Friday 11 September, 2026
[email protected]
Resilience Media
  • News
    • Events
    • Interview
    • Startups
    • Venture
    • Weekly Digest
  • Resilience Conference
    • Resilience Conference London — Oct 2026
    • Resilience Conference Copenhagen — May 2026 (PAST)
    • Resilience Conference Warsaw — Apr 2026 (PAST)
  • Launch
  • About
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
  • News
    • Events
    • Interview
    • Startups
    • Venture
    • Weekly Digest
  • Resilience Conference
    • Resilience Conference London — Oct 2026
    • Resilience Conference Copenhagen — May 2026 (PAST)
    • Resilience Conference Warsaw — Apr 2026 (PAST)
  • Launch
  • About
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
Resilience Media
No Result
View All Result

A defence tech startup has a target on its back

If you’re running a defence tech startup, you’ll be on the radar of powerful threat actors like adversary nation states sooner than you think. But by starting early and implementing a systematic security programme, you can effectively counter even the most capable threats and protect your IP, your business operations and your people as you grow

Ed HareDavid CollinsbyEd HareandDavid Collins
September 11, 2026
in Cyber, Guest Posts, Startups
A dartboard with two green darts and one orange dart embedded in it
Share on Linkedin

Increasingly, defence tech founders have no military or government background. That’s a good thing, because it’s driving innovative, out of the box thinking. But civilian founders may not instinctively be tuned in to some of the threats facing the defence sector, particularly in the early stages of building their business.

You Might Also Like

Meet the LAUNCH@RC and SCALE@RC 2026 Cohorts

Orbital inks deal with Germany’s Reflex to build AI data centres in space

Swarmer scoops up UGV maker Ratel Robotics in deal worth up to $224M

The reality is, from the moment you come out of stealth you’ll be on the radar of powerful threat actors. And as you grow, the threat will increase significantly.

This threat — and the rhetoric around it — is escalating rapidly as the UK’s support to Ukraine is increasingly viewed through the lens of defence technology and manufacturing. In August 2026, an advisor to the Kremlin told the BBC that “I cannot exclude 100% that there might be some semi-military [action] … with the factories which are producing drones for Ukraine.”

The threat from nation states: cyber attacks

Most founders will be aware that cyber attacks are a serious threat to any business, and of course companies in the defence sector face the same threats from financially-motivated cyber criminals as any business in any sector. But for companies in the defence supply chain, the cyber threat from nation states is real and growing, and many startups make the mistake of thinking they are too small to warrant such attention right now.

It’s true that nation states, like all threat actors, have finite resources, and need to prioritise. They allocate more resources, and their most highly skilled personnel, to high value targets such as governments, critical infrastructure, and defence primes.

But, like most hackers, they also take the easiest option available. If they can get into a target with a simple piece of social engineering, that’s what they’ll do.  Promising early-stage startups who haven’t yet invested in cyber security may present inviting targets.

The payoff for attackers might not be that large right now, but nation state hackers can ‘dwell’ in that startup’s network indefinitely, waiting for the day when that access becomes important, such as when that startup sells its first product to a military client.

For many companies, their primary concern when it comes to cyber security is financially motivated cyber crime. In that case, while initial access to the target’s network may be stealthy, at some point the attackers usually declare their presence. They encrypt files. Or exfiltrate data and threaten to publish it unless a ransom is paid. Or sell access to user accounts on cyber crime marketplaces.

Not so with nation states. Their primary objective is espionage, and the key to that is maintaining persistent, stealthy access so that they can continuously exfiltrate IP and monitor the firm’s activities and those of its clients, which are usually ministries of defence, militaries or primes.

The other factor that founders in the defence sector need to consider when it comes to cyber security is compliance.

In the UK, Cyber Essentials is the minimum standard for any government procurement or framework, and the new Defence Cyber Certification is increasingly becoming a requirement. It’s much easier to get these certifications if you’re building from a solid early base. And your chances of attracting serious customer interest increase if you can show you’ve already taken measures to reduce cyber risk. More importantly, implementing the Cyber Essentials controls closes down many (although not all) of the low-cost attack pathways, making you a harder target.

