The UK’s approach to research security has improved in recent years, but it still relies on a patchwork of regulations, guidance and institutional practices.
The UK occupies a position of considerable strength within the global S&T landscape. Successive governments, recognizing the importance of S&T, have increasingly framed S&T as a central pillar of national security, military capability, economic resilience and geopolitical influence. This recognition has been reflected in public investment commitments, including an £86 billion S&T funding package for research and innovation in emerging fields, plans to increase annual public R&D expenditure to £22.5 billion by 2029, and targeted support for priority S&T areas, underpinned by dedicated government strategies for these fields.
Simultaneously, the government has sought to bolster protections for the UK’s S&T sector against growing geopolitical and security risks. In recent years, the UK has made significant progress in strengthening its research security policies. While these efforts have enhanced awareness and risk management, the policy landscape has developed reactively and incrementally; responsibilities and capabilities remain dispersed across multiple entities. The government’s forthcoming research security strategy will represent an important next step in consolidating this approach.
Publication of the strategy will provide an opportunity to establish a more coherent national framework that aligns research excellence, international collaboration and national security objectives.
The UK’s research security landscape comprises a layered and increasingly interconnected and fast-evolving system of government policy, regulatory controls, funding conditionality and institutional governance. Overall policy responsibility now sits within the newly created Department for Business, Innovation, Science and Trade (DBIST). Following the July 2026 ‘machinery of government’ reforms introduced by the new prime minister, Andy Burnham, DBIST inherited the science, research and innovation functions previously exercised by DSIT. Research security nevertheless remains a cross-government responsibility, with important roles continuing to be played by the Foreign, Commonwealth and Development Office (FCDO), the Home Office, the Cabinet Office and the Department for Education.
The UK’s research security landscape comprises a layered and increasingly interconnected and fast-evolving system of government policy, regulatory controls, funding conditionality and institutional governance.
The UK has linked S&T capability directly to defence and national security policy, positioning early-stage research and innovation as central to delivering long-term strategic advantage – this imperative is made all the more urgent by Russia’s ongoing war on Ukraine and by the deteriorating global security environment. Within the evolving policy landscape, universities are increasingly viewed as forming part of a whole-of-society approach to defence. For instance, a key objective of the 2025 Strategic Defence Review was the development of closer relationships between defence and the S&T ecosystem, especially in academia. This agenda progressed further through initiatives such as the Defence Universities Alliance (DUA), announced in the 2025 Defence Industrial Strategy, which sought to formalize collaboration between universities, the Ministry of Defence and industry through a structured network for fostering sovereign research, skills and innovation in defence-relevant areas. Together with the recently published Defence Investment Plan – which advocates defence investment in dual-use technology, and emphasizes closer relationships between the defence sector and start-ups, scale-ups and academia – these reforms are likely to reshape research funding, collaboration and technology priorities across the UK R&D ecosystem. As universities become more deeply embedded in the government’s efforts to deliver national capability, they will face growing expectations to demonstrate robust research security practices as a prerequisite for participating in defence-linked partnerships and programmes.
Alongside the government departments mentioned above, the UK’s technical security authorities play a central operational role. Through the Trusted Research initiative, the National Protective Security Authority (NPSA) and the National Cyber Security Centre (NCSC) provide specialist guidance informed by intelligence inputs on physical, personnel, cyber and information security risks affecting universities and research-intensive organizations.
A significant development in the UK framework was the establishment of the Research Collaboration Advice Team (RCAT). Created by the UK government, and launched in 2022, as a dedicated advisory service for the research sector, RCAT was intended to provide universities and research organizations with a clear first point of contact for advice on national security risks associated with international research collaboration. Since its creation, RCAT has become an important intermediary within the UK research security architecture, helping to bridge the gap between government security concerns and the operational realities of academic research. Its role is significant because RCAT offers institutions access to government-backed advice without relying on dispersed formal regulatory enforcement mechanisms. Following the July 2026 ‘machinery of government’ changes, RCAT will continue to play an important role under the direction of the newly formed DBIST.
Beneath the strategic and advisory layer sits a more fragmented set of legislative and regulatory controls (see Annex 1). Research security obligations in the UK are governed through multiple mechanisms, including export controls, investment screening, immigration and visa processes, and IP law – however, the majority of these mechanisms were not originally designed with research security in mind. Research security functions are spread across different departments and agencies, which often have overlapping requirements. As a result, universities frequently describe the UK system as a regulatory ‘patchwork’, in which compliance responsibilities are dispersed rather than consolidated within a single framework. Public funders of research have become increasingly influential in shaping research security behaviour. In recent years UK Research and Innovation (UKRI), the UK’s largest such funder, has strengthened its ‘trusted research and innovation’ guidance and has introduced more stringent compliance requirements.
Sectoral bodies and professional networks play supporting roles in translating national policy into operational practice. Organizations such as Universities UK (UUK), the Russell Group, the Higher Education Research Security Association (HERSA) and the Association of Research Managers and Administrators (ARMA) increasingly provide guidance, training and forums for knowledge exchange. These organizations have an intermediary role in interpreting government expectations, sharing emerging practice, and helping institutions implement research security requirements in ways that are workable within academic environments. Their involvement in co-designing and disseminating practical approaches has helped build trust and legitimacy around the research security agenda, contributing to greater awareness, institutional buy-in and more consistent implementation. Bodies such as HERSA have also become important for building bilateral and multilateral engagement with like-minded international partners at the sectoral level.
At the institutional level, most UK universities now maintain dedicated research security teams. These teams are generally responsible for coordinating compliance with legal, regulatory and funder requirements, conducting due diligence on international partnerships, delivering staff training and overseeing internal risk management. In larger and more decentralized institutions, responsibility for research security may also be distributed across faculties, departments, colleges, ethics committees, export control offices, and legal or compliance teams.
Ultimately, however, responsibility also rests with researchers. Academics are expected to comply with institutional policies and relevant legal obligations. Failure to comply may have consequences ranging from loss of funding and reputational damage to disciplinary action and, in certain circumstances, civil or criminal liability.