The UK’s Ministry of Defence (MoD) has revealed a new programme calling for tech companies to help firm up its cybersecurity.
Under the Reducing the Cyber Attack Surface initiative, companies can apply for grants to help them develop their technologies. Proposals should help enable greater confidence and a level of assurance in military systems against cyber-enabled attack.
Successful companies will be able to receive up to £300,000 of funding as part of a nine-month contract. The first cycle will close on October 20th, 2021.
This will help the MoD to reduce its attack surface, along with that of the defence industry.
In particular, the MoD wants to identify and accelerate the development of next generation hardware and software technologies that will reduce the vulnerabilities within current and future computer networks and systems, focusing particularly on operational technologies.
This includes tech that significantly reduces the opportunity for cyberattack, raises the barrier to entry for adversaries and provides greater confidence against cyber-enabled attack.
In addition, the MoD is after novel systems that are applicable across a whole “class” of attack surfaces rather than solutions tailored to a specific threat.
Launched by the Defence and Security Accelerator (DASA) programme, the initiative is being run on behalf of Defence Science and Technology laboratory (DSTL) and Defence Science and Technology (DST).
Attack Surface
One of the core rules of cybersecurity is keeping surface area as small as possible. By keeping the number of potential points to a minimum, cyberattackers have fewer areas to exploit.
However, as many organisations move their operations online, so too have surface areas increased. This has been compounded by the rise of cloud technologies and work from home practices. Infrastructure can no longer be confined to a single physical location, and systems need to be accessed from multiple points.
The MoD is also faced with the problem of legacy systems. Integrating these with newer systems provides a substantial threat to the organisation, as many older systems lack modern security features and are not being updated to deal with new threats.
All this has served to create a plethora of vulnerabilities and systems so complex and diffuse that it is difficult for cybersecurity professionals to monitor.
Recommended
- Britain is home to more big tech firms than France and Germany combined
- Neurodivergent talent can help fill cybersecurity skills gap
- Deepfaking and open source: How anyone could give a Queen’s speech
For the defence industry, cybersecurity is a particularly prominent issue. Over the last few years, nation states have ramped up their cyber abilities and have added this to their arsenal of conventional weaponry.
A number of high-profile cyberattacks have been linked not just to state actors, but to their militaries. A recent report from US and UK security agents warned that Russian military intelligence, the GRU, was involved in a major ongoing cyberattack against US and European government institutions.





