SOC status:Duty analyst on shift

UK Cyber Defence

Sectors · Defence, research and government contractors

The adversary hereis patient, not opportunistic.

Research institutions, engineering firms and suppliers to the Ministry of Defence, central government and their primes. The threat is long-dwell espionage and supply-chain compromise, and the assurance regime is explicit. We defend against the first and evidence the second.

DEF STAN 05-138Cyber Essentials PlusCMMC Level 3 assessedNCSC CAFUK-based analysts

01The threat picture

State actors want the research, the supply chain and the routers in between.

China-nexus intrusion sets continue to run long-dwell espionage against UK and European defence and research organisations, usually through edge devices and identity systems rather than malware on a desktop. Russia's FSB and GRU units have been the subject of joint advisories in 2026 for systematic compromise of router perimeters across critical infrastructure and defence networks, and for credential-harvesting against federated Microsoft 365 tenants. North Korean operators approach the sector through fraudulent IT-worker recruitment and developer-toolchain compromise. The commercial threat has not gone away either: data-extortion crews target MoD contractors precisely because the data is sensitive. Our weekly report for the sector follows the state actors, the zero-days in the equipment they favour and the assurance implications.

Assurance
DEF STAN 05-138 · Cyber Essentials Plus · CMMC (for US programmes) · NCSC CAF · ISO 27001
Estate
Research networks · engineering and CAD data · federated identity · classified-adjacent document stores · MSP-managed infrastructure
Intelligence
NCSC and Five Eyes advisories · CISA KEV · CiSP · our own honeypots and IP Insights
Weekly report
R&D, military and government contractors — every Friday

What we watch for

The intrusion patterns that matter here

01Initial access

Edge-device zero-days

Firewalls, VPNs and routers exploited by state actors before disclosure, then used for quiet persistence.

02Identity

Federated identity abuse

AD FS and Entra ID weaknesses that turn one server into tenant-wide access.

03Supply chain

MSP and supplier pivots

Managed service providers and sub-tier suppliers as the route into the contractor estate.

04Credentials

Infostealer credential reuse

Valid-account intrusions using credentials harvested from staff and supplier devices.

05Insider

Recruitment and insider approaches

Fraudulent remote-worker placements and engineered approaches to technical staff.

06Extortion

Data extortion

Criminal crews stealing engineering and contract data for leverage rather than encryption.

Weekly report

Defence and government contractor threat intelligence

All insights →

Questions

What contractors ask us

Are your analysts UK-based?

Yes. SOC365 is run from Duxford by UK Cyber Defence's own staff under ISO 27001 and ISO 9001 processes; where a contract requires particular personnel assurance we will tell you plainly what we can and cannot evidence.

We need DEF STAN 05-138 at a given risk level. Can you get us there?

Yes. We map the control set to what you already have, close the gaps with engineering rather than paperwork, and supply the evidence the prime or the MoD assessor expects.

Do you support US programmes?

We hold a CMMC Level 3 assessment ourselves and help UK suppliers to US primes meet the requirements that flow down to them.

Start a conversation

Defend what took years to develop.

Thirty minutes on your estate, your suppliers and the assurance regime you are working to.