The good intelligence stops at the boundary
Defence organisations are usually well served at the classified level. National CERTs, allied sharing arrangements and government advisories cover state activity properly, and for a prime with clearance the strategic picture is not the gap.
The gap is everything below it. The commodity IT running your business systems. The VPN appliance your engineering partner uses. The eleven-person supplier making a bracket for a programme you are three years into, who has one part-time IT contractor and no idea they were posted to a leak site last Thursday. That layer is unclassified, commercially reported and moving daily, and it is where the actual compromises happen.
Meanwhile the people who most need this are the ones least able to buy it. A defence SME carrying DEFCON 658 or CMMC obligations is expected to maintain threat awareness on a budget that does not stretch to an enterprise intelligence subscription. That mismatch is most of why the supply chain is the soft edge.
Why the sector needs its own view
The supply chain is the attack path, not a risk category
A single platform programme can involve thousands of suppliers across four or five tiers, weighted heavily towards small engineering firms. Adversaries do not need to breach the prime to obtain programme data. They need to breach whoever holds the drawings, and that is frequently a company with no security function at all.
The objective is usually collection, not disruption
Design data, technical specifications, export-controlled information, programme timelines and personnel records. That activity is quiet, patient, uses legitimate tooling, and produces no ransom note and no news cycle. It surfaces in advisories and in supplier breach reporting, which means finding it is a collection problem.
Your people are targeted directly
Approaches through professional networks, fabricated recruiters, conference and academic pretexts, and long-running social engineering against cleared and specialist staff. Campaigns of this type have run against aerospace and defence for years and are reported openly, but almost never inside a security tool.
Compliance is contractual, and failure removes you from the bid
In most sectors a compliance failure produces a fine. In defence it produces disqualification. That changes the calculation entirely for a supplier deciding whether threat monitoring is worth the line item.
Activity tracks geopolitics
Deployments, exercises, treaty events, arms transfers and public announcements all move the tempo. Intelligence that is not connected to events is intelligence a defence team has to re-contextualise manually.
Dual-use blurs the boundary
A large share of the defence supply base is commercial companies with a defence line. Their exposure looks commercial and their consequences do not.
What ThreatCluster does for a defence security team
Supplier monitoring across the tiers
Track your suppliers, subcontractors and engineering partners as watched entities. Leak site postings, breach reporting and advisories affecting any of them reach you the day they appear. For a prime, this is the only practical way to see below tier one. For an SME, it is how you learn that your own upstream has a problem.
One record per incident
Density-based semantic clustering groups every source covering the same event into a single record with a sourced timeline, extracted entities, IOCs and MITRE ATT&CK mapping. Roughly 900 articles a day become around 70 clusters.
Actor tracking for the programmes that target the sector
State-aligned collection operations with a demonstrated history against defence and aerospace, tracked as entities with their own timelines, including the campaigns that target personnel rather than infrastructure.
Exploitation status, not CVSS theatre
Confirmed in-the-wild exploitation separated from the rest of the queue. On accredited systems where any change carries a process, that distinction is what justifies starting one.
Evidence your contracts require
Dated, sourced records of what was known and when, exportable as reports written to be handed to an auditor, a prime's supply chain assurance team or a programme security officer without a rewrite.
Nothing ingested from your environment
The platform pushes intelligence outward. It does not collect telemetry, does not connect to your networks, and holds no data about your systems unless you choose to enter it.
Running in an afternoon
- Tell it what you run. Suppliers, platforms, vendors, programmes if you are willing to name them. A few minutes in the setup wizard.
- Pick how it reaches you. Digest, Slack, Teams, RSS or API. Most teams start with a daily digest.
- Wire the outputs in. IOC exports to the SIEM, reports into the assurance pack.
Hosted platform, outbound only, no agents, no site deployment, no connection to accredited or air-gapped environments.
Evidence for the obligations in your contracts
Defence contracts increasingly assess threat awareness rather than let you assert it, and the obligation flows down through the supply chain to firms that have never had to evidence it before.
- CMMC and NIST SP 800-171 / 800-172 for the US defense industrial base, where situational awareness and incident reporting are assessed rather than asserted
- DFARS 252.204-7012 reporting obligations
- DEFCON 658 and Def Stan 05-138 for UK MOD contracts, with Cyber Risk Profile requirements flowing down through the supply chain
- Cyber Essentials Plus where it is a contract condition
- NIS2 for defence-adjacent manufacturers in scope as important entities
- ISO 27001 Annex A 5.7, threat intelligence, as a named control
ThreatCluster is the monitoring and evidence layer underneath these. It does not make you compliant and it does not manage an accreditation. It produces the dated, sourced record showing that threat awareness was maintained and when specific supplier incidents reached your team, which is the part suppliers most often cannot evidence.
Questions we get from defence buyers
“We already receive national and allied threat reporting.”
Keep it. It is authoritative and this does not compete with it. What it does not cover is the commercial reporting layer: your named suppliers, the CVE in the appliance your engineering partner runs, the leak site posting three tiers down. Most of our defence users treat government reporting as primary and use us for everything around and below it.
“Nothing of ours can go into a commercial cloud.”
Nothing of yours does. The platform ingests no telemetry, connects to no networks and requires no agent. The only data it holds about you is what you type into it, and you can run it usefully while entering nothing beyond a supplier list.
“Where is it hosted, and how do you handle export-controlled data?”
Hosting is UK-based and we will confirm the detail in writing. We do not handle export-controlled technical data, because we do not receive customer data of any kind. If your assurance process needs that stated formally, ask and we will put it in a document.
“We are a thirty-person supplier with a contract clause we do not fully understand.”
That is the most common situation in this sector and the reason the free tier exists. Start there, set a digest, add your own upstream suppliers, and you will have more evidence of maintained threat awareness than most firms your size.
“Our accreditation and assurance process takes a year.”
Then start free while it runs. There is nothing to deploy and nothing to connect, which shortens the assessment considerably compared with anything that touches your estate.
What we are tracking in the sector right now
Every incident here is drawn from live clustering. The defence entity page carries the full history: active clusters, associated threat groups, and the most recent reporting, updated continuously.
Defence threat intelligence FAQ
What is threat intelligence for defence?
Monitoring and analysis of the threats specific to defence organisations and their suppliers: state-aligned collection against programme and design data, targeting of cleared and specialist personnel, compromise of subcontractors and engineering partners, and exploitation of the commodity IT that defence businesses run alongside their accredited systems.
Why is the defence supply chain a particular target?
Because it is deep, heavily weighted towards small firms, and holds the same programme data as the prime. A supplier several tiers down may hold detailed technical information while having no dedicated security function, which makes it a far cheaper route to the same objective.
Does this help with CMMC or DEFCON 658?
It supports the threat awareness and monitoring elements of both, and produces the dated evidence assessors ask for. It does not perform assessments, manage accreditation or cover the control implementation those frameworks require.
Does ThreatCluster connect to our networks?
No. It is hosted, outbound only, with no agents and no deployment on your infrastructure. It ingests no customer telemetry and is never connected to accredited or air-gapped environments.
Can I monitor my suppliers rather than only my own organisation?
Yes. Any organisation can be added as a tracked entity, and you are alerted when it appears in reporting or on a leak site. This is the primary use case for primes.
Is there a free version?
Yes. The free tier includes clustered intelligence and a daily digest, with no card required, which is intended to be genuinely useful to small suppliers carrying contractual security obligations.
See below tier one
Free account, no card, nothing connected to anything. Add your supplier list and see what a week of filtered reporting turns up.