Provision of Fully Managed, Cloud Delivered Secure Web Gateway (SWG) Service
Item Details:
- Organisation: World Health Organization
- Reference Number: 2026_053_BOC_IDT_Safer_Internet_Browsing
- Published: 02-Apr-2026
- Deadline: 28-Apr-2026 at 17:00 hours
- Time zone: (GMT 2.00)
- City: Geneva
- Country: Switzerland
- Expires: This ad has expired
Item Description:
The World Health Organization (WHO) invites vendors to submit an Expression of Interest (EOI) for Safer Internet Browsing – Global web proxy which address the following objectives:
In addition to completing Annexes A & B, please provide a PDF document outlining your ability to meet the following requirements and minimum criteria in sections 1 and 2 of this EOI. The PDF should be no longer than 3 to 5 pages in length.
Additional annexes/appendices received will not be considered. We will only invite the proposers who meet the requirements in this Section 1 and are compliant with the criteria from Section 2.
a. Provision of a fully managed, cloud delivered Secure Web Gateway (SWG) service. The solution shall provide a more secure, reliable, and high-performance Internet access for all WHO offices and users globally, including endpoints located within WHO offices, devices on which software agents cannot be installed, and WHO managed endpoints irrespective of their physical location.
b. The proposed solution shall deliver a comprehensive set of Cybersecurity Controls, including but not limited to:
- Cloud native forward web proxy functionality with advanced AI driven protection against malware, ransomware, and phishing
- Integration with real-time threat intelligence feeds and automated updates for malware signatures, phishing databases, and URL blacklists.
- TLS and SSL traffic inspection, including decryption and re-encryption at scale, to address threats delivered over encrypted connections
- Web content and URL filtering with granular policy-based controls to block malicious, inappropriate or non-productive websites
- Advanced threat protection capabilities incorporating anti-malware and anti-virus controls
- Cloud Access Security Broker functionality providing visibility and control over SaaS applications and unmanaged or shadow IT usage
c. The proposed solution shall support the following Service Delivery Model:
- The service must be fully cloud-based, requiring no on-premises hardware deployment or maintenance.
- The platform must operate across multiple geographically distributed data centres to provide high availability, resilience, and consistently low latency for users worldwide.
- The solution must support both office-based and remote or roaming users.
- The solution must support high concurrency, with defined throughput and latency thresholds to ensure consistent performance for all global users.
d. The solution shall support multiple Traffic Forwarding Capabilities, including:
- Endpoint or client software for Windows, macOS, Linux, iOS, and Android
- Proxy Auto-Configuration (PAC) files
- Proxy chaining mechanisms
- IPSec tunnel integration
- GRE tunnel integration
e. The solution shall satisfy the following Integration Requirements:
- Single Sign-On (SSO)
- Multi-Factor Authentication (MFA) including passkeys
- On-premises Microsoft Active Directory (AD)
- Microsoft Entra ID
- RESTful APIs for integration, automation, and orchestration
- Integration with CrowdStrike Next-Generation SIEM
- Centralised management console providing detailed logging, policy configuration, and actionable insights to support security operations, compliance, and both technical and management reporting.
f. The solution shall meet the following Compatibility Requirements:
- CrowdStrike Falcon Endpoint Detection and Response (EDR) agent
- Tenable vulnerability management scanning agent
g. WHO expects the service to adhere to defined SLAs for incident management, change management, and service availability, including but not limited to:
- Continuous 24/7 monitoring of managed devices
- Incident Escalation: Tickets escalated to a certified engineer within 10 minutes of detection
- Incident Acknowledgement: New tickets acknowledged within 15 minutes
- Incident Assessment: Initial assessment provided within 4 hours of ticket creation
- Emergency Incident Handling: Ability to flag incidents as emergencies, prioritizing them over other tickets
- Service Availability for single-site deployments: 99.99%
- Software Updates: Regular deployment of patches, bug fixes, and new features
WHO intends to invite selected vendors to participate in a formal solicitation, via a Request for Proposals (RFP), at a later stage, for the above requirements. Complete details of the requirements will be included in the solicitation documents.
Verified user
Related Ads
Some other Request for EOI ads that you might be interested in...
Provision of Maintenance and Repair Services of UNFICYP’s Water Purif...
The United Nations Peacekeeping Force in Cyprus (UNFICYP) intends to conduct a competitive solicitation exercise for the provision of maintenance and repair services of UNFICYP’s […]
2022-08-02
Provision of Construction Materials and related Professional Equipment, ite...
The United Nations Global Service Centre (UNGSC) requires a long-term contract for the provision of construction materials and related professional equipment, items and accessories on […]
2026-05-22
Refurbishment of the Interior and Façade of UNECLAC Port of Spain Office
The Economic Commission for Latin America and the Caribbean of the United Nations (ECLAC) seeks companies with local representation in Trinidad and Tobago, with at […]
2018-11-23
















