Defence and government contractors threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the R&D, military and government-contractor threat picture remained dominated by state-sponsored cyber-espionage against the defence industrial base.
- Reference: TI-2026-0517-006 (public edition)
- Sector: R&D, military and government contractors
- Reporting period: 11–17 May 2026
- Issued: 17 May 2026 · Lead analyst: Peter Bassill · Analysts: EmilyAI; Peter Bassill
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
During the reporting period 11 May 2026 – 17 May 2026 the R&D, military and government-contractor threat picture remained dominated by state-sponsored cyber-espionage against the defence industrial base. Public reporting carried into the period continues to document the October 2025 Lynx ransomware breach of Dodd Group (UK Ministry of Defence contractor) which exfiltrated approximately 4TB of data including sensitive files on eight RAF and Royal Navy bases. Google Threat Intelligence Group continues to assess that China-nexus cyber-espionage missions directly targeting defence and aerospace industries have exceeded those from any other state-sponsored actor cohort over the last two years. The February 2026 UNC3886 (China-linked) breach of all four major Singapore telecommunications providers in a months-long espionage campaign remains the freshest large-scale example. APT28 (Russian GRU) router-exploitation activity continues at scale globally, with UK Government having sanctioned three GRU Units and 18 GRU officers, and NCSC having called out the AUTHENTIC ANTICS malware. The 14 May 2026 CISA Emergency Directive 26-03 (Cisco Catalyst SD-WAN, CVE-2026-20182) is directly relevant to defence-contractor and research-organisation perimeter estates.
Key Judgements
The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that China-nexus cyber-espionage operations targeting UK defence, aerospace, R&D and government-contractor estates will continue at current tempo over the next reporting cycle. APT5 spearphishing of defence-contractor employees via personal email addresses and UNC5976 spoofing of defence-contractor infrastructure (UK, US, Germany, France, Sweden, Norway, Ukraine, Turkey, South Korea) are the operational reference points (HIGH confidence).
- It is highly likely that Russian GRU (APT28 and adjacent clusters) router-exploitation and password-harvesting activity will continue against research organisations and government-contractor estates. The AUTHENTIC ANTICS malware family attributed by NCSC, plus the wider UK sanctions package against three GRU Units and 18 officers, represents the formal UK posture (HIGH confidence).
- It is likely that CISA Emergency Directive 26-03 (Cisco SD-WAN, CVE-2026-20182) will produce at least one publicly-disclosed defence-contractor or research-organisation exploitation event within the next two reporting cycles (MEDIUM-HIGH confidence).
- It is likely that ransomware-style data-extortion incidents against defence contractors (Lynx / Dodd Group pattern) will continue at low tempo but high impact, with at least one further UK-MoD-contractor disclosure plausible within the next two reporting cycles (MEDIUM confidence).
- There is a realistic possibility of a UK-targeted hybrid disinformation-and-cyber operation during the next reporting cycle attributable to Russian state-aligned actors, particularly around high-profile geopolitical developments (MEDIUM confidence).
2. Sector threat landscape
The R&D, military and government-contractor vertical continues to absorb the most strategically consequential cyber-espionage pressure of any sector covered in this reporting series. Google Threat Intelligence Group assesses that China-nexus cyber-espionage missions directly targeting defence and aerospace industries have exceeded those from any other state-sponsored actor cohort over the last two years. APT5 spearphishing campaigns targeting current and former employees of major aerospace and defence contractors continued through 2024 and 2025, relying heavily on phishing to personal email addresses with lures tailored to professional role, location and personal interests. UNC5976 (Russian espionage cluster) maintained infrastructure spoofing defence contractors in the UK, US, Germany, France, Sweden, Norway, Ukraine, Turkey and South Korea. China-linked UNC3886 breached all four major Singapore telecommunications providers in a months-long espionage campaign disclosed in February 2026.
Russian GRU activity (APT28 and adjacent clusters) continued to target vulnerable routers worldwide to hijack DNS and enable adversary-in-the-middle credential and token theft. UK Government sanctioned three GRU Units and 18 GRU officers for cyber and information-interference operations, and NCSC called out the AUTHENTIC ANTICS malware family. The October 2025 Lynx ransomware breach of Dodd Group (UK Ministry of Defence contractor) — approximately 4TB exfiltrated including sensitive files on eight RAF and Royal Navy bases — remains the structural operational reference case for ransomware-style data-extortion impact on UK MoD-contractor estates.
