DATE: September 22, 2026
TO: Board of Supervisors
SUBMITTED BY: Paul Nerland, County Administrative Officer
SUBJECT: Agreement with Troncore, LLC
RECOMMENDED ACTION(S):
TITLE
Approve and authorize the Chairman to execute an Agreement with Troncore, LLC for information security assessment, penetration testing, and related cybersecurity consulting services, effective September 22, 2026 through September 21, 2029, with two optional one-year extensions, and a maximum total compensation of $900,000.
REPORT
There is no additional Net County Cost associated with the recommended action. Approval of the recommended action will allow the Office of Information Security to continue conducting independent assessments of the County’s information technology environment. Services will include annual internal and external security assessments, vulnerability assessments, penetration testing, remediation validation, targeted supplemental testing, and emergency or urgent cybersecurity testing and advisory services. This item is countywide.
ALTERNATIVE ACTION(S):
Your Board may choose not to approve the recommended action. Non-approval would prevent the Office of Information Security from obtaining contracted independent security assessment and penetration testing services. The County would need to conduct a new procurement or identify another method of obtaining these specialized services, which could delay annual security assessments, vulnerability validation, and testing of the County’s security controls.
FISCAL IMPACT:
There is no increase in Net County Cost associated with the recommended action. Sufficient appropriations for the recommended Agreement are included in the Office of Information Security Org 8909 FY 2026-27 Adopted Budget and will be included in subsequent budgets. The costs associated with the recommended Agreement are included in the Office of Information Security Internal Services Fund enterprise rate.
DISCUSSION:
The County relies on a complex information technology environment to support public services and to store, process, and transmit sensitive information. Independent vulnerability assessments and penetration testing help the County identify security weaknesses, evaluate whether safeguards are functioning as intended, prioritize remediation activities, and reduce the likelihood that vulnerabilities will be exploited.
The Office of Information Security requires annual independent assessments of the County’s information technology environment to verify that access is restricted to authorized users and that preventive, detective, and compensating safeguards are in place and operating effectively. The assessments also provide County leadership and technical personnel with an independent evaluation of cybersecurity risks and recommended corrective actions.
On January 9, 2026, the County issued Request for Proposal (RFP) No. 26-035, which solicited bids for internal and external security audit services. The RFP closed on March 2, 2026, with 17 responsive proposals received.
• Troncore, LLC - $850,000
• RSI Systems - $637,621
• Solvitur Systems - $884,289
• Global Solutions Group (GSG) - $819,025
• JANUS Software - $711,236
• Gaming Laboratories - $524,970
• DotWave Solutions - $825,000
• Brownstone Consulting - $890,908
• Baker Tilly Advisory Group - $2,375,000
• Zones - $659,065
• Federal Cyber Systems - $1,101,605
• Shorebreak IThreat Security - $607,988
• CyberElite - $802,500
• 3L337 Consulting - $656,000
• V3Main Technologies - $859,200
• Howard Technology - $858,105
• Concourse Tech - $562,500
The RFP evaluation committee consisted of the Chief Information Security Officer and two Senior Information Security Analysts from the Office of Information Security division of the County Administrative Office. The RFP evaluation committee conducted a thorough review of each proposal on its own merit, based on bidder-provided data, capability, and qualifications. Troncore was unanimously selected as the top-ranked vendor based on its qualified personnel, comprehensive testing methodology, alignment with industry standards, mature quality assurance and reporting processes, relevant public-sector experience, strong references, and overall cost-effectiveness.
Under the recommended Agreement, Troncore will conduct a comprehensive annual security assessment covering the County’s in-scope internal and external networks, web applications and application programming interfaces, cloud environments, identity and access management systems, endpoints, data protection controls, logging and monitoring capabilities, and incident response safeguards. Testing will include automated and manually validated vulnerability assessments and penetration testing.
Following each annual assessment, Troncore will provide an executive summary, a detailed technical report, prioritized remediation recommendations, supporting evidence, detection and response recommendations, and executive and technical briefings. The recommended Agreement also provides for validation testing of remediated critical and high-risk findings.
The recommended Agreement allows the County to request targeted supplemental testing when new applications, infrastructure, cloud environments, or other high-risk technologies require focused assessment outside the annual engagement.
The County may also request emergency or urgent testing and advisory services in response to critical vulnerabilities, newly disclosed zero-day threats, newly exposed assets, or the need to rapidly validate corrective actions.
ATTACHMENTS INCLUDED AND/OR ON FILE:
On file with Clerk - Agreement with Troncore
CAO ANALYST:
Amy Ryals