Directorates I–VI
Ten areas, one disposition
We are consistently more interested in how a thing fails than in how well it works. Most of what follows is instrumentation, measurement, and the unglamorous distance between a result and a system that can be relied on.
Quantum Systems
Error correction, coherence budgets, and the unglamorous engineering between a physics result and a machine that stays up.
Our interest is not in claiming advantage. It is in the failure modes: what a quantum device does when it is slightly wrong, and whether the surrounding classical system can be built to notice. Most of the work is metrology and thermal engineering.
Current focus
- Surface-code overheads at realistic error rates
- Cryogenic control electronics and heat budgets
- Post-quantum migration paths for existing systems
- Verification of results that cannot be recomputed classically
AI Alignment
Making capable systems legible to the people accountable for them.
We treat alignment as an engineering discipline rather than a philosophical one: instrumentation, evaluation, and the ability to intervene. A system nobody can inspect is a system nobody can be responsible for, whatever its behaviour on a benchmark.
Current focus
- Interpretability tooling for deployed models
- Evaluation that survives contact with distribution shift
- Human oversight that scales sublinearly with capability
- Shutdown and rollback semantics under partial failure
Signal Intelligence
Recovering structure from records that are mostly noise.
Applied to natural and instrumental sources: seismic arrays, radio background, long-baseline interferometry, degraded archival media. The discipline is separating a real weak signal from the many ways an instrument can lie to you. We do not collect against people.
Current focus
- Weak-signal detection below conventional noise floors
- Instrument artefact characterisation and rejection
- Recovery of degraded magnetic and optical media
- Provenance and chain of custody for observational data
Distributed Computing
Consensus, partition behaviour, and systems that degrade honestly.
We are interested in what a distributed system claims about itself while it is failing. Most outages are not the loss of a component but the confident reporting of a state that is no longer true.
Current focus
- Consensus under sustained asymmetric partition
- Verifiable state reconstruction after split-brain
- Deterministic replay for post-incident analysis
- Capacity models that hold at the tail, not the mean
Cyber Defence
Defensive engineering, detection, and disclosure done properly.
Strictly defensive. We build detection and resilience for systems we operate or are asked to review, and we publish what we find through coordinated disclosure. We do not develop offensive capability and we do not sell to those who do.
Current focus
- Detection engineering with measurable false-positive budgets
- Supply-chain integrity and reproducible builds
- Recovery rehearsal and tested restore paths
- Coordinated vulnerability disclosure
Autonomous Systems
Machines that operate unattended, and stop when they should.
Long-duration autonomy in environments without a reliable link home. The research problem is not navigation; it is knowing when the system's model of the world has quietly stopped matching it, and arriving at a safe state before anyone notices.
Current focus
- Fault detection without ground contact
- Graceful degradation under sensor loss
- Energy-limited planning over multi-week horizons
- Provable stop conditions
Secure Communications
Confidentiality and integrity over links you do not control.
Protocol design and analysis, with attention to metadata rather than payload alone. Encrypting content while leaking who spoke to whom, when, and how often solves the smaller half of the problem.
Current focus
- Metadata-resistant transport
- Key management for long-lived deployed hardware
- Formal analysis of handshake state machines
- Interoperability with open standards
Human Factors
How people actually behave around instruments, alarms and procedure.
The most reliable component of a safety-critical system is usually the least studied. We investigate vigilance over long shifts, alarm fatigue, handover failure, and the specific ways written procedure diverges from practice.
Current focus
- Alarm design and attention economics
- Handover and shift-change failure modes
- Procedure drift in long-running operations
- Interface design for degraded and emergency states
Applied Cryptography
Primitives are rarely the weak point. Deployment is.
Implementation work, side-channel analysis, and the migration problem: how an organisation moves a fielded estate to new primitives without a flag day. We publish our own constructions for review before we rely on them.
Current focus
- Constant-time implementation and side-channel testing
- Post-quantum migration for long-lived data
- Threshold schemes and custody splitting
- Verifiable deletion and key destruction
Advanced Networking
Routing and transport where latency is measured in minutes.
Delay-tolerant and intermittently connected networking, developed for our own remote stations and since applied more broadly. Assumes the link is down and treats connectivity as the exception.
Current focus
- Store-and-forward transport with bounded staleness
- Routing under predictable disconnection
- Congestion control at extreme round-trip times
- Time synchronisation without continuous reference
What we do not do
- No offensive capability. Directorate IV is defensive. We do not develop intrusion tooling and we do not sell to those who do.
- No collection against people. Signal Intelligence here means recovering structure from instruments and archives. It does not mean surveillance, and the charter forbids it.
- No contract research. We have no customers, so there is nobody whose preferred result we might drift toward.
- No irreversible deployment. Work that cannot pass the four tests in SEN-23-041 does not leave the laboratory, however good it is.