Back to news

July 23, 2024 | International, Land

NATO’s newfound knack for hefty bulk buys has arms maker RTX perked up

Company executive Tom Laliberty believes the alliance's joint purchasing model could also work in areas other than air-defense interceptors.

https://www.defensenews.com/global/europe/2024/07/23/natos-newfound-knack-for-hefty-bulk-buys-has-arms-maker-rtx-perked-up/

On the same subject

  • Austal USA awarded contract valued up to US$3.195 Billion for up to seven T-AGOS surveillance ships for the United States Navy

    May 24, 2023 | International, Naval

    Austal USA awarded contract valued up to US$3.195 Billion for up to seven T-AGOS surveillance ships for the United States Navy

    The contract includes options for detail design and construction of up to seven T-AGOS 25 class ships which, if exercised, would bring the cumulative value of the contract to US$3,195,396,097

  • What the Pentagon should (and should not) get in the next stimulus bill

    April 28, 2020 | International, Aerospace, Naval, Land, C4ISR, Security

    What the Pentagon should (and should not) get in the next stimulus bill

    By: Mackenzie Eaglen As Washington begins to draft another stimulus spending bill to combat coronavirus, the Pentagon needs a new plan to articulate its needs to lawmakers. Simply submitting unfunded lists whole cloth comes across as tone deaf and opportunistic. A better plan would be to focus on the health, safety and continuity of all the Pentagon's workforce: uniformed, civilian and contractor. Capitol Hill is (virtually) busy as ever these days, completing another injection of funds into the Coronavirus Aid, Relief and Economic Security Act last week. Congress and the White House will now begin formulating a phase 4 bill. President Donald Trump and House Speaker Nancy Pelosi have indicated they would both like to see domestic infrastructure spending inside. Negotiations are just beginning, but this bill will open the spending aperture compared to the CARES Act. For national defense, this legislation must focus on taking care of people and protecting jobs. Even as the U.S. military mobilizes to support the fight against COVID-19, the disease is hitting the Defense Department and its workforce much the same as the rest of America. The first order of business is for the Pentagon to ensure health and wellness for service members, their families, civilians and contractors by encouraging safe and flexible work policies. The Pentagon will need additional funding to pay for COVID-19 support deployments, mitigate the effects of stop-movement orders, increase the availability of personal protective equipment and sanitation, and expand its IT infrastructure for telework. Second, Congress and the Pentagon should provide financial assistance to the thousands of small businesses, subcontractors and suppliers to defense contractors building weapons, conducting maintenance or developing classified software. The defense-industrial base is built for maximum efficiency, not resiliency. Even seemingly minor production pauses of weeks are combining with broader quarantine restrictions to wreak havoc on program schedules. While the Pentagon has many tools at its disposal — accelerating awards and progress payments as well as lifting contracting restrictions — the acquisition team simply cannot respond to this crisis without more resources available. Absent additional liquidity, contractors face the impossible choice between letting workers go or facing the reality that they will have no jobs to return to. Small businesses and subcontractors are particularly vulnerable, as they have far less slack to respond to crises. Many live contract to contract, as indicated by a 2018 Department of Defense report on industrial base fragility. These small firms providing needed materials, labor and technology to companies designated as “essential” are struggling with COVID like everyone else. Their employees are either afraid to come to work out of fear of contraction and contagion, or they're sick with the virus. The vicious cycle — where people want to work but can't — means schedules slip. If there is no work, there is no revenue, which means layoffs. Already around the country, a major defense contractor had to shut down two plants; a shipbuilder is struggling to get employees to show up; another defense firm has laid off employees; and still others can't get to work because classified spaces are off limits. To ensure workforces remain intact, lawmakers need to move quickly to pay contractors who cannot work because of COVID-19 effects, as delays are now averaging three months. Fixing this is as simple as measuring the impact of COVID-19 on contracts and ensuring a reasonable payment for that delay, which will be billions of dollars, according to acquisition czar Ellen Lord. It's no different than legal remedies for “acts of God.” Also, the DoD can consider a subset of its unfunded priorities list to get projects on contract that are executable very quickly and inject liquidity into the defense contractor workforce. These unfunded priorities run the gamut, from weapons production to software development. Similarly, there are always “incremental” projects that can be accelerated, like facilities sustainment and depot maintenance. Using unfunded priorities to inject liquidity into the defense-industrial base isn't the ideal tool, but all options must be brought to bear to deal with this crisis. The majority of defense dollars allocated to the big prime contractors go back out the door to their suppliers and vendors — many of which are small businesses. While many of the easiest financial levers to pull involve getting contracts to primes, Congress and the Pentagon need to emphasize that this money — whether it be new contracts, accelerated contracts or increased progress payments — must be passed on to major suppliers and subcontractors. If the behemoths of defense industry don't share the wealth and take care of their supply chain, there won't be more money, contracts or authority for additional progress payments from Congress. Contractor leadership must take care of workers — including those of its vendors. Lastly, Congress can provide Defense Production Act Title III funding to directly target injections of cash to the emergent needs of small businesses and subcontractors, including many up-and-coming innovative firms and single-source suppliers. So far, DPA funding has been focused on contracting for additional personal protective equipment, but the DPA was equally built to protect the defense-industrial base. The industrial base was already hurt by the Budget Control Act, and it's been busy rebuilding under Trump, only to get whacked again by COVID-19. Employees need to know the work is there, their safety is a priority and their jobs are safe. If the Pentagon and primes don't take care of their suppliers and subcontractors, the defense-industrial base will contract again, losing crucial skills and talents permanently — and possibly seeing those companies bought up by China. https://www.defensenews.com/opinion/commentary/2020/04/27/what-the-pentagon-should-and-should-not-get-in-the-next-stimulus-bill/

