Industry and Regulators Committee
Corrected oral evidence: The relationship between the Government and the defence industry
Tuesday 7 July 2026
11.05 am
Watch the meeting
Members present: Baroness Hayter of Kentish Town (The Chair); Lord Best; Baroness Carberry of Muswell Hill; Baroness Drake; Baroness Harding of Winscombe; Lord Teverson; Lord Udny-Lister; Baroness Valentine.
Evidence Session No. 5 Heard in Public Questions 44 - 52
Witnesses
Colin Maund, Founder and CEO, Hellios; Grace Cassy, Partner, Ten Eleven Ventures.
14
Colin Maund and Grace Cassy.
Q44 The Chair: Good morning and welcome to this meeting of the Industry and Regulators Committee. We are carrying out an inquiry at the moment into the relationship between the Government and the defence industry. This is being broadcast on parliamentlive.tv. There will be a full Hansard report of it and you will have a chance to check that in case we have misunderstood any of your words. If I may introduce myself, I am Diane Hayter, chair of the committee. This is our fifth evidence session. We are very grateful to you for giving your time today. I will introduce my colleagues as they put questions, but for the moment perhaps you could begin by introducing yourselves.
Grace Cassy: Good morning. I am an investor with Ten Eleven Ventures. For the purposes of this inquiry, I also served as one of the additional reviewers on the 2025 Strategic Defence Review (SDR).
Colin Maund: Good morning. I am chief executive of an organisation called Hellios. The relevance of this is that we run a system in the UK called JOSCAR (Joint Supply Chain Accreditation Register) to manage suppliers to 32 or 33 prime contractors and the MoD.
Q45 The Chair: Thank you both for your time. I would like to start with quite a general question. The SDR, which obviously is particularly familiar to you, called for the creation of a new partnership between the Government and the defence industry. So the question for us is: what are the cultural and practical changes needed to bring about that new partnership? As you worked on the Strategic Defence Review, would you like to begin on that?
Grace Cassy: This was a very important part of our review to stress the importance of a shift in the relationship between defence and the industry that serves it. You may be aware that, historically, sometimes that relationship has been somewhat confrontational. It has been somewhat limited at times in terms of the limited number of companies that are able to serve defence historically. We were very keen to encourage the development of a wider, more diverse industrial base in the UK and more broadly among our allies to support the change that we wanted to see in defence. That change was necessary because of the changing nature of warfare. The pace at which technology is developing, and warfare is therefore changing, means that innovation has to be taken more seriously within defence. We need an industrial base that can innovate faster and supply cutting-edge technology to our front-line forces and back-office defence services to make us ready for war in the way the SDR sought.
As to the cultural and practical changes needed for that, I think, culturally, we have to accept that, if we want industry to be seen as a meaningful strategic reserve when it comes to war, we have to move on from a relationship of buyer and seller. That has been the nature of the relationship between defence and the industrial base for some time. I believe that needs to change to a true partnership with the mission at the heart of what each side of that partnership is there to support. In practice, that means involving suppliers much earlier in the life cycle of a contract and co-developing requirements rather than waiting for a very detailed requirement to be created inside the walls of the Ministry of Defence, and only then put over the wall to suppliers later in that process. We would like to see that requirements development process being much more interactive from the very beginning so that it is truly more of a partnership than a kind of fixed requirement being put out too late in the process that cannot be adapted later.
I am sure that speed has come up a lot in your earlier sessions. Pace is not there in the way it needs to be at the moment. I think that is cultural as well as practical. Some very practical things can be done to encourage greater speed, but it is cultural as well. Commercial teams and so on need to understand that it is possible to act faster to deliver contracts faster and lots of benefits flow from that to the industrial base.
Rewarding that speed, adaptability and the ability to upgrade capability is both culturally and practically important if this partnership is to develop in the way that we would like to see. There are some signs that things are improving. Certainly, at the top of defence, senior officials and serving officers recognise the need to build a different kind of partnership. There are some green shoots with organisations such as Commercial X, which has done a good job of demonstrating that it is possible to contract faster, but we still need to see progress in scaling these different methodologies wider in the organisation (MoD) and pushing that way of thinking both more broadly and lower down into the levels of the organisation that are working on these contracts day to day.
