Or for more information:

01488 648468 Have a chat with one of our team.
Need more information? Please get in touch.
Free Demo

Understanding the DEFCON 658 Cybersecurity Regulatory Framework and how to meet it


Thousands of cyber attacks occur daily. They are an unpredictable and dangerous menace to all, from individuals and small start-up businesses to major governmental authorities like the United Kingdom’s Ministry of Defence (MOD).

The MOD duties are vast and varied, and it often works and communicates with various partners and suppliers. This presents numerous risks, such as:

  • Communications between the MOD and partners could be overheard or subject to cyber-attack
  • Data passed between the MOD and its partners could be intercepted or enter the wrong hands

To manage this threat and mitigate risks as much as possible, the MOD has established a clear framework of parameters that all of its partner companies and their suppliers must abide by. This framework is DEFCON 658, a crucial defence supply chain puzzle piece.

What Is DEFCON 658?

DEFCON 658 is a cybersecurity framework that applies to any suppliers or partner companies that are either currently working with the Ministry of Defence or have plans to do so. In other words, it is essentially a set of principles and standards that such companies must adhere to to be allowed to take on MOD duties and handle identifiable information from the MOD (MODII).

It aligns with Def-Stan 05-138 standards, and its purpose is clear: to make the defence supply chain that fuels the MOD and its projects as secure as possible so that any sensitive data passing through that chain is protected and has the lowest possible risk of being targeted, leaked, or seized.

It also extends through the whole supply chain, so it does not only apply to direct partners of the MOD, but also the companies that supply them, their subcontractors, and so on. As such, even if your business is not directly involved in the defence industry, you may still be subject to DEFCON 658 requirements, depending on who you work with and supply.

Those who cannot or will not comply with DEFCON 658 are automatically excluded from participation in MOD projects or receipt of MOD contracts.

Objectives of DEFCON 658

The primary purposes for DEFCON 658 can be summarised in two words: resilience and compliance.

Through this framework launched in 2017, MOD intends to strengthen the supply chain that powers its defensive and protective initiatives across the United Kingdom and beyond. The more resilient the supply chain is, the less chance there will be of successful cyber-attacks.

From a compliance standpoint, DEFCON 658 exists to make compliance more straightforward for all relevant parties – i.e., the firms that work with and supply the MOD. It lays out the rules to follow clearly and succinctly so that there is no confusion among the MOD’s partners and suppliers regarding what they need to do to successfully and safely work together.

It all boils down to the simple adage: a chain is only as strong as its weakest link. Through DEFCON 658, the MOD strengthens every link, from the base of the defence supply chain to its peak.

Key Requirements of DEFCON 658

DEFCON 658 is a complex framework with an extensive list of specific requirements for compliance. From a cybersecurity perspective, for example, compliant parties must:

  • Protect all MODII and other sensitive data from unauthorised access.
  • Define clear access controls.
  • Encrypt data to high standards – critical for protection against evolving cyber threats.
  • Establish strict network security and system configuration protocols.
  • Monitor, detect, and react to any security incidents rapidly and efficiently.

These are just some of the requirements imposed upon DEFCON 658-compliant firms. Essentially, they are obliged to take cybersecurity just as seriously as teams and workers within the MOD. This is at the crux of the philosophy behind DEFCON 658 – it is about sharing responsibility for data protection and a holistic approach to cybersecurity throughout the defence supply chain.

Through DEFCON 658 implementation, the U.K.’s national security interests are more assured, with less risk of cyber-attack, greater confidence in the supply chain, and stronger, more efficient collaboration among partners and supplies at every stage of that chain.

Implementing DEFCON 658

Those wishing to work with the MOD in any capacity, whether directly or indirectly as a supplier to companies partnering with the Ministry, must implement DEFCON 658 comprehensively. That can appear to be a great challenge at first, particularly for those new to such strict, governmental standards and protocols.

Various resources exist to support your process of implementing DEFCON 658, particularly across the gov.uk website. There are also secure collaboration platforms you can turn to that have already been designed to abide by DEFCON 658 standards, making the transition to those standards a much faster and more straightforward process.

Kahootz is an example of this. Kahootz is a widely used public cloud collaboration platform, fully entrusted and accredited by the MOD, Kahootz was crafted to maximise the security of files and data stored on or transmitted through the cloud – a proven solution for the defence supply chain. Consider investing in Kahootz to expedite DEFCON 658 implementation or reach out to the Kahootz team for expert advice on how best to meet 658 standards.

DEFCON 658 – An Invaluable Force for British Cybersecurity

In summary, the value of DEFCON 658 cannot be understated. It plays a crucial role in strengthening the U.K.’s cybersecurity standing, ensuring that all those involved in defence projects, from suppliers through to partners, all uphold the same high standards as the MOD itself. Any company wishing to engage with the MOD at any level will therefore need to understand and abide by this framework.

Start your FREE 30-day trial.

Join hundreds of thousands of people across public sector organisations, enterprises and not-for-profits
who are using Kahootz to collaborate anytime, anywhere. No upfront commitment required.