Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
30APR

Airbus signs for Ultra Cyber from Cobham

4 min read
08:16UTC

Airbus signed a definitive agreement to acquire Ultra Cyber from Cobham, bringing UK MoD sovereign cryptography programme work inside a European defence prime.

TechnologyDeveloping
Key takeaway

MoD cryptography moves under Airbus; the PRA and MoD clearance review will set sovereignty precedent.

Airbus signed a definitive agreement during the window to acquire Ultra Cyber from Cobham, extending the cross-border cyber-sector consolidation track into UK MoD-cleared programme contracts 1. The deal moves Ultra Cyber's UK Ministry of Defence (MoD) sovereign cryptography and cyber-defence programme work inside a European defence prime headquartered in Toulouse. The Prudential Regulation Authority (PRA) and MoD clearance reviews are the gating events; transaction value was not disclosed in the public announcement.

Ultra Cyber holds List X site clearances, MoD-cleared cryptographic key management work and embedded-hardware programme contracts that have historically required UK consolidated ownership for tender eligibility. Airbus is a continental prime with its own cleared-personnel base in France and Germany; the integration question is how MoD cleared-programme contracts pass through the change of consolidated ownership without a sovereign-of-control condition. The MoD review will be the determining political event.

The transaction lands in the same ten-day window as the Beazley takeover, which moves UK Lloyd's-market commercial cyber expertise to Swiss ownership. Two transactions, two different layers of UK cyber capability, both moving outside UK consolidated control. NCSC's SilentGlass commercial launch the same week is the offset, keeping UK government IP onshore while putting product into the channel. The political question is whether MoD-cleared cryptography ought to require sovereignty-of-control conditions on foreign acquisition, with the Airbus review setting the precedent for any subsequent transaction the National Security and Investment Act screens.

Deep Analysis

In plain English

Ultra Cyber holds UK government security clearances and works on cryptography, the mathematical codes that protect government and military communications. Cobham, its current owner, agreed to sell it to Airbus, the European aerospace group headquartered in Toulouse. The UK government has powers under a 2021 law to block or attach conditions to foreign purchases of sensitive defence companies. Whether ministers use those powers here will set a precedent for future European acquisitions of cleared British technology firms.

Deep Analysis
Root Causes

Ultra Cyber's position results from a structural decision taken when Cobham acquired Ultra Electronics in 2021: private equity ownership of List X cleared facilities concentrated MoD-cleared programme capability in a portfolio company without a long-term ownership commitment. Cobham, backed by Advent International, is a financial acquirer rather than a strategic defence prime.

The decision to divest Ultra Cyber to Airbus is a portfolio exit, not a strategic consolidation. MoD's relationship with its cleared cryptography contractor is therefore being shaped by Cobham's fund return timeline rather than by any national-security planning horizon.

What could happen next?
  • Precedent

    The MoD's clearance review will establish whether European NATO-allied ownership satisfies List X sovereignty-of-control requirements, with direct implications for every future transaction involving UK cleared-facility acquisition by a European defence prime.

    Short term · 0.8
  • Risk

    If the MoD review attaches a sovereignty-of-control condition requiring UK management of List X work, Airbus faces an integration constraint that could reduce the commercial value of the transaction relative to the undisclosed purchase price.

    Medium term · 0.7
  • Consequence

    Ultra Cyber's cleared-personnel pool and List X sites transfer to an Airbus-owned structure, immediately expanding Airbus UK's addressable UK MoD cleared-programme tender market.

    Immediate · 0.85
First Reported In

Update #2 · FIRESTARTER puts Cisco below the patch line

PrivSource· 30 Apr 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.