Full analysis, recommended actions, tabletop scenarios, and cited sources in the complete issue.
SUPPLY CHAIN · HIGH
The paperwork said NDAA-compliant. The firmware called China.
Cameras fitted to 20 K3 Scout uncrewed surface vessels operated by the Royal Marines were sending automated “heartbeat” signals — status pings confirming the device is alive — to an IP address in China. The boats came from Kraken Technology Group under a £12.3m contract. Nobody reported an incident and no attacker tipped anyone off: the finding came out of a routine cyber vulnerability assessment. The Ministry of Defence cut internet connectivity to the cameras and said its investigation found no evidence of MoD data or systems being accessed, compromised or transmitted externally. Kraken said the third-party cameras were labelled NDAA-compliant and contained “a small number of components originating from outside the UK”.
Why it matters: an NDAA-compliance label answers one question — whether a component came from a manufacturer named in Section 889 of the 2019 US National Defense Authorization Act. It says nothing about what the firmware does once the box is installed. A camera can clear that list on paper and still beacon out every few seconds. The control that caught this was not a certificate; it was somebody actually testing the equipment they had already bought.
INSURANCE · HIGH
The first marine policy that pays for a course, not a box
Sompo Japan launched cover aimed at economic loss from radio interference with ship navigation systems — paying out when a vessel cannot operate despite suffering no physical damage at all: prevented from entering port, detained, or forced to delay departure after GNSS disruption. It extends the insurer’s existing marine cyber product, which covers hull damage and liability, into pure lost earnings with no collision or grounding involved. The condition of cover is the part worth reading twice: participating seafarers must complete a ClassNK Academy maritime cybersecurity course. No equipment purchase is required.
Why it matters: this is an insurer pricing competence instead of hardware, and it lands in the same fortnight a flag state started subsidising the same skills and a national cyber authority told industry that detecting an incident after it happens is not a control. Three institutions, arriving from three directions, on one conclusion. The open question a buyer should put to the underwriter before signing: whether interference attributed to a state actor — which is most of the interference in the Baltic, Black Sea and Gulf — falls inside the cover or outside it as a war exclusion. No source we found answers that.