A prime contractor should bring in a specialist cyber SME when a defined security obligation could affect price, schedule, acceptance or delivery risk, and the programme does not have the capacity or specialist skill to own it properly.
The decision is rarely as simple as asking whether the prime already employs somebody with cyber in their job title. Large programmes need different security skills at different points. Demand rises during bids, mobilisation, design reviews, supplier onboarding, testing and assurance. It can fall again once the service enters normal operation.
Building a permanent team for every peak is expensive. Asking a small internal team to absorb every peak is risky. The useful middle ground is a specialist SME that can take responsibility for a defined piece of work, operate within the prime's governance and leave the prime with evidence it can use.
The prime still answers to the customer. Bringing in a specialist does not transfer the prime's contractual obligations or its responsibility for the wider programme. It should give the prime a clearer way to meet them.
The decision is about delivery risk
Cyber support is sometimes bought as extra capacity without deciding what that capacity will change. More people attend meetings, review documents and add actions. The programme remains unclear about who owns the work and who can make the decisions it depends on.
A better starting point is the delivery obligation. What must be designed, assessed, evidenced, approved or fixed? When is it needed? Which decision depends on it? Who will accept the output?
If the prime can answer those questions, it can decide whether the work belongs with its permanent team, a commodity service or a specialist partner. If it cannot, appointing another adviser may create more reporting without reducing delivery risk.
Where specialist support earns its place
Demand changes faster than the permanent team
Programme demand is uneven. A bid may need security input into the solution, price and delivery plan within a few weeks. Mobilisation may need several workstreams to start at once. Assurance can expose urgent gaps shortly before an approval or service transition.
This is where surge capability makes sense. The prime can add experienced delivery capacity for the period in which the work is required, then reduce it when demand falls. That can be more proportionate than carrying a large permanent team or asking existing staff to choose which important work will wait.
Surge support still needs a defined role. A short engagement with unclear priorities can consume the same internal time it was meant to save. The specialist needs a work package, access to the right people and evidence, and a route to timely decisions.
I have seen how quickly a prime may need that capacity. In one engagement, a prime needed specialist support for a client at short notice. The right people were confirmed by the following day and met the client at the start of the next week. It shows the value of a small specialist firm when a large programme has a sudden gap and the right people can be mobilised quickly.
The programme needs a skill it does not hold
Cyber is not one discipline. A programme may need security architecture, threat modelling, risk management, supplier assurance, penetration testing, governance, accreditation support or incident preparation. An experienced security manager will not necessarily be the right person to perform each of them.
The NCSC advises organisations to identify specific gaps in cyber expertise and consider buying in specialist knowledge or services where required. That is a stronger basis for outside support than buying a broad block of consultancy days and deciding how to use them later.
The specialist should be attached to a decision or deliverable. A security architect should influence the design. A supplier assurance specialist should determine what evidence is needed and judge what arrives. An assurance lead should show what confidence the evidence supports and what remains unresolved.
Clearance narrows the available team
Government and Defence work can limit who may access information, systems or locations. A capable practitioner without the required clearance may not be able to start the work when the programme needs them.
Existing clearance can help, but it should not be treated as portable property held by the individual. UK Security Vetting guidance explains that a new employing sponsor requests a transfer and UKSV decides whether the clearance is eligible. The sponsor must set out the level needed for the role.
The prime should therefore consider cleared capacity during the bid and mobilisation plan. Waiting until delivery is blocked creates fewer choices. A specialist SME with suitable practitioners may shorten the route to a workable team, but the prime still needs to confirm sponsorship, transfer, access and handling arrangements for the contract.
A workstream needs an owner
Some programmes need more than advice. They need somebody to run a defined security workstream and be answerable for its outputs.
That could mean owning the security plan, coordinating threat modelling, managing security requirements, running supplier assurance, maintaining the evidence position or preparing a service for an assurance decision. The scope should state the outputs, milestones, dependencies and limits of authority.
This arrangement can remove pressure from an internal lead without putting another layer between the problem and the people who can solve it. The specialist owns delivery of the agreed work. The prime provides access, resolves competing priorities and makes the decisions that only it can make.
There is a boundary worth agreeing before work starts. Security work often reveals ordinary IT changes that the client or prime must make. Wuluf can provide security engineers, but we are not there to supply general IT delivery by default. The prime should agree how any IT remediation outside the security scope will be funded and delivered, so that identifying a problem does not leave the client waiting for another contract decision.
The bid needs a delivery model that will survive contract award
Cyber support in a bid should do more than improve the wording of the response. It should test whether the security commitments can be delivered within the proposed price, schedule and operating model.
There is also a credibility question. If an IT prime wins work that includes cyber, a separate specialist can give the customer confidence that the prime has recognised the limit of its own expertise. It shows that the prime is willing to have somebody else check the security work rather than mark its own homework. That only carries weight if the specialist has a real place in delivery after the bid is won.
A specialist can help interpret the requirement, identify evidence obligations, shape the work breakdown, estimate the people and time required, and expose assumptions that need to be priced or clarified. In Defence work, this may include requirements that flow from the prime to lower tiers of the supply chain.
