Skip to main content

Resilience is bought in the quiet years, not during the emergency.

Hardened control systems, security that works with the network down, and inspection that certifies the physical estate, the unglamorous half of national defence that decides the loud half.

Resilience is decided in the quiet years, long before the crisis it is meant to survive. Whether the lights stay on, water keeps moving and the systems behind them keep running when the network fails is settled by choices made when nothing is going wrong and no one is watching. Civil security is a defence problem that does not look like one until the day it becomes the only one that matters, and by then it is too late to buy.

The Cybersecurity Group's infrastructure hardening reduces the attack surface of the OT and SCADA systems behind essential services and keeps them defensible without taking them offline. Its off-grid architectures keep those systems protected when connectivity fails, which is when an attacker most wants them exposed. The NDT Systems House's non-destructive testing certifies the physical estate, using radiography and computed tomography to confirm structural integrity without disassembly, so ageing structures are trusted on evidence rather than habit. One accountable channel covers all of it. The outcome is prosaic and exactly the point: services that hold up under attack, structures that are known to be sound, and a country that spent the quiet years buying the resilience it will need in the loud ones.

Capabilities that solve this

Resilience is bought in the quiet years, not during the emergency.: questions

Which Unstrat capabilities address "Resilience is bought in the quiet years, not during the emergency."?

Unstrat brings together Infrastructure hardening, Off-grid cybersecurity and Non-destructive testing. The Cybersecurity Group's infrastructure hardening reduces the attack surface of the OT and SCADA systems behind essential services and keeps them defensible without taking them offline. Its off-grid architectures keep those systems protected when connectivity fails, which is when an attacker most wants them exposed. The NDT Systems House's non-destructive testing certifies the physical estate, using radiography and computed tomography to confirm structural integrity without disassembly, so ageing structures are trusted on evidence rather than habit. One accountable channel covers all of it. The outcome is prosaic and exactly the point: services that hold up under attack, structures that are known to be sound, and a country that spent the quiet years buying the resilience it will need in the loud ones.

What problem does this solution solve?

Resilience is decided in the quiet years, long before the crisis it is meant to survive. Whether the lights stay on, water keeps moving and the systems behind them keep running when the network fails is settled by choices made when nothing is going wrong and no one is watching. Civil security is a defence problem that does not look like one until the day it becomes the only one that matters, and by then it is too late to buy. Hardened control systems, security that works with the network down, and inspection that certifies the physical estate, the unglamorous half of national defence that decides the loud half.

Can "Resilience is bought in the quiet years, not during the emergency." be procured as one programme rather than several suppliers?

Yes. Rather than integrating several foreign primes yourself, you acquire Infrastructure hardening, Off-grid cybersecurity and Non-destructive testing through one accountable channel, a single team responsible from first briefing through delivery and in-region sustainment. Each capability is sourced from an independent, non-aligned manufacturer, so the programme carries no major-power disclosure rules or political ramifications.

Questions buyers ask

What is civil security in national defence?

Civil security is the defence problem that does not look like one until it is: whether infrastructure stays up, supplies keep moving and systems keep running when networks fail. Resilience is decided before the crisis, in the quiet years, not during the emergency. This solution covers the unglamorous half of national defence, hardened control systems, security that works with the network down and inspection that certifies the physical estate.

See: OT security capabilityResilience and civil security solution

Why is resilience bought before a crisis, not during one?

Because the decisions that determine whether essential services survive an attack are made in advance: hardening the control systems, architecting for disconnection and verifying the physical estate. During the emergency it is too late to build any of that. Treating resilience as a quiet-years investment is the difference between degraded and disconnected when it matters.

See: Infrastructure hardening capabilityHow we deliver

How do you keep essential services running under cyber attack?

You harden the control systems that run them and architect the security to survive disconnection, so a single intrusion cannot cascade and a lost link does not blind the defence. Hardened control systems and off-grid architectures keep power, water and transport running under attack, and non-destructive inspection keeps the physical estate certified. One accountable channel runs across all of it.

See: Off-grid cybersecurity capabilityAir-gapped against connected security

Civil security programme that keeps its findings out of foreign hands

For a resilience programme the disclosure question is central: outsource protection to a foreign-cloud provider and that provider often sees your incidents first, sometimes with obligations about the knowledge. This solution keeps assessment, hardening and findings inside your own environment, accountable to you alone. It is one accountable channel across the cyber and physical estate, with no foreign reporting line.

