This fact sheet is supported by:

  • Role Specific Mandatory Training

  • Security Policy

  • Information Management and Technology Policy

What cyber security risks does BAE Systems face, and how do you manage them?

As a major defence, aerospace and security company, the Group faces significant risks in respect of its information security, continuity of operations, integrity of its products and physical security. These threats are continuous and evolving and are posed by organisations with a broad range of capability, from criminals to nation states, acting independently or with the assistance of an “insider”. Threats include attempts to gain unauthorised access to the Group’s and customers’ sensitive data in order to compromise the integrity, confidentiality and/or availability of that data (in some cases potentially compromising the products to which it relates); attempts to disrupt business operations through the sabotage of the Group facilities, networks and other assets; threats to the safety of employees; theft of assets including potentially hazardous material; and threats to the Group’s supply chain and partners (including joint ventures and joint venture partners). These threats can manifest through cyber, human and/or physical means and directly or indirectly via the supply chain. The continuing war in Ukraine has increased a number of risks to Ukraine’s allies and their defence industries. Further, geo-political instability could give rise to similar threats.

While the impact of any such threats and/or disruption is difficult to predict, it could lead to (among other things): (a) production downtimes; (b) operational delays; (c) reduction in the effectiveness of, and/or introduction of vulnerabilities into, products sold to customers; (d) the compromise, misappropriation, destruction or corruption of the Group’s data or intellectual property and that held or generated by the Group on behalf of its customers, suppliers and partners; (e) other manipulation or improper use of the Group’s or third-party systems, networks or products (e.g. disabling or denying their use and/or altering their performance characteristics); (f) diversion of management’s attention and resources; (g) harm to staff; and/or (h) financial losses from remedial actions, potential exclusion from key markets, or potential liability, penalties, fines and/or damages. Furthermore, as part of its Cyber & Intelligence sector, the Group provides systems, products and services to various customers who also face cyber threats. These systems, products and services could themselves be compromised, may not be able to detect or deter threats, or effectively mitigate resulting losses, which could adversely affect the Group’s customers and therefore result in financial losses from remedial actions, loss of business, or potential liability and/or damages. In addition, a failure by the Group to prevent or mitigate cyber-attacks that impact the Group could have a detrimental impact on the reputation and/or performance of the Cyber & Intelligence sector. Any of these impacts could have a material adverse effect on the Group’s business, results of operations, financial condition, prospects and reputation.

The Board and senior management regularly consider security risk. These senior level reviews cover evolving threats, the Group’s planned responses and the effectiveness of security controls and security investments in meeting intended objectives. Security risk is also reviewed at a functional and operating business level. A robust security risk management framework identifies risks to the Group’s critical assets and personnel, be they based on digital infrastructure, company sites, attending events or on overseas travel. The Group’s internal Cyber Security Standards are aligned to the National Institute of Standards and Technology framework. A formal, three layers of defence assurance programme, which is reviewed both internally and externally, is operated to check adherence to these standards and to customer requirements. Additionally, resulting from the need to comply with government customer requirements, certain of the Group’s IT networks are formally accredited by those customers. Education and awareness to embed a strong security culture across the Group is a vital part of its preventative activities. Employees are required to complete mandatory training which (depending on role) covers cyber security, physical and personal security, document marking, security of export-controlled information and personal data protection. As many cyber-attacks involve email, the Group runs a programme of phishing exercises for all email users across the enterprise. To increase the Group’s resilience against security threats, including insider risk, the Group performs protective monitoring of activity on the Group’s core networks via the Group’s Security Operations Centres, maintains incident response and crisis management plans with updates following regular test exercises and obtains threat intelligence to the Group, utilising its internal security capabilities and from external partners including governments. To address the risk to the security of the Group’s personnel, communications and advice are provided to all employees on personal safety precautions, with additional tailored communications provided in high-threat cases. To mitigate the cyber security risk posed by working with suppliers, the Group performs risk-based due diligence and assurance and (where relevant) seeks to require suppliers to comply with cyber security related contractual provisions. In addition to the above, the Group purchases cyber and property insurance; however, as with all insurance, it does not provide full cover against all potential loss scenarios.

Explain the governance of your cyber security strategy at a Board and executive level.

Cyber security is covered by two group level policies, which are part of our Operational Framework – our Information Management and Technology Policy; and our Security Policy. Compliance with these policies is reviewed every six months, via the Operational Assurance Statement (OAS) process, by sectors and Group functions. Our approach to identifying and assessing cyber security risks is embedded within our approach to risk management.