The threat from nation states: human intelligence and technical surveillance

Hacking is the most cost-effective and therefore most common way that nation states acquire intelligence. But as you grow, and as you harden your cyber defences, nation states will increasingly reach for two other collection strategies: human intelligence operations, and what’s referred to as technical surveillance.

Human intelligence operations involve foreign intelligence officers or their proxies building relationships with your personnel, contractors, suppliers, partners – anyone who has access to your confidential data. These days, such relationships can be formed both in real life and online.

That person your COO met at a trade show who’s now inviting her out to lunch? The friend your chief engineer made while gaming online, who’s now keen to chat about a side project? The recruiter that reached out to one of your devs with a dream job offer? Any of them could be a foreign intelligence officer from Russia, China, North Korea, Iran.

To counter this, you should develop what in security industry parlance is called a personnel security programme. This involves vetting new hires, defined procedures for onboarding and offboarding personnel, and counter espionage briefings for all personnel, among other measures. You and all your employees should be very conscious of what personal details you post online, as this makes you harder for adversaries to research. Where feasible, keep the physical address of company premises off the web, and out of publicly available databases.

While hacking is a technical process, technical surveillance involves techniques such as bugging meeting rooms, gaining physical access to servers and covertly searching offices, residences or hotel rooms. A typical defence tech startup with premises within a business park and only basic physical security measures is highly vulnerable. The well-trained technical surveillance teams of adversary nations can get into such premises with little effort.

As you grow, you should consider commissioning physical security surveys of your premises, and periodic physical penetration testing to check that the recommended security measures are operating effectively. When your personnel travel, adversaries can access hotel rooms, compromise laptops left unattended or phones handed over at airport security, and bug hotel meeting rooms.

Notably, while the primary threat comes from adversary nations, a host of other neutral and even some broadly allied countries may seek to take advantage of the opportunity if they notice someone travelling within their territory with devices containing sensitive information about military systems.

An organised travel security programme can help by briefing personnel before they travel, restricting access to sensitive data that they won’t need while they’re on the road and, where needed, providing dedicated travel devices with reduced access to corporate and personal data that can be wiped after the trip.

The new reality: physical attack by nation states and their proxies

A few years ago, cyber attack, human intelligence collection and technical surveillance would have been the extent of the threat from foreign states. But times have changed. Adversary states now also present a physical security threat to your premises and personnel.

Before it launched its full-scale invasion in 2022, Russia was already waging a hybrid war against Ukraine. Since Western nations made clear that we would be extensively supporting Ukraine, Russia has gradually expanded that hybrid war into Europe and the UK, where Russia is suspected to be behind a large number of physical attacks targeting critical infrastructure, defence firms and entities linked to Ukraine.

Iran and China are increasingly muscular in the types of operation they are willing to launch in the UK and in allied countries. They are both suspected of using proxies to conduct physical attacks against dissidents based in the UK. The criminal networks they have built for these purposes could easily be redirected against defence firms, should the international situation deteriorate further.

Understandably, many founders are reluctant to face up to the possibility of physical attack, and are often also worried that their employees will be panicked by any open discussion of the risk. But your employees aren’t stupid. They read the news and see defence firms being attacked. Whether you know it or not, some are already concerned about safety issues and waiting for management to address them.

Fortunately, pressure from Western security services means that, in the UK and Western Europe, adversary nation states are often being forced to use local proxies for physical attacks. Although these proxies are sometimes organised criminals, their capabilities are well below those of foreign intelligence services, and their attacks, currently at least, tend to be relatively unsophisticated.

Because of that, there are straight-forward ways to reduce the risks. Many of the same physical security improvements that counter technical surveillance will also reduce the risk of physical attacks against your premises. Personal security awareness briefings can show your employees simple steps to reduce their individual risk, without having any great impact on their lifestyles. The travel security programme you first implemented to address information security risks can also help reduce physical safety risks when personnel travel to higher threat environments.

But as you grow and your profile increases, it’s advisable to take additional steps to address the risk of physical attacks. Threat assessments covering both your firm and key employees should be conducted and refreshed regularly. Additional security measures against physical attack on premises should be implemented, such as anti-vehicle barriers (‘Hostile Vehicle Mitigation’ in security-speak). You should consider security improvements to the homes of company leadership. It may be advisable to provide all personnel with personal safety alarms that allow them to connect with a 24/7 response centre with the touch of a button.

