
AEGIS: All in one Cyber Security for defence sector startups
AEGIS: why we built a single answer to the defence sector's cyber problem
For a founder trying to break into the defence sector, it must feel like a giant expensive game of whack-a-mole. Wherever they look there's something else which needs dealing with. Product development — WHACK!; Recruitment — WHACK!; Funding — WHACK!. Cyber security and the associated compliance have, in all likelihood, been sitting in the founder's peripheral vision — unwhacked but growing more prominent by the day.
That's the position most small defence suppliers are in right now, and it's exactly the gap AEGIS was built to close.
The twin problem nobody quite says out loud
First, a key principle. Defence suppliers face the same threats as any other company. Phishing, ransomware, credential theft — the criminal ecosystem doesn't check your SIC code on Companies House before it comes after you. But defence suppliers also carry something most companies don't: the attention of people who aren't in it for the money. Nation states don't care about the size of your order book or value of your invoices. They care about what you're building and who you're building it for. That's not a hypothetical for dramatic effect — it's the actual, documented reason MOD is pushing this down the supply chain in the first place.

Layer on top of that the Cyber Security Model itself, and you've got two problems dressed as one: build a security posture that would actually stop a determined attacker, and do it in a way that satisfies an assessor working from Defence Standard 05-138. Most founders I meet are trying to solve both with whatever's left over after payroll and product development — which is to say, not much.
The obvious answer — hire a security engineer, retain a policy consultant, bolt on a managed IT provider, hope they all talk to each other — doesn't scale for a five person company, and it's not cheap either. You end up with three invoices, three points of failure, and nobody who owns the whole picture when an assessor asks an awkward question. AEGIS exists to change that model. One managed service, one fixed price, one team accountable for the lot — so you can get back to building the business you actually started, instead of running a part-time compliance department nobody budgeted for.
What's actually in the box
Proactive hardening and continuous configuration management. Not a one-off lockdown that drifts the moment someone changes a setting six months later. Your identity, email and endpoint configuration is actively managed and kept secure, on an ongoing basis — because a hardened environment that nobody watches doesn't stay hardened for long.
Continuous monitoring, detection and response. A badge on your website doesn't stop an attacker; someone watching for the attacker does. AEGIS includes the eyes-on-glass work of actually noticing when something's wrong and doing something about it, not a dashboard nobody logs into.
OFFICIAL-SENSITIVE handling. The ability to handle OFFICIAL-SENSITIVE information requires encryption, labelling and secure transmission. But it also requires deliberate risk management. This is the bit that gets skipped by providers who only think in technical controls. Handling OFFICIAL-SENSITIVE properly means the paperwork too — an information handling framework aligned to Government Security Classification guidance and MOD's Secure by Design principles, so your team knows what they're allowed to do with what they've been given, and can prove it.
Cyber Essentials certification. The foundation, not the finish line. It's table stakes for the supply chain and the base a proper security posture is built on — evidence pack, technical controls and the certifying body's fee all folded into your price, so it's not a separate invoice you have to go and chase down.

DCC Level 0 certification. The MOD CISO has asked all industry partners to achieve Level 0 DCC certification by 31st December 2026 and it's increasingly being mandated in MOD tenders. Primes will ask, and "we're working on it" stops being an acceptable answer. This is assessed against Defence Standard 05-138 — technical controls, policy documentation and the fee we pay our certifying body partner to assess you, all covered by the one price we quote you.

Microsoft 365 licensing. Business Premium plus Defender and the Purview suite — every seat licensed, configured and actually managed, because the controls above need a platform to sit on, not a bare M365 tenant and good intentions.
The offer
This is a limited-run offer for companies under ten users operating in or entering the defence supply chain, open until 30 September 2026. Two ways in — a lower upfront cost with a higher monthly rate, or nothing upfront and a slightly steeper monthly figure — both fixed, both inclusive of the licensing, the certifications and the engineering. Optional hardware from £1,850 if you'd rather we handed you a laptop that's already secured than take on the enrolment yourself.

Get in before the deadline stops being a planning exercise and starts being a live problem: defence.nova-blue.net/aegis-offer.html or [email protected].






