Legislation Details

File #: 26-0847   
On agenda: 9/22/2026 Final action:
Enactment date: Enactment #:
Recommended Action(s)
Approve and authorize the Chairman to execute an Agreement with Troncore, LLC for information security assessment, penetration testing, and related cybersecurity consulting services, effective September 22, 2026 through September 21, 2029, with two optional one-year extensions, and a maximum total compensation of $900,000.
Attachments: 1. Agenda Item, 2. On file with Clerk - Agreement with Troncore
Date Action ByActionResultAction DetailsAgenda MaterialsVideo
No records to display.

DATE:                     September 22, 2026

 

TO:                     Board of Supervisors

 

SUBMITTED BY:                     Paul Nerland, County Administrative Officer

 

SUBJECT:                     Agreement with Troncore, LLC

 

RECOMMENDED ACTION(S):

TITLE

Approve and authorize the Chairman to execute an Agreement with Troncore, LLC for information security assessment, penetration testing, and related cybersecurity consulting services, effective September 22, 2026 through September 21, 2029, with two optional one-year extensions, and a maximum total compensation of $900,000.

REPORT

There is no additional Net County Cost associated with the recommended action. Approval of the recommended action will allow the Office of Information Security to continue conducting independent assessments of the County’s information technology environment. Services will include annual internal and external security assessments, vulnerability assessments, penetration testing, remediation validation, targeted supplemental testing, and emergency or urgent cybersecurity testing and advisory services. This item is countywide.

 

ALTERNATIVE ACTION(S):

 

Your Board may choose not to approve the recommended action. Non-approval would prevent the Office of Information Security from obtaining contracted independent security assessment and penetration testing services. The County would need to conduct a new procurement or identify another method of obtaining these specialized services, which could delay annual security assessments, vulnerability validation, and testing of the County’s security controls.

 

FISCAL IMPACT:

 

There is no increase in Net County Cost associated with the recommended action. Sufficient appropriations for the recommended Agreement are included in the Office of Information Security Org 8909 FY 2026-27 Adopted Budget and will be included in subsequent budgets. The costs associated with the recommended Agreement are included in the Office of Information Security Internal Services Fund enterprise rate.

 

DISCUSSION:

 

The County relies on a complex information technology environment to support public services and to store, process, and transmit sensitive information. Independent vulnerability assessments and penetration testing help the County identify security weaknesses, evaluate whether safeguards are functioning as intended, prioritize remediation activities, and reduce the likelihood that vulnerabilities will be exploited.

 

The Office of Information Security requires annual independent assessments of the County’s information technology environment to verify that access is restricted to authorized users and that preventive, detective, and compensating safeguards are in place and operating effectively. The assessments also provide County leadership and technical personnel with an independent evaluation of cybersecurity risks and recommended corrective actions.

 

On January 9, 2026, the County issued Request for Proposal (RFP) No. 26-035, which solicited bids for internal and external security audit services. The RFP closed on March 2, 2026, with 17 responsive proposals received.

 

                     Troncore, LLC - $850,000

                     RSI Systems - $637,621

                     Solvitur Systems - $884,289

                     Global Solutions Group (GSG) - $819,025

                     JANUS Software - $711,236

                     Gaming Laboratories - $524,970

                     DotWave Solutions - $825,000

                     Brownstone Consulting - $890,908

                     Baker Tilly Advisory Group - $2,375,000

                     Zones - $659,065

                     Federal Cyber Systems - $1,101,605

                     Shorebreak IThreat Security - $607,988

                     CyberElite - $802,500

                     3L337 Consulting - $656,000

                     V3Main Technologies - $859,200

                     Howard Technology - $858,105

                     Concourse Tech - $562,500

 

The RFP evaluation committee consisted of the Chief Information Security Officer and two Senior Information Security Analysts from the Office of Information Security division of the County Administrative Office. The RFP evaluation committee conducted a thorough review of each proposal on its own merit, based on bidder-provided data, capability, and qualifications. Troncore was unanimously selected as the top-ranked vendor based on its qualified personnel, comprehensive testing methodology, alignment with industry standards, mature quality assurance and reporting processes, relevant public-sector experience, strong references, and overall cost-effectiveness.

 

Under the recommended Agreement, Troncore will conduct a comprehensive annual security assessment covering the County’s in-scope internal and external networks, web applications and application programming interfaces, cloud environments, identity and access management systems, endpoints, data protection controls, logging and monitoring capabilities, and incident response safeguards. Testing will include automated and manually validated vulnerability assessments and penetration testing.

 

Following each annual assessment, Troncore will provide an executive summary, a detailed technical report, prioritized remediation recommendations, supporting evidence, detection and response recommendations, and executive and technical briefings. The recommended Agreement also provides for validation testing of remediated critical and high-risk findings.

 

The recommended Agreement allows the County to request targeted supplemental testing when new applications, infrastructure, cloud environments, or other high-risk technologies require focused assessment outside the annual engagement.

 

The County may also request emergency or urgent testing and advisory services in response to critical vulnerabilities, newly disclosed zero-day threats, newly exposed assets, or the need to rapidly validate corrective actions.

 

ATTACHMENTS INCLUDED AND/OR ON FILE:

 

On file with Clerk - Agreement with Troncore

 

CAO ANALYST:

 

Amy Ryals