITED
Tim Young
Telephone: 07796951967
Email: tenders@icsconsulting.co.uk
About your service
- Service categories
-
Applications
Enterprise resource management
- Project and portfolio management
- Asset life-cycle management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- None.
- System requirements
-
- Microsoft Edge (Chromium)
- Chrome
- Firefox
- Safari
User support
- Email or online ticketing support
- Yes
- Support response times
-
The response times for each priority of question / incident are :
Priority 1 : 2 business hours;
Priority 2 : 8 business hours;
Priority 3 : 2 business days;
Priority 4 : 4 business days.
These response times are for normal business times : Monday to Friday 8.30am to 5.00pm. Responses outside these hours are next working day.
Enhanced support hours can be provided if required at extra cost. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
ICS provides a tiered support structure: where initial tier 1 support is provided by the client super users and administrators; tier 2 support provided by ICS and is for business use related or minor application issues; tier 3 is the highest level of support provided by ICS and is for the technical resolution of more detailed technical queries and issues.
For tier 2 and 3 support the target resolution times for each priority are : Priority 1 : One business day; Priority 2 : Two business days, Priority 3 : 5 business days, Priority 4 : 10 business days.
The costs for the support are included within the service pricing.
ICS provides an account manager for all clients, who work with the client to make that they gain maximum value from the use of our software. The account manager undertakes regular support calls with the client and co-ordinate with the rest of the ICS team as required. An annual on-site visit will also be co-ordinated by the account manager and provide the opportunity to undertake deep-dives into product features and usage as well as enable the client to understand shape the product roadmap. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Implementation support is provided at the start to ensure that the configuration of the service best supports the requirements and processes of the customer and enables maximum value to be gained from the use of the service. The activities typically included within implementation are:
Customer investment planning approach and process confirmation;
Service design and configuration;
Service mobilisation and acceptance;
User training and materials – face to face, remote, train the trainer;
Service embedment support. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
At end of contract, ICS will provide a complete copy of the data in a portable, usable format. This includes core business data such as the asset register (assets, hierarchies, attributes), reference data, locations, condition/performance inputs, intervention/options data, and any scenario or optimisation outputs produced within the service. Customer content held within the system, such as uploaded files/attachments, can also be included.
Given the large volumes of data, extraction is provided via a managed export undertaken by ICS. The export can be supplied as 'database dump' or in standard formats such as CSV and/or JSON, organised by logical data domains to support re-use in other systems. We would provide supporting schema information so customers can interpret relationships and field definitions.
Extraction is limited to the customer’s own data and does not include any platform source code, proprietary optimisation logic or database design. After an agreed post-contract retention period to support close-out, customer data is securely deleted in line with our retention and deletion policies and any legal or regulatory obligations. - End-of-contract process
-
At the end of the contract, access to the service is closed in line with the agreed end date, unless a renewal or extension is agreed. We work with the client to complete contract close-out activities, which typically include:
Data extraction will be undertaken as described in End-of-contract data extraction.
Transition support can be provided as described in End-of-contract data extraction.
All user accounts and system integrations are disabled to prevent further access.
Customer data will be retained only for an agreed post-contract retention period to support extraction and reconciliation, after which it is securely deleted from live systems in accordance with our retention/deletion policy and any legal or regulatory obligations. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding and off-boarding documentation is available on request from ICS.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
There is no functional difference when accessing the system via a mobile (iPad) or desktop. The service is delivered as a SaaS web application, the main differences are related to usability rather than capability:
File handling: exports/downloads work on both, but depend on the device’s browser and local app support (eg. opening large spreadsheets).
Data entry: on smaller screens bulk-edit editing is less efficient; we expect users to perform intensive data management tasks on desktops.
Performance: mobile performance will be influenced by device specifications.
Security and access controls are consistent across devices using the same authentication, RBAC/permissions and audit logging. - Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- Our API is designed to let customers integrate and transfer data between our service and client system. We provide APIs for key elements of the application based on SOAP and REST standards to enable integration with other systems.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
There are two levels of customisation that are available within the service.
