top of page

Moving Beyond the Illusion of Strategic Autonomy

10 hours ago
6 min read
September 2026, Daryl Flack, Partner


Strategic autonomy has become one of the defining themes of modern defense policy. Across Europe, NATO and allied nations’ governments are investing heavily in domestic industrial capacity, reshoring critical technologies, and reducing dependence on overseas suppliers. The rationale is understandable: Recent geopolitical instability, semiconductor shortages, cyberattacks against critical infrastructure, and increasing tensions between major powers have exposed just how fragile global supply chains can be.


Yet defense organizations cannot be truly resilient without first recognizing that these supply chains are inherently global, dynamic, and interdependent. The idea that any nation can simply eliminate these dependencies altogether is something of a fantasy.


There is a tendency in defense to think in terms of platforms. Fighters, frigates, satellites, and autonomous systems dominate the conversation. But increasingly, the platform itself is almost the easy part. The difficult part is understanding the thousands of interconnected technologies, suppliers, and digital dependencies that sit beneath it.


Modern defense capability has become a giant systems-integration exercise played out across global supply chains. Embedded systems, artificial intelligence (AI) models, semiconductors, software libraries, cloud infrastructure, and specialist subcontractors all have a role to play in delivering military advantage. The uncomfortable truth is that even the most sovereign program is rarely as sovereign as we would like to believe.


Strategic dependencies exist – they’re nearly unavoidable. The real question is whether defense organizations have sufficient visibility into and assurance of those dependencies to manage them when supply chains are disrupted, geopolitical tensions escalate, or adversaries decide to exploit the weakest link.


In many cases, defense organizations have a strong understanding of their Tier One suppliers and the organizations directly responsible for delivering critical capability. However, visibility often deteriorates significantly beyond Tier Two and Tier Three suppliers, precisely where many of today’s most significant operational, cyber, and geopolitical risks can emerge. A vulnerability introduced through a small software provider, component manufacturer, or specialist subcontractor may ultimately have consequences far beyond its position in the supply chain.


GCAP: the future of defense collaboration

The Global Combat Air Programme (GCAP) perfectly illustrates this shift. Bringing together the U.K., Japan, and Italy to deliver a sixth-generation combat aircraft by 2035, GCAP is arguably one of the world’s most ambitious next-generation defense programs. It also reflects the realities of modern defense capability development.


Thousands of organizations will ultimately contribute technologies and services across multiple countries. While international collaboration delivers enormous innovation benefits, it simultaneously introduces significant complexity.


The operational questions become considerably more challenging:

  • Where are critical technologies being developed?

  • Which suppliers represent single points of failure?

  • How resilient are lower-tier suppliers?

  • What geopolitical dependencies exist across critical components?

  • Which software dependencies sit within mission-critical systems?

  • How quickly can supply chain risks be identified and mitigated?


The defense programs of the future will increasingly resemble globally interconnected technology ecosystems rather than traditional military procurement programs.


Adversaries have already adapted

Attackers understand this reality better than many organizations defending against them. Increasingly, state and non-state actors are targeting the weakest links within defense ecosystems rather than attempting to compromise hardened military platforms directly.

The defense sector has already seen numerous examples of supply-chain compromise. One example: The compromise of SolarWinds several years ago demonstrated how trusted software updates can become attack vectors affecting thousands of organizations simultaneously, including government and defense users. Similarly, the exploitation of vulnerabilities within MOVEit Transfer during 2023 showed how a single software dependency can have cascading consequences across critical supply chains.


The compromise of defense contractors has also highlighted the attractiveness of lower-tier suppliers. In many cases, attackers deliberately target smaller organizations with weaker security controls because the lighter security can provide indirect access into strategically valuable programs.


Nation-state cyberactors routinely conduct supply-chain reconnaissance long before any operational attack takes place. Intelligence-gathering against suppliers can provide adversaries with critical information including technical intelligence on defense capabilities, access to sensitive program data, opportunities for intellectual-property theft, potential disruption points across logistics and maintenance operations, and persistent access into wider defense networks. In short, supply chains have become strategic attack surfaces.


Cyberthreat landscape fundamentally changed

The way defense organizations think about cyberthreats has not kept pace with the way adversaries now operate. The old distinctions between cybercrime, espionage, and state-backed operations are becoming increasingly difficult to maintain. Modern geopolitical cyberactivity increasingly exists in the gray space between criminal enterprise and strategic state activity, where techniques, infrastructure, and objectives often overlap.


