West Midlands Cyber

Cyber, Defence and the Midlands

The Midlands has significant defence, aerospace, and advanced manufacturing capabilities. Ensuring cyber resilience is integrated into regional defence strategy will be critical to protecting increasingly interconnected supply chains.

Contents

Cyber and Defence in the West Midlands: Closing the Gap Between Strategy and Delivery

The West Midlands has a credible claim to be one of the UK’s most important defence and advanced-engineering economies. Aerospace, automotive engineering, advanced manufacturing, digital technologies and extensive specialist supply chains create capabilities with obvious relevance to national defence. As defence policy increasingly emphasises resilience, technological advantage and a stronger domestic industrial base, the region should therefore occupy an important position within the UK’s defence economy.

Cyber security complicates that proposition.

Modern defence capability depends increasingly on digitally enabled industrial systems, connected supply chains, software, data, operational technology and secure collaboration between organisations. The security of those dependencies cannot be separated neatly from the physical products being designed, manufactured or maintained. A defence industrial strategy that treats cyber primarily as a specialist technology sector rather than a property of the wider industrial system risks overlooking one of the conditions on which defence production itself depends.

The originating analysis, When It Comes To Cyber The Midlands Defence Blueprint Is Polite Fiction, made that criticism deliberately forcefully. Its underlying argument is more important than the rhetoric: regional defence ambition needs to account for cyber capability throughout the industrial base, including the SMEs and specialist suppliers on which larger organisations depend. A strategy can identify advanced manufacturing, innovation and defence growth opportunities without yet demonstrating that the cyber resilience required to support them exists consistently across the supply chain.

For the West Midlands, this creates both a vulnerability and an economic opportunity. Stronger industrial cyber capability can protect existing defence activity while improving the ability of regional businesses to participate in markets where security and assurance increasingly influence supplier selection.

Key Takeaways

  • Defence industrial capability is increasingly inseparable from cyber resilience because manufacturing, engineering and supply chains depend on connected technology, software, data and external digital services.
  • The principal regional challenge is not simply protecting major defence organisations, but achieving proportionate cyber maturity across the smaller suppliers on which they depend.
  • National business evidence shows a substantial maturity gradient: in 2025/26, 48% of large businesses reviewed cyber risks associated with immediate suppliers, compared with 22% of small businesses and 12% of micro businesses.
  • Cyber assurance is increasingly relevant to market access. For defence suppliers, the ability to demonstrate appropriate controls can become part of commercial qualification rather than an optional security improvement.
  • The West Midlands has an opportunity to specialise around the intersection of cyber security, advanced manufacturing, operational technology and high-assurance supply chains rather than attempting to reproduce a generic cyber cluster model.

Defence Industrial Capability Is Now Digital Capability

The conventional distinction between physical industry and digital technology has become progressively less useful in advanced manufacturing.

Engineering businesses use cloud platforms, computer-aided design, product lifecycle management systems, digitally controlled machinery, connected sensors, remote maintenance and software-intensive production processes. Information moves between customers, suppliers and production environments, while operational systems increasingly interact with conventional enterprise IT.

In defence supply chains, those dependencies can carry additional consequence. Technical data may be sensitive; component availability can affect strategically important programmes; and suppliers can possess digital relationships with customers whose value extends beyond the supplier’s own systems.

Cyber security therefore becomes part of industrial resilience.

This does not mean every manufacturer is a cyber company or that every industrial risk should be reframed as a security problem. It means that the ability to design, manufacture, deliver and recover increasingly depends on technology whose compromise can affect confidentiality, integrity or availability.

The UK’s wider cyber market already reflects part of this convergence. DSIT’s 2026 Cyber Security Sectoral Analysis identifies 2,603 firms active in the UK cyber sector, but industrial specialisms remain a minority of the overall provider base. Seven per cent are associated with SCADA and industrial-control-system security, while analysis of provider websites identifies industrial and operational-technology security among 10% of offerings.

Those national figures do not establish the precise availability of industrial cyber capability within the West Midlands. They do demonstrate that organisations seeking expertise around production environments are drawing from a more specialised segment of the market than those seeking general consulting, governance or conventional enterprise security.

For a region seeking to connect defence growth with advanced manufacturing, that distinction matters.

