UKCT Report: "One Network, Two Systems: The Research Security Risks of UK/China University Cyber Partnerships"
A comprehensive analysis of UK–China university cyber collaborations, highlighting institutional links to China's military and security ecosystem.
On July 1, Natto Thoughts published “The UK’s ‘Special Relationship’ with China’s Defense-Linked Universities,” a piece previewing an upcoming report written by this author for UK-China Transparency (UKCT), a UK-based research and advocacy organization focused on issues related to transparency, governance, and national security in UK–China relations. The report, “One Network, Two Systems: The Research Security Risks of UK/China University Cyber Partnerships,” was released on July 29, 2026, and is available here.
The UKCT report maps the full landscape of UK/China academic partnerships in cyber-related fields and examines, through detailed case studies of two high-risk Chinese universities – Beihang University (北京航空航天大学) and Beijing University of Posts and Telecommunications (北京邮电大学) – how institutional design, funding structures, and personnel linkages connect ostensibly civilian research to China’s security and defence architecture. Below are the report’s 10 key findings and 5 policy recommendations, including the full list of partnerships and the highlighted high-risk ones (key finding 2). See the full report for sources and methodology.
Key Findings
1. The UK and Chinese university systems operate under fundamentally asymmetric frameworks. In the UK, university/defence linkages are bounded, voluntary, and separable from the civilian research enterprise. In China, Military-Civil Fusion (MCF) makes integration with national defence a guiding principle, not an exception, and a subset of universities hold institution-wide clearances for classified weapons research and development (R&D). UK institutions engaging these partners do so as open civilian entities.
2. The UK has disproportionate exposure to China’s highest-risk defence universities. Of 34 UK/China cyber partnerships identified, 13 involve Chinese institutions with close ties to China’s defence research system: four with Top Secret-cleared universities and nine with Secret-cleared or partners affiliated with the State Administration of Science, Technology and Industry for National Defense (SASTIND)1 – more than any other country in Europe. Half of these are joint education institutions (JEI’s), with British faculty travelling regularly to partner campuses to deliver curricula. Globally, the UK is the country that maintains the most partnerships across all academic subjects, with Top Secret-cleared Chinese universities (19), followed by Russia (10) and France (8). Below is the full list of identified UK-China university cyber partnerships, with Secret-cleared Chinese universities highlighted in orange and Top Secret-cleared ones in red.2 3
Four Top Secret-cleared institutions identified in the dataset stand out:
Queen Mary University of London/Beijing University of Posts and Telecommunications (2004): Often described as the first UK/China JEI, this longstanding partnership spans a wide range of cyber-relevant disciplines.
University of Reading/Beijing Institute of Technology (2006): An early MSc Informatics JEP.
University of Aberdeen/Harbin Engineering University (2023): A JEP in Electronic Information Engineering.
Birkbeck, University of London/Nanjing University of Aeronautics and Astronautics (2025): A newly launched JEI offering an MSc in Computer Science and Technology.
Beyond the four partnerships involving Top Secret-cleared institutions, the dataset includes nine additional collaborations with Secret-cleared universities, as shown in table of partnerships above, several of which are affiliated with or supervised by SASTIND.
3. Case studies reveal deep operational integration between Chinese partner universities and the state’s security apparatus. BUPT maintains direct PLA collaboration, structured partnerships with major defence-industrial enterprises, participation in military-civil fusion coordination mechanisms, and faculty research spanning explicitly military applications, classified defence funding, and connections to intelligence agencies including the Ministry of State Security. Beihang University, one of the Seven Sons of National Defence, shows a similar pattern, with direct links to military entities, and faculty research applied to PLA branch-specific scenarios including cyber and electronic warfare.
4. Defence integration extends to the individual faculty level. Analysis of over 100 BUPT and nearly 80 Beihang faculty profiles reveals recurring patterns: explicit military or defence-aligned funding, redacted project titles indicating classified work, affiliations with military command and control bodies, and connections to law enforcement and intelligence agencies. Some faculty simultaneously engaged in defence-designated research are also active collaborators with UK universities.
5. Some faculty have also taken steps to obscure their defence affiliations. Comparison between archived and current profiles shows removal of references to military or intelligence-related project affiliations in the most recent versions, including a BUPT faculty member who removed references to a state-level cybersecurity programme reportedly subject to PLA oversight, and a Beihang faculty member who removed redacted project titles relating to UAV swarm networking and integrated space/air/ground systems. This raises questions about strategic deception and highlights the limits of open-source due diligence.