Militant activists and ‘hacktivists’

While nation states are the standout, they are not the only threat actor defence tech startups need to consider. In recent years, militant activist groups have been actively targeting defence firms. Peaceful protest is a well-established right in democracies, and direct action that does not harm anyone or cause serious damage to property is also a well-established form of protest in countries like the UK. Recently, however, some activist groups have gone well beyond these methods.

For example, they have used lorries to ram through gates and sledgehammers to smash through doors and windows, and attack police and security guards. Less violent but still intimidating techniques have included doxing defence firm personnel (publishing their home addresses and other personal information), and putting up posters in the area of defence firm locations showing the faces of company personnel.

We don’t need to take any specific position on the debate over whether certain groups should be proscribed, or when such actions cross the line into something that might be labelled as terrorism, to see clearly that these kinds of tactics present serious security issues for defence firms.

On the cyber side, so-called hacktivist groups, some broadly aligned to militant activist groups, have also been targeting the defence sector.

Competitors

Industrial espionage is much less common than some people may think, but it does happen, and the risk is higher in the defence sector. Competitors based in certain jurisdictions will often have, at minimum, the tacit endorsement of their host governments, and in some cases active support from those governments. Governments know that a strong local defence sector is a critical part of national defence, and are often willing to use state resources to help their own firms outcompete foreign rivals.

Militant and criminal groups

It would be easy for a new defence firm to overlook criminal groups as a serious threat. After all, a defence tech startup doesn’t operate retail stores subject to everyday crimes such as shop lifting. But transnational organised crime these days has a serious interest in acquiring defence technology, and a lot of money to invest in making that happen. Uncrewed Underwater Vehicles (UUVs) can be used to smuggle drugs and weapons. Aerial drones can be used to attack rival groups. Covert communications equipment can be used to defeat law enforcement monitoring. Militant groups have similar interests, and in many parts of the world cross over heavily with organised crime.

The good news: defend against nation state threats, and you defend against most other threats

Nation states have the highest level of capability and the most resources. And since the hybrid war began in Ukraine, Russia in particular now presents a full spectrum threat to defence firms, from cyber espionage all the way through to physical assault on premises and people. That can be intimidating for small defence startups.

But there is a silver lining: the security measures you take against these highly capable, full-spectrum threats, will also deter and mitigate most other threats as well. By focusing on the most highly capable and well-resourced of the likely threats, you gain maximum ROI from your defensive measures.

Ed Hare started his career in the diplomatic corps. He then moved into consulting, initially training government agencies and then specialising in working with large international technology firms to improve their competitive strategies around AI, big data, cloud and cyber security products. Ed also led many cross-border due diligence projects and investigations.

As the cybersecurity threat worsened in the 2010s, Ed took charge of security for his small consulting firm. He founded Keose in 2022 to help small organisations and individuals in high threat sectors such as defence with cyber and physical security, due diligence and investigations. In 2026, Ed also launched SAFE (Security Assistance for Everyone), a pay what you can afford service for low income or vulnerable individuals and families.

David Collins is an 18-year veteran of the UK Royal Air Force. During his military career he was at the forefront of the development of cyber as a domain of military operations, including time working in the Ministry of Defence, GCHQ and commanding the Royal Air Force’s cyber defence wing in support of operations around the world. He was awarded the OBE in the King’s Birthday Honours List 2024 for services to the cyber defence of the Royal Air Force and Ministry of Defence.

On leaving the military he joined Nova Blue Technologies, a cyber security services company who build and protect secure digital environments for organisations operating in sectors with a heightened level of cyber risk. Dave is Nova Blue’s CTO and leads on their Defence and National Security business, helping defence and dual-use startups build cyber resilience and meet government cyber security compliance requirements.

 

Tags: Cybersecurity
Previous Post

Meet the LAUNCH@RC and SCALE@RC 2026 Cohorts

Next Post

Claude AI helped Russia-based threat actors develop autonomous kamikaze drone swarm

Ed Hare

Ed Hare

Ed Hare started his career in the diplomatic corps. He then moved into consulting, initially training government agencies and then specialising in working with large international technology firms to improve their competitive strategies around AI, big data, cloud and cybersecurity products. Ed also led many cross-border due diligence projects and investigations. As the cybersecurity threat worsened in the 2010s, Ed took charge of security for his small consulting firm. He founded Keosetech in 2022 to help small organisations in high threat sectors such as defence with cyber and physical security, due diligence and investigations. In 2026, Ed also launched SAFE (Security Assistance for Everyone), a pay what you can afford service for low income or vulnerable individuals and families.

