Security / Resilience / Autonomous Systems

Unifying the Cyber Battlespace: Offensive Integration, Persistent Engagement, and the Strategic Mandate of PM Cyber Warfare

Report summary

In the contemporary geopolitical landscape, cyberspace has irrevocably transitioned from an auxiliary support function to a primary, decisive, and continuously active domain of warfare. Operating far beyond the traditional physical front lines, the cyber domain is characterized by constant, friction

Status
Research archive item
Category
Security / Resilience / Autonomous Systems
Length
6,326 words
Reading time
29 minutes
Report type
research-note

Key topics

  • Security / Resilience / Autonomous Systems
  • Security
  • Resilience
  • Autonomous Systems
  • AI
  • .NET
  • Runtime
  • Research Archive
  • Strategy

Research provenance

Archive status
Research archive item
Content identity
sha256:beb2999fcfdc26519995d5e76db73cc327bf16c733e5f816a89b30ca9e2cf4dc

For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.

This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.

Full report

On this page

The Modern Cyberspace Domain and the Paradigm of Constant Contact

In the contemporary geopolitical landscape, cyberspace has irrevocably transitioned from an auxiliary support function to a primary, decisive, and continuously active domain of warfare. Operating far beyond the traditional physical front lines, the cyber domain is characterized by constant, frictionless contact between adversaries, structural ambiguity, and a relentless pace of technological evolution1. National security and modern warfighting readiness are now inextricably linked to a state's ability to secure its critical infrastructure while simultaneously disrupting adversary networks before malicious payloads can be delivered. This reality has catalyzed a fundamental transformation in how the United States military conceptualizes, acquires, and deploys its cyber capabilities. Central to this evolutionary leap is the realization that offensive and defensive cyber operations can no longer exist as siloed, independent disciplines. Instead, they constitute a continuous, dynamic feedback loop1. Forensic insights gleaned from defensive postures must directly inform offensive targeting, just as offensive maneuverings that expose adversary tactics, techniques, and procedures (TTPs) must be utilized to harden defensive perimeters at home1. To operationalize this paradigm shift, the U.S. Army and the broader Department of Defense (DoD) have initiated sweeping organizational, doctrinal, and acquisition reforms. These efforts are anchored by the recent establishment of Project Manager Cyber Warfare (PM CW), a unified command structure designed to seamlessly integrate previously disparate offensive and defensive portfolios1. Concurrently, strategic military doctrine has evolved from traditional, reactive models of deterrence to proactive frameworks characterized by "Defend Forward" mandates and "Persistent Engagement"4. This report provides an exhaustive, multi-layered analysis of the U.S. military's modern cyber warfare strategy. It examines the organizational consolidation under PM CW, the agile acquisition mechanisms propelling software deployment, the theoretical underpinnings of cyber persistence versus deterrence by punishment, the bureaucratic friction between military and intelligence authorities (Title 10 versus Title 50), the integration of the Joint Cyber Warfighting Architecture (JCWA), and the overarching workforce reforms embodied in the CYBERCOM 2.0 initiative.

Strategic Realignment: The Establishment of Project Manager Cyber Warfare

Historically, the U.S. Army managed its cyber capabilities through bifurcated, often disjointed organizational structures. Defensive operations, focused heavily on network hardening, incident response, and the protection of the Department of Defense Information Network (DoDIN), were managed distinctly from offensive cyber and space capabilities, which were tailored for disruption, degradation, and intelligence exploitation1. This artificial separation created operational blind spots, delayed the deployment of dual-use technologies, fractured the acquisition pipeline, and inhibited the rapid sharing of threat intelligence1. In a vital evolution of modern military acquisition, the U.S. Army officially established Project Manager Cyber Warfare (PM CW) in July 2026\. This reorganization, occurring under the Capability Program Executive for Intelligence and Spectrum Warfare (CPE ISW), explicitly merged the portfolios of Project Manager Defensive Cyber Operations (PM DCO) and Project Manager Cyber and Space (PM C\&S) into a single, unified entity1. Led by Project Manager Col. David Bergmann and Deputy Project Manager Dr. Linda Jones, with Ms. Cathy Hammer serving as the Deputy Project Manager for Cyber Warfare focusing on technical and managerial oversight, PM CW is tasked with acquiring, deploying, and operating a full spectrum of cyber capabilities7. These capabilities support national, joint, and allied partners, explicitly including United States Cyber Command (USCYBERCOM) and Army Cyber Command (ARCYBER)7. The strategic rationale for this consolidation is rooted deeply in the concept of the continuous operational feedback loop. Laurence Mixon, Deputy Capability Program Executive for Intelligence and Spectrum Warfare, noted that treating the cyber domain as a cohesive battlefield maximizes operational visibility and allows the Army to rapidly equip cyber forces with the tools necessary to dominate the modern battlespace1. By placing offensive and defensive operations under the same organizational roof, PM CW ensures that these programs share critical connections, leverage similar agile acquisition resources, and expand the use of flexible contracting mechanisms to expedite the handoff of specialized software directly to cyber defenders1. This structural alignment actively forges synergy and functions as a true force multiplier. For example, forensic data captured during a defensive operation against a foreign Advanced Persistent Threat (APT) can be immediately routed to offensive developers. These developers can then reverse-engineer the adversary's malware to craft bespoke payloads for counter-cyber operations. Conversely, offensive operators probing adversarial networks can identify emerging zero-day vulnerabilities and seamlessly pass this intelligence to defensive teams to patch domestic systems before they can be exploited1. Ultimately, a combined portfolio empowers commanders to secure friendly communications, defend critical infrastructure, and actively shape operational environments long before kinetic missions are legally authorized1. It fundamentally changes how the Army conducts business with commercial technology and private industry partners, fostering a holistic approach that accelerates the transition of commercial off-the-shelf (COTS) solutions to the warfighter1.

