










Threat actors hacking tier 3 suppliers to steal VPN and portal credentials for trusted backdoor access into tier 1 prime networks. Supplier portal exploitation. Contractor credential misuse. Defence supply chain used as stepping stone to reach higher-value targets.
Advanced R&D, blueprints, and material formulas exfiltrated to bypass years of development cost. Dual-use technology under Export Control Order targeted by foreign intelligence. Defence electronics and embedded system design theft. Pre-patent IP at vulnerable stages.
Component manufacturer locked down, halting prime assembly lines. CNC machines and MES encrypted. Legacy OT on unpatched systems providing easy entry. Bill of Materials manipulation introducing structural weaknesses during production disruption.
Attackers spoofing MoD or prime contractor domains sending fake RFPs loaded with malware. BEC on defence contract payments. Engineering teams sent malicious CAD files. Finance staff targeted during high-value procurement.
Manufacturing OT running outdated Windows systems. CNC machine network exposure. Insufficient segmentation between corporate IT and factory floor. MES compromise affecting production integrity and delivery schedules.
Lapsed CE+ certification locking suppliers out of MoD bidding. Def Stan 05-138 non-compliance at contract renewal. Prime contractor security audits identifying unacceptable risk. Loss of MODI handling authorisation.
DCPP-mandated cyber security across Very Low, Low, and Moderate risk profiles
Legally required for MoD contracts handling MODI
Comprehensive resilience standard for defence SMEs
MoD security policy for handling OFFICIAL and OFFICIAL-SENSITIVE data
Contract-specific security requirements at five levels
Digital blueprint protection for dual-use technology
Employee, contractor, and supply chain PII
OT/ICS security for defence manufacturing environments
Where defence suppliers are designated OES
BAE, Babcock, Thales audit obligations
Internal and external penetration testing for tier 2/3 supplier environments. Active Directory and identity management. Network segmentation between corporate IT and factory floor OT. Supplier portal access security.
CNC machine and MES assessment. Factory floor OT security. IT/OT segmentation validation. Legacy system risk assessment. Bill of Materials integrity. IEC 62443 alignment for defence manufacturing.
Web application and API testing for MoD-facing platforms. Cloud security for defence-hosted environments. CI/CD pipeline security. Secure coding assessment. GovTech platform reviews.
CE+ and ICA certification as authorised body. Def Stan 05-138 baseline fulfilment. DCPP audit evidence. MoD contract eligibility. Annual recertification for contract retention.
Def Stan gap analysis across risk profiles. JSP 440 alignment for OFFICIAL and OFFICIAL-SENSITIVE handling. DCPP audit preparation. Export control data protection advisory. Prime contractor audit readiness.
Phishing simulations targeting procurement and engineering with fake RFPs and malicious CAD files. Security awareness for factory and office staff. Incident response for manufacturing disruption and IP compromise.
Independent testing tier 1 primes require before connecting tier 2/3 suppliers to defence portals and networks.
View serviceTest MoD-facing platforms, logistics software, and defence GovTech applications for exploitable vulnerabilities.
View serviceAssess cloud environments hosting defence software, CAD files, and OFFICIAL-SENSITIVE design data.
View serviceAudit PLM platforms, secure file transfer systems, and third-party tools in your defence supply chain.
View serviceDef Stan 05-138 gap analysis, JSP 440 alignment, DCPP audit preparation, and export control advisory.
View serviceAchieve CE+ to satisfy mandatory MoD contract eligibility and MODI handling requirements.
View servicePhishing simulations for procurement and engineering teams using fake RFPs and malicious design files.
View serviceTest defence field apps, logistics tools, and fleet management applications for critical vulnerabilities.
View serviceHarden M365 against BEC targeting defence procurement and contract payment communications.
View service
Most SMBs and mid-market firms have “silent” gaps in their people, process and tech controls implementation. Take the 90-second maturity audit to see your percentile rank.