Cobham Satcom partnered with Eficode to build a security-by-design operating model that embeds risk, compliance, and governance into everyday engineering. By integrating Jira, Confluence, SoftComply, Black Duck, and AWS, the company made ISO 27001 certification a natural byproduct of its workflows while enabling secure cloud, DevSecOps, and AI adoption.
In a nutshell
Company
Cobham Satcom, a provider serving regulated industries including defence, government, and maritime.
Needed to modernize its technology landscape while maintaining strict security and compliance requirements.
Challenges
Scale security and compliance alongside cloud, DevOps, and AI without slowing the business.
Maintain ISO 27001 certification and align with evolving regulations such as NIS2, RED, and CE.
Improve visibility, consistency, and traceability across engineering, risk, compliance, and vendor governance.
Connect existing tools and processes into a unified operating model rather than adding more standalone controls.
Solution
Partnered with Eficode to design and implement a security-by-design operating model.
Integrated Jira, Confluence, SoftComply, Black Duck, and AWS into a connected platform for engineering, security, risk, and compliance.
Embedded security controls, risk management, and evidence generation into day-to-day engineering workflows.
Re-architected existing platforms instead of replacing them, creating a policy-driven execution model.
Results
ISO 27001 certification and other required certifications became a byproduct of normal operations rather than separate audit projects.
Successfully passed ISO 27001 audits with minimal incremental effort, with auditors recognizing the integrated approach.
Implemented the core operating model in months rather than years.
Established centralized, automated risk management across technical, operational, and vendor risk.
Improved AWS governance, contributing to more than €80,000 in annual savings.
Built a scalable foundation for secure cloud adoption and responsible AI implementation.
Building a future-proof, AI-enabled security operating model in a regulated environment
Cobham Satcom needed to modernize its technology landscape while maintaining strict compliance in a highly regulated industry. Rather than treating this as a compliance exercise, the company—led by its cybersecurity leadership—set out to build a future-ready operating model where security, engineering, and governance are fully integrated by design.
The ambition was not simply to strengthen controls, but to ensure that security and compliance could scale with cloud, DevOps, and AI—without slowing the business down—even across demanding sectors such as defence, government, and maritime, and evolving frameworks like ISO 27001, NIS2, and product regulations such as the Radio Equipment Directive (RED).
A key design requirement was clear: enable Cobham Satcom to obtain and maintain certifications as a natural outcome of how the organization operates—not as a separate, high-friction effort.
To accelerate execution, Cobham Satcom partnered with Eficode, bringing external expertise in DevSecOps, cloud, and regulated environments—supporting implementation, validating direction, and providing practical input throughout the transformation.
"Transformation doesn’t require multi-year programs. We redesigned how our existing tools work together, stayed disciplined, and built a system where security, engineering, and regulation evolve at the same pace."
Certifications as a byproduct
Cobham Satcom obtains and maintains ISO 27001 and other required certifications as a side effect of its operating model—using evidence already generated through normal workflows, rather than running separate audit-driven projects.
Months, not years
The core operating model was designed and implemented in months, not years —by restructuring how existing tools and processes worked together, rather than launching an open-ended transformation program.
Turning compliance into an engineering capability
As Cobham Satcom evolved, the challenge was not the absence of controls—but to ensure they were consistently visible, usable, and connected across a complex and growing environment.
Security activities existed but needed stronger connection to how engineering operates
Workflows varied across teams, creating unnecessary complexity
Visibility across delivery, risk, and compliance needed to scale
Risk, supplier governance, and knowledge were distributed across silos
At the same time, the organization needed to:
Maintain ISO 27001 certification through recurring audits
Align with NIS2 expectations on resilience and supply chain accountability
Support high-assurance customers across regulated domains
Meet product-level requirements such as RED and CE
Advance cloud and introduce AI responsibly
Rather than layering additional processes, a clear principle guided the transformation: If security and compliance are not embedded into how teams work, they will not scale.
From tooling requirement to operating model transformation
The engagement began with improving tooling for ISO 27001—particularly in embedded systems and C++ environments.
Together with Eficode, Cobham Satcom evaluated the DevSecOps landscape and selected Black Duck based on integration, signal quality, and long-term fit.
But this quickly led to a more fundamental realization:
“The real challenge wasn’t tooling—it was how governance, risk, and engineering come together as a system.”
This marked the shift from tooling enablement to a full operating model transformation.
Embedding security, risk, and compliance into the flow of work
A key milestone was the development of a policy-driven execution model, embedding controls directly into day-to-day work.
