Sponsored by Spectra Group
————————————————————————————————————————————————————————————————————————————————————————————————————————————–
19 Nov 24. AI used in UK defence review stays unnamed, but is “segregated” from networks. In response to a Freedom of Information (FoI) query from Army Technology, the SDR Secretariat declined to state which AI was being used.
The UK government has declined to disclose which artificial intelligence (AI) program is being used to assist in the analysis of submissions for the ongoing Strategic Defence Review (SDR), citing a public interest in favour of withholding the information.
In response to a Freedom of Information (FoI) query from Army Technology, the SDR Secretariat declined to state which AI was being used as its release “would likely prejudice current and future strategy development and operational capability”.
Of five specific queries, three regarded information that was being withheld in accordance with Section 22, Section 26(1)(b), and Section 43(2) on grounds of qualified exemption.
The FoI questions posed by Army Technology sought information on the AI program being used, the company which owns the program, and the value of the contract for SDR analysis.
However, the SDR Secretariat did respond to queries regarding the operating structure of the AI in its analysis of SDR submissions, stating that it was performing its function “within a segregated cloud architecture (e.g, virtual private cloud)” that was “isolated” from broader organisational systems and external networks.
“This compartmentalised structure ensures that operations remain independent, with no direct connectivity to other internal programs or the wider digital architecture. By maintaining this closed environment, we enhance data security and integrity whilst following robust data protection practices,” the SDR Secretariat’s response read.
AI use in UK defence review
In October 2024 it was revealed that the UK was using AI to assist in the analysis of thousands of responses into the future SDR), which is due to report in 2025 amid the potential for cuts to key defence procurement programmes amid a claimed £22bn ($27.8bn) black hole in the country’s public finances.
Disclosing the use of AI on 15 October, Minster for the Armed Forces Luke Pollard said it was “helping” to “comprehend and analyse over 8,000 responses across the propositions, totalling over 2.2 m words”.
Pollard said that the use of AI was “enhancing” the SDR team’s ability to “focus on complex tasks”, such as applying “robust challenge” to submissions through panel sessions during October and November this year.
“AI is not a replacement for human judgment, but an enabler of greater efficiency and one part of facilitating a more comprehensive review process. Decisions on drafting are solely made by the reviewers: Lord George Robertson, General Sir Richard Barrons and Dr Fiona Hill,” said Pollard.
The UK government confirmed on 15 October that over 1,700 individuals and organisations responded to the SDR request for comment, providing more than 8,000 answers across 23 propositions.
Respondents included serving and retired members of the UK military, the defence industry, the public, academics, members of the UK parliament, as well as UK allies and partners, including Nato.
GlobalData: AI sector growth “explosive”
Business and news analytics company GlobalData has projected generative AI to grow from $1.8bn in 2022 to $33.0bn as the rise in use of such technology continues to increase, particularly in areas such as data analytics.
Generative AI sees the creation of video, text, and images by AI models when presented with a dataset or prompt, with the most common example of its kind OpenAI’s ChatGPT AI chat program.
Manish Dixit, practice head of disruptive tech at GlobalData, said that the AI sector was experiencing “explosive growth”, driven by unprecedented levels of investment and the emergence of new players in the industry.
“The successful implementation of [hybrid neural architectures and cognitive systems] will fundamentally reshape decision-making, operational efficiency, and strategy across industries,” Dixit said.
Across the defence sector, AI has cemented its position as one of the most crucial technologies for the coming battlespace and is already being used in areas such as data analysis and mission operations. (Source: army-technology.com)
20 Nov 24. The EuroDASS consortium, the industrial partnership responsible for the Eurofighter Typhoon’s ‘Praetorian’ defensive suite, has unveiled details on the next generation of Typhoon sensing and jamming capabilities following the completion of concepting work and technology flight trials. EuroDASS partners Leonardo, ELT Group, Indra and Hensoldt, drawing on Europe’s sovereign electronic warfare expertise, are working with systems integrator BAE Systems to develop the system in support of its Typhoon Next Generation initiative.