Colin Maund: I totally agree with the thrust of what Grace said, but we also look at embracing the wider supply market. There is a huge opportunity out there. Thousands of companies wish to be suppliers into the defence community but, for one reason or another, feel constrained. Sometimes those constraints are reasonable because the companies are not really fit for defence; they are not sufficiently qualified and need to up their own game, but sometimes just the process and bureaucracy around getting into the defence market is off-putting.
Speed is absolutely crucial. We can see that exceptionally well-illustrated in the whole Ukraine war, where techniques, tools and equipment that were not even thought about five years ago are now absolutely crucial. The speed of innovation is along the path of weeks and months rather than years. Our traditional programmes that are very long-lasting over multiple years, even decades, look incredibly old-fashioned. There is also the requirement to understand the need for information across all tiers of the supply chain, whether that is directly into MoD, into the primes or subcontractors to the primes, but there is a dearth of good-quality data sitting behind the industry. I think that is an absolutely crucial aspect.
Another thing that needs to be thought about as well—I am not saying it has not been, but I think it needs more attention—is technical specifications. They can be a massive burden to innovation if they are overrestrictive and not functional, based almost on past technologies. That is an area that I think needs some attention.
Finally, when you are looking at the whole supply chain you need to be aware of the vulnerabilities as well as anything else. The obvious example everybody is thinking about at the moment is cybersecurity and the risks to our supply chain and the sovereign infrastructure that sits behind our supply chain. That is where a lot of particularly small suppliers are struggling, not because they are inept or unable, but simply the speed of advance is quite alarming for them.
The Chair: When you say there is a lack of data, do you mean the MoD does not have the data on who is outside and who could help, or do you mean that people outside do not have the data on what is needed?
Colin Maund: It is a bit of a combination of both. I have a self-interest here. We run a system of 6,200 registered suppliers and 32 primes plus the MoD using the data, but it is not always widely deployed everywhere in big organisations such as the MoD and some of the larger primes. Just making data more available and that it is accurate and up to date is a constant issue.
Q46 Baroness Carberry of Muswell Hill: Good morning. Could I follow up what both of you have said about the need for greater speed and pace to adapt to the demands of new technology? You have given some specific examples about how changes in processes could help. You have certainly reinforced, as Ms Cassy has anticipated, the messages that have strongly come through the inquiry up to now. One suggestion that we have heard a few times is that the Government need to be prepared to accept more risk in the procurement of particularly new technologies and capabilities. Would you like to comment on that specifically?
Grace Cassy: I would agree that the Government need to be prepared to accept more risk, but it is not just a question of accepting more risk; it is more a question of moving from what I think has been risk avoidance to risk management, and accepting that we have, I think, optimised over the past few decades to avoid commercial risk. That is the envelope within which we are asking officials to operate when they seek to procure equipment. How can they best minimise or avoid any commercial or financial risk? That is for understandable reasons; we are talking about public money, but it has not led in every case to the reduction of commercial and financial risk anyway.
As to the length of time some of these procurements take, I am sure you are aware of some of the numbers being quoted. I think seven-plus years was the average length of a procurement, as told to us during our review process. In many cases that has led to financial loss in any case and so, even when the system has been optimised to try to avoid waste of public money, none the less in some cases it has led to that.
I would, therefore, encourage a different kind of approach to risk, which is accepting that, if we need to move faster, which the SDR makes the case for and the Government have accepted, we will be buying equipment that will become obsolete much faster than we have ever been used to in the past. It may be that in a matter of weeks or months something we have bought—some software, a drone or some kind of air defence capability—becomes obsolete more quickly. We cannot, therefore, expect people any longer to provide very long-term value for money statements when they are looking to buy equipment. It is not suitable to the environment in which we now operate.
I would argue that we need to accept more risk than we have been used to accepting in the past and a different type of risk. Experimentation in itself is a risk. Things you might buy or trial might not work; they might go wrong; they might have a short shelf life. I think we need to move to accepting that that is the new normal. It is, as we say in the software world, a feature, not a bug. Equipment turns over very quickly. In a sense it is a sign that we are doing things right. If we are trying lots of things, they work for a while and we move on to something else; that is a good thing. We are not holding on to things that have gone beyond their useful life, and we should not apply the same assurance criteria when we are experimenting and using new technologies as we do when we are using things we have used for a very long time, or are very large scale, often metal platforms, so to speak.
