Defence
Cyber Security

Vulnerability volume down 20%.
91 critical flaws eliminated.

A human-machine teaming model that lets AI rank, cluster and flag vulnerabilities across Ministry of Defence systems — while every prioritisation, exception and sign-off stays with an accountable human.

20% Reduction in total
vulnerability volume
91 Critical vulnerabilities
removed
100% Historical vulnerabilities
cleared across 13 systems
3 months Of remediation work exceeding
the previous two years combined

Client

Defence Digital, the digital function of the UK Ministry of Defence, running vulnerability triage across complex, distributed defence systems in a high-risk national security environment.

Goal

Design and implement a human-machine teaming model for vulnerability triage that accelerated remediation across the client’s systems — while preserving full human accountability, decision traceability and operational control.

AI could generate answers faster than anyone could own them.

Defence Digital was contending with a fast-growing volume of vulnerabilities across complex Ministry systems, running on an unsustainable ‘patch everything’ posture that made prioritisation slow, inconsistent and operationally risky.

The deeper issue was governance, not throughput. Triage relied on fragmented manual judgement with no escalation architecture for low-confidence AI outputs or high-impact decisions, and no audit trail for prioritisation, exceptions, approvals or oversight. Introducing AI-assisted triage risked outrunning the organisation’s ability to define who was accountable for what.

Three constraints were non-negotiable:

  • Low-confidence AI outputs and high-impact decisions needed a formal escalation path, not ad hoc judgement
  • Prioritisation, exceptions, approvals and oversight all needed a complete, audit-ready decision trail
  • AI had to stay recommendation-only — humans needed to remain the accountable decision-makers for every consequential call

AI recommends. Humans decide. Every step is logged.

Defence Digital designed the Vulnerability Management Support Team (VMST) and a human-machine teaming model: AI ranks, clusters, summarises and flags anomalies across vulnerability data, while humans retain authority for prioritisation, trade-offs, exceptions and sign-off. The whole system runs under a ‘Reliable, Resilient, Responsible’ AI governance framework, built to keep pace under pressure without giving up control or assurance.

AI can spot the pattern in seconds. In defence, someone still has to be able to say why the decision was made — and that stays human.

A new risk-scoring methodology, V-Score, replaced static scoring with a structured, evidence-based approach that adapts to organisational context — benchmarked to outperform the CVSS industry standard, and peer-reviewed and published in the Journal of Cyber Security (July 2025) as ‘An Open and Adaptable Approach to Vulnerability Risk Scoring’. The triage and exception workflow was redesigned to capture a complete decision trail — rationale, inputs, approvals and timing — creating an audit-ready assurance record.

Confidence cues, escalation triggers and mandatory human-in-the-loop checkpoints ensure low-confidence or high-risk cases always reach a human before action is taken. The division of labour is formal and fixed: AI is recommendation-only by design, and humans remain the accountable decision-makers for every consequential action.

Two years of backlog, cleared in three months.

20% ↓ Reduction in total vulnerability volume, with more remediations completed in three months than in the previous two years combined.
91 Critical vulnerabilities removed from designated MOD systems, with full human accountability preserved for every decision.
100% Of historical vulnerabilities cleared across 13 MOD systems, without losing operational control or decision traceability.
Peer-reviewed The V-Score methodology was benchmarked against CVSS and published in the Journal of Cyber Security (July 2025), giving the approach both scientific and operational validation.

Consistency across teams and shifts improved as a governed, repeatable triage model replaced fragmented manual judgement — proof that AI can accelerate cyber remediation in a national security environment without compromising the human accountability the mission demands.

* Case studies reflect work undertaken by our Heads of AI either during their tenure with Head of AI or in prior roles before they were part of the Head of AI network; they are provided for illustrative purposes only and are based on conversations with our Heads of AI.

More case studies.

Your biggest pain point.
Fixed in 14 days. 50% off.

This started with one conversation. Book a 30 minute brainstorm call — we’ll plan your first AI project together and issue your 50% discount code. No payment today.

Book your 30 min brainstorm call → (free — we’ll plan your first AI project together)

*Case studies reflect work undertaken by our Heads of AI either during their tenure with Head of AI or in prior roles before they were part of the Head of AI network; they are provided for illustrative purposes only and are based on conversations with our Heads of AI.