The next-generation electronic warfare system will future-proof Typhoon against new and emerging threats through to 2060 and beyond, providing improved situational awareness and increased survivability.
Key features will include advanced complex threat characterisation, Digital Radio Frequency Memory (DRFM) capabilities and the provision of interfaces for an external, high-powered electronic attack pod for Suppression of Enemy Air Defence (SEAD) missions; a key NATO requirement. Wideband Active Electronically Scanned Array (AESA) Electronic Counter-Measures (ECM) will be provided with increased power for self-protection.
The new system will be a form-fit retrofit option for Typhoon’s in-service Defensive Aids Sub-System (DASS), named Praetorian after the elite Roman bodyguard corps. It will have no impact on the outer mould line of Typhoon and impose no restrictions on the current flight envelope. This minimises aircraft clearance and ensures ease of integration for new build aircraft as well as retro-fit to existing platforms. Typhoon will be more capable, more survivable, and more available, meeting the operational needs of air forces across Europe and the Middle East for decades to come.
The EuroDASS consortium has already completed substantial development work on the next-generation system, including the ‘Praetorian eVolution’ concepting phase and flight trials of component parts of the new capability.
Following concept finalisation, trials in 2023 saw digital receiver and band extension technologies flown on a test aircraft. Then in 2024, flight trials on-board a Eurofighter Typhoon were executed successfully. As well as maturing the capabilities, the partners were able to gather substantial data on representative threat scenarios to support further development.
Because threats to combat aircraft are expected to rapidly evolve in the decades to come, the Typhoon’s new defensive capabilities are being designed with a data-centric architecture at its core.
This includes the provision of high-speed, high-bandwidth infrastructure to transmit raw signal data to an advanced central processing hub. This will enable pilots to identify and prioritise multiple complex threats at once, and at greater ranges. Cognitive Electronic Warfare (CEW), using AI and machine learning will exploit the high-fidelity data captured and respond to new threats as they emerge.
The in-service Praetorian system has protected the aircraft for more than 30 years from threats including Infra-Red (IR/heat-seeking) and radar-guided missiles. Under the ongoing Eurofighter four-nation Phase 4 Enhancement (P4E) package, this system is being upgraded to make the most of its integration with Typhoon’s AESA radar options, including the in-service European Common Radar System (ECRS).
18 Nov 24. India, Japan to co-develop UNICORN mast for INS ships.
The UNICORN mast is designed to enhance the stealth characteristics of naval platforms.
The governments of India and Japan have signed a memorandum of implementation (MOI) for the co-development of the Unified Complex Radio Antenna (UNICORN) mast.
The signing took place at the Embassy of India in Tokyo.
The MOI was signed by India to Japan ambassador Sibi George, and Japan Ministry of Defence (MoD) Acquisition Technology and Logistics Agency commissioner Ishikawa Takeshi.
The UNICORN mast, featuring integrated communication systems, is designed for fitment onboard Ships of Indian Navy and enhance the stealth characteristics of naval platforms.
Originally developed by NEC, Sampa Kogyo, and The Yokohama Rubber, the UNICORN mast is currently fitted on Mogami-class frigates.
In August, a joint statement was made by Japan Minister of Foreign Affairs, Japan MoD, India MoD and India Minister of External Affairs on the development.
It noted that the four ministers “appreciated the progress made for the transfer of Unified Complex Radio Antenna (UNICORN) and related technologies and early signing of related arrangements.”
Bharat Electronics will now co-develop these systems in India with Japanese collaboration, marking the first instance of co-development of defence equipment between India and Japan.
Besides, the Indian Navy held a ‘keel laying’ ceremony for the first of five Fleet Support Ships (FSS) at Hindustan Shipyard in Visakhapatnam.
The Indian Navy had signed a contract with Hindustan Shipyard in August 2023 for the acquisition of these ships, which are scheduled for delivery starting mid-2027.
The FSS, each with a displacement of more than 40,000 tonnes, is expected to enhance the Indian Navy’s ‘Blue Water’ capabilities by replenishing fleet ships at sea.
