Ensuring a UK’s leading defence company is secure by design

The defence industry is strongly regulated, and for cyber security, it decided to move away from a long-standing accreditation-based approach towards a Secure by Design (SBD) based one. All providers were expected to interpret the SBD principles and adopt ways of working that align with them. 

 

In recognition of this, the customer’s Executive Committee set an ambitious corporate goal of being world-class in cyber security, aiming to provide a differentiator in the market. 

 

Project One was engaged to help shape and embed the foundations of the approach to SBD and to transform the cyber assurance approach. 

Challenge

With an annual turnover of £28bn, the organisation comprised diverse and autonomous business units, ranging from heavy manufacturing to professional services. It faced the challenge of interpreting industry expectations of Secure by Design (SBD) while bringing a common and shared approach for its business units to adopt. 

 

Recognising the autonomy of business units, there was a challenge to transition to a single, enterprise-wide approach built on the foundations of cyber standards, cyber risk, evidence-based assurance, and robust governance. All employees would need to play a part in cyber security, presenting a shift in mindset. 

 

There was a lack of visibility and depth of understanding of the extensive networks and systems on the estate, their cyber compliance, or a route to enhancing adherence to industry cyber standards. This limited grip and ability to manage cyber risks was to be addressed through a challenging and ambitious cyber security assurance programme to deliver compliance transformation. 

 

There was a need for clarity, consistency, and simplicity on how to assure the IM&T estate with evidence at scale and pace, while remediating and enhancing cyber compliance. With the autonomy that business units enjoyed, the challenge was to secure their buy-in while providing direction and practical actions to assure and deliver operational transformation and a business culture shift towards SBD. 

 

The changing landscape across the industry continually presents cyber threats, posing risks to operations, whether manufacturing or the delivery of services to customers. By doing nothing, the impact and likelihood of these risks would increase, with the organisation facing potential reputational damage in not meeting industry-wide expectations and its contractual commitments. Combined with the Executive Committee’s goal to be world-class in cyber security, to provide a differentiator in the market, doing nothing was not an option. 

Approach

Designing an approach to tackle the challenges 

 

The Group Cyber Function focused on designing and implementing a single and consistent approach towards Secure by Design (SBD), combined with the enterprise-wide cyber security assurance programme intended to deliver compliance transformation. The Function interpreted the principles for SBD and designed an approach based on the foundations of embedding industry cyber standards with proactive risk management, assurance, compliance, and robust governance. They developed a clear approach for the cyber security assurance programme, which could be distilled into practical actions for Business Units while valuing their autonomy. The approach was based on a cycle with measurable steps for planning, assuring with evidence against cyber standards, remediating, and validating. 

 

 

Engaging the right groups and learning from them 

 

Regular engagement with the MOD helped to better understand the SBD principles and expectations, providing the opportunity to test and refine the design and approach as it matured. Extensive engagement with business unit teams was essential to gain buy-in prior to mobilising their teams for Programme planning and delivery. 

 

 

Discovering, planning, and delivering 

 

The Group Cyber Function led the Business Units through detailed and rigorous discovery to confirm the networks and systems on the estate. This exercise identified several thousand assets and gathered related information based on scale, complexity, and potential cyber risk, helping business units to prioritise their assets for cyber assurance and remediation. Cyber security standards, controls, and groupings were confirmed and reflected in a cyber assurance tool, geared for business unit assessors to complete cyber assessments, gather evidence, and plan for remediation against each asset. A consistent approach and toolset for business unit planning and tracking progress for assurance and remediation was embedded, providing a data-rich, business unit and enterprise-wide view of the assets, including their current compliance status and future plans. 

 

 

The power of learning and education 

 

A programme of education was rolled out to bring a consistent understanding of the standards, the tooling, how to undertake evidence-based assessments against standards, and how to plan and execute remediation. With the first of the assessments, there was continual learning and feedback among assessors to calibrate on aspects of gathering evidence and the level of rigour to be applied against standards. At this point, business units were ready for the drumbeat of delivery against their plans. 

 

 

The key challenges that were overcome 

 

Designing an approach that can be distilled into simple, measurable steps to be repeated at scale, whether it is a manufacturing business unit or one that delivers professional services.  

 

Building confidence in a single approach and alignment across business units, identifying and engaging the right stakeholders, and communicating the aims and the approach.  

 

Equipping the teams with the knowledge, skills, and tools to succeed. 

 

 

The cultural and operational transformation from a long-standing accreditation-based approach towards a holistic one is a first for this customer. Combined with the ambition of the Executive Committee to have world-class cyber security as a differentiator in the market and the top level of visibility of the Programme, this made the initiative unique. The autonomy and nuances between the business units, with a drive towards standardising the approach, presented challenges at all stages, setting this up for an interesting assignment for Project One. 

Outcome

This is a multi-year journey, and the organisation now has a single and clear approach that has been adopted by its autonomous and diverse business units. There is a road map, supporting plans, and clear priorities for the coming years. A common and shared understanding of SBD expectations, the approach, and cyber standards exists among stakeholders. Teams are now equipped with the knowledge and skills to undertake assurance and enhance cyber compliance. 

 

Clear and robust governance wraps around cyber security, bringing greater grip, better control, and decision-making, with more confidence in cyber resilience. This is supported by the enhanced breadth and depth of compliance evidence across the business units, which continues to grow as compliance levels against standards rise. A set of dashboards and intelligence provides clarity on the expansive IM&T estate and its status in meeting cyber security standards. This enterprise-wide and business unit view, while drilling into the detail of individual networks and systems, supports governance with better prioritisation and decision-making, focusing on the most impactful activities first and ensuring better allocation of resources. 

 

Working towards the organisation’s goal of world-class cyber security as a market differentiator enhances its credibility with customers and builds confidence in its ability to deliver with robust cyber resilience and security. 

 

A common assurance approach with a clear set of steps is now understood and embedded across very diverse and autonomous business units. Skilled team members and the necessary tools are in place, providing the confidence to continue focusing on the right priorities. 

 

 

Project One value-add: 

 

  • Our expertise in and experience of shaping, leading and delivering change and enabling the organisation to do this 

 

  • Clarity and simplification of what is complex and challenging, with an approach and plan that stakeholders understand, believe in and can follow 

 

  • Empathy to understand the challenges, and getting the answers right, so that they land and will stick with our customers. 

 

Unlock the full potential of your business with our expert insights. Contact us today to discover how we can help you achieve your goals. theteam@projectone.com

Are you looking for critical business transformation?

Let’s talk real change
Related insights and customer stories
Sign up to our eNewsletter

Get the latest news, relevant insights and expertise from our change experts

Marketing updates confirmation(Required)
Privacy policies confirmation(Required)