Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology8 min read

Made in China, flying for Britain: Who really knows what’s inside our defense tech? | TechRadar

Chinese tech in Royal Navy Drone incident serves as a warning Discover insights about made in china, flying for britain: who really knows what’s inside our defe

TechnologyInnovationBest PracticesGuideTutorial
Made in China, flying for Britain: Who really knows what’s inside our defense tech? | TechRadar
Listen to Article
0:00
0:00
0:00

Made in China, flying for Britain: Who really knows what’s inside our defense tech? | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

Made in China, flying for Britain: Who really knows what’s inside our defense tech?

Chinese tech in Royal Navy Drone incident serves as a warning

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Nytt DDo S-rekord (Image credit: Shutterstock / Zinetro N)

Reports that cameras intended for Royal Navy drones contained Chinese-made components sending “heartbeat” signals to China sound like the opening of a spy thriller. The reality is more mundane, but arguably more useful as a warning.

There is currently no evidence that Ministry of Defence data, imagery or classified systems were accessed or exfiltrated. Routine cyber testing reportedly identified third-party camera components sending automated heartbeat communications to an IP address in China, after which internet connectivity to the affected camera subsystems was removed and the vulnerabilities closed.

So, based on what we know today, this is not a story about confirmed data theft. It is a story about something potentially much more widespread. How little organizations can know about what is happening several layers down in their technology supply chains.

A heartbeat signal sounds fairly innocuous. A device is effectively saying: “I’m alive.”

The danger is assuming that because the data looks insignificant, it has no intelligence value.

UK Navy forced to strip out internet connectivity from drones after finding it sent 'heartbeat communications' to China

"$10.22 million and counting": US cyber breaches have become a boardroom issue

Basic telemetry can potentially disclose device presence, uptime and temporal patterns. You could see when something comes online, how long it remains active and whether there are patterns in when it is being used.

None of that necessarily tells you much in isolation. Intelligence, however, rarely comes from one perfect piece of information. It comes from joining lots of apparently insignificant pieces together.

Combine those signals with OSINT, SIGINT, routing metadata or knowledge of exercises and deployments and they could potentially contribute to a much richer picture.

That does not mean this incident exposed Royal Navy locations, personnel or operational movements. There is no public evidence to support that conclusion.

But it shows the question is more than “Did sensitive information leave the system?” We also need to ask “What could somebody infer from the information that did?”

‘Resilience comes from designing for disconnection, not assuming more connectivity’: The future of battlefield AI systems lies in both coordination and local capability

Technology sovereignty is about keeping control, not geography

How open-source malware is re-targeting UK supply chains

With cameras and other connected sensors, there is another consideration. If you discover an unexpected external communications path, you need to understand what it can do. What has already travelled across it is only part of the picture. You also need to know what the component could potentially transmit.

The instinctive response to supply-chain concerns is often greater sovereignty. But telling defense companies to simply “buy British” misunderstands how modern technology is built. Pull apart a supposedly trusted product and the processors, cameras, communications modules, microcontrollers and firmware inside it may originate from suppliers scattered around the world.

Modern defense capability has effectively become a giant systems-integration exercise conducted across global technology supply chains.

Defense organizations may have a strong understanding of their Tier One suppliers. However, visibility can deteriorate considerably at Tier Two, Tier Three and beyond, precisely where specialist manufacturers, smaller technology providers and software dependencies enter the system.

You can perform assurance to the nth degree. The problem is doing it across every component in every system without making innovation painfully slow and expensive.

That is particularly difficult for startups. Switching from a commercial component to a sovereign or trusted alternative can mean higher costs and longer lead times, but also hardware redesign, software changes, testing and recertification.

This tension is becoming more important because modern conflict is simultaneously pushing defense towards technologies that benefit from rapid commercial development.

Ukraine has demonstrated the military value of relatively inexpensive unmanned systems that can be produced, modified and replaced quickly. They do not eliminate the need for sophisticated missiles or high-end platforms, but they are changing the economics of warfare.

Future militaries will need exquisite capability, but they will also need technology that can be manufactured at scale and adapted rapidly as battlefield conditions change.

Commercial off-the-shelf components help make that possible.

That creates a fundamental tension at the heart of strategic autonomy. The global technology ecosystem that allows defense companies to innovate quickly and relatively cheaply can create exactly the dependencies governments are attempting to reduce.

Risk should be determined by what a component can actually do, not simply which country appears on the label.

The questions I would ask are: what can it see? What can it do? Can it communicate independently? Can its behavior be changed?

A connected, programmable camera warrants considerably greater scrutiny than a passive component. Cameras, radios, sensors and communications modules deserve particular attention because they can collect or process information, run firmware and potentially create communications paths of their own.

Programmable sub-components are another area of concern because their behavior can potentially be altered through software or firmware.

As defense moves further into AI, the same principle will increasingly need to extend beyond physical hardware. Assurance will need to consider where models came from, what data they depend on, who can update them and how their integrity is maintained.

Supply-chain assurance should not be the only defense. Architecture matters too. If a component does not need internet access, why give it internet access?

If a camera only needs to communicate with another system locally, restrict it to that. Network segmentation, telemetry suppression, tightly controlled communications paths and air-gapping where appropriate can all reduce the consequences of unexpected behavior.

There is also a strong argument for a shared repository of vetted components from trusted manufacturers and vendors. This could include a Bill of Materials (BOM): a formal, nested inventory of software and hardware components. The Cybersecurity and Infrastructure Security Agency (CISA) promotes BOMs to improve supply-chain security, increase transparency and accelerate vulnerability management.

But such a repository cannot become a static approved shopping list. Firmware changes. Manufacturers substitute components. Vulnerabilities emerge. Supply chains move. Trust must therefore be continuously maintained rather than awarded once. This ongoing assurance is ultimately what identified the Royal Navy issue.

Perfect knowledge and assurance of every component is neither realistic nor economically viable if it makes defense innovation impossibly slow.

What we need instead is explicit, risk-based assurance of trusted manufacturers and vendors. Understand which components and software present the greatest threat, scrutinize them accordingly, and use architectural controls and ongoing assurance to reduce exposure elsewhere.

Strategic autonomy goes far beyond where a platform was assembled or which flag sits above the company that built it. What this incident highlights is the risk when an unvetted external communications path exists inside technology intended for a military platform. Sometimes good cybersecurity comes down to asking the simplest question: why is this thing talking to the internet at all?

We've featured the best endpoint protection software.

This article was produced as part of Tech Radar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of Tech Radar Pro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit

You must confirm your public display name before commenting

The tiny Fujifilm Instax Pal 2 has bags of personality — and one huge sticking point

Obsolete programs are powering 97% of US database systems — and the reason why won't surprise anyone

Blizzard says Star Craft will have the same 'gritty' atmosphere and be inspired by the 'interstellar western' of the original RTS — 'Our real world has asymmetry to it, and so I think leveraging that and putting that into this world was key for us'

i Fi's newest hi-res headphone DAC squeezes into a tiny USB-C-to-earbuds cable — just add IEMs

IPVanish says server count doesn't matter, so it rebuilt the parts that do

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.