  • THE DOD’S APP STORE DOES THIS ONE CRUCIAL THING TO STAY SECURE

    July 5, 2018 | International, C4ISR

    THE DOD’S APP STORE DOES THIS ONE CRUCIAL THING TO STAY SECURE

    Lily Hay Newman EVERY DAY, COMPANIES like Google and Apple wage a constant battle to keep malicious apps out of their marketplaces and off people's phones. And while they do catch a lot of malware before it does any damage, there are always a few nasty infiltrators that manage to sneak by and end up getting downloaded by thousands of consumers. No one wants these mistakes to happen, but when you're a crucial app store for the Department of Defense, these mistakes can't happen. That was the problem facing the National Geospatial-Intelligence Agency as it set about creating a flexible yet ultrasecure app store in 2012. NGA is a combat support organization that primarily assesses and distributes geospatial intelligence. The agency wanted to provide sensitive and mission-critical apps to groups across the DOD through a platform that had the security and resilience of a government defense product, while also offering a streamlined, up-to-date user experience similar to ubiquitous commercial app stores. "We recognized that we did not know everything when it came to apps, and we wanted to be using the innovation that was happening in the commercial sector," says Joedy Saffel, division chief and source director of NGA who has worked on the GEOINT App Store from the beginning. "But how do we do that in a safe, secure manner? How do we do that from a contractual perspective? And how do we do that in a way that nontraditional vendors will trust doing business with the government? It was a great challenge." The key, Saffel says, is getting developers to agree to hand over the source code of their apps for in-depth analysis and review. Whether an app is a simple time/speed/distance calculator for a pilot or a hyper-specialized classified tool, sharing source code is a big risk for developers, because it means trusting third parties with the core intellectual property they have built their businesses on. But NGA soon realized that full access was the only way its project could work. So NGA's GEOINT App Store runs its security protections and screening processes in a way a commercial platform never could. Need To Know You can browse through the GEOINT App Store yourself today and see many of the mapping, aeronautical, weather-forecasting, location-sharing, and travel-alert services that it hosts for Android, iOS, desktop, and web. But that's just the public unclassified section—one crucial aspect of designing the platform was building segmentation controls so DOD employees with different levels of clearance, or simply different needs, could have gated access to different apps. "We built the App Store to be a completely unclassified environment that's open to the public," says Ben Foster, a technical director at NGA who is the product manager for the app store. "But it also has identity management that uses a federated approach to authentication. It's even flexible enough to integrate with other identity-management platforms across DOD. If a user is a helicopter pilot, they might see and get different apps then someone who is a tactical operator in the Army." This system also works with the platform's pricing variations: Some apps are free to everyone, some downloads come with a fee that needs to be taken out of a particular department's budget, and some apps are licensed by NGA or another agency. The most radical part of the GEOINT App Store from a government perspective is the speed with which NGA can process apps and get them live in the store. In general, government acquisition processes take many months or years, a clear problem when it comes to constantly evolving software. So NGA worked with its chief information officer, IT Directorate, legal team, international affairs division, and contracting office to establish a streamlined app-vetting process that would be acceptable under federal acquisition regulations. The agency also contracted with a private firm called Engility to directly manage the outreach, acquisition, and development environment for customizing prospective apps to NGA's requirements. The process, known as the Innovative GEOINT Application Provider Program, or IGAPP, minimizes bureaucratic hurdles and guides developers who want to submit an app through a pipeline that vets, modifies, and generally grooms apps for NGA's store. "What we focused on early on was providing tools so developers can bring their app and do a lot of the pre-testing and development with Engility," NGA's Saffel says. "We're