The first level is during the mobilisation phase where ICS work together with the client to make the service fully suitable for the client specific assets, risk assessment criteria, service performance, investment decisions and business processes.
The second level is during the use of the service where administrators and advanced users can customise key elements of the service to solve the specific investment decisions that they are making. This includes key financial parameters, whole life cost and benefit methodologies, investment planning logistics and constraints.
Scaling
- Independence of resources
-
We minimise the impact through a combination of capacity management and protective limits, so one customer’s peak usage does not materially degrade the experience for others. For customers with higher assurance, performance, or segregation requirements, we can provide a dedicated client environment to provide predictable performance.
We also employ workload separation, where user activity is kept separate from heavy/background processing such as optimisation runs. Long-running tasks run as asynchronous jobs so they don’t impact normal UI responsiveness.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The service provides usage and operational metrics presented via dashboards and audit/activity views in the application.
Typical metrics include:
User activity: active users over time, login/activity trends, and usage by role/team.
Feature usage: volumes of key actions (eg. asset records viewed/edited, workflows completed, scenarios created/run).
Data volumes: counts of assets/records, data storage usage/availability. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Users can export their data using self-service export functions within the application.
Authorised users can download datasets directly from relevant screens, reports, and data views (eg. asset register, hierarchies, reference data, inputs, and results/outputs where applicable).
Exports are provided in common formats such as CSV and/or XLSX, so they can be reused in spreadsheets, BI tools, or other systems.
Since the optimised datasets are very large we provide access to optimisation outputs through our data Warehouse. This data can be replicated as a background task to be available BI tools for further analysis. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- JPEG/PNG
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Our SLA is measured on a monthly basis and expressed as a percentage uptime for the production service. Our standard commitment is 99.8% monthly uptime for the production application, excluding any agreed planned maintenance windows.
Planned maintenance is scheduled outside peak hours where possible, communicated in advance, and excluded from the uptime calculation where this is defined in the contract. The SLA also excludes unavailability caused by factors outside our control, such as customer network issues, misconfigured customer devices or browsers, or customer-managed integrations.
We operate severity-based incident response and restore targets with regular progress updates during incidents, and if availability falls below the SLA, service credits or other contractual remedies apply as defined in the agreement. Where a customer requires higher assurance and isolation, we can provide a dedicated client environment with availability targets aligned to the customer’s requirements. - Approach to resilience
-
Our service is designed for resilience across platform architecture, data protection, and operational processes to ensure continuity of service and rapid recovery from incidents. We host the service within a dedicated, professionally managed UK data centre environment with resilient facilities controls, including redundant power arrangements (UPS and generator-backed supply), environmental monitoring, and fire detection/suppression.
At the platform layer, the service is engineered to remove single points of failure wherever practical. Core components are deployed in a way that supports failover and recovery, and we separate key service tiers (for example, web/application and database) to prevent faults in one area propagating across the full stack. Capacity is managed to maintain headroom and ensure stable performance during peak demand, maintenance activities, or partial component failure.
Data resilience is provided through robust backup and recovery controls. We perform regular backups, protect backups from accidental deletion or corruption, and test restoration processes to validate that data can be recovered within agreed recovery objectives.
Operationally, resilience is supported by proactive monitoring and alerting, documented incident response procedures, and routine maintenance of the underlying infrastructure. This ensures issues are detected quickly, response is coordinated, and service is restored efficiently while maintaining data integrity and security. - Outage reporting
-
We continuously monitor the service for availability, performance, and underlying infrastructure health. If an outage or performance issue is detected, we log an incident and notify the customer as soon as possible via the agreed communications route, typically an email to nominated contacts, or alternative channels if required.
Our notifications include the time the issue was identified, the known or suspected scope/impact (for example, complete outage vs degraded performance), and the immediate actions being taken. We provide follow-up updates at appropriate intervals until service is restored, then issue a closure message confirming resolution. For significant incidents, we can also provide a post-incident summary on request.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels is restricted using role-based access control (RBAC) and least-privilege principles. Administrative access is limited to authorised personnel only, protected with strong authentication including MFA where available, and granted through controlled joiner/mover/leaver processes with periodic access reviews.