Acquisition Agility and Modern Software Procurement

The operational speed of cyberspace dictates that traditional defense acquisition models—characterized by rigid requirements, multi-year funding cycles, and lengthy developmental milestones—are fundamentally inadequate. Technology moves faster than the traditional acquisition system can support8. By the time a cyber capability is developed, tested, and fielded under traditional frameworks, the underlying technology is often obsolete, and the adversary has already pivoted to entirely new vectors of attack8. To counter this, PM CW and its predecessor organizations have pioneered the implementation of highly agile acquisition methodologies to funnel capabilities swiftly to Soldiers while bypassing bureaucratic rigidity1.

Overcoming the Bureaucratic Lag Through Alternative Authorities

In alignment with Army Directive 24-02, “Enabling Modern Software Development and Acquisition Practices,” and the overarching "Continuous Transformation" initiative, PM CW heavily leverages rapid prototyping and flexible contracting mechanisms9. The Continuous Transformation initiative formally mandates streamlining mission-critical elements to prepare the U.S. Army for large-scale combat operations in a rapidly changing global security environment, moving deliberately beyond the counterinsurgency focus of previous decades9. A cornerstone of this agile approach is the extensive use of Other Transaction Authority (OTA) agreements. OTAs allow the government to bypass the traditional, cumbersome Federal Acquisition Regulation (FAR) processes, enabling rapid collaboration with commercial technology partners, academic institutions, and non-traditional defense contractors. Through OTAs, PM CW can prototype and field innovative technologies in a fraction of the standard time8. For instance, utilizing rapid prototyping frameworks, the organization successfully delivered a data analysis prototype to ARCYBER data scientists in just two weeks, fully developed the capability within 30 days, and secured an authority to operate (ATO) in merely six months9.

The Financial Mechanism: Budget Activity 08 (BA-08)

A critical financial enabler of this agility is the use of Budget Activity 08 (BA-08) funding, formally known as the "Software and Digital Technology Pilot Program." Traditional procurement mechanisms require programs to forecast their financial needs years in advance through the Program Objective Memorandum (POM) cycle. If a sudden cyber threat emerges, executing a reprogramming effort or a POM adjustment can result in devastating delays of 12 to 24 months9. BA-08 resolves this by allowing PM CW to acquire software and hardware via a single, color-agnostic appropriation, regardless of the technology’s developmental stage9. This financial flexibility proved instrumental in the rapid procurement of critical cloud infrastructure for Insider Threat and User Activity Monitoring programs. By leveraging BA-08 funds, the Army quickly procured cloud capability functionality, bypassing lengthy reprogramming efforts and saving on overall program costs9.

User-Centered Design and Commercial Integration

The modern acquisition strategy is also heavily predicated on user-centered, or human-centered, design principles. Cyber operators, ARCYBER product owners, data scientists, and specialized "tool champions" are embedded directly into the software development lifecycle from initial conceptualization to final deployment9. This tight collaboration ensures that customer research and real-world Soldier feedback drive continuous, iterative software improvements, adapting systems to adhere to the priorities established by the Continuous Transformation directives9. This agility ensures that specialized software, successfully scaled-up pilot programs, and commercial solutions are handed off directly to cyber warriors without the traditional friction that historically plagued defense procurements1.

