Defence Cybersecurity | Built for Startups & SMEs

TURN CYBER
SECURITY INTO
OPERATIONAL
ADVANTAGE.

Defence tech startups and SMEs are a high priority target. Nation-state adversaries, supply chain attacks, and IP theft don't wait for Series B. Neither should your security.

AEGIS — our flagship defence service Operational cyber security for the defence sector. We bring your Microsoft 365 environment up to defence standard, protect it around the clock, and produce the evidence you need for DefStan 05-138 and Defence Cyber Certification. Delivered at DCC Levels 0 to 3 — built by us, protected by us, owned by you. Level 0 introductory pricing — limited places, closes 30 Sep 2026 → Explore AEGIS
Free Instant CSMv4 Readiness Check Explore Services
3,000+
SMEs in the UK
defence supply chain
43%
of UK businesses hit
by cyberattack last year
£3.29M
average cost of a
UK data breach
60%
of breaches linked to
unpatched vulnerabilities
// Where are you on your journey?
FIND YOUR STARTING POINT
01
NEW STARTUP
You are starting a brand new company and want to lay secure foundations.
02/A
FIRST STEPS
You are ready to enter the market and need Cyber Essentials in place as table stakes.
03
RAPID GROWTH
Your business is growing fast and you need cyber security that grows with you.
04/A
DEFENCE MATURITY
Time for your first big defence contract — don't let cyber compliance hold you back.
05
SCALE SECURELY
As you continue to grow, so do your cyber risks. We're there at every step on the way.
⚠ Limited offer
AEGIS LEVEL 0
New to defence? Get secure and certified in one managed package. Introductory pricing — limited places, closes 30 Sep 2026.
02/B
UK ENTRANT
You are looking to build in the UK and need to get Cyber Essentials as a first step.
04/B
INTERNATIONAL GROWTH
You are established overseas and now need to navigate UK cyber compliance.
AEGIS — wherever you are on this journey
One service across the whole path. Your Microsoft 365 environment hardened and protected around the clock, OFFICIAL-SENSITIVE handling with the documentation built for you, and the evidence for DefStan 05-138 and Defence Cyber Certification. Delivered at the level your contracts demand, 0 to 3.
Explore AEGIS →
// Our Services

WE DON'T TELL
YOU HOW.
WE DO IT.

Three capabilities. Delivered by former government and military cyber experts who spent careers defending the nation from the threats you're now facing.

For the defence sector, all three come together as one service: AEGIS, sized to the Cyber Risk Profile your contracts demand.

01
Security Leadership
Seasoned executive-level security leaders who design, prioritise, and run the right cyber programme for your stage. We build a strategic roadmap aligned to your business growth - not a generic framework - and own the delivery so you don't have to.
vCISOStrategic RoadmapRisk ManagementInvestor Readiness
02
Compliance Support
Our SC and DV cleared experts helped build and implement MOD's own cyber security requirements. Whether you're starting with Cyber Essentials, evidencing DefStan controls, or preparing for Defence Cyber Certification - we prepare you to interface with MOD, or do it for you.
Cyber Essentials / CE+DefStan 05-138DCCCSM v4
03
Managed Services
We design, build, and operate your cyber security capabilities end-to-end. We harden your networks, devices and identities - then our UK-based, 24/7 security team delivers around-the-clock protection. No tool sprawl. No part-time CISO. Just security that actually runs.
24/7 SOCHardeningIncident ResponsePosture Management
// Case Study
A data-driven private equity firm needed board-level confidence in their cyber posture to manage their cyber risk and project confidence to partners. We designed and delivered a comprehensive security programme - building resilience from the ground up, reducing material risk across back office and software development functions, and producing the evidence their partners needed to see.
Outcome: Demonstrated maturity to LP partners. Established cyber security risk as part of operational decision making.
// Case Study
A US defence contractor entering the UK market needed rapid compliance against an unfamiliar framework. We guided them through the UK regulatory landscape, achieved Cyber Essentials Plus certification ahead of their contract deadline, and built the evidence required to meet the new DefStan 05-138 obligations.
Outcome: CE+ achieved within tender window. DefStan controls implemented and evidenced.
// Case Study
shadowlink, a newly launched dual-use defence tech company, needed security built in from day one - not bolted on later. We deployed a fully hardened Microsoft 365 environment within hours and had them Cyber Essentials certified within a week, giving the founders the confidence to focus on building their product.
Outcome: Secure M365 environment live same day. Cyber Essentials certified in under one week.
// Our flagship defence service

AEGIS.

Operational cyber security for the defence sector. We bring your environment up to defence standard, we protect it, and we produce the evidence that proves it — in that order.

The order matters. A gap report doesn't make you secure and a certificate doesn't stop an intrusion. Defence suppliers are live targets, so the security has to be real first. Because the environment is genuinely built to the standard, the evidence comes out of it.