The Supply Chain Is Part of the Defence Attack Surface

Large defence organisations can maintain substantial internal security capabilities. They can employ specialist teams, procure managed services, conduct testing and impose formal governance over sensitive systems. Their supply chains contain businesses operating at very different scales.

That variation creates a structural problem.

A smaller supplier can be operationally or informationally significant without possessing the security resources of the organisation it serves. It may manufacture a specialist component, hold engineering information, provide maintenance, develop software or access customer systems. The supplier’s economic size is therefore an imperfect measure of the consequence associated with its compromise.

The 2025/26 Cyber Security Breaches Survey illustrates the broader disparity. Formal incident-response plans were held by 76% of large businesses and 57% of medium-sized businesses, compared with 21% of micro businesses. Immediate supplier cyber risks were assessed by 48% of large businesses but only 22% of small businesses and 12% of micro businesses.

These are economy-wide figures rather than defence-specific measurements, so they should not be used to infer the maturity of individual defence suppliers. They nevertheless show the capability gradient within the business population from which complex supply chains are constructed.

For defence, the problem is compounded because an attacker does not need to compromise the largest or best-defended organisation if a weaker relationship elsewhere provides access to useful information or capability.

Supply-chain cyber security therefore needs to move beyond the assumption that assurance at the prime contractor creates resilience throughout the system.

Assurance Is Becoming Part of Industrial Competitiveness

The response to supply-chain risk increasingly includes assurance.

Customers want evidence that suppliers manage cyber risk appropriately. Procurement exercises can include security questionnaires, contractual requirements, recognised standards and obligations concerning incidents or data handling. Government-backed mechanisms such as Cyber Essentials provide one way for organisations to demonstrate baseline technical controls.

Adoption remains uneven across the economy but is increasing. The 2025/26 Breaches Survey found that 5% of businesses held Cyber Essentials certification, compared with 3% the previous year. Among small businesses the proportion rose from 5% to 12%, while among large businesses it increased from 21% to 35%.

The direction is significant because cyber maturity can become a condition of commercial participation.

For a supplier, the business case for stronger security may consequently be broader than reducing the probability of a breach. The ability to provide credible evidence about security can help satisfy procurement requirements, respond to customer due diligence and demonstrate that the business is suitable for higher-assurance work.

This is particularly relevant where companies are attempting to enter defence markets from adjacent sectors. A manufacturer may possess excellent engineering capability but still need to demonstrate that its information systems, people and processes satisfy the expectations associated with defence work.

Cyber capability therefore becomes part of supplier readiness.

Regional economic-development programmes concerned with defence should recognise that connection. Helping firms understand procurement opportunities without helping them understand the security expectations attached to those opportunities leaves part of the market-access problem unresolved.

A Proliferation of Requirements Can Create Its Own Friction

The case for stronger supplier assurance does not imply that more questionnaires and overlapping requirements automatically produce better resilience.

Smaller businesses can serve several customers, each using different security terminology, evidence requirements and contractual clauses. A supplier may repeatedly demonstrate similar controls through different processes, consuming technical and management time without materially improving security.

This creates a difficult balance for defence supply chains.

Customers legitimately require confidence because the consequences of supplier compromise can be serious. At the same time, assurance mechanisms that are unnecessarily fragmented can create fixed costs that fall disproportionately on smaller organisations.

The objective should therefore be proportionate and reusable evidence wherever possible.

Recognised baseline schemes can help by creating common expectations. Higher-consequence relationships will still require additional assurance, but the reasons for those requirements should be connected clearly to actual risk rather than accumulated through procurement convention.

This distinction is economically important for the West Midlands. If smaller engineering companies face high and unpredictable costs simply to demonstrate security, cyber assurance can become a barrier to diversification into defence. If requirements are clear, proportionate and connected to recognised standards, they can instead provide a progression route through which capable businesses become credible defence suppliers.

The difference lies in assurance design rather than in lowering the required level of security.

Operational Technology Makes Defence Cyber an Industrial Discipline

Cyber security within manufacturing environments cannot be reduced to protecting office IT.

Production systems can contain programmable logic controllers, industrial networks, engineering workstations, robotics, specialist machinery and equipment maintained remotely by vendors. Some assets remain operational for decades, while safety and availability requirements can limit when systems can be modified or taken offline.

