Skip to content
Cyber Defense Technologies

Threat Intelligence

Nation-State Targeting of the Defense Industrial Base

Defense contractors hold technology and access that foreign intelligence services want. Why the defense industrial base is targeted, the techniques public advisories describe, and the defenses that matter most.

By Cyber Defense Technologies March 10, 2026 4 min read

The companies that design, build and support U.S. military capabilities hold information that foreign governments want: weapons designs, program schedules, performance data and the technologies that give U.S. forces their edge. They also hold something equally valuable: trusted connections to prime contractors, suppliers and government networks.

For years, U.S. government agencies have warned that nation-state actors target the defense industrial base (DIB) persistently. The CMMC program exists largely because of that threat.

What adversaries seek from the defense industrial base

  1. Weapons and technology data

    Designs, specifications, test results and source code.

  2. Program information

    Schedules, capabilities, vulnerabilities and requirements.

  3. Access to partners

    Trusted connections into primes, suppliers and government networks.

  4. People and credentials

    Accounts, contacts and information useful for further targeting.

  5. Operational disruption

    The ability to delay or degrade production and delivery.

Why the DIB is targeted

Technology and military advantage

Stealing designs, research and test data can save an adversary years of development and billions in cost, and can reveal weaknesses to exploit.

Program information

Schedules, requirements, capabilities and known vulnerabilities help adversaries anticipate and counter U.S. systems.

Access to partners

A breached supplier can be a stepping stone. Trusted connections, shared credentials and exchanged files can give attackers a path into larger contractors or government networks.

Disruption

In a crisis, the ability to disrupt production or delivery could affect military readiness.

Smaller suppliers are not too small

It is tempting for small and midsize contractors to assume they are not interesting enough to target. Public advisories and investigations suggest otherwise. Smaller companies may hold the same controlled unclassified information as larger ones, often with fewer security resources, and their connections to primes make them valuable stepping stones.

Techniques described in public advisories

Joint advisories from CISA, NSA, FBI and international partners over several years have described state-sponsored activity against defense contractors and related sectors. Common themes include:

  • Credential theft through phishing, password spraying and theft of authentication tokens
  • Exploitation of internet-facing devices such as VPNs, firewalls and email servers, often shortly after vulnerabilities are disclosed
  • Living-off-the-land techniques that use built-in administrative tools to avoid detection
  • Long-term persistence, with access maintained quietly for months or years
  • Targeting of cloud and email accounts to collect sensitive communications and documents
  • Supply chain compromise, including through software updates and service providers

Defenses that matter most

Many of the NIST SP 800-171 requirements that CMMC assesses map directly to these techniques. The highest-value measures include:

  • Phishing-resistant multifactor authentication, especially for remote access, email and administrative accounts
  • Rapid patching of internet-facing systems, prioritizing known exploited vulnerabilities
  • Monitoring and logging that can detect unusual logons, administrative activity and data movement
  • Least privilege and segmentation, so a single compromised account cannot reach everything
  • Encryption of CUI at rest and in transit with FIPS-validated cryptography
  • Incident response capability and rapid reporting under DFARS 252.204-7012
  • Supplier and service provider oversight, including what access they have and how it is protected

Don't forget the people

Nation-state actors also target people directly: through social media, fake recruiters, conference contacts and approaches to employees with access. Security awareness for defense contractors should cover these approaches, and employees should know how to report suspicious contacts. Cleared contractors have specific reporting requirements under the National Industrial Security Program.

Frequently asked questions

Does compliance mean we are protected? Compliance with NIST SP 800-171 addresses many of the techniques these actors use, but compliance on paper is not the same as effective implementation. Controls need to be implemented well, monitored and tested.

How would we know if a nation-state actor was in our network? These actors work hard not to be noticed. Proactive threat hunting, informed by published advisories, and strong logging are the best ways to find them.

Should we report suspicious activity even if we are not sure? DFARS 252.204-7012 requires reporting of cyber incidents affecting covered defense information within 72 hours. When in doubt, consult counsel quickly. The Department also operates voluntary information-sharing programs for DIB companies.

What to do this week

  • Confirm multifactor authentication covers email, remote access and every administrative interface.
  • Check internet-facing devices against CISA's Known Exploited Vulnerabilities catalog.
  • Verify you can produce authentication and administrative logs for the past several months.
  • Make sure your incident response plan includes DFARS 72-hour reporting and a current medium assurance certificate.
  • Review which suppliers and service providers can reach systems holding CUI.

How CDT can help

CDT helps defense contractors protect CUI and prepare for CMMC through CMMC and NIST SP 800-171 readiness, tests defenses with penetration testing and red team exercises, and finds hidden intrusions through cyber hunt.

Sources

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.