David Collins

David Collins

Related News

Something new, something BIG at Resilience Conference London

Meet the LAUNCH@RC and SCALE@RC 2026 Cohorts

byLeslie Hitchcock
September 11, 2026

This year, more than 100 companies applied to take part in LAUNCH@RC, our showcase for early-stage companies building across defence...

Orbital inks deal with Germany’s Reflex to build AI data centres in space

Orbital inks deal with Germany’s Reflex to build AI data centres in space

byIngrid Lunden
September 10, 2026

A new partnership between two startups in Germany and the US hopes to bring the moonshot concept of space data...

Swarmer scoops up UGV maker Ratel Robotics in deal worth up to $224M

Swarmer scoops up UGV maker Ratel Robotics in deal worth up to $224M

byLuke Smithand1 others
September 10, 2026

Ukrainian-founded drone autonomy company Swarmer has agreed to acquire Ratel Robotics, one of Ukraine’s leading manufacturers of unmanned ground vehicles,...

The Exploration Company

The Exploration Company raises $450M to build Europe’s answer to SpaceX

byPaul Sawers
September 8, 2026

The Exploration Company (TEC), a five-year-old aerospace firm headquartered in Germany, has raised $450 million in a Series C round...

white textile on white textile

France’s Mistral raises €3B for AI with an accent on sovereignty

byIngrid Lunden
September 8, 2026

Mistral, the French artificial intelligence startup, aims to carve out a position for itself as the “sovereign” solution for organisations...

The German flag flying above the Reichstag building in Berlin, Germany

Berlin launches crisis response after Rhysida dumps 5.79TB of allegedly stolen government data

byCarly Page
September 7, 2026

Berlin has launched an emergency review of data stolen from its administration after ransomware gang Rhysida published what it claims...

Airlogix and Auterion bag $300M AI-guided heavy strike drone deal

Airlogix and Auterion bag $300M AI-guided heavy strike drone deal

byIngrid Lunden
September 3, 2026

Back in February, during the Munich Security Conference, we wrote about how German/Swiss/US startup Auterion and Ukrainian startup Airlogix were...

HyImpulse fuels up with €50M+ to build its breakthrough rocket launchers

HyImpulse fuels up with €50M+ to build its breakthrough rocket launchers

byIngrid Lunden
September 2, 2026

HyImpulse Technologies, a startup out of Germany building a new approach to launching and travelling in space using paraffin-based hybrid...

Load More
Next Post
Website interface with text and abstract drawing

Claude AI helped Russia-based threat actors develop autonomous kamikaze drone swarm

Top stories

The German flag flying above the Reichstag building in Berlin, Germany
Cyber

Berlin launches crisis response after Rhysida dumps 5.79TB of allegedly stolen government data

September 7, 2026
Resilience Conference London a
News

The Resilience Conference London 2026 Agenda is live

September 2, 2026
The Exploration Company
European Defence

The Exploration Company raises $450M to build Europe’s answer to SpaceX

September 8, 2026
Stark inks Virtus deal with NATO member in Northern Europe, one week after expanding to Sweden
Drones & UAS

Stark buys Raydiant RF because electronic warfare is not going away

September 3, 2026

Resilience Media is an independent publication covering the future of defence, security, and resilience. Our reporting focuses on emerging technologies, strategic threats, and the growing role of startups and investors in the defence of democracy.

  • About
  • News
  • Resilence Conference
    • Resilience Conference Copenhagen 2026
    • Resilience Conference Warsaw 2026
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions
  • Mission Statement & Code of Practice
  • Press

© 2026 Resilience Media

No Result
View All Result
  • Home
  • About
  • Subscribe
  • Events
  • Guest Posts
  • Interview
  • News
  • Resilience Conference London 2026
  • Resilience Conference Copenhagen 2026
  • Resilience Conference Warsaw 2026

© 2026 Resilience Media

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.