Our Cyber Security Board, held quarterly, is a BAE Systems Plc meeting and is attended by our Chief Technology and Information Officer (CTIO) who is a member of our Executive Committee, our Group Security Director who reports to the CEO, as well as senior leaders across IT, legal, supply chain, engineering and manufacturing.  Its purpose is to direct and track cyber security risk reduction priorities, escalate any significant risks or control gaps, and to oversee the execution of cyber strategy.

Cyber security is reviewed as part of the Quarterly Business Review and Chief Executive’s Business Review Process. In addition, two detailed security briefings are delivered to the Board and Executive Committee per year.

The Board level Audit Committee is responsible for oversight of cyber security controls and risk management. The Chief Executive attends the Audit Committee meetings and is responsible for our cyber security strategy.

Do members of your Board and Executive Committee have cyber security experience?

 

Dr Ewan Kirk is the lead Board Member for cyber security. He is a member of the Audit and Risk Committee and has a strong background in technology risk, having led multiple ventures to identify, apply and leverage technology and mathematics research in both business and philanthropy. 

Julian Cracknell, Chief Technology & Information Officer (CTIO) and member of our Executive Committee, has a first-class degree in computer science.  As former Managing Director of the BAE Systems Digital Intelligence business he has a strong understanding of cyber security and digital transformations.

 

Do members of your Board and Executive Committee have cyber security incident recovery experience?

All of the Executive Committee have participated in a number of incident response exercises as well as 1-1 cyber security awareness training.  The Board has also received 1-1 cyber security awareness training.

Which role or function has responsibility for cyber security within the Company?

The Chief Information Security Officer (CISO) reports directly to the CTIO, who is a member of the Executive Committee. The CTIO reports directly to the Chief Executive

The CTIO develops and leads the Company’s overall technology strategy, which includes cyber security.

Do you have a cyber security strategy?

The cyber security strategy is overseen by members of the Board and Executive team with relevant experience in cyber security.  

Our cyber security strategy contains six objectives:   

  • Establish Strong Cyber Foundations - Increase control inheritance through modern tooling, patterns, and awareness. Strengthen defences using Zero Trust architectures, while securely enabling cloud adoption and AI exploitation.
  • Secure the Supply Chain - Collaborate with industry partners to standardise, simplify, and enforce effective supplier cyber risk management.
  • Embed Cyber Security Responsibilities into Roles and Processes - Promote a cyber security-conscious understanding of risk and compliance.
  • Strengthen Governance Risk & Compliance - Build on company cyber security standards to deliver targeted assurance and track prioritised remediation across IT and OT environments.
  • Enhance Cyber Resilience - Protect our most critical systems and data, routinely exercise cyber response scenarios, and coordinate incident management with minimal operational impact. 
  • Deliver Efficient Cyber Security - Standardise security processes and maximise the value of enterprise automation as part of wider digital transformation. 

Progress against the Cyber Security Strategy is tracked at the Cyber Security Board.

Explain your incident response systems.

We have a Group Incident Response Plan and more detailed plans, which are aligned to the overall Incident Response plan, in each of the business units. The Cyber Security Incident Response plan describes the key areas and processes that need to be followed. If a major incident is declared a ‘Crisis’, it is escalated in line with the Crisis Management plan. 

We regularly test these plans with tabletop exercises. We also have Business Continuity plans in place that are tested at least semi-annually. We conduct third party vulnerability analysis and regular penetration testing including full red teaming. 

We have a multi-channel approach for security incident reporting. Employees can either complete an incident report form on the intranet, which contacts the relevant teams, or telephone Site Security. Contact numbers are well communicated. We also have an Ethics Helpline that allows anonymous reporting. 

We regularly remind staff how to recognise an incident and stress the importance of fast reporting.

We make use of various security awareness and reporting tools – for example, we've embedded a button in Outlook that reports phishing emails.

Who do you report incidents to?

We report incidents in line with both the regulations of the country we are operating in and our contractual obligations to our government customers, including the UK MOD, the US DOD and the Australian MOD.

Do you conduct internal or external security audits, vulnerability assessments or penetration (pen) testing?

We perform vulnerability assessments across our Enterprise networks and perform regular pen testing using CREST certified pen testers. The pen tests include full red teaming exercises to thoroughly assess our systems against the latest threats. We perform evidence-based assurance against our Global Cyber Security Standards as part of our three lines of defence assurance model.  

