By Cyber Defense Technologies March 10, 2026 4 min read
The companies that design, build and support U.S. military capabilities hold information that foreign governments want: weapons designs, program schedules, performance data and the technologies that give U.S. forces their edge. They also hold something equally valuable: trusted connections to prime contractors, suppliers and government networks.
For years, U.S. government agencies have warned that nation-state actors target the defense industrial base (DIB) persistently. The CMMC program exists largely because of that threat.
What adversaries seek from the defense industrial base
-
Weapons and technology data
Designs, specifications, test results and source code.
-
Program information
Schedules, capabilities, vulnerabilities and requirements.
-
Access to partners
Trusted connections into primes, suppliers and government networks.
-
People and credentials
Accounts, contacts and information useful for further targeting.
-
Operational disruption
The ability to delay or degrade production and delivery.
Why the DIB is targeted
Technology and military advantage
Stealing designs, research and test data can save an adversary years of development and billions in cost, and can reveal weaknesses to exploit.
Program information
Schedules, requirements, capabilities and known vulnerabilities help adversaries anticipate and counter U.S. systems.
Access to partners
A breached supplier can be a stepping stone. Trusted connections, shared credentials and exchanged files can give attackers a path into larger contractors or government networks.
Disruption
In a crisis, the ability to disrupt production or delivery could affect military readiness.
Smaller suppliers are not too small
It is tempting for small and midsize contractors to assume they are not interesting enough to target. Public advisories and investigations suggest otherwise. Smaller companies may hold the same controlled unclassified information as larger ones, often with fewer security resources, and their connections to primes make them valuable stepping stones.
Techniques described in public advisories
Joint advisories from CISA, NSA, FBI and international partners over several years have described state-sponsored activity against defense contractors and related sectors. Common themes include:
- Credential theft through phishing, password spraying and theft of authentication tokens
- Exploitation of internet-facing devices such as VPNs, firewalls and email servers, often shortly after vulnerabilities are disclosed
- Living-off-the-land techniques that use built-in administrative tools to avoid detection
- Long-term persistence, with access maintained quietly for months or years
- Targeting of cloud and email accounts to collect sensitive communications and documents
- Supply chain compromise, including through software updates and service providers
Defenses that matter most
Many of the NIST SP 800-171 requirements that CMMC assesses map directly to these techniques. The highest-value measures include:
- Phishing-resistant multifactor authentication, especially for remote access, email and administrative accounts
- Rapid patching of internet-facing systems, prioritizing known exploited vulnerabilities
- Monitoring and logging that can detect unusual logons, administrative activity and data movement
- Least privilege and segmentation, so a single compromised account cannot reach everything
- Encryption of CUI at rest and in transit with FIPS-validated cryptography
- Incident response capability and rapid reporting under DFARS 252.204-7012
- Supplier and service provider oversight, including what access they have and how it is protected
Don't forget the people
Nation-state actors also target people directly: through social media, fake recruiters, conference contacts and approaches to employees with access. Security awareness for defense contractors should cover these approaches, and employees should know how to report suspicious contacts. Cleared contractors have specific reporting requirements under the National Industrial Security Program.
Frequently asked questions
Does compliance mean we are protected? Compliance with NIST SP 800-171 addresses many of the techniques these actors use, but compliance on paper is not the same as effective implementation. Controls need to be implemented well, monitored and tested.
How would we know if a nation-state actor was in our network? These actors work hard not to be noticed. Proactive threat hunting, informed by published advisories, and strong logging are the best ways to find them.
Should we report suspicious activity even if we are not sure? DFARS 252.204-7012 requires reporting of cyber incidents affecting covered defense information within 72 hours. When in doubt, consult counsel quickly. The Department also operates voluntary information-sharing programs for DIB companies.
What to do this week
- Confirm multifactor authentication covers email, remote access and every administrative interface.
- Check internet-facing devices against CISA's Known Exploited Vulnerabilities catalog.
- Verify you can produce authentication and administrative logs for the past several months.
- Make sure your incident response plan includes DFARS 72-hour reporting and a current medium assurance certificate.
- Review which suppliers and service providers can reach systems holding CUI.
How CDT can help
CDT helps defense contractors protect CUI and prepare for CMMC through CMMC and NIST SP 800-171 readiness, tests defenses with penetration testing and red team exercises, and finds hidden intrusions through cyber hunt.