/

July 13, 2026

Decent Cybersecurity Selected for the NATO DIANA Decision Superiority Challenge

On 9 July 2026, NATO’s Defence Innovation Accelerator for the North Atlantic (DIANA), working with Allied Command Operations (ACO), selected ten companies for its Decision Superiority for NATO Warfighters Challenge. Decent Cybersecurity is one of them. The programme is being delivered by the company’s Czech entity, based in Czechia.

The ten are Matrix Pro Sim, Hadean, Watchtower Labs, Flai, Grist Mill Exchange, Decent Cybersecurity, ETE Technology, Onebrief, Picogrid and Levato AS. Each receives €100,000 in contractual funding to integrate and demonstrate its solution with NATO stakeholders and operational end users.

The platform behind the challenge

The challenge is anchored to Maven Smart System NATO (MSS NATO), acquired by the NATO Communications and Information Agency in March 2025 for Allied Command Operations at SHAPE. The procurement took six months, among the fastest in Alliance history. MSS NATO fuses many data sources into a real-time, geospatially contextualised operational picture, and its architecture is open and extensible. That is the opening DIANA is using.

NATO’s stated problem is not a shortage of data. It is that planning remains linear and manual, and plans stop tracking reality the moment reality diverges from the assumptions inside them. The published challenge statement asks for AI and ML that plugs into existing warfighting platforms: red and blue force simulation, agent-based modelling of adversary and friendly units, reinforcement learning and probabilistic optimisation, rapid course of action analysis, automated scenario preparation, targeting workflows, insight extraction from raw ISR feeds, and natural language interfaces to the operational picture.

The illustrative scenario NATO published is a Baltic grey-zone crisis: an unidentified drone near a civilian airport, a severed undersea cable, two vessels changing course near the break, unmarked convoys surfacing on social media. Radar alone cannot classify the drone. Analysts alone cannot correlate the rest in time. Commanders need a course of action in minutes.

Why the format matters

Dynamic Challenges are built for urgent needs, not early research. The maturity bar here was TRL 7 or above, meaning systems already demonstrated in an operational environment.

There is no accelerator site and no Phase 2. Selected innovators go straight into workshops with ACO and other NATO stakeholders, integrate inside a cloud-based environment, and demonstrate. Integration with other vendors is an explicit requirement, not an afterthought. Successful innovators are then eligible for follow-on contracts through DIANA’s Rapid Adoption Service, for prototyping and potentially full deployment, without further competition.

This is DIANA operating less like an accelerator and more like a fast procurement front door. To be precise about what it is not: selection is not a deployment decision and not a production contract. It is an invitation to prove a capability in front of the people who would have to rely on it.

Why cybersecurity belongs in a decision superiority cohort

A post-quantum cryptography company can look like an outlier next to simulation and planning specialists. The challenge statement explains why it is not.

Integrity comes before speed. The published scenario fuses military ISR with commercial feeds, maritime tracking, weather and open-source reporting. Every input is also an attack surface. A poisoned or spoofed input does not slow the decision loop down. It accelerates the wrong decision, carrying the authority of an AI-generated common operating picture.

Provenance has to become cryptographic. NATO’s scenario has analysts validating provenance and reliability by hand. That check is correct, and it does not scale to machine speed. At the tempo the challenge demands, trust in a feed, a report or a model output has to resolve as a signature verified in microseconds. ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) exist so that those signatures survive the arrival of quantum computers.

The data has a decades-long confidentiality life. The challenge lists asset specifications, historical adversary behaviour, force posture, logistics and targeting data: precisely the material that retains value long after collection, and precisely what harvest-now-decrypt-later collection targets. The EU roadmap requires high-risk and critical infrastructure use cases migrated by the end of 2030, and NIST IR 8547 disallows quantum-vulnerable public-key cryptography after 2035. A platform fielded today will still be running inside both windows.

Models become assets worth attacking. Once scenario libraries, simulation artefacts and machine-generated recommendations sit inside the command chain, their integrity is a security objective in its own right. An adversary who cannot outrun a decision cycle may prefer to corrupt it quietly.

Under the terms of the programme, the specifics of each innovator’s solution stay between the participating companies and NATO.

What happens next

The ten companies will spend the coming months integrating and iterating with NATO stakeholders in a cloud-based environment aligned to real use cases, ending in a demonstration phase where each solution is assessed for operational potential and future adoption pathways.

The cohort spans the United States, the United Kingdom, the Nordics and Central Europe, integrating on a shared platform. That is NATO’s stated principle, that Allied strength comes from integrating Allied capabilities, expressed as engineering rather than communiqué. A Czech deep-tech SME inside that group is a reminder that the Alliance’s technological edge is not built only where the defence budgets are largest.