These ships will carry fuel, water, ammunition, and stores, enabling prolonged operations without returning to harbour.
Additionally, the ships will be equipped for humanitarian aid and disaster relief operations, enabling personnel evacuation in emergencies and the quick delivery of relief supplies during natural calamities.
19 Nov 24. Protecting aircraft with artificial intelligence: Thales and partners selected for first European project to develop sovereign AI for embedded cyberdefence.
- Thales has been selected for the Artificial Intelligence Deployable Agent (AIDA) project funded by the European Commission through the European Defence Fund (EDF). A total of 28 European industry partners, start-ups and research centres have joined forces on this project to develop a sovereign AI-enabled cybersecurity agent to protect aircraft systems from cyberattacks.
- The goal of this three-and-a-half-year European project is to design an AI with an autonomous or semi-autonomous response capability to provide cybersecurity protection for aircraft systems such as onboard computers and electronic warfare systems on combat aircraft, which are vulnerable to increasingly sophisticated cyberattacks in today’s high-intensity conflicts.
- AIDA is the first European structural framework project in support of the NATO concept of Autonomous Intelligent Cyberdefence Agent (AICA).1
Created by AI
Thales is technical coordinator for the AIDA project funded by the European Commission, with CR14 in Estonia in charge of overall project coordination.
This EDF project is a response to three major challenges faced by the armed forces today: attack surfaces are growing due to battlespace digitisation; the cyberattack detection-response chain needs to be automated due to the ever-greater use of autonomous systems such as drones and robots; and AI is being used ever more widely both to launch and respond to cyberattacks.
Christophe Salomon, Executive Vice President, Secure Communications & Information Systems, Thales: “This project initiated by the European Union is fundamental to the security of our combat systems and the sovereignty of our cyberdefence capabilities. It is a chance for Thales to consolidate its strengths in onboard aircraft systems and sovereign cybersecurity solutions, and a further opportunity to leverage our AI hacking expertise. Thales’s AI accelerator, and in particular cortAIx, will be directly involved in the AIDA project. The ultimate goal is to employ AI-enabled techniques for detecting threats and protecting aircraft systems from the growing risks and dangers encountered in today’s high-intensity, technology-driven conflicts.”
Responding to the 2023 European Defence Fund call for projects for the development of deployable autonomous AI agents,1 Thales submitted an innovative proposal based on the training of intelligent cyberdefence agents capable of identifying, protecting, detecting and responding to cyberthreats in real time in the five military operating domains:2 land, air, sea, space and cyberspace.
Thales will also lead the project to develop a prototype aircraft using frugal AI agents to protect electronic warfare equipment installed on combat aircraft. This prototype will be tested, using Thales’s Cybels Analytics solution in particular, in scenarios including cyber-electromagnetic threats and advanced adversarial AI attacks.
AI is being used increasingly in the theatre of operations to increase the detection performance of air defence radars, for example, and to help plan tactical missions and assign tasks to swarms of drones and robotic systems. This type of AI must be reliable, robust and cybersafe to prevent it being exploited by hostile forces in any environment (land, sea, air, space and cyberspace). To counter this type of threat, Thales’s Friendly Hacker Unit will conduct a battery of adversarial AI attacks and define appropriate countermeasures to ensure that these cyberdefence AI agents can never become targets themselves.
Global leader in data protection and cybersecurity
As a world leader in cybersecurity, with more than 5,800 experts in 68 countries, Thales is involved at every stage in the civil and defence value chain: Identify, Protect, Detect, Respond, Restore. Thales develops sovereign products including encryptors and sensors for governments and institutions to protect their critical information systems, as well as sovereign cyberthreat detection products to protect embedded and onboard systems. Thales is a trusted partner of the Galileo satellite navigation system, operating a number of national encryption laboratories in Europe and supplying NATO member countries with the only tactical IP encryptor with “Cosmic Top Secret” security certification. Thales is also a strategic partner of the German, UK, French and Belgian defence ministries for the construction and handover of key management centres and infrastructure.
