Client Story

Security by Design, Compliance by Default at Cobham Satcom

JUL 21, 2026

Cobham Satcom partnered with Eficode to build a security-by-design operating model that embeds risk, compliance, and governance into everyday engineering. By integrating Jira, Confluence, SoftComply, Black Duck, and AWS, the company made ISO 27001 certification a natural byproduct of its workflows while enabling secure cloud, DevSecOps, and AI adoption.

In a nutshell

Company

  • Cobham Satcom, a provider serving regulated industries including defence, government, and maritime.

  • Needed to modernize its technology landscape while maintaining strict security and compliance requirements.

Challenges

  • Scale security and compliance alongside cloud, DevOps, and AI without slowing the business.

  • Maintain ISO 27001 certification and align with evolving regulations such as NIS2, RED, and CE.

  • Improve visibility, consistency, and traceability across engineering, risk, compliance, and vendor governance.

  • Connect existing tools and processes into a unified operating model rather than adding more standalone controls.

Solution

  • Partnered with Eficode to design and implement a security-by-design operating model.

  • Integrated Jira, Confluence, SoftComply, Black Duck, and AWS into a connected platform for engineering, security, risk, and compliance.

  • Embedded security controls, risk management, and evidence generation into day-to-day engineering workflows.

  • Re-architected existing platforms instead of replacing them, creating a policy-driven execution model.

Results

  • ISO 27001 certification and other required certifications became a byproduct of normal operations rather than separate audit projects.

  • Successfully passed ISO 27001 audits with minimal incremental effort, with auditors recognizing the integrated approach.

  • Implemented the core operating model in months rather than years.

  • Established centralized, automated risk management across technical, operational, and vendor risk.

  • Improved AWS governance, contributing to more than €80,000 in annual savings.

  • Built a scalable foundation for secure cloud adoption and responsible AI implementation.

Building a future-proof, AI-enabled security operating model in a regulated environment 

Cobham Satcom needed to modernize its technology landscape while maintaining strict compliance in a highly regulated industry. Rather than treating this as a compliance exercise, the company—led by its cybersecurity leadership—set out to build a future-ready operating model where security, engineering, and governance are fully integrated by design. 

The ambition was not simply to strengthen controls, but to ensure that security and compliance could scale with cloud, DevOps, and AI—without slowing the business down—even across demanding sectors such as defence, government, and maritime, and evolving frameworks like ISO 27001, NIS2, and product regulations such as the Radio Equipment Directive (RED). 

A key design requirement was clear: enable Cobham Satcom to obtain and maintain certifications as a natural outcome of how the organization operates—not as a separate, high-friction effort. 

To accelerate execution, Cobham Satcom partnered with Eficode, bringing external expertise in DevSecOps, cloud, and regulated environments—supporting implementation, validating direction, and providing practical input throughout the transformation. 

"Transformation doesn’t require multi-year programs. We redesigned how our existing tools work together, stayed disciplined, and built a system where security, engineering, and regulation evolve at the same pace."

Lemuel Valdez CISO at Cobham Satcom

Certifications as a byproduct 

Cobham Satcom obtains and maintains ISO 27001 and other required certifications as a side effect of its operating model—using evidence already generated through normal workflows, rather than running separate audit-driven projects. 

Months, not years

The core operating model was designed and implemented in months, not years —by restructuring how existing tools and processes worked together, rather than launching an open-ended transformation program. 

Turning compliance into an engineering capability 

As Cobham Satcom evolved, the challenge was not the absence of controls—but to ensure they were consistently visible, usable, and connected across a complex and growing environment. 

  • Security activities existed but needed stronger connection to how engineering operates 

  • Workflows varied across teams, creating unnecessary complexity 

  • Visibility across delivery, risk, and compliance needed to scale 

  • Risk, supplier governance, and knowledge were distributed across silos 

At the same time, the organization needed to: 

  • Maintain ISO 27001 certification through recurring audits 

  • Align with NIS2 expectations on resilience and supply chain accountability 

  • Support high-assurance customers across regulated domains 

  • Meet product-level requirements such as RED and CE 

  • Advance cloud and introduce AI responsibly 

Rather than layering additional processes, a clear principle guided the transformation: If security and compliance are not embedded into how teams work, they will not scale. 