The 14 May 2026 addition of CVE-2026-20182 (Cisco Catalyst SD-WAN Controller authentication bypass) to the CISA KEV catalogue under Emergency Directive 26-03 is directly relevant to defence-contractor and research-organisation perimeter estates. Ivanti EPMM CVE-2026-6973 (active exploitation, FCEB deadline 10 May passed), Citrix NetScaler and Palo Alto PAN-OS edge CVEs, the Ivanti Xtraction CVE-2026-8043 and Fortinet FortiAuthenticator CVE-2026-44277 / FortiSandbox CVE-2026-26083 additions from the May 2026 Patch Tuesday cycle are the prioritised patching set. SAP S/4HANA CVE-2026-34260 carries particular relevance to large defence-contractor ERP estates.
The criminal ransomware ecosystem remains a sub-dominant but persistent secondary concern. The April 2026 Breachsense leak-site picture — 772 victims across 70 groups — does not show R&D / contractor entities as a leading target subset, but Cl0p / ShinyHunters / WorldLeaks data-extortion against trusted file-transfer / SaaS platforms is operationally relevant to any contractor with shared-services exposure to the wider supply chain. The MOVEit Automation CVE-2026-4670 active-exploitation reporting realigns the operator signature with these dependencies.
Edge-appliance exposure is the dominant gating factor for any contractor with public-facing remote-access infrastructure. The Citrix NetScaler ADC / Gateway CVEs (CVE-2026-3055, CVE-2026-4368), the Ivanti EPMM CVE-2026-6973 (KEV-listed 1 May, FCEB deadline 10 May) and the Palo Alto PAN-OS User-ID portal CVE-2026-0300 (KEV-listed 6 May, FCEB deadline 27 May) collectively define a patch-wave that NCSC's 4 May 2026 blog characterises as the proximate operational concern across all UK CNI verticals.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.
Threat Actor Profile — APT5
- Aliases: Manganese, Keyhole Panda, UNC2630-adjacent
- Suspected Origin: China
- Suspected Sponsor: State-sponsored — PRC
- Primary Motivation: Cyber-espionage — defence and aerospace IP
- Sector Targeting: Aerospace, defence, R&D, government contractors
- Geographic Focus: Global; documented UK / US / EU / Asia-Pacific operations
- Signature TTPs: Spearphishing of current and former defence-contractor employees via personal email; tailored lures based on role, location and personal interest; supply-chain exploitation
- Tooling / Malware Families: Custom backdoors; living-off-the-land; cloud-service abuse
- Recent Activity: GTIG-attributed spearphishing campaigns through 2024 and 2025 targeting current and former employees of major aerospace and defence contractors
- Assessed Threat to Vertical: HIGH — sustained UK-defence-contractor targeting
- Analytic Confidence: HIGH
Threat Actor Profile — APT28
- Aliases: Fancy Bear, Sednit, GRU Unit 26165
- Suspected Origin: Russia
- Suspected Sponsor: State-sponsored — Russian GRU
- Primary Motivation: Cyber-espionage, influence, disruption
- Sector Targeting: Defence, government, research, media, civil society
- Geographic Focus: Global
- Signature TTPs: Router exploitation; DNS hijack for adversary-in-the-middle credential and token theft; AUTHENTIC ANTICS malware deployment; spearphishing
- Tooling / Malware Families: AUTHENTIC ANTICS, X-Tunnel, X-Agent and successor families
- Recent Activity: UK Government sanctioned three GRU Units and 18 GRU officers for cyber and information-interference operations; NCSC called out AUTHENTIC ANTICS malware family
- Assessed Threat to Vertical: HIGH — UK-government-attested targeting
- Analytic Confidence: HIGH
Threat Actor Profile — UNC3886
- Aliases: —
- Suspected Origin: China
- Suspected Sponsor: State-sponsored — PRC
- Primary Motivation: Cyber-espionage — telecommunications, defence, government
- Sector Targeting: Telecommunications, defence, government, R&D
- Geographic Focus: Asia-Pacific; expanding global footprint
- Signature TTPs: Zero-day exploitation of edge / virtualisation appliances; long-dwell-time supply-chain operations
