
Mercury’s hands-on cyber testing strengthens military defense
Mission success begins at the cyber level
There are Department of War (DoW) programs responsible for providing life cycle support to the aircraft, weapons and systems that the Armed Services rely on. This support includes but is not limited to research, design, development, systems engineering, acquisition, testing and evaluation, training facilities and equipment, and maintenance. The data and systems associated with this work are high-value targets, and any potential cyber vulnerabilities put infrastructure, mission success, or lives at risk. With advances in artificial intelligence (AI) and quantum computing adding to an already complex threat landscape, a certain DoW program needed to ensure its systems were cyber hardened and resilient.
Cyber hardening, including first-of-its-kind penetrating testing for Advanced Data Transfer Systems (ADTS)
Mercury Systems facilitated a number of initiatives to increase the cyber hardening of the program’s systems and data. This included successful, first-of-its-kind penetrating testing at the National Cyber Range Complex, conducting simulated real-world attacks on the Advanced Data Transfer System (ADTS), a device within aircraft that allows secure and modular transfer of aircraft data. Mercury also conducted cyber hardening testing of program systems with Security Technical Implementation Guide (STIG) analysis, Security Requirements Guide (SRG) analysis, and Dynamic Application Security Testing (DAST), along with penetrating testing. Mercury’s subject matter experts also built trusted and collaborative relationships with program cybersecurity personnel, working alongside them via cybersecurity tabletop meetings to prepare them for conducting their own exercises in alignment with requirements for cyber hardened systems.
Compliant systems and increased security in a world of evolving threats
Through successful hardening and penetrating testing, the program met Risk Management Framework (RMF) compliance across multiple platforms for accreditation, accelerating Authorization to Operate (ATO) timelines and reducing risk for mission deployment. The increased defense helped to ensure that mission systems were capable of operating securely, even in contested and disconnected environments. Systems also underwent cryptographic modernization against post-quantum threats, positioning them for compliance with evolving Department of Defense (DoD) and National Security Agency (NSA) cryptographic requirements, including FPS 140-3, AES-256, and SHA-2/3. Through these initiatives, the program was also able to evolve its supply chain risk management to reduce the supply chain attack surface without affecting development timelines. The end result: Mercury supported the mission to provide secure, compliant, and resilient systems to those who put themselves in harm’s way.
Did you know?
Mercury Systems offers much more than cyber testing services. A holistic cyber protection program goes above and beyond existing frameworks to protect against threats that continue to evolve and grow. We can provide evaluated and fielded commercial security products that can be integrated with your systems and accelerate your program timelines.
Contact us for more information.




















