Microsoft's most recent patches marked the largest security updates in the company's history — a signal that the threat landscape has fundamentally shifted — most likely because of AI models. For Rolls-Royce suppliers, the message is clear: Updating your systems is no longer optional.
"Microsoft is pushing patches out because they have been running AI on their own systems," said Rolls-Royce's new Chief Information Security Officer Christine Maxwell, drawing on two decades of experience in defence and finance. "Get them in as fast as you can. The less likely you are to be attacked as a result."
Why This Matters Right Now
The urgency isn't theoretical. Cyber attacks successfully targeting suppliers across the economy are making headlines. And even when experts are brought in to help restore operations quickly, such incidents underscore a hard truth: Attacks on the supply chain are a weapon, and they're being deployed at scale.
The UK has watched a wave of high-profile breaches ripple through major retailers. Marks & Spencer. Jaguar Land Rover. Incidents that finally made boardrooms across Britain sit up and take the threat seriously. "This is real," said Maxwell, who previously served as CISO for the UK Ministry of Defence. "This isn't something we can just ignore."
For suppliers working in defence and aerospace — where national security capabilities depend on secure infrastructure — the stakes are even higher. Cyber operations now precede kinetic attacks in conflicts worldwide. That reality demands urgent, practical action from every link in the supply chain.
What You Need to Do
Maxwell emphasized the fundamentals:
- Patch your systems immediately. This is not a future task. Make it a normal business process, not a panic-driven scramble.
- Manage user access tightly. Don't give privileged access to more people than necessary. Ensure staff members have access only to what they genuinely need.
- Strengthen passwords and awareness. Use three random words, not patterns. Train employees to recognize phishing emails and report suspicious activity.
- Plan for recovery. If an attack does penetrate your defences — and Maxwell’s framing is "when, not if" — how will you restore operations? What's your continuity plan? For a 75-person company, this doesn't demand huge investment. It demands thought. Know what you'll do before it happens.
"Good IT environment, nicely up to date, good awareness of users and people," the CISO said. "That's actually the answer in order to defend against attacks that are going to come faster and with more sophistication in the age of AI."
A Call for Collective Action
Rolls-Royce understands the pressure on smaller suppliers. Cybersecurity regulations — UK Cyber Essentials, new defence sector certifications — can feel daunting. But the regulations exist to lift the security baseline of the whole country.
"As the big company, we communicate to help our supply chain be as secure as possible,” Maxwell said.
That commitment means Rolls-Royce is looking to share expertise, offer guidance, and work collaboratively to strengthen the entire ecosystem. Defence primes across the industry are exploring how to do this more systematically — not just reacting to crisis but building resilience.