- Tooling / Malware Families: Custom implants; living-off-the-land
- Recent Activity: February 2026 disclosure of breach of all four major Singapore telecommunications providers in a months-long espionage campaign
- Assessed Threat to Vertical: HIGH — capability and operational dwell time
- Analytic Confidence: HIGH
Threat Actor Profile — Lynx
- Aliases: —
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware and data extortion (with cross-cutting state-tolerant alignment)
- Sector Targeting: Mid-market across multiple verticals; defence-contractor in target set
- Geographic Focus: Global
- Signature TTPs: Initial access via stolen credentials and edge-appliance exploitation; rapid lateral movement; data-exfiltration prioritised
- Tooling / Malware Families: Lynx encryptor; commodity LOLBins
- Recent Activity: October 2025 Dodd Group breach (UK MoD contractor) — approximately 4TB exfiltrated including sensitive files on eight RAF and Royal Navy bases
- Assessed Threat to Vertical: HIGH — proven UK MoD-contractor victimology
- Analytic Confidence: HIGH
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1566.002 | Spearphishing Link | APT5 spearphishing of current and former defence-contractor employees via personal email addresses; tailored lures by role and personal interest. | H |
| Initial Access | T1190 | Exploit Public-Facing Application | Cisco Catalyst SD-WAN CVE-2026-20182 (KEV 14 May, ED 26-03), Ivanti EPMM CVE-2026-6973 (active exploitation, FCEB deadline passed), Ivanti Xtraction CVE-2026-8043, Fortinet FortiAuthenticator / FortiSandbox CVE-2026-44277 / CVE-2026-26083, SAP S/4HANA CVE-2026-34260. | H |
| Initial Access | T1133 | External Remote Services | Citrix NetScaler ADC / Gateway, Palo Alto PAN-OS, F5 BIG-IP APM expose remote-access infrastructure across multi-site defence and research estates. | H |
| Initial Access | T1078.004 | Valid Accounts: Cloud Accounts | APT31 use of cloud services for stealthy access; sustained adversary interest in cloud-hosted research IP. | M |
| Initial Access | T1199 | Trusted Relationship | UNC5976 spoofing defence-contractor infrastructure across UK, US, Germany, France, Sweden, Norway, Ukraine, Turkey, South Korea — supply-chain and partner-impersonation pattern. | H |
| Initial Access | T1556.004 | Modify Authentication Process: Network Device Authentication | APT28 router-exploitation and DNS-hijack credential and token theft; AUTHENTIC ANTICS family. | H |
| Impact | T1486 | Data Encrypted for Impact | Lynx and adjacent RaaS clusters deploying encryptors against UK MoD-contractor estates (Dodd Group pattern). | M |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| Carry-forward | Dodd Group breach (UK MoD contractor) | Lynx | Approximately 4TB exfiltrated including sensitive files on eight RAF and Royal Navy bases; ransomware deployment; visitor logs, staff details and construction records exposed | CSIS; vendor reporting; press |
| Feb 2026 | UNC3886 breach of all four Singapore major telecommunications providers | UNC3886 (China-linked) | Months-long espionage campaign across all four major operators; representative of regional China-nexus telco-targeting pattern | Cyber Security Agency of Singapore; The Hacker News |
| Ongoing | APT28 router exploitation / DNS hijack | APT28 (GRU) | UK Government sanctions package against three GRU Units and 18 officers; NCSC AUTHENTIC ANTICS malware attribution | NCSC; UK Government |
| Ongoing | APT5 personal-email spearphishing campaign against defence-contractor employees | APT5 (China) | GTIG-tracked sustained spearphishing of current and former employees of major aerospace and defence contractors via personal email addresses | Google TIG |