In practice, I think we need to hold senior officials responsible for more than commercial risk. There is a really important role here, possibly the most important role, for those of you who hold officials to account and scrutinise their behaviour to ask different kinds of questions of them, not just the financial and commercial ones, which obviously remain important. To me, the most important question in this era of war fighting is whether we are staying ahead of our adversaries, not just whether we are moving quickly. We can move more quickly and still buy the wrong things. We can buy the wrong things quickly. We need to buy the right things quickly and focus on the outcome of the procurements we are making and whether that is keeping us ahead of our adversaries. In the process, it may lead to shorter shelf lives and money, according to an old way of looking at things, being wasted because it does not have a 10-year value-for-money schedule attached to it, but it is putting us in a better place to be ready to deter our adversaries.
Colin Maund: I would chime in with that. Risk is something that all parts, not just the public sector but the private sector, are always nervous about and for very reasonable reasons, but if we are to get that speed and pace we need to move to an environment in which we are supportive of officials making decisions that include some element of risk. It is no good asking people to accept a higher degree of risk in their roles and so on, and then castigating them if something goes wrong. Inevitably, as you move to a higher speed of activity, some things will go wrong and some programmes will not be as effective as you hoped, but to learn from that and move on is the key thing.
I return to the point I made a little earlier about information. Nobody wants to accept risk that is unnecessary; nobody wants risk that could not have been reduced or mitigated. Organisations need to look at things in the context of having good data on potential suppliers before they get to the contracting process so they have the comfort that the organisation knows what it is doing.
To give you an illustration, we ran a webinar recently where Boeing popped up and said, “We used information sources to find some high tensile strength straps”. The interest was that these were completely unknown to Boeing but were picked up very quickly. Because there was information around the process quality of the organisation they were able to move to contract very quickly without having to go through the laborious process of collecting information, going through it, validation and so on before they could place a contract.
Q47 Lord Udny-Lister: Thank you for coming along. My question is directed to Grace. We have heard that the defence industry is not an attractive financial proposition. I cannot help but observe that it seems to be for foreign companies to buy British ones, but never mind. What can the Government do in procurement, budgeting and contracting to make the industry financially attractive?
Grace Cassy: The first thing I would say up front is that there are some myths circulating that there is a lack of capital for companies in defence, certainly at the more innovative end of the market. From what I see in my day job as an investor that is not the case. There is no shortage of capital that is interested in investing in defence and dual-use technology. In fact there has never been as much capital that is interested in investing in this space. Possibly one of Vladimir Putin’s unintended consequences of his invasion of Ukraine is that it has encouraged more private investors to throw off previous concerns around investing in this space and become much more interested in supporting the creation of novel technologies that can support western democracies.
However, there is a shortage of confidence that there is a market in UK defence. That is at the core of the problem around the funding challenge for some companies here and elsewhere in our European and NATO allies. The inability to get meaningful contracts out of the door to a wider range of suppliers is, in my opinion, the biggest block to more investment flowing into this sector. Capital follows contracts. I think the Government have spent quite a lot of time talking about how to encourage capital to flow into defence, trying to be venture capitalists themselves and setting up pension funds and so on. I do not think any of that is necessary if they can fix the market problem and accept that they are the market; they have this lever in their hands to buy from a wider range of suppliers at a more meaningful level than has been the case to date. If they can do that, the money will look after itself; the investors will look after themselves. We are pretty simple people; we follow where we think there is a good market and a good return. The problem at the moment is not lack of capital; it is lack of confidence that there is a meaningful return in the UK.
I am concerned in particular because I think some of our peer allies are doing a better job of this than we are. We are potentially going to miss the development of this generation of defence and dual-use deep technology companies that have some kind of application in defence and security because the market is better among some of our key allies. They will go there, and investors will go there, and we are playing catch-up.
My key message through the SDR and since has been this. The good news is that we have this lever in our hands. We—the UK, the Government—are the customer here. We can really shape this market. The Ministry of Defence is unusual in the public sector in that it is the only part of that sector that has a sufficiently scaled budget and need for technology that can absolutely shape the market it wants to create. Most of the rest of the public sector does not have either the budget or technology need to do that. Defence does; it can do it, and it needs to get on with it.
The publication of the Defence Investment Plan is an important first step because the uncertainty around when it would be published or what it would say has certainly been chilling to investors. It is important that it has been published, but it is very important that it is not seen as the end of the process; it is step one. Step two is to go out and start deploying the money, not just into the hands of all the people who have traditionally received that money but to the more diverse set of suppliers that we want to create. I think that will unlock a lot of the capital that is ready and willing.