These characteristics alter how familiar security principles are implemented.

Patching is an obvious example. In conventional enterprise IT, rapid security updates are often an important defence against known vulnerabilities. In an industrial environment, an update may require compatibility testing, vendor approval or a planned production shutdown. Where immediate patching is not possible, organisations need compensating controls such as segmentation, access restrictions and monitoring.

The distinction becomes important for defence industrial resilience because production continuity itself can be strategically significant.

A cyber programme designed exclusively around enterprise IT may therefore leave important operational dependencies poorly understood. Conversely, an industrial cyber programme needs knowledge of engineering and production processes as well as conventional security expertise.

This intersection is one of the areas in which the West Midlands has a credible opportunity to develop distinctive capability. The region’s industrial base creates real demand against which cyber expertise can be developed, tested and commercialised.

That is a stronger proposition than treating defence cyber merely as another vertical market for general security services.

Cyber Security and Resilience Regulation Will Reinforce the Dependency Model

The direction of UK cyber regulation strengthens this argument.

The Cyber Security and Resilience Bill is intended to expand the existing Network and Information Systems framework, bringing additional technology providers within scope and creating mechanisms through which certain suppliers can be designated as critical where their disruption could significantly affect regulated services.

Not every defence supplier will be affected directly by that legislation, and defence supply chains have their own security requirements. The broader regulatory principle is nevertheless relevant: cyber criticality increasingly reflects dependency rather than simply organisational category.

A relatively small technology or engineering company can become important because larger organisations rely upon a service or capability that is difficult to replace.

This is closely aligned with the problem faced in defence supply chains. Understanding risk requires more than identifying the largest companies. It requires mapping which suppliers, systems and services create material dependencies.

For regional resilience, this suggests a more targeted approach than attempting to raise every business to an identical level of cyber maturity.

Organisations supporting higher-consequence functions need correspondingly stronger capability. Businesses whose role creates limited systemic consequence may require a robust baseline without the full assurance architecture expected of a strategically important supplier.

The challenge is identifying the difference.

Defence Growth Requires Progression, Not Just Recruitment into the Supply Chain

Regional defence strategies often focus understandably on helping businesses identify opportunities and enter supply chains. That is necessary, but entry is only one stage of economic development.

Suppliers need to progress.

A business capable of winning an initial defence contract must then be able to maintain assurance, invest in capability, develop customer relationships and potentially move into higher-value work. Cyber maturity can form part of that progression because requirements generally become more demanding as the sensitivity and consequence of work increase.

The same principle applies to cyber providers serving defence and manufacturing customers.

The UK cyber sector has grown strongly, with the 2026 sectoral analysis estimating £14.7 billion in revenue and £9.1 billion in gross value added. The number of firms earning more than £10 million annually from cyber activity has risen to 241, compared with 105 two years earlier.

That progression is encouraging nationally, but regional economic value depends on whether local providers can make similar transitions from technical capability to sustainable commercial scale.

Defence and industrial customers can contribute by providing demanding environments in which products and services are validated. A cyber company that can demonstrate successful deployment within complex manufacturing or high-assurance supply chains gains evidence that can support wider commercial expansion.

This creates a potential reciprocal relationship: regional industry provides real demand and validation environments, while regional cyber capability improves the resilience and competitiveness of industry.

Skills Need to Cross the Cyber-Engineering Boundary

The convergence between defence, manufacturing and cyber security also has consequences for skills.

Cyber labour-market policy often treats security as a distinct occupational field. That is appropriate for many roles, but industrial cyber increasingly requires combinations of expertise that do not fit neatly within a conventional cyber pathway.

An OT security practitioner may need to understand industrial networking, engineering constraints and safety requirements alongside security architecture and threat behaviour. A security professional supporting defence manufacturing may need familiarity with supply-chain assurance and information-handling requirements. Engineers responsible for connected systems increasingly need enough cyber knowledge to understand how design decisions affect resilience.

The skills problem is therefore partly interdisciplinary.

This matters because the UK’s cyber labour market has changed. The 2025 labour-market research estimated an annual net workforce shortfall of approximately 3,800 people, considerably below earlier estimates, while persistent technical skills gaps remained across the economy. Employer demand has also shifted towards experience, with a large proportion of advertised core cyber roles requiring several years of prior experience.

