Britain’s push for cheaper, faster military technology comes with a catch: somewhere inside that shiny new British-built drone, there may still be technology sourced from China.
That problem came into sharp focus this week after it was reported that cameras fitted to the Royal Navy’s K3 Scout drones, supplied by British defence company Kraken Technology Group, sent “heartbeat” data to an IP address in China. The communications, discovered during a routine Ministry of Defence security assessment, reportedly indicated whether the cameras were online and functioning, prompting the MoD to cut their internet connectivity.
The K3 Scout is exactly the kind of platform the UK wants more of as it looks to field autonomous systems faster and at lower cost. The Royal Navy acquired 20 of the vessels under the ongoing Project Beehive, with potential roles including surveillance and force protection.
But building at speed means drawing on complex commercial supply chains. In this case, the cameras were sourced from a third-party supplier rather than manufactured by Kraken – illustrating how even British-built defence technology can depend on components sourced elsewhere.
A Ministry of Defence spokesperson told Resilience Media: “The first duty of government is national security, and we take the security of our equipment, networks and data extremely seriously.
“Our assurance and testing processes are designed to identify and address potential vulnerabilities early, and we continue to undertake routine security activity across our systems and equipment.
“We have found no evidence of MOD data or systems being accessed, compromised or transmitted externally.”
The MoD added that the third-party supplier responsible for the component had provided assurances regarding its security. Asked for further details, including what information was contained in the communications and what security assurances had been provided, the department told Resilience Media that it could not comment further for operational security reasons.
Kraken did not respond to questions from Resilience Media.
Even basic data can compromise a position
Whether any MoD data was compromised is only part of the picture. Even basic telemetry can reveal useful information.
Gavin Knapp, the principal lead for cyber threat intelligence at UK-based cybersecurity firm Bridewell, said that in a military environment even metadata can have intelligence value.
“A simple check-in can reveal that a device is powered on, functioning and potentially where (IP data can infer approximate geolocation) or when it is being used,” he told Resilience Media. “If that is repeated over time and combined with other sources, it can contribute to a picture of deployment patterns, maintenance cycles or operational tempo.”
That doesn’t mean the K3 Scout communications exposed any of those things, nor is there evidence that images of military personnel were transmitted.
Daryl Flack, partner at Avella Security and cyber security advisor to the UK government, told Resilience Media that exposing personnel or faces would likely require more than basic heartbeat telemetry, such as video, still images, thumbnails or metadata derived from imagery.
While current reporting indicates only heartbeat signals were transmitted, the concern is instead what apparently insignificant pieces of information can reveal when accumulated or combined with other intelligence.
“Intelligence rarely comes from one perfect piece of information. It comes from joining lots of apparently insignificant pieces together,” Flack said.
A heartbeat indicating that a device was active at a particular time could, for example, potentially be correlated with information about where an exercise was taking place or when particular military activity was expected.
Where do we draw the line for ‘sovereign’?
The incident also raises a harder question for the UK’s rapidly-expanding defence tech sector: how far down the supply chain should “sovereign” technology actually be sovereign?
A platform can be designed, assembled and sold by a British company while containing cameras, processors, communications modules, firmware and smaller components sourced through multiple international suppliers.
For startups in particular, removing those dependencies is easier said than done. Commercial off-the-shelf technology allows companies to build prototypes quickly and avoid the enormous cost of developing every element themselves. Dig far enough into almost any modern technology supply chain and provenance becomes considerably murkier.
Trusted alternatives can also cost more and take longer to procure. Once a product has been designed around a particular camera, processor or communications module, replacing it can mean redesigning hardware and software and putting the resulting system through testing and certification again.
That creates a tension for a government simultaneously pushing defence companies to innovate faster and demanding greater resilience in their supply chains.
“If every startup is expected to establish the complete provenance of every component and sub-component before it can get near a defence contract, you risk making the cost of entry prohibitive,” Flack said. “That disproportionately affects smaller businesses. A large defence prime can absorb extensive assurance processes. A 10-person startup trying to move from prototype to deployment cannot necessarily do the same.”
Knapp similarly warned that tougher sourcing requirements could damage smaller defence companies if they are “blunt, retrospective or expensive to evidence,” arguing instead for proportionate assurance and better procurement support.
Both point towards one possible solution: a trusted catalogue of components that have already undergone security assessment, giving smaller companies access to vetted technology without requiring each startup to repeat expensive assurance work. (Others have suggested such repository directories previously around cybersecurity products, too: see this guest post for more on that subject.)
But such a list could not simply certify a component once and forget about it. Firmware changes, newly discovered vulnerabilities, alterations to manufacturing and even changes in company ownership can alter the risk attached to technology that was previously considered safe.
Knapp said a repository should include “component provenance, firmware versions, vulnerability status, telemetry behaviour, supplier assurance, SBOM/HBOM-style records and continuous re-testing”.
The K3 Scout case therefore presents a bigger challenge than whether one camera component should have been aboard one Royal Navy platform. Britain’s push towards autonomous, software-driven and lower-cost military systems inevitably brings defence closer to commercial technology and its sprawling international supply chains.
The question is how much of that chain Britain can realistically control – and how much additional cost, scrutiny and delay it is prepared to accept to know exactly what is inside the systems it wants to deploy at speed.