See: Off-grid cybersecurity capabilityOff-grid cybersecurity in the catalogue

Hardening control systems for power, water and transport

Attacks on utilities and transport across the region have moved from theory to precedent, and much of the installed control base is decades old and never built for hostile networks. Hardening reduces the attack surface methodically: assess the estate as it is, reduce exposure in priority order, segment control from corporate networks and verify the fixes hold. It is unglamorous work that decides whether the lights stay on.

See: Infrastructure hardening capabilityIT against OT cybersecurity

Security that keeps working when the network is down

The most critical systems are often the ones that cannot reach a security cloud, and adversaries target the gap between connected tooling and disconnected reality. Off-grid architectures use local detection and response and procedures the site team can run alone, so protection does not lapse when connectivity does. Everything stays inside your environment rather than flowing to foreign infrastructure.

See: Off-grid cybersecurity capabilityAir-gapped against connected security

Certifying the physical estate as well as the networks

Resilience is structural as well as digital, so this solution pairs cyber hardening with physical verification. Non-destructive testing inspects platforms, components and stocks without disassembly, so a force can certify what it owns rather than assume it is serviceable. The condition data stays with you rather than flowing through a foreign prime's service network.

See: Non-destructive testing capabilityNon-destructive testing in the catalogue

One accountable team across cyber hardening and physical inspection

Split resilience across separate suppliers and the seam between cyber and physical usually goes unowned. This solution runs hardened control systems, off-grid security architectures and non-destructive inspection through one accountable channel. A single team answerable for both halves is the point, because civil security fails at exactly the joins no one owns.

See: Resilience and civil security solutionCritical infrastructure resilience solution

Resilience is bought in the quiet years, not during the emergency. Where does a government start?

Start with an honest assessment of the estate as it actually is, then harden in priority order and architect the security to survive disconnection. Hardened control systems and off-grid architectures keep essential services running under attack, while non-destructive inspection keeps the physical estate certified. We deliver the whole of that through one accountable channel, staged to a budget rather than delivered in a panic.

See: Resilience and civil security solutionHow we deliver

Civil security does not look like a defence problem until it is. How do we make the case for funding it?

The case is that a country loses if essential services fail, supplies stop or systems go down, regardless of whether a border is crossed. Attacks on utilities, ports and transport across the region are now precedent, not theory, and the installed base is often ageing and poorly documented. Framing resilience as a defence problem decided in the quiet years is exactly how it competes for funding before the emergency arrives.

See: OT security capabilityBriefing

How do we protect isolated and air-gapped sites that cannot phone home to a security cloud?

You architect for the disconnection rather than assume it away. Off-grid cybersecurity uses local detection and response, integrity mechanisms that work over intermittent links, and procedures the on-site team can execute alone. Deployed forces, remote installations and classified enclaves share the pattern, and nothing depends on telemetry flowing to foreign infrastructure.

See: Off-grid cybersecurity capabilityOff-grid cybersecurity in the catalogue

Our ageing fleet and stocks came from many sources with no manufacturer support. How do we certify them?

Sovereign inspection lets a force certify what it owns without depending on a foreign prime's service network or revealing its fleet condition to one. Non-destructive testing verifies structural integrity without disassembly, and it can be procured as equipment, a service, or a transfer programme that builds a national inspection capability with trained inspectors. The condition data, and the capability to produce it, stay with you.

See: Non-destructive testing capabilityNon-destructive testing in the catalogue

What does a national resilience and civil-security programme cost, and can you name a figure yet?

We do not publish price bands, because the cost turns on the size and condition of the estate, the number of isolated sites and how much of the defence you run in-house. The shape is consistent: assessment first, then prioritised hardening, off-grid architecture where connectivity fails, and physical verification, staged to your budget. We will scope before we cost, and we will not offer a figure we cannot stand behind.

See: Resilience and civil security solutionBriefing

How does civil-security resilience overlap with critical-infrastructure protection, and do we buy both?

They share most of the same work, so buying them as two disconnected procurements usually duplicates effort or leaves a gap. Resilience and civil security leans on the physical-verification and off-grid half, while critical-infrastructure resilience adds continuous defensive operations across the estate. We run the shared elements, hardening, off-grid architecture and inspection, through one accountable channel, and scope how far the continuous-defence layer needs to extend.

See: Critical infrastructure resilience solutionOT security capability

Who keeps a national resilience capability running once the delivery contract closes?

The capability is structured so your own people run it: hardening is executed with the operators who run the systems, off-grid procedures are ones the site team can carry out alone, and inspection can be delivered as a transfer programme that trains national inspectors. One accountable team carries the work in-region rather than a foreign service network. Resilience that depends on an outside team to sustain it is not resilience.

See: Non-destructive testing capabilityHow we deliver

Contact us

Tell us the requirement. Specifications and the export position are confirmed in briefing, not published here.