From tooling requirement to operating model transformation 

The engagement began with improving tooling for ISO 27001—particularly in embedded systems and C++ environments. 

Together with Eficode, Cobham Satcom evaluated the DevSecOps landscape and selected Black Duck based on integration, signal quality, and long-term fit. 

But this quickly led to a more fundamental realization: 

“The real challenge wasn’t tooling—it was how governance, risk, and engineering come together as a system.”

Lemuel ValdezCISO at Cobham Satcom

This marked the shift from tooling enablement to a full operating model transformation. 

Embedding security, risk, and compliance into the flow of work 

A key milestone was the development of a policy-driven execution model, embedding controls directly into day-to-day work. 
Crucially, this was achieved by re-architecting existing platforms, not replacing them. 
Using Jira and Confluence as the backbone—and extending them with SoftComply—Cobham Satcom created a connected model across: 

  • Regulatory frameworks (e.g. ISO 27001, NIS2, RED) 

  • Engineering workflows and delivery pipelines 

  • Security validation and controls 

  • Risk management and vendor governance 

  • Evidence generation across both system and product requirements

SoftComply enabled: 

  • Centralized enterprise and vendor risk workflows 

  • Vendor assessment and threat modelling

  • Automated risk assessment and scoring 

  • Clear ownership and traceability

Eficode supported implementation and scaling, ensuring the model worked effectively across teams. 

The result is a working system, not a framework: 

  • Security, risk, and compliance are applied continuously 

  • Evidence is generated by default 

  • Vendor risk is embedded, not isolated 

  • Teams operate with clarity and accountability 

“The objective wasn’t just visibility,—it was usability. The system has to work for the people responsible for managing risk.”

Lemuel ValdezCISO at Cobham Satcom

Driving tangible outcomes through integration 

The impact has been both measurable and externally validated. Most importantly, certifications became a byproduct of the operating model. 

“We didn’t prepare for certification—we showed what was already there,” says Lemuel. 
“The system did the work.” 

Cobham Satcom successfully passed its ISO 27001 audits with minimal incremental effort, with auditors specifically recognizing the integrated approach to security, risk, and compliance. 

At the same time: 

  • A centralized, automated risk model unified technical, operational, and vendor risk and provided visibility across the organisation 

  • AWS optimizations improved governance and delivered €80,000+ in annual savings, with Eficode contributing to further refinements 

All of this was achieved within a constrained timeframe and budget, by focusing on high-impact changes and leveraging existing tooling. Well-designed systems reduce effort while increasing control. 

Recognized maturity through integration 

The level of integration achieved across systems and workflows has positioned Cobham Satcom as a high-maturity organization within its domain. 
By combining tool such as Jira, Confluence, SoftComply, and Black Duck into a unified operating model, the organization created a connected system spanning: 

  • Software development and DevSecOps 

  • Security controls and validation 

  • Risk and compliance management 

  • Vendor and supply chain governance 

This has been recognized both internally and externally: 

  • Auditors commended the integrated, operational approach to compliance and risk 

  • During an Eficode user group session, peers highlighted the level of maturity and integration achieved using standard platforms 

“What stood out was not the individual tools, but how everything was connected into a single operating model that puts users in mind,” Valdez notes. 

Enabling secure cloud-native adoption 

Cloud adoption was driven by clarity, not compromise. 

Cobham Satcom defined: 

  • Standardized patterns 

  • Built-in governance guardrails 

  • Clear ownership structures  

Eficode contributed external validation and technical depth, helping accelerate progress. 

“The external perspective helped validate our approach and move faster with confidence,” Valdez notes. 

A pragmatic and controlled approach to AI 

AI adoption has been intentional and grounded in value.  Use cases focus on: Developer productivity and code quality, documentation and knowledge accessibility, and internal workflow efficiency.

Eficode supported this by sharing experience across regulated environments and helping align stakeholders on risk and opportunity. 

