Summary
- Peraton has won a roughly $117 million recompete supporting the US Army Regional Cyber Center-Europe through 2031.
- Work covers round-the-clock monitoring, incident response, threat hunting, malware analysis, penetration testing, and infrastructure management.
- The award shows the scale and duration of outsourced cyber operations supporting military networks in Europe.
Peraton has won a cybersecurity and network-operations contract worth approximately $117 million to continue supporting the US Army’s main regional cyber-defence hub for Europe and Africa through 2031.
The recompete covers the Army Regional Cyber Center-Europe, headquartered at Clay Kaserne in Wiesbaden, Germany. Peraton has supported the centre for nearly two decades, making the new award an extension of an established operational relationship rather than a new supplier entering the Army network.
The work includes 24-hour network-security monitoring, incident response, threat hunting, digital forensics and malware analysis, penetration testing, and enterprise infrastructure management. RCC-E is responsible for operating and defending networks used by US forces to plan, coordinate, and sustain military operations across the European and African theatres.
The contract is commercially modest compared with the largest defence programmes, but it places a concrete value on a function that has become inseparable from military readiness. Communications, logistics, intelligence, command systems, and ordinary administrative services all depend on networks remaining available in environments where cyber disruption can be part of a wider geopolitical confrontation.
That dependence is particularly visible in Europe. Russia’s war against Ukraine has demonstrated how cyber operations can accompany conventional conflict without replacing it, while military organisations also face the same ransomware, credential theft, software vulnerabilities, and supplier risks affecting large civilian enterprises.
A regional cyber centre therefore has to manage two different realities at once: routine enterprise-security operations and the possibility that a network is being targeted because of its role in military activity. Threat hunting, malware analysis, and incident response sit alongside the less dramatic work of maintaining infrastructure, monitoring networks continuously, and managing access across a distributed organisation.
The Peraton award also illustrates the degree to which those functions are dependent on contractors. Governments retain command responsibility, but specialist suppliers can become deeply embedded in the systems used to monitor, investigate, and operate military networks. A relationship approaching two decades creates accumulated technical knowledge and operational continuity, while also making supplier governance part of the resilience model.
Cybersecurity procurement in defence is therefore not simply a question of purchasing tools. Service contracts determine who has visibility into sensitive environments, who maintains specialist expertise, how quickly incident-response capacity can scale, and how knowledge is retained when military or civilian personnel rotate.
The five-year duration of the recompete gives Peraton continuity through a period when European defence spending and infrastructure protection remain under sustained pressure. NATO members have increased attention to the resilience of communications, logistics, energy, transport, and other systems needed to support collective defence, while hostile cyber activity has continued against both governments and suppliers.
RCC-E’s position in Germany also gives the contract a direct European infrastructure dimension despite the customer being the US Army. American forces operate through a network of European bases and rely on relationships with allies, telecommunications providers, contractors, and host-country infrastructure. Cyber resilience within those systems can therefore have operational consequences across national boundaries.
Peraton has described its role as protecting both US and allied operations, although the public contract announcement does not disclose operational details, specific threat activity, or the exact networks covered. Those limits are appropriate for a military environment and mean the award should not be interpreted as evidence of a particular new attack campaign.
Instead, the contract provides a view of how sustained cyber defence is being institutionalised: permanent monitoring, response, hunting, forensic capability, and infrastructure operations procured as a long-term mission rather than an emergency service activated after an incident.
The strategic value of the award will ultimately be measured in events that do not become public — attacks detected before disruption, compromised systems contained, and military networks that continue working when they are being actively contested.




