Leidos takes cyber detection onto the tactical edge

Leidos takes cyber detection onto the tactical edge

Leidos has demonstrated tactical cyber detection during Valiant Shield 2026. The system moves monitoring closer to deployed platforms, where rugged hardware, assured software, bandwidth limits, platform certification, and controlled updates shape operational resilience.


IN Brief:

  • The Cyber and Electromagnetic Activities Resiliency System detected simulated intrusions across tactical platforms and networks.
  • CRS is designed to provide real-time warning where enterprise cybersecurity tools have limited visibility.
  • Fielding will require rugged hardware, assured software, platform-specific integration, manageable alerts, and secure updates.

Leidos has demonstrated its Cyber and Electromagnetic Activities Resiliency System during Valiant Shield 2026, placing real-time cyber detection within a large Indo-Pacific military exercise.

The trial took place in Guam during the joint exercise held from 22 June to 2 July. CRS monitored connected tactical platforms and networks, identifying simulated intrusions and abnormal behaviour while operational systems remained in use.

Military platforms often rely on specialised operating systems, proprietary interfaces, intermittent communications, and equipment that cannot be managed in the same way as office networks or commercial cloud services.

A deployed force may connect vehicles, aircraft, ships, sensors, radios, command posts, weapons, and logistics systems across several security domains. Compromise within one element can affect data integrity, availability, or trust throughout the wider network.

CRS is intended to give operators earlier warning by observing the behaviour of mission equipment close to the point of use. Tactical-edge detection reduces dependence on sending every event to a distant security operations centre before analysis begins.

Such systems must work within severe communications constraints. Deployed networks may offer limited bandwidth, high latency, intermittent connectivity, or periods of deliberate radio silence.

Cybersecurity equipment cannot assume continuous access to central databases or large cloud-processing resources. Detection, storage, and initial analysis must therefore remain useful when the platform is disconnected.

Hardware faces the same physical environment as the host system. Processing units, network interfaces, storage, power supplies, and connectors may encounter vibration, shock, dust, salt, moisture, temperature extremes, and unstable power.

The resulting product combines rugged computing, protocol interfaces, secure software, detection logic, data management, and a controlled update process. Analytics alone cannot be installed across a fleet without the associated hardware and integration engineering.

Data collection needs careful design. Monitoring every packet and event can create more information than a tactical network can store or transmit, while excessive processing may compete with mission systems for electrical power and cooling.

CRS must therefore identify the signals most useful for detecting compromise without overwhelming operators or infrastructure.

False alarms carry particular cost in an operational environment. Crews cannot interrupt a mission whenever software sees unfamiliar behaviour, especially when battle damage, network congestion, equipment failure, or rapid reconfiguration can resemble an attack.

Alerts need enough context to distinguish malicious activity from unusual but legitimate use. That requires knowledge of the platform’s normal behaviour and the flexibility to account for different mission states.

Machine-learning tools may support anomaly detection, although models trained on laboratory or peacetime data can struggle when systems are used under stress or in configurations absent from the original dataset.

Cyber monitoring equipment must also be protected against compromise. A device connected across sensitive networks occupies a privileged position and could become an attractive route into the platforms it is intended to defend.

Secure boot, signed software, controlled administration, hardware provenance, vulnerability management, and tamper protection consequently belong inside the manufacturing and support model.

The risks associated with trusted infrastructure were demonstrated by the Firestarter warning around persistent compromise of security appliances. Defensive equipment can provide an attacker with broad access when its software, credentials, or update chain is undermined.

Platform certification creates another constraint. Installing hardware or software aboard an aircraft, vehicle, ship, or weapon network can affect timing, bandwidth, power, electromagnetic compatibility, and safety.

Updates cannot always be pushed at the speed associated with commercial computers. A change may require testing against representative platform traffic and approval before deployment.

Leidos will need integration kits and controlled baselines for different systems. A naval combat network, armoured vehicle, and expeditionary command post may share detection logic while requiring separate connectors, protocols, physical mounts, and power arrangements.

Modularity can prevent every installation becoming a bespoke engineering project. Common edge-computing hardware paired with controlled interface modules offers one route, provided the configuration remains traceable across fleets.

Manufacturing records will need to capture installed components, firmware, software, cryptographic material, and platform interfaces. When a vulnerability emerges, support teams must be able to identify which units are affected without inspecting every installation manually.

The Valiant Shield exercise provided a more demanding environment than a closed laboratory. Joint and multinational operations create changing users, temporary links, unfamiliar traffic, distributed nodes, and operational pressure.

A demonstration remains only one stage towards fielding. Procurement, security accreditation, training, spares, software maintenance, integration, and operational procedures must follow before the capability can be used routinely.

Human workflow is central. Alerts need to reach people with enough authority and knowledge to respond, while cyber teams, platform crews, commanders, and maintainers require agreed procedures.

Isolating a compromised system may prevent further intrusion but also remove a sensor, communications path, or weapon function. Resilience depends on controlled degradation and recovery rather than automatic disconnection.

Support arrangements must allow software and threat data to change without destabilising certified platforms. Update packages need authentication, testing, distribution, rollback, and records showing which systems accepted them.

Where communications are intermittent, updates may have to move through removable media or deployable support teams, increasing the importance of physical custody and verification.

CRS reflects the broader movement of cybersecurity into physical defence systems. As platforms become more connected and software-defined, cyber engineering is merging with electrical, systems, and support engineering.

The Valiant Shield demonstration showed that detection can operate closer to deployed equipment. Scaling across fleets will depend on whether Leidos can produce a rugged, certifiable, modular, and updateable system without creating another collection of platform-specific cyber appliances.


  • Leidos takes cyber detection onto the tactical edge

    Leidos takes cyber detection onto the tactical edge

    Leidos has demonstrated tactical cyber detection during Valiant Shield 2026. The system moves monitoring closer to deployed platforms, where rugged hardware, assured software, bandwidth limits, platform certification, and controlled updates shape operational resilience.


  • PAC-3 motor deal attacks the interceptor bottleneck

    PAC-3 motor deal attacks the interceptor bottleneck

    L3Harris will nearly triple American PAC-3 MSE propulsion production capacity. A seven-year framework will support new processing bays, automated inspection, supplier investment, and workforce growth across one of the missile sector’s tightest industrial constraints.