“AI is not a strategy—it’s a capability,” says Valdez. “Value comes from applying it where it strengthens how we operate—within a system that already understands risk and context.” 

A strategic partnership supporting execution and scale 

What began as a tooling initiative evolved into a pragmatic working partnership. 

Eficode’s role was to support execution, provide external perspective, and contribute experience from similar environments, including: acting as a sounding board for key decisions, providing DevSecOps, cloud, and tooling expertise, supporting implementation and scaling, and bringing insight from other regulated organizations.
 “Eficode has been valuable as a partner we can challenge ideas with and draw on for experience,” Valdez says. “That perspective helped us move faster without losing direction.” 

This approach ensured Cobham Satcom retained ownership of strategy and design, while accelerating execution through targeted expertise. 

From fragmented effort to intentional design 

Today, Cobham Satcom operates as a deliberately engineered system: 

  • Security, compliance, engineering, and AI operate as one 

  • Controls are embedded—not added 

  • Risk is managed within delivery—not separately 

  • Teams move faster because guardrails are built in 

  • Frameworks like ISO 27001, NIS2, and RED are absorbed into operations 

The shift is fundamental: 

From reacting to requirements → to designing for continuous change 

A platform for intentional change 

This operating model is not an endpoint—it is a foundation. 

  • New regulations map into existing structures 

  • Cloud capabilities scale under known guardrails 

  • AI is introduced where it creates real value 

“Transformation doesn’t require multi-year programs,” Valdez concludes. “We redesigned how our existing tools work together, stayed disciplined, and built a system where security, engineering, and regulation evolve at the same pace.” 

  • AI
  • Atlassian
  • Cloud
  • Security
  • DevOps

Talk to our experts to start your own transformation

‌‍​‍​‍‌‍‌​‍‌‍‍‌‌‍‌‌‍‍‌‌‍‍​‍​‍​‍‍​‍​‍‌‍‌​‌‍​‌‌‌​‌‍‌‍​‌‍‌‌​​‍‍‌‍​‌‍‌‍‌​‍​‍​‍​​‍​‍‌‍‍​‌​‍‌‍‌‌‌‍‌‍​‍​‍​‍‍​‍​‍‌‍‍​‌‌​‌‌​‌​​‌​​‍‍​‍​‍‌‍‌‌‌‍‌‍‌‍‍‌‌‍​‌‍‌‍‌​‌‍‌‌​‍‍‌‍​‌‌‍‌​‌‍‌‌‍‍‌‌‍‍​‍‍‌‍‌​‌‍​‌‌‌​‌‍‌‍​‌‍‌‌​​‍‍‌‍​‌‍‌‍‌​‍‌‍‌‌‌‍‌​‌‍‍‌‌‌​‌‍‌​‍​‍‌‍‍‌‌‌​‌‍‌‌‌‍‌‌‌‌‌​‌‍‌‌​​‌‍‌‌‌​​‍‌​​‍‌‍‌‌‌‍‌‍‌‌‍‍‌‍‍‌‌‍‍‌​‍‌‌​‌​‍​‌​‌‌‌​‌‌‌‍‌‍​‌‍‌​‌‌‌​‍‌‍‍‌‍‌​‌‍‍​​​‌‍‌​‍‌‍‍‌‌‌​‌‍‌‌‌‍‌‌​​‍‌​‍​​‌‍‍‌‌​​‌​‌​​‍‌‍‍​‌​‍‍‌‌​‌‌‍‌‌‍​‌‌‌​‌‌‍​‌‌‍‌‍​‌‍‌‌​‍​‌‌‌‌‌‌​‌​‌‌‌​​‌‍‌​‍‌‍‌‌‌‍‌​‌‍‍‌‌‌​​‍​‌‍‌‍‌‍‍‌‌‍‌‌‌‍​‌‍‌​‌‌​​‌‍​‌‌‌​‌‍‍​​‌‌‍​‌‍‌‍‍‌‌​‌‍​‌‌‍​‌‌​​‍‍‌‌​‌‍‍‌‌‌​‌‍​‌‍‌‌​‍​‍‌‌

Contact us

Talk to our experts to start your own transformation​​​​