Summary
- Defence networks are becoming more distributed across cloud environments, suppliers, allied systems, deployed platforms, and edge locations, weakening traditional perimeter-based security assumptions.
- Zero Trust replaces inherited network trust with verification at the user, device, and data level, helping limit lateral movement when credentials or partners are compromised.
- Carter argues that defence organisations should embed identity governance, device validation, and data micro-segmentation into business-as-usual operations.
Elliot Carter, Head of Digital Capabilities at MASS
The UK defence ecosystem is becoming more connected, distributed and dependent on the rapid exchange of sensitive data. Defence is no longer a single, tightly controlled estate, with the UK Ministry of Defence’s focus on multi-domain operations breaking down the traditional boundaries of military networks.
Multi-domain operations now see data, users and devices move continuously across cloud environments, deployed platforms, supplier networks, allied systems and edge locations. As a result, traditional perimeter-based cyber security is no longer enough.
Moving beyond the castle and moat
Operational success now depends on information moving securely between organisations, domains and geographies at near real time speed, rather than remaining inside a fixed boundary. With data quickly moving between locations, the assumption that anything inside a network can be trusted is no longer true.
For decades this assumption underpinned defence cyber security and the sector has relied on a “castle-and-moat” model. This means that once a person or device passed the perimeter firewall, it was often trusted with access to internal systems and data. In today’s environment of sophisticated state-backed threats, cloud-native deployments and hyper-connected battlespaces, inherited trust has become a serious vulnerability.
Security today must travel with the user, the device and the data itself, wherever they operate. This is why the industry is turning to the Zero Trust approach to cyber security, which is based on a more resilient principle of “never trust, always verify”. In practice this means that every access request requires identity verification for each user and device – both inside and outside of the network perimeter.
Protection at the user, device and data level
This is particularly important as modern military capability depends on a complex network of commercial primes, academic partners and specialised SMEs. These businesses have become key targets for malicious actors looking to exploit softer entry points to steal intellectual property or disrupt critical programmes. Small and medium-sized organisations can be considered softer targets as they may hold sensitive information but lack the resources of prime contractors.
The threat is also increasingly difficult to detect as sophisticated adversaries do not simply attack the perimeter; they exploit valid credentials and previously unknown vulnerabilities to blend into legitimate activity. In fact, a report released by Google ahead of the Munich Security Conference revealed a “relentless barrage of cyber operations” against EU and US industrial supply chains, including defence companies.
A Zero Trust approach helps contain risk by limiting how far an attacker can move if a partner is compromised. It protects access at the user, device and data level, enabling collaboration without sacrificing control. Continuous verification within a Zero Trust environment also makes it harder for attackers to move laterally and remain undetected.
The path forward
Zero Trust creates space for defence innovation by removing legacy barriers to secure collaboration. With stronger control over identity, devices and data, organisations can adopt cloud services more confidently, share information more effectively and deploy new digital capabilities at pace without increasing operational risk.
For businesses and organisations operating within the defence ecosystem, the priority must be to embed Zero Trust into business-as-usual operations. This should start with stronger identity governance, robust device validation and data micro-segmentation supported by specialist domain expertise and an understanding of resilient Zero Trust frameworks.
By adopting the Zero Trust model, all businesses within the defence ecosystem can confidently embrace multi-domain operations with the peace of mind that they have controls in place to limit the impact of a potential cyberattack on their organisation or the reach of one via a supply chain partner.
| About the author | |
|---|---|
| Elliot Carter is Head of Digital Capabilities at MASS. | |