It is possible that some of the more kinetic end of defence may still have a block to raising capital. Ammunition, missiles and so on are really at the sharpest end of this market. It can still remain a challenge for companies to get funding in that area. Although institutional investors, LPs[1] and so on, have become much more relaxed in the past three or four years about defence exclusion in what they are asking of the funds they invest in, for many of them that last mile of the absolutely kinetic explosive area is still challenging. The Government probably have a role to play there because the market struggles to fund that part of it in the way that 95% of this can be funded from private capital.
Lord Udny-Lister: Perhaps I can jump back in on two points.
The Chair: I am conscious that we have a lot of questions we would like to pose. Maybe Mr Maund would like to come in as well.
Colin Maund: I have just a couple of quick points. One is that we have definitely seen a change over the past 18 months in the number of people wanting to be active in the defence industry. To give you an illustration, as I said, we have 6,200 suppliers on our system, of whom 100% two years ago were nominated by the prime contractors or the MoD to be on the system. We then opened it to people to self-nominate to suppliers so that new suppliers from different industries could enter. There was a bit of a trickle at first, but that trickle has become a substantial number. In the past 18 months 600 suppliers have registered, many of them from different industries and backgrounds that have been attracted to defence because they see the potential. A lot of them are technology companies; a lot are very small companies, SMEs and so on, so it is a positive sign. We are trying to help them understand what they have to do to become a defence supplier.
The Chair: Lord Udny-Lister, will you hold your question, and if we have time at the end we can come back to it?
Q48 Baroness Valentine: May I ask to what extent it is clear where SMEs and non-traditional suppliers should go for advice and support to become involved in supplying defence requirements? What more could the Ministry of Defence do to signpost this support? To add one rider, what are we learning from other huge infrastructure projects that also try to push things down the supply chain? I am thinking of the Olympics, HS2 and Sizewell C. I know something called CompeteFor. I would be interested in learning about how to get primes to push things down the supply chain. Colin, do you have any observations on that, if you would not mind starting?
Colin Maund: I think the MoD has improved significantly the amount of support it is trying to give to SMEs. It has set up the Defence Office for Small Business Growth, which is still in its very early stages but it is making some progress. The trade associations have been particularly virulent about the whole area and are pushing the role of SMEs and so on. As for our system, as I said, we have 6,200 suppliers, of whom 4,300 are SMEs. There is a lot of SME interest, and a lot of those suppliers are quite small and very niche.
In terms of people getting into these major infrastructure projects, there are always two issues. One is how you get noticed, how you get to that stage. The second is that the size of these projects can be difficult for small businesses. They are trying to play a role when, actually, their best role is as a sub-subcontractor or a subcontractor, because the size of the contracts at the very top of the pyramid is enormous and not really suitable, and the technical complexity and the ability to pull on other subcontractors and bring them together in a cohesive group takes a lot of skill and understanding. A lot of SMEs—and I am saying this as an SME—do not really have that capability.
To give people a wider view of where they can add most value, one thing is to get the SME community to really understand where its niche fits and how it can make itself most attractive. We do a lot of work with SMEs trying to help them, such as filling in information. Many SMEs do not understand some of the basic requirements of the defence industry— things like cybersecurity, information security, ITAR[2] or other export controls and so on. These need to be explained to people. They are not naturally always au fait with what they do.
It is a developing picture. It has improved for SMEs, and we see that as so many are nominating themselves to go through the process, but it has some way to go.
Q49 Lord Teverson: Good morning. How can the Ministry of Defence better support and promote innovation in the supply of defence requirements? I take that as being how it can be innovative in the way that it has those purchasing procedures. Grace, you said earlier that it needs to move from a buyer and seller relationship to a partnership relationship, which to me focuses in on this question. How do we stop those becoming sweetheart deals and moving towards elements of corruption? Corruption is big in global defence procurement. The time of Covid showed we are not completely necessarily immune to this within the UK. How do we make sure that does not happen either?