| 14 May 2026 | Cisco Catalyst SD-WAN exploitation surface (sector-wide) | Multiple — CISA ED 26-03 | CVE-2026-20182 authentication-bypass added to KEV; ED 26-03 hunt-and-hardening direction; defence-contractor and research-organisation perimeter estates immediately exposed | CISA; NCSC |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller (authentication bypass) | 9.8 | Yes (14 May) | Yes | Patch immediately; align with CISA ED 26-03 / Supplemental Direction; hunt for compromise; FCEB hardening guidance applies |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) | 8.8 | Yes (1 May) | Yes | Patch immediately; FCEB deadline now passed (10 May); rotate admin sessions; review MDM admin auth logs |
| CVE-2026-0300 | Palo Alto Networks PAN-OS User-ID Portal | 9.8 | Yes (6 May) | Yes | Patch immediately; FCEB deadline 27 May; restrict portal exposure |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway | 9.3 | Yes | Yes | Patch; rotate session keys; hunt for indicators |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway | 8.8 | Yes | Yes | Patch; audit Gateway session logs |
| CVE-2026-4670 | Progress MOVEit Automation (< 2025.1.5 / 2025.0.9 / 2024.1.8) | 9.8 | Yes | Yes (low-complexity) | Patch; audit MFT operator and admin authentication |
| CVE-2026-8043 | Ivanti Xtraction (external control of file name, RCE) | 9.6 | — | Pending | Patch; restrict reporting console exposure |
| CVE-2026-44277 | Fortinet FortiAuthenticator (improper access control) | 9.1 | — | Pending | Patch; restrict management plane exposure |
| CVE-2026-26083 | Fortinet FortiSandbox (missing authorisation, RCE) | 9.1 | — | Pending | Patch; restrict sandbox API exposure |
| CVE-2026-34260 | SAP S/4HANA Enterprise Search for ABAP | 9.6 | — | Pending | Patch; restrict access to enterprise search endpoints |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. The IP Insights enrichment service (https://ipinsights.io) provides the underlying threat-score and blocklist coverage.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IPv4 | 136[.]232[.]11[.]10 | 20 Apr 2026 | H | SSH brute-force pattern — Reliance Jio IN (AS55836); IP Insights threat 100/critical, 7 active blacklists; carry-forward IOC |
| IPv4 | 87[.]236[.]176[.]45 | 02 May 2026 | M | Constantine Cybersecurity Ltd / INTERNET-MEASUREMENT (AS211298) — IP Insights threat 100/critical; mass scanning |
| IPv4 | 185[.]220[.]101[.]30 | 03 May 2026 | M | Tor exit (for-privacy.net) — IP Insights threat 100/critical |
| ASN | AS200651 | Ongoing | H | FlokiNET — 112/134 known IPs blacklisted; risk 100/critical; risk breakdown low 19 / med 3 / high 31 / critical 81; bulletproof hosting |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite |
|---|---|---|---|
| China-nexus cyber-espionage (APT5 / UNC3886 / APT31) compromise of UK defence or aerospace R&D estate | H | H | CRITICAL |
| Russian GRU (APT28) router-exploitation and credential-token theft against research / contractor estates | H | H | CRITICAL |
| Cisco SD-WAN exploitation chain (CVE-2026-20182, ED 26-03) against defence-contractor perimeter | M | H | HIGH |
| Ransomware-style data-extortion against UK MoD-contractor estate (Lynx / Dodd Group pattern) | M | H | HIGH |
| UNC5976-pattern infrastructure-spoofing leading to credential harvesting or supply-chain compromise | M | M | MEDIUM |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection priorities for the next reporting cycle should focus on five concurrent threads. First, Cisco Catalyst SD-WAN Controller telemetry and the CISA ED 26-03 hunt-and-hardening hypotheses retrospectively across sixty days. Second, edge-appliance exploitation telemetry on Citrix NetScaler, Ivanti EPMM, PAN-OS, Fortinet and F5 BIG-IP. Third, sustained hunting for APT28 router-exploitation indicators (AUTHENTIC ANTICS-related, plus the wider GRU unit indicator set). Fourth, anomalous personal-email-to-corporate-system pivot patterns — APT5 spearphishing targets employees on personal email addresses, with the pivot to corporate access occurring later. Fifth, sustained living-off-the-land and dual-use-tool hunting (Cobalt Strike, Brute Ratel, Sliver) across research-organisation and defence-contractor estates.