We continually run and monitor an external scan of our estate using BitSight, NCSC Early Warning System, and we also use independent CREST approved pen testers. An external consultant performs an independent audit of certain financial systems, and our Internal Audit function also performs independent 3rd Line audits on areas of concern or risk. In addition, due to the classified nature of our work a number of our networks, are accredited by our customers independently.

Do you have a dedicated team to manage cyber security?

To have a coordinated capability with sufficient scale, we have a central cyber security team in Head Office and an equivalent central team for our US business, as well as a Sector cyber team and teams embedded within our programmes and geographies. Our Concept of Operations and governance model provides clarity of role and coordinated capability. We have invested in our in-house UK Security Operations Centre. We have state of the art tooling as well as a team of expert cyber analysts that triage and investigate alerts. We have a market leading threat intelligence team in our Digital Intelligence business along with NCSC approved incident response team and CREST approved pen testing team. These capabilities from our Digital Intelligence business are used extensively within the Company, as well as by our government and defence customers around the world.

Is your IT infrastructure certified to ISO 27001, NIST or similar?

Our internal Cyber Security Standards, applicable to all Company IT and OT networks, are aligned to the NIST framework and controls. A formal, three lines of defence assurance programme is operated to check adherence to Company standards and customer requirements, which is reviewed both internally and externally. Additionally, many of our networks are formally accredited by our government customers. 
 
For more information:
See our SASB Disclosures.  
 
For NIST Standards, please see https://www.nist.gov/cybersecurity
 
For a mapping of ISO 27001 standards to relevant NIST controls that has been compiled by NIST, please see 
 
https://csrc.nist.gov/projects/olir/informative-reference-catalog/details?referenceId=154#/olir/home

What is your cyber security policy for suppliers?

It is imperative that our suppliers recognise the critical importance of cyber security and have the appropriate controls in place to protect the information that they hold and generate in the work they do for us and our customers.

We include clauses within our supplier contracts and Standard Conditions of Purchase. For example, we flow down cyber security clauses within contracts relating to US Federal Acquisition Regulation (FAR) and the US Defense Federal Acquisition Regulation Supplement (DFARS). These clauses have clear requirements for how information is to be protected and how cyber incidents are to be reported. 

Our UK Standard Conditions of Purchase require suppliers to meet ‘Cyber Essentials’. Suppliers that handle more sensitive information are required to implement controls equivalent to Cyber Essentials Plus.  Cyber Essentials is a UK government backed scheme that helps organisations guard against cyber-attacks and certifies companies’ levels of preparedness. Further information can be found here. Where required, we also request Defence Cyber Certification. Further information can be found here.

Additionally, where suppliers aren’t yet governed by regulations and contractual requirements, our cyber risk management processes will incorporate our own supplier cyber assessment model that parts of our business will use to scope the extent to which nominated suppliers are, or have, implemented cyber security measures.

The Supplier Code of Conduct states that BAE Systems expects its suppliers to develop, implement and maintain appropriate security measures to protect the information they create, collect, handle, store or are responsible for, in accordance with applicable laws, regulations and contractual requirements, regardless of whether such information belongs to the supplier, BAE Systems and/or its customers. We also expect our suppliers to address any security issues proactively and to notify and support BAE Systems in responding to and remedying any security breaches.  More information is available in our Procurement Policy

For more information:  Supplier IT security requirements 

How do you engage and train employees on cyber security?

All employees must complete our comprehensive, risk and threat-based programme of security. The programme is designed to make us less vulnerable to attack and to enforce the security policies and processes we have in place to protect our data and systems. 

Educations and awareness to embed a strong cyber security culture across all employees and staff is another vital part of our activities.  We take a holistic approach providing training coupled with events and activities to drive better engagement and learning outcomes. We strive for the training to be relatable, both on a professional and personal level, and for hybrid working staff to maintain a strong sense of cyber awareness whether at home or in the office. Employees and staff are subject to annual mandatory training which, depending on role, covers cyber security, physical security, document marking, security of export-controlled information, and personal data protection. As many cyber-attacks still involve email, we run a programme of phishing exercises. Phishing tests occur for all employees at least four times a year. Users that click on the phishing test emails receive targeted training, and repeated clickers may be subject to disciplinary proceedings.

The information contained in this fact sheet is for PLC managed businesses and is accurate as at the date of its publication.

Publication date: 18 September 2026

Get in touch
Sustainability

Governance and Disclosure