Iranian-linked cyber activity provides a clear example of this evolution. Groups such as MuddyWater have demonstrated how ransomware techniques can be used alongside espionage and disruption campaigns, blurring the line between financially motivated crime and operations designed to advance wider geopolitical objectives. The attack method may look familiar, but the intent behind it can be far more strategic.


North Korea represents another example of how cyberoperations have evolved. Its activity increasingly combines intelligence collection with large-scale financial theft, using cybercapability not only to gather information but also to generate revenue, evade sanctions and support broader national objectives. Cyberoperations have effectively become another tool of statecraft.


Russia has demonstrated a different but equally significant shift: the industrialization of access. Stolen credentials and compromised accounts have become highly valuable commodities, traded through increasingly professionalized criminal ecosystems. Once legitimate access is obtained, it can be reused to support espionage, ransomware deployment, data theft, or operational disruption, often long after the initial compromise has taken place.


The important lesson for defense organizations is that attackers do not always need highly sophisticated capabilities to create strategic impact. In many cases, the greatest risks come from exploiting weaknesses that already exist.


Increasingly, attackers are looking beyond individual organizations and targeting their connecting ecosystems. Supply-chain compromise and third-party exploitation have become attractive attack paths because they enable adversaries to bypass hardened systems by compromising trusted relationships. Rather than attempting to break through the front door of a defense organization, attackers are increasingly looking for a weaker entry point somewhere else in the network.


These real threats are why supply-chain visibility has become a core component of modern defense resilience.


Embedded systems are increasingly exposed

For the embedded defense community, perhaps the most important shift is that the complexity of modern systems is no longer contained within the platform itself. The technologies that provide military advantage are also creating new layers of dependency and new questions around trust, provenance, and resilience.


The move toward software-defined capability has transformed defense platforms into constantly evolving digital ecosystems. Embedded systems now sit at the center of this change, bringing together commercial components, advanced semiconductors, software-defined radios, AI accelerators, thirdparty firmware, open-source software dependencies, and increasingly sophisticated security architectures.


Defense organizations must fully understand the chain of trust behind them. Organizations should be asking:

  • Where was a critical component manufactured?

  • Who contributed to the software running on an embedded system?

  • Can firmware integrity be validated throughout the entire supply chain?

  • Are software bills of materials providing genuine visibility into dependencies, or simply creating another compliance exercise?

  • Do organizations understand where mission-critical AI models are trained, maintained, and updated?


The growing use of AI-enabled capabilities adds another layer of complexity. Autonomous systems, sensor-fusion platforms, EW capabilities, and battlefield decision-support tools all depend upon secure data pipelines, trusted models, and continuous validation. A compromised dataset, manipulated model, or insecure software dependency could introduce risks that are difficult to detect and potentially impossible to correct once systems are deployed.


These factors are why AI-by-design and secure-by-design principles must become central to defense resilience. Security cannot be added after capability has been developed; it must be embedded across the entire life cycle of the system, from component selection and software development through to deployment, maintenance, and operational use.


Strategic visibility: a defense capability in its own right

The defense community is beginning to recognize that resilience cannot simply be designed into the platform itself. It must extend across the entire industrial ecosystem that creates, supports, and sustains that capability.


That reality means having a clearer picture of where critical components originate, how software and hardware dependencies evolve, where supplier concentration risks exist, and how geopolitical events could affect access to essential technologies. It also means strengthening assurance across AI systems, semiconductor supply chains, and third-party providers, while ensuring that operational continuity is considered before disruption occurs rather than after it has already happened.


Ultimately, resilience by design applies as much to the industrial ecosystem behind a defense capability as it does to the embedded technologies, software architectures, and cybersecurity controls within the platform itself.


Strategic autonomy will remain politically compelling and operationally important. However, autonomy without visibility risks creating a false sense of resilience. The future of defense will be determined by how effectively governments and industry understand, manage, and adapt to the increasingly complex ecosystems that make those platforms operational.


Daryl Flack, partner at Avella Security, is an experienced cybersecurity professional and has spent more than 25 years dedicated to protecting the U.K.’s national interests. He works at the forefront of securing the UK’s Critical National Infrastructure (CNI) and is a veteran of HM Forces in the U.K. and overseas operating air-defense systems.



bottom of page