IT and cyber security for the defence supply chain.

Primes and their suppliers carry demanding obligations: flow down cyber clauses, a JOSCAR registration, OFFICIAL-SENSITIVE material, and evidence that survives a supplier assurance review. We run, secure, build, and prove the technology behind it, so the controls a prime asks about are already in place and evidenced. UK-based, with UK-hosted infrastructure for the systems we manage, and working to Def Stan 05-138, DEFCON 658 and 659, and the MOD Cyber Security Model.

A precision aerospace engineer inspecting a machined component in a clean UK machine shop
Verified
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber EssentialsCertification body Cyber Essentials PlusCertified NCSC AssuredCyber Advisor CISSPHeld by Daniel McClure Fisher
Defence and Aerospace / 01 · The context

Def Stan 05-138, DEFCON 658, and the MOD Cyber Security Model.

Prime contractors are increasingly flowing down cyber security requirements, and the MOD expects specific, evidenced controls from its supply chain. Getting it wrong does not just fail an audit; it can put the contract at risk.

Def Stan 05-138 DEFCON 658 and 659 MOD Cyber Security Model JOSCAR Cyber Essentials Plus AS9100 ITAR and EAR aware
658DEFCON 658 and 659The MOD contract clauses for cyber risk management, and the flow down to your subcontractors. If they are in your contract, your IT has to answer them.
CSMMOD Cyber Security ModelA risk profile from Very Low to Very High, set by the sensitivity of what you handle, with a matching baseline of controls.
JOSCARSupplier assuranceThe pre qualification register the major primes use. We complete the cyber sections with evidence behind them.
Defence and Aerospace / 02 · The framework

The Cyber Security Model, grade by grade.

The MOD assigns each contract a risk profile based on the information and systems involved, and each profile sets a minimum security baseline. Knowing where your contract sits is the difference between a clean supplier assurance review and an awkward one.

01
Very Low and Low
No access, or OFFICIAL information with no MOD system access. Basic cyber hygiene, rising to Cyber Essentials as the floor.
02
Moderate
OFFICIAL-SENSITIVE information and limited MOD connectivity. Cyber Essentials Plus as the minimum baseline.
03
High and Very High
Critical systems and significant integration, up to national security implications. Cyber Essentials Plus with additional controls, through to a tailored security regime.
01Def Stan 05-138The MOD standard for supplier cyber security, across people, process, and technology.
02DEFCON 658/659Cyber risk clauses, flowed down to your subcontractors.
03JOSCARPre qualification and annual renewal for the primes.
04AS9100Aerospace quality management, underpinned by compliant IT and traceability.
Defence and Aerospace / 03 · The pressures

What we hear from suppliers and primes.

01Win and keep work

Prime questionnaires

A prime's questionnaire lands with cyber clauses you have to evidence, and the next stage of the contract depends on the answers. Get it wrong and the work is at risk.

02Handle it correctly

Sensitive material, sensitive data

OFFICIAL and OFFICIAL-SENSITIVE information has to be encrypted, access controlled on a need to know basis, logged, disposed of securely, and kept in the UK. Default cloud configuration does not get you there.

03Protect the IP

Design and test data

Test data, flight systems, and design files are exactly what a capable adversary is after. The work has to be defended, monitored, recoverable, and evidenced as such.

Defence and Aerospace / 04 · How we help

Managed IT, security, software, and evidence.

01Run it

Managed IT and infrastructure

UK-based support and UK-hosted infrastructure for the systems we manage, with Managed Detection and Response (MDR) included as standard and a service desk staffed by engineers.

02Secure it

Cyber Essentials and monitoring

We are an appointed Cyber Essentials certification body, so we know what the standard requires. We prepare you for Cyber Essentials Plus, the baseline most supply chain work now expects; formal assessment is scoped separately. Monitoring and incident response sit behind it.

03Build it

Software, secure by design

Custom software, integration, and applied AI, with UK-hosted deployment available and an audit trail behind it, built by the team that also runs and secures it.

04Prove it

Evidence and supplier assurance

We build and maintain the evidence packs, policies, and audit trails primes and assessors ask for, and help you complete JOSCAR and prime specific questionnaires, with the controls mapped to the Cyber Assessment Framework (CAF).

We name the sector, not the client. In defence and aerospace especially, the detail that would identify a client, or help an attacker, stays behind closed doors.
Defence and Aerospace / 05 · Clearance and residency

British owned, UK based, and no SC or DV clearance.

We do not hold SC or DV clearance, and we will not pretend otherwise. Where a contract requires cleared personnel, we work with you through the sponsorship process. Our team is UK-based, with UK-hosted infrastructure for the systems we manage.

01StaffUK-based. SC and DV not held; higher clearances via sponsorship.
02DataUK-hosted cloud and backups for the systems we manage for you.
03SupportUK-based service desk and escalation.
04ITAR and EARWe build the access controls; export control law stays with your specialist advisers.
FAQ

Common questions

Do we definitely need Cyber Essentials for MOD work?

For most supply chain work it is the floor. Under the MOD Cyber Security Model, a Low risk profile generally expects Cyber Essentials, and a Moderate profile, where OFFICIAL-SENSITIVE information is involved, expects Cyber Essentials Plus. Which applies depends on your contract's risk profile, which we can read with you. As an appointed certification body we know what the standard asks for and prepare you for it; formal assessment is scoped as its own piece of work.

What is the difference between DEFCON 658 and 659?

They are MOD contract clauses for cyber security. 658 sets out the cyber risk management requirements that apply to you under the contract; 659 covers flowing those requirements down to your own subcontractors. If either appears in your contract, your IT and your suppliers both have to answer it, and we help you build and evidence that.

What security clearances do your staff hold?

We do not hold SC or DV clearance, and we do not claim clearances we do not have. Where your contract requires cleared personnel, we work with you through the sponsorship process. Our team is UK-based, and we will tell you what we can and cannot cover on a given contract.

How do you handle OFFICIAL-SENSITIVE material?

With encryption at rest and in transit, access controlled on a need to know basis, audit logging, secure disposal, and UK-hosted storage for the systems we manage. The controls match the risk profile of the contract rather than a generic template, and the evidence is produced as a matter of course rather than reconstructed before a review.

Can you help us complete a JOSCAR registration?

Yes. We help clients complete JOSCAR registrations and annual renewals, including the detailed cyber security sections, and the prime specific supplier assurance questionnaires alongside them. The aim is accurate, evidenced answers backed by controls that are in place, because that is what stands up when a prime checks.

We handle ITAR controlled data. Can you support us?

We build and run the IT environment and the access controls designed to keep restricted material away from unauthorised foreign access, with a UK-based team and UK-hosted infrastructure for the systems we manage. ITAR and EAR compliance is a legal and procedural matter, so we work alongside your export control advisers rather than replacing them; the legal interpretation stays with the specialists.

Talk to us about your contract.

Send us the clauses in your contract, or the questionnaire from your prime. We will tell you where you stand and what it takes to close the gap.

Reading, Berkshire  /  UK-based team  /  reply within one working day