Current MOD Cyber Security Model guidance places responsibility for flow down on suppliers. The prime must assess the cyber risk of subcontracted work and pass the relevant requirements through the supply chain. That work affects supplier selection, contracts, assurance and continuing oversight. It should not first appear after contract award.
The specialist named in the bid should also have a credible role in delivery. Using an SME's experience to strengthen a response and then replacing it with an undefined resource model can leave the prime owning promises that nobody has planned to meet.
A cyber issue threatens delivery
A programme may discover that assurance evidence is weak, a supplier cannot meet an obligation or a design decision creates more exposure than expected. A specialist SME can help the prime establish the facts, define the options and take responsibility for a recovery workstream.
Speed matters in that situation, and so does an independent view. I have seen a client request an independent review after cyber reporting had remained green for some time. Its leaders had begun to doubt that the rating matched what was happening. The review gathered evidence across the areas assessed and found significant weaknesses and business exposure. The issue had been suspected for a while. By the time the review happened, a substantial backlog of technical work and IT investment had built up.
The timing can work in the other direction. In another engagement, an organisation sought security input before expanding its business. The necessary changes were identified while the operation was still smaller and easier to alter. The client could put the fundamentals in place before growth made each change harder. In my view, that saved considerable time, money and effort compared with dealing with the same work during or after expansion. New work now starts from those foundations.
What the specialist can own and what the prime retains
The engagement works best when both sides understand the boundary. The examples below provide a starting point. The exact split depends on the contract and the authority each party has been given.
| Reason for support | The specialist SME can own | The prime must retain |
|---|---|---|
| A peak in demand | A defined package of work with milestones, outputs and handover | Priorities, access, funding and decisions |
| A specialist skill gap | The relevant analysis, design, testing or assurance activity | Acceptance of the output and ownership of resulting risk |
| Cleared delivery | Suitable practitioners and continuity within the agreed scope | Sponsorship, access decisions and handling instructions |
| Bid support | Security input to the solution, estimate, assumptions and delivery plan | Accuracy of the tender and all commercial commitments |
| Delivery recovery | Establishing the facts, a recovery plan and delivery of agreed corrective work | Funding, programme tradeoffs and acceptance of residual risk |
The prime cannot outsource accountability
A specialist subcontractor can own work. It cannot make the prime's wider contractual responsibility disappear.
NCSC guidance expects organisations to assess suppliers during selection, put necessary security controls into contracts and check that supplier security provisions remain effective during delivery. Government classification guidance also states that subcontractors handling classified information should follow the same conditions as the prime contractor.
The prime therefore needs enough internal understanding to govern the specialist, judge whether the work meets the contract and act on the evidence produced. Delegation without oversight leaves the prime exposed. Oversight without delegated authority leaves the specialist unable to deliver.
The useful balance is clear workstream ownership inside a governance model that keeps the prime in control of customer commitments, risk decisions and the wider delivery outcome.
When a specialist SME is the wrong answer
A specialist is unlikely to help when the programme has not defined the problem, will not provide access to the necessary people or evidence, or expects the supplier to carry risk without authority to change anything.
It is also a poor arrangement when the SME appears in the bid only to add credibility, when the work is a commodity task that an existing service can perform, or when the prime wants another report rather than ownership of the action that follows.
The test is practical. Can the prime describe the work, the output, the decision it supports and the authority the specialist will have? If not, the first task is to define the need.
Questions to answer before appointing a specialist
A prime contractor should be able to answer these questions before work begins.
- Which contractual or delivery obligation does the specialist support?
- What workstream, output or decision will the specialist own?
- Which specialist skill or capacity gap cannot be covered sensibly by the existing team?
- What clearance, access or handling arrangements are required, and who will provide them?
- Who within the prime will accept the work and act on the evidence?
- Which dependencies, customer decisions and supplier inputs could block delivery?
- What should remain when the engagement ends, including evidence, decisions, knowledge and unfinished actions?
Clear answers make it easier to buy the right support and judge whether it worked. They also protect the internal security team from being handed another supplier to manage without the time or authority to use them well.
Use specialist support where it can own an outcome
Prime contractors do not need an outside specialist for every cyber task. They do need to recognise when the customer would benefit from independent scrutiny, a specialist skill, cleared capacity or a rapid response that the permanent team cannot provide.
The strongest engagement has a clear boundary. The SME owns a defined workstream and produces evidence the programme can use. The prime retains the customer commitment, provides the authority and makes the wider risk and delivery decisions.
Used that way, a specialist cyber SME can move quickly and still give the prime an independent view. Its work must have a clear boundary, including who will fund and deliver any wider IT changes it uncovers.
Used well, a specialist cyber SME is not extra commentary around the programme. It is accountable delivery capacity applied where the prime needs it most.
Need specialist cyber support for a bid, delivery workstream or programme under pressure? Talk to Wuluf about bid support, specialist workstreams and delivery capacity.

