The US Military’s Cyberwarfare Challenge

National Interest

 

by Mark Montgomery and Matthew Ferren

    Since its inception, US Cyber Command has struggled to find its place within the US military.

    Days after the United States launched Operation Epic Fury, Chairman of the Joint Chiefs of Staff General Dan Caine described how US Cyber Command had been “layering” cyber effects with space and other non-kinetic capabilities to disrupt Iranian communications and sensors. The remarks came weeks after President Donald Trump implied that US forces used cyber effects to “turn out the lights” in support of the raid to capture Venezuelan President Nicolas Maduro. Once a highly classified tool of espionage, cyber operations have emerged as a normal part of how the US military fights.

    Despite the administration’s positive narrative, offensive cyber operations remain difficult to fit into the joint warfight. For a decade, US cyber forces have postured to disrupt malicious cyber threats below the level of armed conflict. The doctrine of persistent engagement, the delegation of authorities under NSPM-13 and the concentration of elite operators within the Cyber National Mission Force were all optimized to wield cyber as a standalone instrument. This posture enabled US Cyber Command to dismantle terrorist propaganda networks and disrupt ransomware gangs, but it is less well-suited to cyber’s emerging role as a combat enabler.

    The US military needs to adapt how it plans, resources and employs cyber effects to support joint operations across all domains. Cyber operations should become so tightly integrated that commanders can employ cyber effects as readily as they can call for kinetic fires or resupply. Iran and Venezuela are best understood as qualified successes, where cyber succeeded against less capable adversaries and with time to plan and rehearse. Against a peer competitor like China, deficiencies in how the US military currently develops joint plans, generates cyber forces and employs them in joint operations will be exposed.

  • Challenge 1: Joint Planning with Cyber

    Today, cyber effects remain inconsistently integrated into joint operational and contingency plans, particularly at the operational and tactical levels. Cyber is often confined to a domain-specific annex and poorly synchronized with activities in other domains. The US military’s planning process must overcome three barriers to integrating cyber effects.

    The first is reliability. Producing a cyber effect at the time and place a commander chooses requires gaining and holding access to a contested adversary system and fielding a payload that produces predictable effects on demand. Every weapon carries uncertainty—a missile can be intercepted, its guidance system jammed, or its warhead rendered a dud—but planners can measure the missile’s probability of success. Adversary defenses, the complexity of the target network and the challenge of reliably generating real-world effects from a digital payload all introduce uncertainty into the planning cycle. While commanders are accustomed to planning for uncertainty, cyber’s uncertain probability makes it difficult to trust as a load-bearing element of a joint plan.

    The second barrier is the lack of shared visibility. US Cyber Command and the NSA manage the most sensitive capabilities. There are inherent trade-offs between employing those capabilities and preserving them for intelligence collection or to support a different operational requirement. But centralization prevents theater commanders from seeing every cyber capability available to them.

    US Cyber Command embeds Cyber Operations-Integrated Planning Elements (CO-IPEs) in combatant command planning staffs to close this gap. Still, they often operate as liaison cells with limited visibility or authority to deliver capabilities to joint commanders. The Joint Staff’s non-kinetic effects cells, which supported planning for operations in Iran and Venezuela, show promise for synchronizing effects globally. Yet they are designed for national-level planning, not for weaving cyber into theater-specific plans and below.

    The third and final barrier is coordination. While “layering” effects allows planners to solve for the reliability issue, such as how a strike package might dedicate multiple munitions to one target, the lack of a single coordination mechanism across kinetic and non-kinetic effects raises the risk of friendly fire. For example, electronic jamming or a kinetic strike can disrupt access to a network node that a cyber planner was counting on to deliver an effect.

  • Challenge 2: Cyber Force Generation

    The United States military’s ability to generate, sustain and retain the cyber workforce it needs to fight and win in the digital domain has been broken for years and incremental fixes have consistently failed. America’s cyber force generation system is clearly broken.

    The problem is structural. US Cyber Command comprises approximately 6,200 military and civilian personnel organized into nearly 150 Cyber Mission Force teams, but depends entirely on the military services to recruit, train and deliver cyber operators. Each of the five services conducts the initial recruiting, training, maintenance and retention of its cyber personnel.

    Still, they have consistently been unwilling or unable to prioritize efforts to recruit the right people with the competencies, technical acumen and skill sets needed to be effective in the cyber domain. The services are structured, incentivized and culturally oriented toward producing infantrymen, aviators and surface warfare officers. Cyber is an afterthought in their force generation priorities and the talent pipeline reflects it.

    The consequences are severe and persistent. Cyber billets remain unfilled across the services. Skilled cyber operators are routinely reassigned to non-cyber roles to meet service personnel requirements, destroying the continuity of expertise that effective cyber operations demand. Similar deficiencies affect the officer level. Of the approximately 13 general and flag officers assigned to Cyber Command, only one is a one-star general with a cyber background—a stunning indictment of how the military services have prioritized cyber leadership development over two decades.

    The Pentagon’s attempts to reform within the existing structure have not resolved the underlying problem. Cybercom 2.0 preserves the core role of the existing five services in generating cyber forces while empowering Cyber Command with additional service-like authorities. Still, it continues the false dichotomy between having Cyber Command act like a force generator and building a dedicated force generator by establishing a Cyber Force, choosing the former over the latter. Asking combatant commands to both generate and employ forces will not succeed because these roles are structurally incompatible.

