Skip to main content
Insider Risk

Sabotage and Insider Risk at UK Defence Suppliers:
7 Controls

Hostile states are recruiting proxies to watch and attack the factories that supply Ukraine and the UK armed forces. Seven controls for drone, munitions and component manufacturers, most of which cost little.

Behavioural analysis visualisation for insider threat detection showing anomaly indicators

UK defence suppliers now face a sabotage threat that most of them were not built to handle: hostile states recruiting ordinary people, often online and for small sums, to carry out reconnaissance and attacks on their behalf. On 9 September 2026, a 31-year-old man from Swindon was charged under the National Security Act 2023 with assisting a foreign intelligence service and preparing an act of sabotage. The prosecution alleges that between March and September 2026 he took instructions from someone linked to the GRU Volunteer Corps, a group the UK government designated a national security threat in July, and passed on the addresses of four drone manufacturing sites. He has not been tried and the allegations are unproven. The pattern the case illustrates is not new, and it lands on the sector at the moment it is scaling fastest: £140m for drone and counter-drone technology through UK Defence Innovation, and more than 1,000 uncrewed systems ordered for the Army on 16 September. This page sets out seven controls for drone, munitions and component manufacturers, most of which cost little.

Proxy sabotage is the use of recruited intermediaries, often with no prior link to the hostile state, to carry out surveillance, arson or disruption. Intelligence services use proxies for deniability and scale: tasks are broken into small, paid steps (photograph a site, record a delivery, buy a component) so that no single step looks like espionage to the person doing it.

Why defence suppliers are the target now

Three things have converged. First, European support to Ukraine has made the defence industrial base a strategic target: a warehouse in Leyton supplying Ukraine-linked businesses was set alight in 2024 by men recruited on behalf of the Wagner Group, who were convicted under the National Security Act in 2025, and German prosecutors charged men in 2024 over alleged sabotage plans against military and industrial sites. Second, drone manufacturing in particular is expanding through smaller, newer firms whose security maturity has not kept pace with their order books. Third, the proxy model means the threat actor can be a local resident with no clearance, no access and no obvious connection to anyone, which is exactly the profile that traditional vetting never sees.

The implication for a supplier is that two different risks now overlap. The outsider doing reconnaissance from the street, and the insider, whether an employee, contractor or agency worker, who is approached because they already have access. A programme that only addresses one leaves the other open.

Seven controls for drone and munitions manufacturers

#ControlAddressesFirst stepEffort
1Treat site information as sensitiveOutsiderAudit website, job adverts, Google Maps listings and staff posts for site and shift detailsLow, one afternoon
2Detect hostile reconnaissanceOutsiderBrief guards and reception on reconnaissance indicators; set a reporting route to policeLow
3Screen everyone with accessInsiderExtend BPSS to contractors, agency staff and regular delivery personnelModerate
4Guardrails on surge hiringInsiderSet a non-waivable minimum screening standard; log every exceptionLow
5Train staff on approachesInsiderRun NPSA "Think Before You Link" awareness; publish a no-blame reporting routeLow
6Insider risk programmeInsiderName an owner; correlate HR, physical access and IT signals monthlyModerate
7Harden physical and RF securityBothTest CCTV and alarm resilience to RF interference; review out-of-hours coverModerate to high

1. Treat site and production information as sensitive

Reconnaissance starts online. Company websites that name production sites, job adverts that describe shift patterns and product lines, press releases celebrating a new contract with a photo of the factory floor, and staff posting from inside the building all do the adversary's work for them. Remove what customers do not need, and brief staff on what not to post.

2. Detect and deter hostile reconnaissance

The NPSA's guidance on hostile reconnaissance is built on a simple finding: attackers are most vulnerable while they are gathering information, and visible, confident security deters them. Train security and reception staff to notice repeated loitering, photography of entrances and fences, questions about deliveries or shift changes, and drone overflights, and give them a fast route to report it.

3. Screen everyone with access, including contractors

A proxy does not need to be your employee. Cleaners, agency pickers, subcontracted engineers and regular delivery drivers often have more physical access and less scrutiny than permanent staff. The Baseline Personnel Security Standard is the minimum; apply it across the whole access population, and require your labour providers to evidence it. See personnel security vetting for where point-in-time checks stop working.