AI at Thales
Thales is a major player in trusted, cybersafe, transparent, explainable and ethical AI for armed forces, aircraft manufacturers and critical infrastructure providers. The Group employs over 600 engineers specialising in AI and around 100 doctoral candidates are conducting their AI research with Thales. Organised within Thales’s AI accelerator for research (AI Lab), systems, including decision support systems, (AI Factory) and sensors, including sonar, radar, radios and optronics, (AI Sensors), these experts are helping to incorporate AI into over 100 of Thales’s products and services. Thales’s AI capabilities draw on the most advanced sensor and system technologies to address the full spectrum of user requirements in the defence, aviation, space, cybersecurity and digital identity industries. Trusted AI is designed to meet the specific security and sovereignty needs of Thales’s customers. It brings greater efficiency to data analysis and decision support and speeds up the detection, identification and classification of objects of interest and target scenes, while taking account of specific constraints such as cybersecurity, embeddability and frugality in critical environments.
In 2023, the Group was Europe’s top patent applicant in the field of AI for mission-critical systems. Also in 2023, the Group’s Friendly Hacker Unit demonstrated its credentials at the CAID challenge (Conference on Artificial Intelligence for Defence) organised by the French defence procurement agency (DGA), which involved finding AI training data even when it had been deleted from the system to preserve confidentiality.
Thales’s European partners in the AIDA project:
SIHTASUTUS CR14 (CR14)
THALES SIX GTS France (TSGF)
THALES SA (TRT)
THALES AVS FRANCE SAS (TAVS)
THALES DMS FRANCE SAS (TDMS)
INDRA SISTEMAS SA (IND)
LEONARDO – SOCIETA PER AZIONI (LDO)
TELESPAZIO SPA (TPZ)
AIT AUSTRIAN INSTITUTE OF TECHNOLOGY GMBH (AIT)
SPACE HELLAS ANONYMI ETAIREIA SYSTIMATA KAI YPIRESIES TILEPIKOINONIONPLIROFORIKIS ASFALEIAS – IDIOTIKI EPICHEIRISI PAROCHIS YPERISION ASFA (SPH)²
HONEYWELL INTERNATIONAL SRO (HON)
WOJSKOWA AKADEMIA TECHNICZNA IM.JAROSLAWA DABROWSKIEGO (WAT)
EVIDEN TECHNOLOGIES SRL (EVD)
Decent Cybersecurity s. r. o. (DEC)
GYALA S.R.L. (GYA)
FORSVARETS FORSKNINGINSTITUTT (FFI)
SensorFleet Oy (SEN)
NIXU OYJ (NIX)
Aliter Technologies, a.s. (ALI)
THALES EDISOFT PORTUGAL, S.A. (EDI)
HITEC LUXEMBOURG SA-HITEC (HIT)
MINISTERUL APARARII NATIONALE (MET)
INSTITUTO SUPERIOR DE ENGENHARIA DO PORTO (ISEP)
DOTOCEAN (DOT)
WB Electronics S.A. (WBE)
ADVOKAADIBUROO SORAINEN OU (SOR)
HarfangLab SAS (HAR)
AKHEROS SAS (AKH)
19 Nov 24. ThreatQuotient™, a leading threat intelligence platform innovator, today released the Evolution of Cybersecurity Automation Adoption 2024. Based on survey results from 750 senior cybersecurity professionals at companies in the U.K., U.S. and Australia from a range of industries, this in-depth research report examines the progress senior cybersecurity professionals are making towards adopting automation, its key use cases and the challenges they face. The fourth edition of this annual survey highlights how automation is maturing and how, in a world of continuous change, organisations are adopting cybersecurity automation for resilience, scale and collaboration. The report examines approaches to integration, whether respondents are taking a single-vendor platform approach or best-of-breed, the adoption of AI and the importance of cyber threat intelligence sharing.