Grace Cassy: It probably relates to what I said earlier about accepting a faster turnover of products and focusing on an outcome-based assessment of whether what you have bought is delivering and keeping you ahead of your adversaries. If we become more comfortable with the idea that capability turns over quickly, people cannot stay in long-term, comfortable sweetheart deals because they know that their capability will be tested ruthlessly and will be got rid of if it does not work. Defence, as an industry in the past, has been able to be in very long-term, quite comfortable contracts where—I do not want to say you could get away with things not performing over time—given the length of these contracts and the slowness of it all, in effect, things could coast along. If we can move successfully to a culture of expecting performance quickly and sustainably, and suppliers understanding that if they no longer perform they will be moved on and the next one will come in, that should hopefully help to counter the risk that you are describing.
More generally on your question of how to support innovation, I do not think the UK has an innovation problem. We are very good at inventing things. We have lots of great people, whether in universities or start-ups, who come up with great ideas and invent things that get to a pilot stage. Our challenge has been translating that innovation from a pilot level to a scaled level, and that is where we need to focus more attention. Things like the Defence Office for Small Business Growth and the Defence Innovation Unit and so on are very good ideas in principle, but we must judge them over time on whether they are actually pulling capability through into the hands of users. There are associated scaled contracts with that, so we cannot afford to have innovation theatre any longer where there are lots of lovely projects, handshakes and photo shoots and so on where something sounds great but does not have a lifespan beyond a small experimentation or contract. The proof of the pudding will be whether any of this over time leads to more smaller businesses or younger businesses being able to meaningfully grow their revenue, and grow and create more jobs and so on over time beyond a pilot contract. That speaks to changing procurement, as we are hinting at. It is some quite practical things like paying on time so that you are not leaving small businesses with a very difficult cash-flow crunch; you are not requiring their investors to step in and give them some kind of funding extension because they have a cash-flow problem. So I would point to some quite simple, practical things there.
Allowing your suppliers to say they supply you is a quite simple and helpful thing, particularly for dual-use innovation technology. If you are able to say, as a start-up or scale-up, that you are supplying the MoD, that can be incredibly helpful if you want to go and supply a telecom or a pharmaceutical company that might have a similar use for the same technology, but it has been quite difficult sometimes when you have successfully made it through MoD procurement if you are not allowed to tell anyone about it; you cannot really leverage that with a wider customer set.
The Chair: Do you want to add anything?
Colin Maund: Yes, very quickly. First, technology is moving so quickly. If you go back 10, 20 or 30 years, these programmes were vast and only a few people could do them. The nature of technology and the advance in technology means that there is now much more of a broader group of people who could supply, so the length of these projects is shorter. There is no natural conflict between having robust procurement and having innovation. It is a question of setting things up in such a way that you encourage innovation and the tools and techniques are ready for it rather than simply a “throw the baby out with the bathwater” type of approach of saying, “Well, we can go straight to award contracts with no proper process”. Some of the most successful organisations acting in procurement and technology have quite robust procurement processes, but they are geared towards speed and accuracy. I do not think there is an issue there.
There is always a tendency in defence to be a little bit incestuous in that everyone knows everyone and it is a bit close. Entering a market in which new people are entering all the time is always a bit tricky and is a bit of a shake-up for the defence community, but that is inevitable. We see that in the defence industry in the US with new players coming in, disrupting the market, changing relationships and undermining some of the traditional players, and that is a good thing.
Q50 Baroness Drake: Good morning. My question is on supply chains. It is in two parts: the problem and the resolution. The first part of the question is this. We have heard that the visibility, or lack of it, of supply chains and their inputs can be an issue, such as not understanding key risks or critical inputs through the supply chain. How does responsibility for this visibility pass up and down the supply chain from the prime company through to the small SME? Subsequently, how should the MoD and defence contractors ensure that the supply chains are secure and reliable? Have you seen any progress on this through the Defence Supply Chain Capability Programme?
Colin Maund: That is a really interesting question and, in fact, not easy to solve. Anyone who claims that they are able to solve supply chain mapping and be able to look down the supply chain is being either deceitful or gullible. It is a real problem. How do you get down in a supply chain that may have 1,000 actors?
The other thing you find is that, as you drop down the supply chain, many of those actors are not willing to share the information on who is a supplier to them. That is their competitive information that they hold very closely to their chest, and they hate telling everyone because they are terrified of being disintermediated, as used to be the “in” word—basically, people going direct to their suppliers and cutting them out of the picture and losing control. It is a really crucial issue. It is absolutely essential, if you are going to get high-quality capacity in the market sufficient to manage a scenario in which there could be a potential conflict and you need to have enough information about what is happening down the supply chain, to know how you could ramp up production by a matter of really large percentages or large factors.
