Dragonfly and the UCL School of Management secured £704,863 from Innovate UK for an 18-month project to improve how organisations assess software security across entire technology stacks. The initiative will build a secure stack advisory layer designed to evaluate interconnected software components, trace data flows across tool boundaries, identify weak links and shadow IT exposure, and map findings to the UK Software Security Code of Practice and other relevant standards.
The project is intended to address rising cyber risk tied to growing software complexity and the rapid expansion of AI-enabled application use, which have made manual compliance and compositional risk reviews increasingly difficult for businesses. Dragonfly is contributing a knowledge graph covering 300,000 vendors, while UCL researchers will provide expertise in optimisation, machine learning, and decision-making under uncertainty, aligning with broader UK concern over the economic impact of cyber attacks on organisations.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
The 18-month Dragonfly-UCL project is set to begin in August 2026, building a secure stack advisory layer and compositional risk engine using Dragonfly's vendor knowledge graph and UCL research expertise.
Dragonfly launched as a company, prior to the later Innovate UK-funded collaboration with UCL on software stack security assessment.
The UK government released the Software Security Code of Practice, which later became a framework the Dragonfly-UCL project aims to support and cross-map against other standards.
Dragonfly and the UCL School of Management secured £704,863 from Innovate UK under the Secure Software for Resilient Growth competition to improve software security assessment. The project is intended to help organisations assess whole software stacks, detect weak links and shadow IT exposure, and map findings to the UK Software Security Code of Practice and other standards.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.