Simply increasing the number of people completing generic cyber training will not necessarily produce the specialist capability required at the intersection of security and industrial engineering.

The West Midlands is well placed to address this through relationships between universities, further education, manufacturers, defence businesses and cyber providers. The relevant objective is not to create a separate training ecosystem for every sector, but to expose cyber practitioners to industrial environments and engineers to security principles early enough for hybrid capability to develop.

Regional Cyber Capability Should Be Connected to Defence Demand

The West Midlands already contains many of the components required for a stronger relationship between cyber and defence: industrial customers, specialist SMEs, universities, technology companies, cyber providers and organisations concerned with regional economic development.

The challenge is coordination.

A cyber cluster can help make defence and industrial demand visible to providers. Larger organisations can articulate the assurance and technical problems they encounter within supply chains. Universities can connect research with operational requirements. Smaller suppliers can access support that helps them understand the cyber expectations associated with defence opportunities.

This should not involve creating regional alternatives to national defence-security requirements or NCSC guidance. Consistency is important, particularly for businesses operating across multiple regions and customers.

Regional value lies in translation and connection.

A supplier should be able to understand what an assurance requirement means for its actual systems. A manufacturer seeking OT security expertise should be able to identify credible specialists. A cyber company developing relevant technology should have routes to potential industrial customers and environments in which capability can be demonstrated.

These are practical economic functions. They provide a stronger basis for regional cyber-defence activity than simply placing both sectors within the same strategic document.

The Regional Opportunity Is Industrial Cyber Resilience

The West Midlands should be cautious about defining success as becoming another generic cyber security centre.

The UK’s cyber economy already contains substantial concentrations of capability, and different regions possess different structural advantages. The West Midlands’ strongest proposition comes from the characteristics of its wider economy.

Advanced manufacturing, engineering, automotive, aerospace and defence-related supply chains create a large population of organisations whose resilience increasingly depends on digital systems. These organisations generate demand for operational-technology security, supply-chain assurance, secure technology adoption, incident preparedness and specialist security services.

That demand can support a cyber economy built around real industrial problems.

The distinction matters because cluster development is more sustainable when capability emerges in response to persistent customer need rather than promotional positioning. Cyber firms that solve industrial problems can develop specialist expertise, generate reference customers and potentially export that capability beyond the region.

The West Midlands therefore has an opportunity to treat industrial cyber resilience as both an economic specialism and an enabling capability for its existing industrial base.

Defence strengthens that proposition because the consequences and assurance expectations are higher, creating environments in which mature cyber capability has demonstrable value.

A Defence Strategy Is Incomplete Without Cyber Execution

The central weakness identified in the original critique was not that the West Midlands lacks defence capability or that regional defence ambition is misplaced. It was that cyber security could be acknowledged rhetorically without being integrated sufficiently into the mechanisms through which industrial capability is expected to grow.

That distinction remains important.

Cyber should not appear in a defence strategy merely as another technology specialism alongside AI, autonomy or advanced manufacturing. It is also part of the infrastructure that allows those technologies, businesses and supply chains to operate with confidence.

For the West Midlands, meaningful integration would be visible in practical outcomes. More suppliers would understand and satisfy proportionate cyber assurance requirements. Industrial organisations would have better access to specialist OT capability. Cyber providers would gain opportunities to validate products and services against genuine defence and manufacturing demand. Skills pathways would recognise the overlap between engineering and security. Supply-chain programmes would treat cyber readiness as part of supplier development rather than a separate technical concern.

These outcomes require coordination, but they do not require another layer of strategy for its own sake.

The region already possesses much of the industrial demand on which a distinctive cyber proposition can be built. The task is to connect that demand with capability strongly enough that cyber resilience becomes embedded within how defence and advanced-manufacturing growth are delivered.

If that happens, the relationship between cyber and defence in the West Midlands becomes considerably more substantial than a shared place in a regional blueprint. Cyber becomes part of the region’s industrial capacity: protecting production, strengthening suppliers, enabling trusted participation in high-value markets and helping ensure that increasingly digital defence capability remains resilient throughout the supply chains on which it depends.