Eight-in-ten respondents (80%) now say cybersecurity automation is important, up from 75% last year and 68% the previous year. Additionally, budget for cybersecurity automation has increased every year, and this year’s survey is no different with 99% of respondents increasing spend on automation. Interestingly, 39% of respondents now have net new budget specifically for automation, a significant rise on the 18.5% who said this last year. Previously, decision-makers were diverting budget from other cybersecurity tools or reallocating unused headcount funds. In 2024 respondents have a better understanding of key uses cases and the benefits automation delivers is helping them make a stronger business case for dedicated budget, which is another indication that cybersecurity automation is maturing.
Key research findings also include:
- Key use cases: Incident response was the top use case for automation (32%), rising consistently through the course of the study. This was followed by phishing analysis (30%) and threat hunting (30%) which has also continued to rise.
- Challenges are evolving: Nearly every survey participant reported problems with cybersecurity automation: the top three challenges were technological issues, lack of budget and lack of time. As automation deployments mature, trust in the outcomes of automated processes has increased. Just 20% of respondents reported a lack of trust in outcomes, compared to 31% last year. In 2023 there was also significant concern around bad decisions, slow user adoption and lack of skills, but these concerns have abated in 2024.
- Top measurement metrics: Employee satisfaction and retention remains the main metric for assessing cybersecurity automation ROI for 43% of leaders, but this has dropped from 61.5% citing it as the key metric in 2023. Resource management, in terms of staff efficiency, effectiveness and budget (42%), and how well the job is being done in terms of MTTR and MTTD (38%) have both become more prevalent as measurement tools as organisations home in on metrics more closely linked to productivity and efficiency.
- Growth in threat intelligence sharing: Ninety-nine percent of cybersecurity professionals say they share cyber threat intelligence through at least one channel; 54% share cyber threat intelligence with their direct partners and suppliers and 48% share with others in their industry through official threat sharing communities.
- Integration is key: Two thirds (67%) of respondents integrate best of breed solutions into their architecture to effectively deliver their cybersecurity strategy. Regardless of whether they focus solely on best of breed tools or they start with a single vendor platform and then supplement with best of breed tools, integrating tools is an important activity.
- AI gathers momentum: Fifty eight percent of respondents say they are using AI in cybersecurity. Half are using it everywhere, and half in specific use cases. A further 20% are planning deployments in the year ahead.
- Expected attack vectors in the year ahead: Cyber-physical attacks are considered most likely in the year ahead, followed by phishing and ransomware. Although not a top three attack vector, 20% of respondents expect to see attacks via the supply chain and one in five see state-sponsored attacks affecting their business.
“It is tough for cybersecurity professionals who now face fast-changing cyber and cyber-physical threats of unprecedented sophistication, volume, velocity and variety,” said Leon Ward, Vice President, Product Management, ThreatQuotient. “Defending their business is an enormous task, and cybersecurity professionals must become more resilient.
“What we are seeing in this ‘new normal’ landscape is the need for more automation, scale and better threat intelligence sharing. A collaborative approach to cybersecurity helps organisations better defend as industries scale their knowledge to respond to attacks.”
As organisations double down on cybersecurity automation use cases that deliver value and embrace more intelligence sharing, this will result in more effective and proactive cyber defence. This year the survey highlights the focus has shifted toward ROI metrics that are more closely linked to productivity and efficiency and – while employee retention and satisfaction remains important – it is no longer heavily outweighing performance and efficiency KPIs.
Ward concludes, “We believe that scaling security operations and collaboration across teams, ecosystems and industries is the most urgent challenge facing cybersecurity professionals. Successfully uniting human expertise, automation and AI and enabling seamless integration across tools and intelligence feeds will drive cyber resilience and agility at organisational, industry, and international levels.”
To download the full Evolution of Cybersecurity Automation Adoption in 2024 report, including more detail on the survey questions, regional and industry snapshots, and recommendations for senior security professionals to follow if they are looking to automate their security processes, click here. Leading threat intelligence platform innovator, ThreatQuotient, commissioned a survey undertaken by independent research organisation, Opinion Matters, in June 2024. 750 senior cybersecurity professionals in the UK., US. and Australia from companies employing 2,000+ people from a range of industries including Central Government, Defence, Critical National Infrastructure, Retail, and Financial Services sectors, with 150 respondents from each.