Crucially, this was achieved by re-architecting existing platforms, not replacing them.
Using Jira and Confluence as the backbone—and extending them with SoftComply—Cobham Satcom created a connected model across:
Regulatory frameworks (e.g. ISO 27001, NIS2, RED)
Engineering workflows and delivery pipelines
Security validation and controls
Risk management and vendor governance
Evidence generation across both system and product requirements
SoftComply enabled:
Centralized enterprise and vendor risk workflows
Vendor assessment and threat modelling
Automated risk assessment and scoring
Clear ownership and traceability
Eficode supported implementation and scaling, ensuring the model worked effectively across teams.
The result is a working system, not a framework:
Security, risk, and compliance are applied continuously
Evidence is generated by default
Vendor risk is embedded, not isolated
Teams operate with clarity and accountability
“The objective wasn’t just visibility,—it was usability. The system has to work for the people responsible for managing risk.”
Driving tangible outcomes through integration
The impact has been both measurable and externally validated. Most importantly, certifications became a byproduct of the operating model.
“We didn’t prepare for certification—we showed what was already there,” says Lemuel.
“The system did the work.”
Cobham Satcom successfully passed its ISO 27001 audits with minimal incremental effort, with auditors specifically recognizing the integrated approach to security, risk, and compliance.
At the same time:
A centralized, automated risk model unified technical, operational, and vendor risk and provided visibility across the organisation
AWS optimizations improved governance and delivered €80,000+ in annual savings, with Eficode contributing to further refinements
All of this was achieved within a constrained timeframe and budget, by focusing on high-impact changes and leveraging existing tooling. Well-designed systems reduce effort while increasing control.
Recognized maturity through integration
The level of integration achieved across systems and workflows has positioned Cobham Satcom as a high-maturity organization within its domain.
By combining tool such as Jira, Confluence, SoftComply, and Black Duck into a unified operating model, the organization created a connected system spanning:
Software development and DevSecOps
Security controls and validation
Risk and compliance management
Vendor and supply chain governance
This has been recognized both internally and externally:
Auditors commended the integrated, operational approach to compliance and risk
During an Eficode user group session, peers highlighted the level of maturity and integration achieved using standard platforms
“What stood out was not the individual tools, but how everything was connected into a single operating model that puts users in mind,” Valdez notes.
Enabling secure cloud-native adoption
Cloud adoption was driven by clarity, not compromise.
Cobham Satcom defined:
Standardized patterns
Built-in governance guardrails
Clear ownership structures
Eficode contributed external validation and technical depth, helping accelerate progress.
“The external perspective helped validate our approach and move faster with confidence,” Valdez notes.
A pragmatic and controlled approach to AI
AI adoption has been intentional and grounded in value. Use cases focus on: Developer productivity and code quality, documentation and knowledge accessibility, and internal workflow efficiency.
Eficode supported this by sharing experience across regulated environments and helping align stakeholders on risk and opportunity.
“AI is not a strategy—it’s a capability,” says Valdez. “Value comes from applying it where it strengthens how we operate—within a system that already understands risk and context.”
A strategic partnership supporting execution and scale
What began as a tooling initiative evolved into a pragmatic working partnership.
Eficode’s role was to support execution, provide external perspective, and contribute experience from similar environments, including: acting as a sounding board for key decisions, providing DevSecOps, cloud, and tooling expertise, supporting implementation and scaling, and bringing insight from other regulated organizations.
“Eficode has been valuable as a partner we can challenge ideas with and draw on for experience,” Valdez says. “That perspective helped us move faster without losing direction.”
This approach ensured Cobham Satcom retained ownership of strategy and design, while accelerating execution through targeted expertise.
From fragmented effort to intentional design
Today, Cobham Satcom operates as a deliberately engineered system:
Security, compliance, engineering, and AI operate as one
Controls are embedded—not added
Risk is managed within delivery—not separately
Teams move faster because guardrails are built in
Frameworks like ISO 27001, NIS2, and RED are absorbed into operations
The shift is fundamental:
From reacting to requirements → to designing for continuous change
A platform for intentional change
This operating model is not an endpoint—it is a foundation.
New regulations map into existing structures
Cloud capabilities scale under known guardrails
AI is introduced where it creates real value
“Transformation doesn’t require multi-year programs,” Valdez concludes. “We redesigned how our existing tools work together, stayed disciplined, and built a system where security, engineering, and regulation evolve at the same pace.”
- AI
- Atlassian
- Cloud
- Security
- DevOps
Talk to our experts to start your own transformation
Related client stories