Information is an important area. We have to accept that we will never get complete information. It is just not going to happen. One of our NEDs is a professor at Oxford who worked with another guy at University of Tokyo. They tried to map Toyota’s supply chain following the Fukushima earthquake, or tsunami, and discovered that they were not looking at a nice clinical pyramid; they were looking at a complete ball of relationships where everyone was connected to everyone, and many suppliers had many different points of access or points of relationship. Mapping the whole thing is not just a point in time; it needs absolutely continuous attention because the ball is changing all the time. I do not know if that answered your question.
Baroness Drake: It does. Do you want to take the second bit about what the MoD and defence contractors can do and the Defence Supply Chain Capability Programme (DSCCP)?
Colin Maund: Yes. I am sorry, I ignored that.
Baroness Drake: I posed them together because we are short of time.
Colin Maund: The MoD is taking a lot of steps forward in terms of gathering information, better managing information and creating opportunities to collect that data. Using the JOSCAR system that we run, we have been part of that and have been feeding information in on suppliers that may be apt. In terms of DSCCP, it is part of a wider process, but inevitably it needs to involve people like the prime contractors as well. You cannot just do it in isolation, because 70% of all SME contracts come through the prime contractors. To do it without their support or without their involvement is a bit of a hiding to nothing.
Q51 Lord Best: Colin, you have mentioned already that cyberattacks and the security angle for SMEs are a particular problem. The question goes first to Grace because this is her special subject. What do these small SMEs require to overcome the hazards of cyberattacks? How much of that is down to government to do something?
Grace Cassy: This is a very difficult challenge. In the age of AI, this is as much a problem for large suppliers as it is for small suppliers. The nature of the threat is changing. It is accelerated by AI. There are new attack surfaces as a result of AI. Everybody in the defence supply chain and everybody in the economy is facing a challenge to become cyber-resilient in this era. The good news is that AI can also be very helpful in defending against cyber threats. Much day-to-day cyber work has been very manual: people in security teams responding to huge numbers of alerts from various sensors on their systems, trying to triage those, trying to work out which are the false positives and so on. That has been hard manual work for a number of years. AI gives us the opportunity to automate a great deal of that and to free up humans to apply judgement to the edge cases and the threats that might be more specific to your own organisation where you have a greater knowledge of your own systems and needs. There is a good news story alongside the negatives that AI can bring in here.
Automation for SMEs should be a positive. Some very interesting vendors are emerging that can provide suites of products that will take a lot of this away from an overpressed IT team in a small or medium-sized business. In the next couple of years, I expect that we will find that many smaller medium-sized businesses will be able to raise their level of basic cybersecurity because the tooling will improve. It is improving already. If you are talking, though, at the highest level where a smaller supplier may be vulnerable to more of a nation-state-level cyber threat, that is something where the Government need to step in and support SMEs. I do not think it is reasonable to expect an SME with potentially a small IT budget to defend against a nation-state-level threat. That is where government resources can and should be applied in support of parts of our supply chain. I know the National Cyber Security Centre (NCSC) runs a number of working groups in this area to support sensitive sectors. As we think about defence and the amount of new money that is now flowing into defence and will flow in in future, and the kinds of companies that we want to encourage into that, there will be a longer tail of cyber risk associated with that, and government will need to remain part of that defensive effort at the higher level of risk. Some of the more automatable risk is positive—
Lord Best: Government has that capacity, does it?
Grace Cassy: I cannot speak to the capacity that exists in the agencies and the NCSC. My guess is that it would need to be increased. We would need to have a better understanding of what we think counts as critical national infrastructure (CNI) in future. We all have an instinctive understanding of power grids and certain parts of the financial machinery that count as critical national infrastructure. In this newer era of deterrence we are going to see that a much broader set of our national infrastructure becomes critical, and some readings of that could include critical parts of a supply chain where there is a company providing something unique to a defence or security capability and it needs to be given the kind of CNI protection that has traditionally only been given to the power grids, the undersea cables and so on. Even in that area, it is fair to say that the SDR called for a significant increase in support even to that higher end of CNI. It needs more attention than it has had to date.
The Chair: Thank you. Mr Maund, do you want to add anything?
