In summary
- WorkCover Queensland has gone to market for a Continuous Threat Exposure Management (CTEM) platform to consolidate cyber-security exposures into a single, prioritised enterprise view.
- The target environment is heavily Microsoft, running Azure, Entra ID, Microsoft 365, Sentinel and Defender alongside AWS, ServiceNow, GitHub and Obsidian SSPM.
- WorkCover may award the platform and implementation services to different suppliers.
WorkCover Queensland has gone to market for a Continuous Threat Exposure Management (CTEM) platform, seeking to consolidate cyber-security exposures from across its enterprise technology environment into a single, prioritised enterprise view.
The government-owned statutory body - the state’s workers’ compensation insurer since 1997, covering around 180,000 employers and processing about 95,000 claims a year - says the strategic procurement will establish a capability to continuously identify, prioritise, validate and remediate cyber-security exposures.
It forms part of WorkCover’s Cyber Hygiene Program and its WorkCover 2030 strategy, and is aligned to the National Institute of Standards and Technology (NIST) Cyber Security Framework.
The problem WorkCover describes is one of fragmentation: it already runs a range of security tools across its identity, cloud, endpoint, SaaS, application and network domains, but says they operate largely independently and require manual effort to correlate findings, understand business risk and prioritise remediation.
CTEM - a programmatic approach to cyber risk popularised by analyst firm Gartner - is intended to close that gap through what WorkCover calls an Enterprise Exposure Assessment Platform, providing continuous asset discovery, exposure correlation, contextual risk prioritisation using business criticality and threat intelligence, exposure validation through attack-path analysis, and integration with remediation workflows, topped by executive dashboards and analytics.
The scope covers the supply, implementation and ongoing support of the capability - platform licensing, implementation and configuration, integration with WorkCover’s existing technology ecosystem, threat-intelligence integration, knowledge transfer and administrator training, and ongoing product support.
WorkCover said that it may decide not to award the implementation services, and points bidders to an “independent evaluation and multiple award” arrangement - meaning the software platform and the delivery work could go to different suppliers.
Much of the concrete detail is in the target environment, which is heavily Microsoft.
WorkCover describes a cloud-first estate running Microsoft Azure and Amazon Web Services for cloud, Microsoft Entra ID for identity, Microsoft 365 for productivity, Microsoft Sentinel for security operations, Microsoft Defender for endpoint, Defender for Cloud and AWS Security Hub for cloud security, Obsidian SSPM for SaaS security, ServiceNow for IT service management, and GitHub for application security.
The CTEM platform must integrate across all of it - and continue to as the environment evolves - through standards-based APIs, cloud-first deployment and automation.
WorkCover is clear that the platform should complement its existing strategic security investments and provide a central exposure-management capability rather than replace established operational security tools.
The Invitation to Offer closes at 4pm on 9 October 2026.
Earlier this month, WorkCover went to market for an enterprise GRC platform, seeking both a software-as-a-service product and an implementation partner to replace the system it has run since 2019.




