When people talk about defence, they still tend to picture military bases, government departments and major defence contractors.
Yet some of the organisations developing critical defence capabilities today would never describe themselves as defence companies. Defence capability now depends on a much broader and rapidly growing ecosystem. Software developers, engineering firms, manufacturers, logistics providers, universities, specialist consultancies and technology companies all contribute. Many wouldn’t describe themselves as defence organisations, yet they’re developing critical technology, protecting valuable intellectual property and supporting capabilities that defence depends on. As defence capability has become more distributed, the number of organisations that can influence its success or failure has grown significantly.
Attackers have already adapted to this reality.
Attackers already work this way
Years of Red Teaming show that attackers are remarkably pragmatic. They don’t care whose logo is on the building or where an organisation sits in the supply chain, they only care about finding the easiest route to what they’re trying to achieve.
If compromising a specialist supplier, software company or technology partner gives attackers access to critical programmes, capabilities or intellectual property, that’s where they’ll focus their efforts. They don’t think in terms of sectors or organisational boundaries. They think in terms of opportunity.
Compliance is only part of the picture
Historically, assurance has tended to focus on individual organisations rather than the wider ecosystem that critical capabilities depend on. While that is beginning to change, much of the discussion is still centred on organisational compliance rather than operational resilience.
Standards and certifications remain important, but they don’t always tell us how an organisation will respond when something goes wrong.
Some organisations have every certification their customers could ask for, yet still raise questions about how well they would cope if ransomware stopped production, a critical supplier failed or valuable intellectual property was compromised. Others may have fewer certifications but much stronger resilience because they understand what is critical to their business and have prepared for those scenarios.
Weaknesses rarely stay isolated
Weaknesses rarely remain isolated as within an interconnected defence ecosystem, problems affecting one organisation can quickly affect others.
That’s why we also need to stop treating cyber security, operational resilience, physical security and supply chain assurance as separate conversations.
Attackers certainly don’t see them that way. They’ll use whichever route gives them the best chance of success, whether that’s exploiting a technical weakness, compromising a supplier, manipulating an employee or gaining physical access.
Customers want confidence, not just certification
That is increasingly reflected in the questions defence customers are asking.
They’re not just asking whether suppliers meet a recognised standard. They want confidence that sensitive information will be protected, critical capabilities will continue to be delivered and problems affecting one supplier won’t put the wider programme at risk.
In other words, they’re looking for assurance that extends beyond compliance.
The shift is already underway
That shift is already beginning to show in Defence Cyber Certification (DCC). While certification remains an important part of the process, DCC places greater emphasis on giving defence customers confidence that organisations can protect sensitive information and continue operating when it matters most. The growing focus on DCC reflects a broader recognition that cyber resilience across the defence supply chain is as important as the security within individual organisations.
Certification will continue to play an important role. It establishes a common baseline, builds trust and helps organisations demonstrate they meet defence requirements.
What matters after that is whether those organisations can continue protecting information, managing disruption and delivering the capabilities that defence depends on when they’re tested.
A broader view of readiness
That’s why genuine defence readiness requires a broader view. It means understanding how critical capabilities are delivered across an interconnected ecosystem and having confidence those capabilities can continue when organisations across that ecosystem are tested.
Ultimately, the question is no longer simply whether one organisation can demonstrate compliance. It’s whether the wider defence ecosystem can continue delivering the capabilities that matter when it comes under pressure, disruption or attack.