Colin Maund: Yes. I have some figures, which is always great fun. Of our 6,200 suppliers, which I have mentioned several times—this is quite a surprising figure—46% as of now do not have any form of cybersecurity credentials. Despite much urging from the MoD, the prime contractors and others in the field, 46%—2,888—do not have any form of cybersecurity certification. They are not all SMEs. You might think they would be. Of those, 1,145 are either medium or large suppliers. Of the 2,888, 1,213 are accessing sensitive data shared by their customers. That is a pretty alarming figure when you put the whole thing together. We have been working with defence over several years to try to improve that. It has improved. It has dropped from 70% two or three years ago to 46% today, but it is still a long way from where you would expect it to be.
The Chair: I do not think those were the sorts of numbers that I wanted to hear today, but there you are. I am really sorry, but we are really out of time. There will be a chance for you to write in later.
Q52 Baroness Harding of Winscombe: When we started this inquiry a month or so ago, I thought I knew nothing about defence at all. The more evidence we take, the more I hear echoes of Covid and the absence of a British industrial capability, which we did not have in vaccines or diagnostics, and this lack of collaborative working relationship between the private sector, academia and the public sector. That is my experience. What do you think the defence sector should learn from other sectors of which you have experience? How does the UK defence sector, particularly with regard to its relationship with government and its ways of working, compare to those of other countries? Grace, you already mentioned you thought that other countries and other of our key allies’ markets were working better. What can we learn from other industries? What can we learn from other countries?
Grace Cassy: It is a great question. Perhaps the cybersecurity industry may in some senses be too close to defence, but I will none the less use it as an example. Cyber has done a good job as an industry in the last decade or so of becoming far more collaborative: financial services organisations sharing information between themselves about the threat, sharing intelligence that can be valuable to others in their sector, understanding that an attack on one may well be an attack on others very quickly, and that it is in the whole sector’s interest to share things even when things have gone wrong for you. That has been a really important shift in the cybersecurity industry where, if a company has had a breach, being transparent about it with others is an important learning, because then you stop others suffering the same fate, and from a national perspective that is obviously important.
On the point about comparison with other countries—I mentioned this earlier—I would be specific that among our European allies Germany and Poland are at the top of the list for how they have managed to really operationalise what they mean by a different partnership between industry and the Government. They have put real money behind the warm words, and we are seeing genuine development in the industrial base of those countries and the way that they interact with their host Governments.
At a smaller scale, another great example is Estonia and the Baltic states where, again, there is a much more established pattern of proper partnership, proper co-working, and people on the front lines very familiar with working with private companies and sharing that information back and forth so that you have an iterative process of improving the things that you are deploying.
In terms of our scale, Germany and Poland are very interesting, instructive examples for us. The US is somewhat of an example of its own because of its scale. I do not think it is easy for us to expect that we could replicate how the US is doing this. Setting aside the scale issue, there are some things that it is doing that we could draw from in terms of prioritising pace, prioritising iteration and understanding that things can go wrong and that is okay.
The Chair: Thank you. Mr Maund, do you want to add anything?
Colin Maund: Yes. We run another system rather like JOSCAR for the financial services industry. We have 89, I think it is, banks and insurers that share supplier data and so on between themselves, and there are about 5,500 suppliers on that system that input the data. They are very strong on issues such as cybersecurity and information security. They have been very pushy on that, and they have driven their suppliers along a road of getting a fair degree of compliance around those areas, which has been really important. There is something for the defence industry to perhaps take on board in terms of strength of message and so on around what is acceptable and unacceptable, and what is an acceptable risk.
In the case of other countries, I agree with what you said about Germany and Poland, and the focus they are putting on this. We run a similar system in Australia. It is very exacting. It has very particular requirements and it is really quite well organised. There is also an element in the Australian defence industry that is quite collaborative. It does not have this slight degree between MoD and the primes, which can be a bit of a tension. It tends to work more collaboratively with the primes to achieve results, and that is a good thing to see.
The Chair: I thank you both enormously. You will have heard about our areas of interest. This is not the end point. If you would like to write in with more questions of the type that we have asked, we would very much welcome that. For the moment, I thank you both for coming here today. That ends this particular public session.
[1] An LP, or limited partner, is an investor who provides capital to a venture capital fund but does not manage day-to-day operations.
[2] ITAR is the International Traffic in Arms Regulations, US government regulations which govern the export of weapons and defence items such as missiles.