able to be flexible with that because it's being done outside of the government footprint in a brokered environment. And then NGA has a governance board that meets every week, and the whole process has matured enough that by the time an app comes to NGA, we can review it and get that application into the app store and exposed within two weeks' time." Though the process might be even faster if NGA only did the minimum vetting required, Saffel says that the GEOINT team worked to find a balance where the apps go live quickly, but there's still time for the automated code analyses and human audits that commercial app stores can't do. Check It Out After a developer submits their app, Engility does extensive source code analysis and vulnerability scanning and produces an initial findings report. John Holcomb, the IGAPP program manager from Engility, notes that an initial vulnerability report can have as many as 1,000 items on it that a developer needs to address. "It's a little intimidating at first," Holcomb says. "But we walk them through it, and they go back and modify their code—it's their code, we don't modify it for them. We might go through four runs of that on a brand-new app, but by the time we're done, they will have remediated their code down to the level that the government needs. There are still going to be bureaucratic hurdles, but it's our job to break through those." In addition to digging deep into source code, IGAPP also tests how apps function in practice, to make sure that there aren't benign-looking aspects of the code that actually underlie a shady function. "We take the compiled application and we watch what it does," Holcomb says. "Who does it phone home to? Is it sending private information unencrypted?" After an app gets approved for inclusion in the GEOINT App Store, developers continue to work with IGAPP on developing and vetting software updates so that patches and improvements can be pushed out quickly. The brokered vetting process means that the government never holds developers' source code directly. The inspection is always mediated by Engility, which signs nondisclosure agreements with developers and isn't a software maker itself. Holcomb says that the company carefully guards app data while storing it, and once a project is done, Engility doesn't just do a soft data deletion; it hard-purges the information from its cloud servers within 30 days. NGA's Saffel and Holcomb both note that developers were apprehensive about the unusual workflow at first, but over the years the app store has gained credibility. Developers say they benefit from the IGAPP process both by securing lucrative government contracts and by integrating the improvements from the IGAPP development into their commercial products. The code audits and security vetting IGAPP offers are expensive, so developers generally don't do such extensive assessment on their own. "Everyone's dream is to sell to the government, but it normally takes years of effort to get to a position where you can. In our case, I was able to sell to the government in less than a month," says Bill DeWeese, CEO of the firm Aviation Mobile Apps, which has had six apps accepted into the GEOINT App Store. "You do feel a little anxiety about sharing source code, you worry about your IP leaking and someone getting ahold of it. But I haven't had any issues, and the benefit is the increased quality of your products at no cost—you get the analysis for free and you can put it in your commercial offerings." NGA's Saffel says the governance board that evaluates the apps at the end of the process is careful to stay vigilant so nothing goes into the store by accident. The board will still push back on apps or turn them away when warranted, but Saffel says the process has matured such that most of what the board sees these days is ready or very near ready to go live. And IGAPP prioritizes its patching process and infrastructure, to make it easy for developers to push bug fixes and improvements throughout the life of an app. All of this means a consumer-grade turnaround time for critical Department of Defense tools without the consumer-grade security concerns. "NGA is kind of a unique combat-support agency," Saffel says. "With the GEOINT App Store we chose to go into a very risky new frontier for DOD and the government in general, but I think we've demonstrated that we can do things differently and still be secure and still control access. We're supporting a lot of different mission sets, and I expect that the app store will keep growing." https://www.wired.com/story/dod-app-store-does-this-one-crucial-thing-to-stay-secure/

All news