The Indian Army is establishing six AASHVAST cyber laboratories to examine drones and other electronic systems for hidden firmware and embedded-system vulnerabilities, adding a new layer of technical screening to military equipment procurement.
One laboratory has already been inaugurated in Delhi, with five more planned across the country. The programme initially focuses on drones, while Army-procured CCTV cameras are expected to be brought into the screening process later.
AASHVAST can look beyond the physical inspection of hardware. Its purpose is to examine what is inside the software and firmware that controls electronic equipment, including the possibility of hidden commands, embedded credentials and mechanisms that could be used to interfere with a system.
What the laboratories are looking for
According to reporting on the Army programme, the system can identify around 14 categories of vulnerabilities. These include hidden code, embedded passwords and encryption keys, remote-access tools, location or time-triggered behavior and faults that could affect a drone’s ability to complete a mission.
That kind of analysis is more important because modern military equipment is a combination of mechanical hardware, electronics, firmware, operating systems and communications software. A component can pass a physical inspection while still containing software that introduces a security risk.
The programme was developed by QuickPay Pvt Ltd for the Directorate General of Electronics and Mechanical Engineers. The Army issued a request for proposal in April for customised licensed software for firmware and embedded-system validation.
The initiative comes amid concerns about foreign-origin components in military drones. India has previously restricted the use of Chinese-origin components by domestic military drone manufacturers over national-security and data-security concerns. The new laboratories provide a technical method for checking the actual contents of electronic systems rather than relying only on supplier declarations.
That distinction is important in complex supply chains. A system may be assembled in one country while containing processors, sensors, communications modules or software components produced elsewhere. Firmware inspection can reveal characteristics that are not visible from the product’s final assembly location.
Why drones are a particularly sensitive target
Military drones depend heavily on software. Flight control, navigation, communications, sensors and mission systems are coordinated electronically. A vulnerability in one of those layers could potentially affect how the platform behaves, although the existence of a vulnerability does not by itself establish that a system has been compromised.
Location- and time-based triggers are of particular concern because they could remain dormant during routine testing. A device might operate normally in a laboratory and behave differently only under specific conditions. Firmware analysis aims to make such mechanisms easier to identify before equipment enters operational use.
The Army’s plan to extend similar checks to CCTV cameras shows that the approach is broader than drones. Surveillance equipment can also contain network connectivity, proprietary protocols and embedded software. Screening those systems can help identify security issues before they become part of a larger military network.
The initiative also reflects a wider change in defence procurement. Cybersecurity is increasingly treated as a property of the entire supply chain rather than a separate software problem. Hardware provenance, firmware integrity and software update mechanisms can all affect the security of a platform.
For Indian defence manufacturers, that creates another requirement beyond physical production. Equipment will increasingly need to show that its electronic components and firmware can be inspected and validated. For the Army, the AASHVAST laboratories provide an internal capability to perform that analysis rather than relying entirely on vendors.
The six-lab network will not eliminate every cyber risk. Firmware analysis can identify many classes of problems, but network configuration, software updates, supply-chain changes and operational practices can introduce additional vulnerabilities later. Still, bringing embedded-system inspection into the procurement process gives the Army another control point before sensitive equipment is deployed.
The broader significance is that military cybersecurity is moving deeper into the hardware itself. For drones and connected surveillance systems, the question is no longer simply whether the network is protected. It is also whether the device can be trusted from the firmware level upward.
The Army’s approach also gives manufacturers a clearer technical target. Instead of treating cybersecurity as a general statement of compliance, suppliers may have to provide equipment that can withstand deeper firmware inspection. That could encourage better documentation, stronger software provenance and more controlled update mechanisms across the defence supply chain.
The move is particularly relevant as drones become more capable and more connected. A platform that carries cameras, navigation sensors and communications equipment can contain a large software stack. Validating that stack before deployment is So becoming as important as testing the airframe and propulsion system.