Management interfaces are separated from customer access, protected by network controls via IP allow-listing and VPN. Support channels are restricted to verified customer contacts, and we use agreed identity checks before discussing account-specific information or performing sensitive actions, which includes password resets, data exports, or configuration changes. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
-
Our security governance and software delivery processes are aligned to the UK Software Security Code of Practice and its recommendations for establishing a baseline of software security and resilience across the lifecycle (design, build, deploy, maintain, and customer communications).
These controls include defined security ownership and governance, secure-by-design and secure-by-default engineering, review and security testing prior to release, access control and audit logging, dependency/third-party component management, secure configuration and hardening in production. - Information security policies and processes
-
We operate documented information security policies and processes aligned to recognised good practice and underpinned by independent assurance. We are Cyber Essentials certified, and our data centre/hosted environment is ISO27001 certified, providing a robust baseline of technical and organisational controls.
Information security is governed by senior management, with an appointed security lead responsible for maintaining the security framework (policies, risk register, control monitoring), coordinating incident management, and reporting security performance and issues to leadership. Service and technical owners are accountable for implementing controls in their areas, and all staff are required to comply with policies as part of their roles.
We embed compliance through mandatory staff training, role-based procedures, and technical enforcement (for example MFA, controlled access, secure configuration baselines, and audit logging). Ongoing adherence is checked through routine access reviews. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
We operate controlled configuration and change management to ensure service stability, security and traceability across application, database and infrastructure components.
Service components are tracked throughout their lifecycle, including application modules and versions, databases/schemas, infrastructure elements, key configurations, and third-party dependencies. Each is managed through version control and release management. Code and configuration are maintained in source control with tagged releases and deployment records. Administrative actions and configuration updates are protected by role-based access control and captured through audit logging.
All changes are assessed for security impact proportionate to risk. The assessment considers data handling and permissions, authentication and access controls. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We operate a risk-based vulnerability management process covering identification, remediation, verification and communication. Potential threats are assessed using severity, exploitability and active exploitation, exposure (internet-facing vs internal) and potential impact to confidentiality, integrity and availability.
Patches are deployed according to risk. Critical or actively exploited issues follow an expedited change route and are applied as soon as practicable after validation, often within days and faster where feasible. Lower are severities handled via planned maintenance. Threat intelligence comes from vendor advisories, CVE/NVD feeds, UK NCSC guidance, CISA KEV, security mailing lists, scanning and penetration testing. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We use protective monitoring to detect suspicious activity and potential compromise across the service and hosting environment. We identify issues through centralised logging and alerting from key sources, including authentication and privileged access events, system and application logs, with correlation for anomalies such as repeated failed logins, unusual access patterns.
When a potential compromise is detected we contain the issue, for example, disabling accounts, isolating affected components, and blocking malicious traffic. We preserve relevant evidence and remove/disable the cause to restore services safely. We respond to security incidents as soon as practicable, with expedited response for high-severity events. - Incident management type
- Undisclosed
- Incident management approach
- We operate a documented incident management process with scenarios for common events (for example service outages, suspected security incidents, access issues and data/restoration requests). Incidents can be reported by users via our support email and/or agreed service desk channel, with clear escalation routes for urgent issues. Each incident is logged, prioritised by impact and urgency, and managed through assessment, containment/mitigation, recovery, and closure, with time-stamped communications to nominated contacts where appropriate. Following resolution, we can provide an incident report on request, including a timeline, customer impact, root cause, corrective actions taken, and preventative measures to reduce recurrence.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- ICS provide a free trial of the service for a period of one month. This free trial provides access to a preconfigured application with a varied number of asset types. The trial allows the user to explore the full features of the application albeit on a limited set of data.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7.5%
- Between £2,500,001 and £5,000,000
- 7.5%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI Group
- ISO 9001 accreditation date
- Monday 25 March 2024
- What the ISO 9001 doesn’t cover
- Our ISO 9001 certification excludes "Monitoring and Measuring Equipment" as this is not relevant to the services that we provide.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 7abcd0b1-7c53-4466-85bb-188d96206366
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-