01
Harden & Protect
Hardening of identity, email and endpoints, plus active threat detection and response from our UK-based team. Built by us, protected by us, owned by you — the tenant is yours, and it stays yours if you ever walk away.
IdentityEmailEndpoint24/7 Response
02
Handle OFFICIAL-SENSITIVE
Sensitivity labelling, data loss prevention and label-based encryption, configured for OFFICIAL-SENSITIVE. Plus the part everyone underestimates: the Secure by Design documentation, pre-built. You name a risk owner and sign.
Secure by DesignRisk assessmentHandling policy
03
Evidence & Certify
Closing the gap against Defence Standard 05-138 at your level, and getting you assessment-ready for Defence Cyber Certification. DCC is awarded by an IASME-approved certification body, not by us. Our job is to make sure you pass.
DefStan 05-138DCCCSM v4

You don't choose your level — your contract does. The MOD assigns a Cyber Risk Profile and states it in the invitation to tender, or your prime flows it down. AEGIS is delivered at all four.

0
Basic
Very low assessed risk. Cyber Essentials, UK GDPR evidence and resilient networks. Sold as a fixed-price package including licences and the certification body fee.
1
Foundational
Low to moderate risk. 101 DefStan 05-138 controls spanning technical measures and governance.
2
Advanced
High risk. 139 controls, with Cyber Essentials Plus rather than standard Cyber Essentials.
3
Expert
The most critical contracted outputs. 144 controls and a full defence-in-depth approach.
Explore AEGIS → Free readiness check
// Threat Landscape

THE FRONT LINE
RUNS THROUGH
YOUR SERVERS.

Four active threat themes targeting the defence industrial base right now:

🎯
Russia-Nexus Actor Targeting
APT44 and UNC5976 are actively spoofing UK, US, and European defence contractor infrastructure - using your own product documentation as the lure. UAS and anti-drone developers are a primary focus.
⚠ Hundreds of contractor domains spoofed in 2025 alone
🪪
Your People Are the Vulnerability
DPRK operatives are getting hired by defence contractors. Iranian actors are deploying malware via fake job portals. APT5 targeted employees on personal email using lures built around their hometown, university, and family activities.
⚠ Most of this activity is invisible to enterprise security tools
🔬
China-Nexus Espionage
The highest-volume state threat to the DIB - by a significant margin. UNC5221's BRICKSTORM campaign sat inside target networks for an average of 393 days undetected. The goal is silent, long-term access to R&D and programme data.
⚠ 24+ zero-day edge device exploits since 2020
🔗
Supply Chain Ransomware
Manufacturing has been the #1 ransomware target sector for five consecutive years. One 2025 attack on a UK manufacturer with military vehicle contracts disrupted production for weeks and cascaded across 5,000 connected organisations.
⚠ IT-only breaches can degrade wartime defence production capacity
Source: Threat Intelligence Group - Beyond the Battlefield: Threats to the Defense Industrial Base, February 2026

WE USED TO
DEFEND THE
NATION.

Nova Blue was founded by former government and military cyber security experts who spent decades protecting the nation's most critical information and digital systems from cyber threat.

  • 01
    We Know the System
    Our SC and DV cleared team includes people who spent careers inside the systems, threat environments, and compliance frameworks you're now navigating. We've worked at the heart of government and MOD and know how to navigate the system.
  • 02
    Founders don't have to be CISOs
    You're managing innovation, capital, hiring and delivery simultaneously. We know how hard this is - because we're a startup too. We absorb the full-spectrum defence cyber requirement so you don't have to. Scaled expertise at startup economics.
  • 03
    Compliance Aligned to Growth, Not the Other Way Round
    We build sequenced compliance roadmaps tied to your contract pipeline - hitting the right bar at the right time without over-investing prematurely or missing a bid deadline.
  • 04
    Anglo-Canadian Reach
    Operating across UK and Canadian defence ecosystems with an understanding of both MOD and allied procurement frameworks - including CMMC for US-facing supply chains.
Cyber Essentials
Cyber Essentials Plus
CSM v4 (Dec 2025)
DefStan 05-138
Defence Cyber Certification
Secure by Design

We've created a document to explain the CSM in more detail and set out a playbook that DefTech startups can follow to get their cyber security moving.

↓ Download the playbook & CSMv4 explainer

Or read the straight answers: how a UK defence SME achieves DCC Level 0, what CSM v4 requires of your company, and what the 31 December 2026 DCC Level 0 date really means. All 10 guides →

// Who We Support

TRUSTED BY
THE BUILDERS.

DSRB logo
Raven logo
shadowlink
Tiberius logo
Resilience Media
DIANA
Janus Allies
L-Pace logo
SECURE

YOUR FIRST
MOVE IS FREE.

Book a free Readiness Assessment. We'll review your current posture, identify your most critical gaps, and give you a clear view of what you need - with no obligation to proceed.

Current State Assessment
We'll build a picture of your current cyber security state to understand whether your current posture is ready for the threats you face.
Microsoft 365 Security Review
If you're on Microsoft 365, our free VANGUARD service gives you instant clarity on your security posture. We review your tenant configuration, highlight weaknesses, and show you exactly where your setup falls short - no jargon, no commitment.
Compliance Gap Report
A high-level picture of where you stand against Cyber Essentials+ and any contract-specific requirements.
Prioritised Roadmap
A practical, prioritised list of what to do next - calibrated to your budget and timeline.
Book Your Assessment
// No cost. No commitment. No hard sell