4. Put guardrails on surge hiring

Firms scaling to meet a new order book are under pressure to put people on the line quickly. That is precisely when screening gets deferred "until after start date". Set a minimum standard that production targets cannot override, and track every exception at board level. Remote technical hiring has its own version of this risk; see how to detect a deepfake job candidate.

5. Train staff to recognise and report approaches

Hostile-state recruitment increasingly looks like gig work: a message on a social platform or job site, a small payment for an innocuous task, then escalating requests. Staff should know that approaches happen, what they look like, and that reporting one will not get them into trouble. The NPSA's "Think Before You Link" campaign covers online approaches and is free to use.

6. Run an insider risk programme, not just a vetting process

Vetting tells you who someone was on the day they were checked. An insider risk programme tells you what has changed since. At its simplest, that means a named owner and a regular review that brings together HR concerns, physical access anomalies and IT alerts. The five insider threat detection layers set out the full model, from honeytokens and UEBA through to behavioural precursors.

7. Harden physical and RF security

Assume that a capable adversary will research how to defeat your alarms, cameras and access control, including radio-frequency interference with wireless systems. Test whether wireless CCTV and alarm links fail safely, confirm that out-of-hours coverage matches the value of what is on site, and involve your insurer and local police counter-terrorism security advisers.

The person carrying out a proxy task often does not think of themselves as a spy. That is the point of the model, and it is why awareness and reporting routes do more than vetting alone.

EchoDepth Defence analysis

Where behavioural monitoring fits, and where it does not

Most of the seven controls above are procedural and should come first; none of them requires EchoDepth. Behavioural monitoring earns a place in control 6, for a small number of high-consequence roles such as those with access to sensitive design data, test facilities or final assembly. There, sustained deviation from an individual's own affective baseline, measured across 44 facial Action Units using existing cameras, can give an analyst an early prompt that something has changed for a person under pressure, whether that pressure is financial, personal or coercive. It is a prioritisation input reviewed by a human, never an alert acted on alone, and it requires a data protection impact assessment and clear proportionality. See insider threat detection for how it integrates with existing security tooling.

Funding and routes for SME suppliers

The Defence Investment Plan commits the Ministry of Defence to increasing spending with small and medium-sized enterprises by 50% by 2028, and the Defence Office for Small Business Growth, opened in January 2026, is now the single entry point for SMEs. Security maturity is increasingly part of how primes and the MoD judge supplier risk. A documented insider risk and physical security posture is becoming a commercial asset as well as a protective one.

Note on the Swindon case: the defendant has been charged and has not been tried. The facts given here are limited to the charges as publicly reported, and nothing on this page should be read as suggesting guilt.

Frequently asked questions

What should UK drone manufacturers do about sabotage risk?

Seven controls cover most of the risk: treat site and production information as sensitive; train staff to detect hostile reconnaissance; apply BPSS screening to everyone with access including contractors and agency staff; set non-waivable screening standards during surge hiring; train staff to recognise and report online approaches; run an insider risk programme that correlates HR, physical and IT signals; and harden physical and radio-frequency security. Most of these are procedural and low cost.

What is the GRU Volunteer Corps?

It is a group controlled by Russia's GRU military intelligence service that recruits, organises and deploys volunteers and proxies to support Russian military and intelligence objectives. The UK government designated it a national security threat in July 2026. In September 2026 a man from Swindon was charged with assisting a foreign intelligence service after allegedly taking instructions from someone linked to the group; he has not been tried.

What is proxy sabotage?

Proxy sabotage is the use of recruited intermediaries, often with no prior link to the hostile state, to carry out surveillance, arson or disruption. Tasks are split into small paid steps, such as photographing a site or buying a component, so that the person doing them may not realise they are working for an intelligence service. It gives the hostile state deniability and scale.

Is vetting enough to stop insider sabotage at defence suppliers?

No. Vetting is a point-in-time check, and most insider cases involve people who passed it. Proxies may also be contractors, agency workers or outsiders who were never vetted at all. Vetting needs to sit inside an insider risk programme that monitors for change after hiring and alongside physical security that addresses reconnaissance from outside.

Where can UK defence SMEs get security guidance?

The National Protective Security Authority publishes free guidance on insider risk, employment screening, hostile reconnaissance and online approaches, including the Think Before You Link campaign. Local police counter-terrorism security advisers can review site security. The Defence Office for Small Business Growth is the MoD's single entry point for SMEs.

Related capability

Behavioural precursor monitoring for high-consequence roles

Individual baseline deviation from existing cameras. On-premise. Human review of every signal.