  • Challenge 3: Tactical Employment of Cyber

    Recent conflicts show that cyber’s most dependable battlefield contributions come not from grand strategic strokes but from small, close-in effects that support tactical actions. In Ukraine, Russian cyberattacks against Ukrainian energy infrastructure produced only short-term disruption and were soon replaced by missile and drone strikes. As the conflict evolved, Russian cyber operators turned to supporting the conventional fight by disrupting sensors and command networks, enabling strikes on logistics and collecting tactical intelligence to inform fires and maneuver.

    US cyber forces are postured to deliver high-end effects remotely. These often depend on access gained months or years earlier and held against a patching, hunting adversary. Using such delicate resources requires time-consuming approval from senior commanders. A close-in effect, in contrast, is developed on a target the operator can reach by radio frequency or proximity. While such capabilities may not deliver the same impact as one developed at Fort Meade, they can be delivered quickly and to meet tactical requirements.

    The Army’s 11th Cyber Battalion fields Expeditionary Cyberspace and Electromagnetic Warfare (CEMA) Teams to deliver radio-frequency-enabled cyber and electronic attack alongside maneuver forces and the Marine Corps folds cyber and electronic warfare into its Marine Expeditionary Force Information Groups. But these units still rely on Cyber Command for approval and even simple actions often move through a slow, centralized decision-making process. Tactical integration is further limited because most forward cyber operators are not organic to the units they support. They are attached for a specific mission and then pulled back, so neither the operator nor the supported unit builds a working understanding of the other’s needs and limits.

  • How to Prepare for Peer Cyber Conflict

    Unlike operations in Iran and Venezuela, a conflict with China would pit US forces against a peer cyber competitor able to defend its networks and conduct its own offensive operations. Such a fight would intensify each of the challenges described above.

    The People’s Liberation Army segments and hardens its military networks, making access difficult. Pre-positioned access would be useful only in the opening phase of a protracted conflict. Sustaining cyber support would require generating new access and capabilities during the conflict itself and a planning process suited to dynamic regeneration rather than the deliberate, first-mover operations conducted against Iran and Venezuela.

    Sustained conflict would also demand adaptation. The war in Ukraine shows that countermeasures to a given technique can emerge within weeks and that advantage accrues to the side that adapts more quickly. Adaptation depends on the ability to determine whether a cyber effect achieved its intended result and to quickly and repeatedly turn wartime lessons into new capabilities.

    A peer conflict would require US forces to conduct defensive cyber operations. China would attack US and allied weapons systems and military networks and disrupt the civilian infrastructure on which mobilization and sustainment depend. Cyber forces would have to defend and reconstitute friendly systems while also enabling offensive activities. Joint exercises nominally include non-kinetic interference, but they do not fully simulate combat under degraded conditions.

    A war with China would be a coalition undertaking, which would compound the coordination and deconfliction problems already present within the US military. Allied forces would conduct their own operations in cyberspace and across the electromagnetic spectrum, under different authorities and with differing levels of capability. The absence of a shared picture of available effects, which already limits integration within the US joint force, would be more consequential once operations had to be synchronized across national forces.

  • How to Integrate Cyber into the US Military

    The US military must improve how it integrates cyber effects into joint plans. This requires making cyber effects legible to commanders by developing a methodology for characterizing cyber effects, including the probability of success and the likely real-world impact. For the purpose of joint planning, a predictable effect of modest consequence is more useful than an exquisite one whose likelihood of success cannot be estimated.

    US Cyber Command should build a deconflicted picture of cyber effects and capabilities available to theater planners. Building it would require identifying which of its sensitive capabilities can be exposed to theater staffs and under what controls.

    The Pentagon should review its contingency and operation plans to fully integrate cyber effects rather than confining them to supporting annexes. CO-IPEs that currently connect Cyber Command to the combatant commands should be reformed or replaced by the Joint Task Force-Cyber construct considered in the most recent defense authorization cycle, so that the connection is a planning and employment relationship rather than a liaison function.

    The Pentagon should establish tactical cyber units that embed permanently with forward units to deliver close-access effects. These units must meet the same fitness standards as their supported component, have standardized equipment and provide meaningful cyber support under delegated authorities. While high-end effects will still be delivered remotely, forward commanders should be able to employ close-access effects to enable their missions.

    Congress and the administration should establish an independent US Cyber Force—modeled on the Space Force and housed within the Department of the Army—with full statutory responsibility for recruiting, training, equipping and retaining military cyber personnel. The new service should absorb the Cyber Mission Force teams from all existing services, develop a distinct cyber culture and doctrine and create dedicated career paths that compete with the private sector on talent. Cybercom 2.0’s service-like authorities should serve as transitional scaffolding for the new service, not replace it.

    Cyber Command should mature its processes for cyber battle damage assessment and develop a cell for continuous capability iteration, ensuring cyber units can assess their effectiveness and evolve in the event of a peer conflict. All joint units should train and exercise under cyber-degraded conditions, assuming their networks, sensors and communications cannot be perfectly defended against adversary interference.

    Finally, US cyber forces must be prepared to operate alongside key partners, in particular Japan, Australia, the Philippines, Korea and Taiwan. This requires combined planning that includes cyber, procedures to deconflict effects, shared spectrum management and authorization to employ effects in a partner’s operating area. These arrangements are difficult to establish and must be developed before a conflict breaks out.

icon
Users of Guests are not allowed to comment this publication.
Discussion