This article covers Dragonfly, a cybersecurity startup, securing a £704,863 grant from Innovate UK to develop a "secure stack" advisory layer with researchers at UCL School of Management as part of an 18-month project starting in August 2026. The project aims to produce machine-queryable assessments of multi-vendor software stacks to surface compositional security risks and map findings to standards such as the Software Security Code of Practice, ISO 27001 and NIS2, supporting procurement teams, auditors and smaller organisations.
Dragonfly, a cybersecurity startup, has secured £704,863 in a grant funding round from Innovate UK to develop a “secure stack” advisory layer with researchers from UCL School of Management. The award, made through Innovate UK’s Secure Software for Resilient Growth competition, will fund an 18-month project starting in August 2026 to evaluate multi-vendor software stacks and surface compositional security risks.
Organisations now operate hundreds of software tools alongside emerging AI systems and autonomous agents. Existing security tools typically assess vendors in isolation, but real-world risk often arises from the connections between tools: data flows, integrations, over-privileged connectors and shadow IT. Cyber attacks cost the UK economy an estimated £14.7 billion a year, and fragmented software infrastructure is a recurring weakness.
At the same time, the UK Government’s Software Security Code of Practice, published in January 2025, has set expectations for software security across supply chains. Many businesses lack the tooling or expertise to verify whether their stacks meet these standards or to make security-informed procurement choices. Dragonfly’s project aims to fill that gap by producing machine-queryable assessments that map to existing standards.
The project will build on Dragonfly’s existing knowledge graph of more than 300,000 software vendors. All 14 principles of the Software Security Code of Practice will be encoded as attributes that can be queried by machines and cross-mapped to standards including ISO 27001, NIS2 and the EU Cyber Resilience Act.
A compositional risk engine will evaluate complete, multi-vendor stacks by tracing data flows across tool boundaries, identifying weakest links and shadow IT exposure, and translating findings into plain-language, citation-backed recommendations for non-technical decision makers and AI agents. The intent is to move beyond vendor-level checks toward assessments of how technologies work together in situ.
The award is a grant from Innovate UK, made under the Secure Software for Resilient Growth competition. The funding is shared between Dragonfly and research partners at UCL and will support the academic-industry collaboration over 18 months from August 2026.
Dragonfly itself launched publicly in October 2025 after a £2.6 million pre-seed round led by Episode 1, with participation from Dreamcraft and Portfolio Ventures. That earlier round provided the company with initial commercial traction and data assets which this Innovate UK grant now aims to extend through rigorous academic research and tooling development.
If you're researching potential backers in this space:
In the announcement, Sean King, Co-founder at Dragonfly, said:
We're entering a world where every business will have both human and AI colleagues working together. The technology decisions organisations make over the next decade will fundamentally shape their ability to innovate, compete and adopt AI safely. This partnership with UCL allows us to tackle some of the hardest problems in technology decision making. Innovate UK's support is an incredible validation of both the problem and the opportunity ahead.
In the announcement, Sven Sabas, Co-founder at Dragonfly, said:
Today, businesses are expected to understand not only whether a piece of software is best-in-class, but whether it's secure, compliant, interoperable and appropriate within the wider context of their organisation. That's becoming an impossible task to solve manually. Together with UCL, we're building the intelligence layer that will help businesses understand not just what technology exists, but how it should work together: encoding the reasoning of an expert security consultant into a system that any business, or any AI agent, can query in seconds.
In the announcement, Onesun Steve Yoo, Professor at UCL School of Management, said:
As businesses increasingly rely on complex ecosystems of software and AI systems, there is a growing need for trustworthy and explainable approaches to technology decision making. This collaboration brings together cutting-edge academic research with real-world industry challenges to develop practical solutions that can help organisations navigate complexity with greater confidence. We're excited by the opportunity to contribute both rigorous research and meaningful impact through this partnership.
The project sits at the intersection of industry, academia and regulation. Mapping SSCoP principles to ISO 27001, NIS2 and the EU Cyber Resilience Act recognises that compliance regimes and procurement decisions are converging on systemic assessments of software ecosystems. The deal reflects growing interest from cybersecurity investors in tooling that assesses whole stacks rather than individual vendors.
If successful, the output could help smaller organisations and procurement teams translate technical standards into actionable decisions, and provide auditors and regulators with clearer evidence of compositional risk. It also illustrates a broader trend in the UK: public innovation funding increasingly targets projects that combine research rigour with commercial datasets to address pressing security gaps.
This collaboration is another example of how UK government funding and university partnerships are being used to turn academic methods into operational tools for industry across Europe, at a time when regulators and businesses are both racing to make complex software ecosystems safer.
| Investors | Investment Focus | Startup Investments | Round Size | Connect |
|---|---|---|---|---|
![]() | ||||
![]() Episode 1 Ventures( ) The firm specialises in investing in Pre-Seed and Seed stage B2B software compan... London | ||||
![]() Dreamcraft( ) Copenhagen, Denmark | ||||
![]() Portfolio Ventures( ) The PV Angel Fund is an early-stage investor focusing on fintech, SaaS, and vert... London | ||||
| All investors | All investor sectors | All funded startups | All funding rounds |
Click here for a full list of 7,589+ startup investors in the UK