Skip to content

The strategic imperative of openness: securing the defence supply chain

21 May 20266 min read
Guest Insights
The strategic imperative of openness: securing the defence supply chain



Dean Clark

Architect, EMEA Defence Strategy, Red Hat



Nick Maynard

Principal Technologist, UK Defence, Red Hat



Jonny Williams

Chief Digital Adviser, UK Public Sector, Red Hat

The landscape of National Security is undergoing a fundamental shift. For decades, the Defence community relied on the concept of the "walled garden." We built proprietary systems, often disconnected from the wider world, under the assumption that isolation and obscurity were our best defences. But in an era of software-defined warfare and interconnected logistics, those walls have now become glass.

As we take in techUK’s Supply Chain Security Campaign week, it is time to have a candid conversation about the nature of trust across our digital foundations. Leading technical strategy within the Defence sector at Red Hat, we see that  threats to our resilience go beyond the adversary to a lack of understanding of the tools we use to defend against them: where they come from, who created them, and what they can do. To secure the UK’s next generation of land, air, and sea platforms, we must move away from the “black box” and truly embrace the “open source way”.

The myth of proprietary security

For too long, both industry and customers believed that proprietary software was inherently more secure due to its “hidden by default” nature. In reality, this creates a single point of failure. If a vulnerability exists in a closed-system component, you must implicitly trust the vendor to identify, acknowledge, and fix it. In a Defence context, waiting for a patch that may or may not be coming while a platform is deployed should be an unacceptable risk.

Open source completely flips this paradigm on its head. Operating on the principle of Linus’s Law: “given enough eyeballs, all bugs are shallow”. When we build on open source foundations, we are leveraging a global immune system. Thousands of developers, including those from Red Hat and other industry leaders, are constantly auditing the code, finding vulnerabilities, and contributing fixes. For the Ministry of Defence and its tier 1 suppliers, this means the ability to verify security for ourselves, rather than relying on a vendor’s “trust me” assurance.

Operationalising trust through standards

A secure supply chain is not a static product, instead it is a rigorous, verifiable process. This is where open standards become the DNA of our protection.

Consider the Software Bill of Materials, or SBOM. In the physical world, every component of a Type 45 destroyer is tracked: from the turbine to the smallest bolt. We know where it was forged and what it is made of. Until recently, we did not have that same level of granularity for software. A single application might contain hundreds of sub-components and libraries, many of them open source, pulled from various repositories.

By adopting open standards like SBOM and the SLSA (Supply-chain levels for Software Artifacts) framework, we can move from “blind trust” to “verifiable trust”. We can now automatically scan our entire digital inventory to see if a newly discovered vulnerability, (Log4j as an example) exists within our environments. This isn’t just a technical “nice-to-have”, it is a sovereign requirement. It allows the UK to maintain control over its own digital destiny.

Red Hat == Upstream first

At Red Hat, we live by a principle called “Upstream first”. This means that every time we find a bug or create a security enhancement, we contribute it back to the original open-source project before we include this in our enterprise products.

From a Defence perspective, this is a strategic force multiplier. It ensures that the entire ecosystem becomes more resilient. If we harden the Linux Kernel for a specific high-security Defence use case, those improvements benefit the wider community, which in turn continues to build upon and test those very same features. This creates a virtuous cycle of continuous improvement that no proprietary vendor can match.

Additionally, this approach tackles the problem of legacy and obsolescence. Proprietary systems often die when the company that made them loses interest or goes out of business, creating a fixed point of vulnerability that must be mitigated. Open-source projects, supported by a diverse community and open standards, ensure that our long-lived Defence platforms can be maintained and secured for decades, not just until the next contract cycle.

Shadow AI and the risk of the unknown

The techUK campaign rightly highlights the risks of “Shadow AI”. We are seeing an explosion of the Large Language Models used by employees to solve problems quickly. In a Defence environment, the use of unapproved, “black box” AI models is a significant supply chain risk. How do we know what data the model was trained on? How do we know if the model’s output or Inference has been subtly compromised?

The answer, again, lies in openness and transparency. By pushing for Open Source AI. we allow the same level of scrutiny we apply to traditional software. We can audit the training data, the model weights, and the algorithms. This transparency is the only way to safely integrate AI into our land, air, and sea platform without compromising our national security posture.

A shared responsibility

Securing the supply chain is not something the MoD can do alone, nor is it something a single  vendor can solve. It requires a collaborative fabric where government, industry and the open-source community work in tandem.

This brings us to the core of Red Hat’s opinionated stance that Security is a team sport. By using open-source practices, we are not just sharing code, we are sharing risk intelligence and best practices. We are building a “Digital Commons” that is more resilient than individual siloes of self-interest.

As we participate in TechUK’s campaign week, our message to the Defence community is this: do not be afraid of the transparency that open-source brings. It is not a vulnerability, it is our greatest strength. It allows us to build systems that are secure by design, verifiable by anyone, and resilient enough to withstand the evolving threats of the 21st century.

We must demand SBOMs from every provider. We must contribute back to the upstream projects that underpin our critical infrastructure. And we must move toward a future where our digital supply chains are as visible and hardened as the physical hardware they control.

The “Open Source Way” is more than just a development methodology. For the UK’s National Security, it is the only way forward. By embracing openness, we ensure that our platforms remain autonomous, our data remains sovereign, and our defences remain strong.  Use this campaign week to commit to a more transparent, collaborative and ultimately more secure future for the British Defence supply chain.