6. The Beijing University of Posts and Telecommunications/Queen Mary University of London partnership is the most deeply integrated UK/China cyber collaboration. Established in 2004, it spans four joint bachelor’s programmes, co-supervised doctoral pipelines, joint laboratories, a shared innovation centre, and a second campus in Hainan. By 2024, it had produced over 9,600 dual degree graduates. Scopus records 465 co-authored publications in computer science between the two universities. Some BUPT faculty active in this collaboration carry defence funding affiliations and conduct classified research.
7. Significant collaboration occurs below the level of formal partnerships. Beihang lists Queen Mary University of London, Manchester, and Surrey as “strategic partners” on its cyber school’s website, yet none of these universities references a Beihang partnership prominently on its own institutional webpages. Bibliometric data nevertheless reveal co-authored research output in dual-use technology areas with several Beihang faculty engaged in defence-designated research, including work with redacted titles and military applications.
8. Beihang University maintains a joint cybersecurity laboratory with a firm subsequently sanctioned for state-sponsored cyber operations. Beijing Integrity Technology Co. was sanctioned by the US, UK, and EU in 2025 to 2026 for facilitating operations linked to the threat actor Flax Typhoon, which targeted government agencies, critical infrastructure, and technology networks globally.
9. The UK’s research security framework remains primarily advisory and individually focused. Existing mechanisms – including the Trusted Research framework, RCAT, and ATAS – do not establish clear restrictions on collaboration with high-risk partners, do not systematically govern the institutional formats (joint programmes, co-supervised doctorates, research centres) through which sensitive knowledge transfer occurs, and do not address the financial incentives that sustain high-risk partnerships.
10. Other countries and institutions have moved further. The United States placed all ‘Seven Sons’ and BUPT on its Entity List. Canada restricts funding eligibility for collaborations with defence-linked foreign institutions. Taiwan sanctioned the Seven Sons outright. The EU has excluded them from parts of Horizon Europe. Individual universities in the US, the Netherlands, Belgium, Switzerland, and France have adopted categorical restrictions or enhanced screening. The UK has not implemented comparable measures at the institutional level.
Policy Recommendations
The report sets out five policy recommendations:
1. Establish a UK Named Research Organisation List modelled on Canada’s approach to identify high-risk institutions and guide restrictions on grants and institutional partnerships, including joint programmes and co-supervised doctorates.
2. Mandate research security officers at universities engaged in high-risk partnerships to oversee such partnerships, supported through access to government threat briefings and specialised training.
3. Address financial dependency through relief funding to enable institutions to terminate or restructure high-risk partnerships and to prevent viable research projects from being blocked due to concerns about high-risk partners or funders.
4. Encourage pre-travel security briefings and post-travel reporting for staff engaged in China-related teaching, supervision, and partnership management.
5. Maintain balanced and consistent messaging, clearly communicating that research security is about targeted risk management, not blanket restrictions on collaboration with China.
In the table, Joint Education Institutions (JEIs) are long-term, jointly governed entities, either standalone universities or colleges within Chinese universities, with shared faculty and dual-degree arrangements, typically operating in China. By contrast, Joint Education Programs (JEPs) are cooperative degree programs embedded within existing Chinese university departments that do not establish a new institution, are easier to create or terminate, and more often involve student mobility between China and the foreign partner, although some are delivered primarily in China.
In the table, Approval/Start Year (Est.) refers to the earliest verifiable year of a partnership based on available sources, typically the first publicly identifiable record or online trace of collaboration. In some cases, MOE data reflects only the most recent recorded iteration or approval period of a partnership rather than its original inception (e.g. a partnership may have begun earlier but only appears in later cycles such as 2020–2024). As a result, the estimate may refer either to initial approval, renewed approval, or actual start, with an approximate uncertainty of 1–2 years due to reporting lag and gaps in historical coverage.
On its official website, SASTIND describes itself as the Chinese government’s administrative agency responsible for managing the national defense science and technology industry. It oversees and coordinates major matters related to the research and production of weapons and equipment in the nuclear, aerospace, aviation, shipbuilding, armaments, and electronics sectors, as well as the development of core military-industrial capabilities.





