skip to main content
Concurrent logo

Our commitment to security

Security is fundamental to the way we operate and to the trust our customers place in us.

We support customers operating in defence and other mission-critical environments, where protecting information, systems and operations is essential.

Across our UK and US businesses, we take a consistent, risk-based approach to cyber and information security. Our framework combines strong governance, recognised security standards, layered technical controls and continuous improvement to help protect our people, our operations and the information entrusted to us.

A Group-wide approach to security

Our security framework applies across our employees, contractors, third parties, IT systems, infrastructure, services and data.

It is built around four core areas:

  • governance and security policy

  • data protection and information handling

  • identity, access and user lifecycle management

  • operational security controls

Together, these help us manage cyber risk, protect sensitive information, maintain secure IT operations and meet the regulatory, contractual and defence-sector requirements relevant to our work.

Protecting sensitive and controlled information

We have strengthened the way information is classified, accessed and protected across the business.

Our controls include least-privilege access, Data Loss Prevention (DLP), information classification and sensitivity labelling, alongside measures designed to protect Controlled Unclassified Information (CUI), ITAR-controlled information and other sensitive business data.

We also embed security reviews into technology procurement and supplier management, helping us extend our security approach beyond our own systems and into the technologies and services we rely on.

Cyber resilience and active security monitoring

Cyber resilience is about more than preventing an attack. It also means being prepared to detect, respond to and recover from one.

We have developed cyber incident response and crisis management processes, supported by executive response playbooks and decision frameworks. Our security operations include third-party Security Operations Centre support, enhanced monitoring and threat detection, vulnerability and patch management, advanced logging and security monitoring, as well as modern firewall, MDR and NDR capabilities.

We have also strengthened disaster recovery, backup governance, recovery testing and business continuity planning for critical services.

Supporting cyber resilience and software vulnerability management

As cyber security requirements continue to evolve, we are strengthening the way we identify and manage software-related risk across our products and development processes.

As part of our cyber security and software vulnerability management programme, we use Black Duck, an industry-leading software composition analysis platform, to help identify, prioritise and manage software component risks in support of our obligations under the EU Cyber Resilience Act (CRA).

This gives us greater visibility of software components and potential vulnerabilities, helping us take a structured and proactive approach to cyber resilience throughout the product lifecycle.

UK security assurance

In the UK, our security approach is supported by recognised external accreditation.

Cyber Essentials Plus

Concurrent has achieved Cyber Essentials Plus certification.

Cyber Essentials Plus is the independently verified level of the UK Government-backed Cyber Essentials scheme. It provides assurance that key technical controls are in place to protect against common cyber threats.

For our customers, this provides independent evidence that our cyber security controls have been assessed and tested.

Defence Cyber Certification

We also hold Defence Cyber Certification (DCC) Level 0, supporting our ability to operate securely within the UK defence supply chain.

This provides further evidence of our commitment to meeting the cyber security expectations associated with defence programmes and safeguarding the information entrusted to us.

US security and defence requirements

Our US operations are aligned to the cyber security requirements associated with working in the US defence environment.

We are progressing our security programme against NIST SP 800-171 and Cybersecurity Maturity Model Certification (CMMC) Level 2 requirements, supporting the protection of Controlled Unclassified Information and other sensitive defence data.

Our US environment also uses Microsoft 365 Government Community Cloud (GCC) as part of our approach to strengthening governance and protection of sensitive information.

These measures form part of a broader Group security framework designed to support the contractual and regulatory expectations of customers operating across US defence programmes.

Security accreditations and assurance

View our current security certifications below.

Cyber Essentials Plus Certificate

Defence Cyber Certification (DCC)

Our commitment to security | Concurrent