NOVA BLUE

An Army Marches on its Stomach. And its Cyber Security.

An Army Marches on its Stomach. And its Cyber Security.

July 09, 20265 min read

An army marches on its stomach. And its cyber security.

Spend any time around military operations and you learn a deeply unglamorous truth: capability lives and dies at the boring end. The jet is useless without fuel. The vehicle is scrap without the part that never turned up. And a cold, hungry soldier who hasn't been fed or paid is not one you want holding the line. The sharp end runs on the blunt end, and the blunt end is logistics, infrastructure and services.

Which is exactly why the pressure no longer comes through the front door. It comes sideways, in the grey zone: hybrid disruption pitched deliberately below the threshold of open conflict, aimed at the parts of the machine nobody thinks to guard.

The bit nobody's guarding

For years the working assumption across the defence supply chain was that the cyber threat was aimed at the clever kit: the drone start-ups, the sensor manufacturers, the companies with intellectual property worth stealing. Fair enough. But grey-zone disruption works by avoiding your strengths entirely. You don't go at the target's strongest point; you go at the thing they forgot to defend, quietly enough that nobody can be sure who did it or whether it even counts as an attack.

Right now that thing is logistics and infrastructure, and it is being probed by every method going, cyber very much included. Across Europe we have watched a wave of hybrid attacks against exactly this unglamorous layer. In March 2024 an east London warehouse storing aid and communications kit bound for Ukraine was set alight in an arson attack later shown to have been arranged on behalf of Russian intelligence; five men were sentenced last year. The same year, incendiary devices concealed in parcels ignited at DHL depots in Leipzig, Birmingham and Poland, which prosecutors judged to be a rehearsal for getting firebombs onto cargo aircraft. In November 2025 an explosion ripped up a section of the Warsaw to Lublin railway, a key resupply route, which the Polish prime minister called an unprecedented act of sabotage and attributed to Russia. CSIS recorded 34 Russian sabotage and subversion incidents across Europe in 2024, nearly triple the 12 in 2023. The warehouse, the depot, the rail line, the parcel moving through the network: all now fair game.

Most of that has been physical rather than digital. The point is what it tells you about intent. Once an adversary has decided your loading bay is a legitimate target, the cyber version is only a matter of time, because it is cheaper, cleaner and far easier to deny.

When the building turns on you

A warehouse is just a computer with a roof

Here is where it gets uncomfortable for the "we're only a logistics firm" crowd. The modern warehouse, depot or office is a computer with a roof. Heating, cooling, access control, power, refrigeration: all of it now runs on networked building management systems, and a great deal of it is bolted onto the internet with roughly the security of a garden shed. Claroty examined nearly half a million of these devices last year and found three quarters of organisations running kit with known, exploitable holes in it. Around half had those vulnerable systems wired straight to the internet, often chattering away over ancient protocols with no encryption and the factory-default password still in place. Switch off the cooling in a cold store, or the power to a distribution centre, and you have stopped supplies moving without firing a shot.

It's the whole company now

Here is the part that catches people out. The MOD's Cyber Security Model used to concern itself mainly with the systems that touched MOD information. The current version, live since the end of 2025, does not. It is about the resilience of the whole organisation. You do not get to ring-fence one server and wave the rest through as out of scope.

You don't ring-fence one server

If you hold a contract with the MOD, or with a prime, the model applies to you. Cyber Risk Profiles flow down the chain: the prime carries out the risk assessment and hands you your required level, and the Defence Standard that sits behind it sets the controls you then have to meet. Even at the bottom rung, CRP Level 0, that means Cyber Essentials, a proper grip on your GDPR obligations and a credible plan for keeping your networks running when something breaks. Climb towards the more critical contracts and you are looking at a Cyber Risk Profile carrying well over a hundred controls across policy, process and technology. That is not a box you tick on a Friday afternoon.

And it is no longer a "nice to have". The MOD's Director of Cyber Defence and Risk, Eleanor Fairford, has asked all industry partners to reach Level 0 of the new Defence Cyber Certification by 31 December 2026. DCC is organisation-wide by design and open to any company, whether or not you happen to be bidding right now. Read that as the direction of travel, because that is precisely what it is.

Sort it before you need it

Sort it before you need it

The mistake I see again and again is treating compliance as something you scramble at when a tender lands. By then it is a fire drill. You are trying to stand up controls, gather evidence and rewire people's working habits in the few weeks you have to respond, and it shows in the quality of the bid.

Do it the other way round. Get Cyber Essentials in place as a baseline; it is cheap, it is quick, and it shuts the most common doors. Work towards DCC Level 0 so that when a prime asks the question, the answer is already sitting on the shelf. Understand the Cyber Risk Profile your work is likely to attract, and close the gap while it is still a project rather than an emergency. Compliance done early is a competitive advantage. Done late, it is the reason you never made the shortlist.

Next steps

At Nova Blue we built AEGIS for exactly this: a managed route to defence compliance that gets suppliers to Cyber Essentials and DCC Level 0 without turning your team into full-time paperwork clerks. For more information and our limited launch offer click here.

For larger organisations staring down a higher Cyber Risk Profile and a hundred-plus controls, we do the heavier lifting too. If you want to know where you actually stand, our free CSM v4 readiness check will tell you in a few minutes.

The next war, if it comes, will be won or lost at the boring end. Best not to leave the door open.

David Collins OBE

David Collins OBE

OBE-recognised cyber defender with a proven record securing critical national infrastructure.

LinkedIn logo icon
Back to Blog

© 2026 Nova Blue Technologies Ltd · Registered in England & Wales · Company #12840005 · All rights reserved