About ThreatQuotient
ThreatQuotient improves security operations by fusing together disparate data sources, tools and teams to accelerate threat detection and response. ThreatQ is the first purpose-built, data-driven threat intelligence platform that helps teams prioritise, automate and collaborate on security incidents; enables more focused decision making; and maximises limited resources by integrating existing processes and technologies into a unified workspace. The result is reduced noise, clear priority threats, and the ability to automate processes with high fidelity data. ThreatQuotient’s industry leading integration marketplace, data management, orchestration and automation capabilities support multiple use cases including threat intelligence management and sharing, incident response, threat hunting, spear phishing, alert triage and vulnerability management. ThreatQuotient is headquartered in Northern Virginia with international operations based out of Europe, MENA and APAC. For more information, visit www.threatquotient.com.
19 Nov 24. Global: Zero-day vulnerability heightens espionage risk posed by Chinese state-sponsored groups. On 18 November, international news outlets reported that the Chinese state-sponsored group ‘BrazenBamboo’ is exploiting a zero-day vulnerability in an ongoing cyber espionage campaign. The vulnerability affects Fortinet’s FortiClient Windows VPN service and allows threat actors to steal credentials from a system’s memory. BrazenBamboo deploys a custom post-exploitation toolkit (‘DeepData’) to exploit the vulnerability and obtain stolen credentials. It is likely that the group uses stolen credentials to infiltrate targeted systems by hijacking VPN accounts. Subsequently, BrazenBamboo likely moves laterally within compromised systems for additional espionage activities, including deploying a new Windows variant of the ‘LightSpy’ malware for data exfiltration. The vulnerability was disclosed in July and has not been patched yet, highlighting the need for monitoring for unusual VPN account activity in the short term. This campaign underscores the continued exploitation of zero-day vulnerabilities by Chinese state-sponsored groups, pointing to heightened long-term espionage risks facing global entities. (Source: Sibylline)
18 Nov 24. Global: New malware distribution technique elevates information-theft, financial risks from cyber criminals. On 16 November, international news outlets reported that fake artificial intelligence (AI) content generator applications are being used to distribute the ‘Lumma Stealer’ and ‘AMOS’ information-stealing malware. Threat actors are reportedly sharing deepfake political videos on the social media platform ‘X’ (formerly Twitter) to trick users into visiting fraudulent websites. Users then unknowingly install the malware onto their systems by clicking on malicious links displayed on the websites, purporting to download fake AI applications. The malware can steal cryptocurrency wallets as well as other sensitive information (including login credentials and credit card details) from Chromium-based browsers. Subsequently, the stolen data is likely sold on the dark web or used in follow-on attacks for illicit profit. The adoption of information-stealing malware has seen a rapid increase since the beginning of 2024, sustaining elevated information-theft and financial risks to global entities in the medium term. (Source: Sibylline)
15 Nov 24. Global: New malware points to increased information-theft, financial risks facing users. On 13 November, the software company Gen Digital reported that a new information-stealing malware (‘Glove’) is bypassing a new security encryption mechanism in Chromium-based browsers to steal sensitive user data. Threat actors typically use social engineering tactics to deploy Glove, tricking potential victims into downloading a malicious file via phishing emails. Upon installation, Glove exfiltrates browser cookies, data and sensitive information (including cryptocurrency wallets, session tokens and password managers) from browser extensions and local applications. Notably, threat actors obtain administrative privileges prior to extracting data, underscoring the sophistication of this campaign. We assess that threat actors likely use the stolen information to hijack user accounts in order to garner illicit profit. Cyber criminals are increasingly incorporating this technique into information-stealing malware, highlighting their increased ability to bypass modern security measures. Glove is likely still in its development phase as it contains minimal obfuscation mechanisms, pointing to medium-term information-theft and financial risks.
(Source: Sibylline)
————————————————————————————————————————————————————————————————————————————————————————————————————————————–
Spectra Group (UK) Ltd
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.
Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
———————————————————————————————————————————————————————————————————————————————————————————————————————————-