Defend
Patch posture is the single most operationally consequential defensive action for the next reporting cycle. CVE-2026-20182 (Cisco SD-WAN, ED 26-03), CVE-2026-6973 (Ivanti EPMM), CVE-2026-0300 (PAN-OS), CVE-2026-3055 / CVE-2026-4368 (NetScaler), CVE-2026-8043 (Ivanti Xtraction), CVE-2026-44277 (FortiAuthenticator), CVE-2026-26083 (FortiSandbox), CVE-2026-34260 (SAP S/4HANA) and CVE-2026-4670 (MOVEit Automation) are the prioritised set. Enforce hardware-token MFA on all engineer, scientist and admin accounts. Apply strict allowlisting on personal-email-to-corporate-system bridges and on corporate VPN access from non-managed endpoints. Where research organisations collaborate with non-UK partner institutions, apply enhanced supplier cyber-assurance against the same patch set.
Disrupt
Disruption priorities for the next reporting cycle are concentrated in three areas. First, indicator sharing within CiSP CNI Trust Group, DSIE / Defense Industrial Base Sector Coordinating Council, and bilateral NCSC liaison channels — the IP Insights enrichment service should be used to support prompt indicator submission. Second, takedown coordination on UNC5976-pattern infrastructure spoofing defence contractor brands. Third, intelligence exchange with peer R&D and contractor organisations around APT28 / APT31 / APT5 / UNC3886 / UNC5976 TTP signatures and observed targeting of UK estates.
10. Forward outlook
It is highly likely that China-nexus and Russia-nexus cyber-espionage operations against UK defence, aerospace, R&D and government-contractor estates will continue at current tempo. It is likely that CISA ED 26-03 (Cisco SD-WAN) will produce at least one publicly-disclosed defence-contractor exploitation event within the next two reporting cycles. It is likely that ransomware-style data-extortion activity against UK-MoD-contractor estates (Lynx / Dodd Group pattern) will continue at low tempo but high impact. There is a realistic possibility of a UK-targeted hybrid disinformation-and-cyber operation during the next reporting cycle attributable to Russian state-aligned actors.
Trigger conditions warranting forecast revision: confirmed exploitation of CVE-2026-20182 against a UK defence-contractor or research-organisation estate (raises the vertical-risk to CRITICAL); attribution of a fresh spearphishing or supply-chain campaign against UK defence employees to APT5 / UNC3886 / APT31; publication of a new GRU-attributed router-exploitation TTP variant by NCSC; ransomware-style data-extortion incident publicly attributed against a named UK MoD contractor or defence-research organisation.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC – Reports & Advisories (rolling) | NCSC | A1 |
| 2 | NCSC – Cisco Catalyst SD-WAN advisory and ED 26-03 alignment (May 2026) | NCSC / CISA | A1 |
| 3 | NCSC – Citrix NetScaler ADC / Gateway CVE-2026-3055 / CVE-2026-4368 | NCSC | A1 |
| 4 | NCSC – F5 BIG-IP Access Policy Manager unauthenticated RCE advisory | NCSC | A1 |
| 5 | NCSC – Middle East cyber posture review guidance | NCSC | A1 |
| 6 | CISA Known Exploited Vulnerabilities Catalogue (rolling) | CISA | A1 |
| 7 | CISA Alert – CVE-2026-20182 Cisco Catalyst SD-WAN Controller added to KEV (14 May 2026) | CISA | A1 |
| 8 | CISA Emergency Directive 26-03 – Mitigate Cisco SD-WAN Vulnerabilities | CISA | A1 |
| 9 | CISA Alert – Ivanti EPMM CVE-2026-6973 active exploitation | CISA | A1 |
| 10 | Check Point Research – State of Ransomware Q1 2026 | Check Point Research | B2 |
| 11 | Breachsense – April / Q1 2026 ransomware tracking | Breachsense | B2 |
| 12 | Ransomware.live – sector and group leak-site index | Ransomware.live | B2 |
| 13 | IP Insights – IP reputation and blocklist enrichment service | UK Cyber Defence | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Defence and government contractors threat intelligence report — 4–8 May 2026
The R&D and military / government-contractor threat picture for the reporting period continues to be dominated by sustained state-sponsored activity.
Defence and government contractors threat intelligence report — 16–22 May 2026
The reporting cycle has been shaped by sustained state-sponsored espionage interest in UK and EU defence supply-chain entities, continued Chinese APT operational tempo across the supply-chain pivot model that produced the 2024 MOD payroll-provider breach…
Defence and government contractors threat intelligence report — 27 April – 3 May 2026
The R&D and military-government-contractor threat picture for the reporting period is dominated by sustained state-sponsored activity.