Request a quote
Emergency SectorsCareers About us Blog Get in touch
NLNederlandsENEnglishESEspañolFRFrançaisTRTürkçe
Worker in an apron at a workstation with a monitor in a greenhouse full of orchids

IT for those who supply into defence

Around defence sits a chain of suppliers, machine builders, maintenance firms and research institutes. They are handed requirements they did not write: who may reach a drawing, where data sits and what has to be traceable about a delivery. We build the IT that meets those, and we say where our limit is.

What is at stake

The requirements come from your customer

In this chain information security is not a trade-off but a condition of being allowed to take part.

A company supplying parts, maintenance or knowledge to a defence organisation meets requirements that go further than what is usual elsewhere. They are about access: who may reach a drawing, how that is recorded and how quickly it is withdrawn when somebody leaves. They are about provenance: which parts went into which delivery, where did they come from and can that be shown afterwards. And they are about location: where does the data sit, who can technically reach it and does that party fall under foreign legislation.

That last question has grown heavier in recent years. For part of the chain the requirement is now that data stays inside Europe and that the supplier is under no obligation to hand it over under legislation from outside the EU. That is not a political position but a purchasing condition, and it decides which cloud choice is open to you.

Export control touches IT sooner than you think

Technical data on military or dual-use equipment falls under export control, and that does not begin with a shipment but with access. A drawing opened from an office outside the EU is, in that logic, already an export. We take that into the design: where does the data sit, who can reach it from which location, and is that recorded in a way that can answer a question about it.

In practice that means separation: project data from one customer kept apart from another, access by role and by project rather than by department, and a trail per document. It looks heavy until the first time somebody asks.

Where our limit sits

We work on the corporate IT of organisations in this chain. We do not manage classified systems and we do not supply an environment for classified information: that requires an accredited setup and cleared personnel under the applicable rules, and we do not have that. Where your customer mandates a classified element, that element stays with the party approved for it; we make sure the rest of your environment sits properly alongside it and that the separation is recorded.

In practice

What we take on in the defence chain

You choose what you need. It all falls under one contract, one report and one point of contact.

  • Access by role and by projectWho may reach which drawing follows the job and the project, with multi-factor verification and immediate withdrawal when permanent or contracted staff leave.
  • Project data separated per customerWhat belongs to one customer sits apart from what belongs to another, with a trail of who could reach it and when.
  • Data inside Europe where that is requiredStorage and management with parties under European legislation, so a purchasing condition about disclosure can be answered with a fact.
  • Provenance and changes recordedDocuments, versions and access stay traceable, so a question about a delivery from two years ago does not end up in somebody’s mailbox.
  • Availability of production and maintenanceThe systems a delivery or a service interval hangs on get a recovery time agreed in advance and demonstrably rehearsed.
  • No classified environmentsWe manage corporate IT. A classified element stays with the party approved for it, and we record the separation rather than letting it emerge.
Approach

How we take over an environment in this chain

In this order, because a customer’s first question is about your setup and not about your intentions.

Collect your customers’ requirements

What the contracts and terms of delivery actually say about access, location and record-keeping. That is the starting point, and it sits in annexes more often than in the main contract.

Map where the data sits

Which systems, which suppliers, which countries. This step almost always surfaces a service nobody knew held project data.

Separate and record

Access by role and by project, data from different customers kept apart, and logging that can answer an auditor’s question without somebody hunting for an afternoon.

Adjust on what we see

The reporting shows access, changes and incidents. Those figures exist to improve the environment and are usable in your own account to the customer.

What we bring

The services that come up most here

These building blocks come up most in the defence chain.

Other sectors

Looking further

Recognise the picture but work in another industry? Then look at the other sectors.

Frequently asked

Questions we get about this

The ones that come up most, answered briefly.

Are you allowed to work on classified systems?

No, and we say so up front. Classified information requires an accredited environment and cleared personnel under the applicable rules; we do not have that. We manage the corporate IT around it, and the classified element stays with the party approved for it.

Can you guarantee our data stays inside Europe?

Where your customer requires it, we set it up that way: storage and management with parties under European legislation, with a record of what sits where. That is a design choice made in advance and not something to repair afterwards.

What does export control have to do with our IT?

More than most companies think. Technical data on military or dual-use equipment falls under it, and that does not start with a shipment but with access: a drawing opened from an office outside the EU already counts in that logic. So we record who can reach it from which location.

Tell us what your customer requires

Name the conditions in your contracts about access, location and record-keeping. We build the separation, the cover and the evidence around them, with the limit clearly stated.

Request a quote Call