The Architecture of Cyberspace Superiority: PM CW Portfolios

The unification of the PM CW portfolio brings together a formidable, integrated array of offensive and defensive platforms designed to provide a decisive warfighting information advantage. These tools range from deployable tactical hardware for operations at the absolute edge to cloud-based big data analytics platforms hosted in secure enclaves7.

Offensive Cyber Warfare Programs

Offensive Cyber Operations (OCO) are designed to project power, disrupt adversary networks, degrade enemy capabilities, and manipulate information systems in Red or Gray spaces using deception, spoofing, and decoying techniques6. The offensive portfolio is engineered for stealth, precision, and deniability.

Program NameAcronymMission and Technical Description
Joint Common Access PlatformJCAPA protected, managed, and orchestrated environment that serves as the common firing platform for USCYBERCOM. It enables Cyber Mission Forces (CMF) to coordinate and execute the delivery of cyber effects against approved targets while carefully managing detection and attribution, ensuring operational security during high-stakes engagements7.
Foundational ToolkitFTKA bespoke collection of highly modular software components and payloads. These tools can be dynamically combined, reconfigured, and deployed to keep pace with the rapidly shifting cyber threat landscape, providing tailored solutions for specific adversary architectures7.
Rapid Capability Development NetworkRCDNA remotely accessible, closed network supported by COTS hardware and open-source software. It acts as a secure, isolated sandbox to drive the rapid development, testing, and validation of emerging cyber capabilities for Department of War equities prior to real-world deployment7.
Tactical Cyber Equipment Radiofrequency Delivery Effects PlatformTCE RDEPTactically deployable, radiofrequency (RF)-enabled hardware and software systems utilized by Army Cyber forces. Supporting both dismounted/wearable and mounted/fixed-site configurations via the C5ISR/EW Modular Open Suite of Standards (CMOSS), it pushes cyber and electronic warfare convergence directly to the tactical edge7.

Defensive Cyber Warfare Programs

Defensive Cyber Operations (DCO) involve proactive actions taken to protect, monitor, analyze, detect, and respond to unauthorized activity within the Department of Defense Information Network (DoDIN)6. Under PM CW, the defensive portfolio has shifted from static firewalls to dynamic, automated, and AI-driven hunting mechanisms.

Program NameAcronymMission and Technical Description
Cyber Analytics (Gabriel Nimbus)CA (GN)The U.S. Army’s Big Data Platform. It ingests, aggregates, processes, and visualizes petabytes of data from the DoDIN and open sources to detect malicious actors and automate decision-making. By FY26, it will complete upgrades to the Joint Cyber Warfighting Architecture Common Runtime Stack – Data (JCRS-D) and integrate AI to empower defenders7.
Deployable Defensive Cyberspace Operations SystemDDSHighly mobile, modular kits equipped with dedicated compute and storage resources designed to fit in commercial overhead compartments. Fielding of DDS-Mv2 includes delivering 25 kits to COMPO 1, providing Cyber Protection Brigades with rapid evaluation and response capabilities7.
Forensics and Malware AnalysisF\&MAPortable capabilities allowing defenders to triage incidents and perform remote forensic analysis without altering volatile data. By FY26, this capability will award and field labs to ARCYBER G3X and deliver Live Box capabilities to Regional Cyber Centers (RCCs) for real-time memory capture7.
User Activity MonitoringUAMA scalable software solution supporting the Insider Threat program. It evaluates policy violations, unauthorized device connections, and anomalous behaviors. FY26 plans include deploying UAM on JWICS and SIPRNet, backed by advanced AI and machine learning for predictive behavioral analysis7.
Counter InfiltrationC-IProvides mission assurance against near-peer advanced persistent threats (APTs) by deploying decoys, credentials, and digital lures. It offers early warning detection by tricking adversaries into engaging with fabricated targets, wasting their resources and revealing their TTPs7.
Threat EmulationTEThe passive emulation of adversary tactics, techniques, and procedures to identify vulnerabilities and gaps in current safeguards. This functions as continuous stress-testing for the network without causing actual harm or operational degradation7.
Castle KeepCKDevelops the Special Security component to support intelligence warfighting functions. FY26 projected activities include achieving Full Operational Capability, adding NSA SCIFs into Castle Keep, upgrading SCIFs to ICD standards, and implementing organizational-based workflow enhancements7.
Garrison DCO PlatformGDPCollects, analyzes, and stores data at line speeds exceeding 40Gbps in garrison environments. It interoperates with the NETCOM Global Enterprise Fabric system. FY26 goals involve updating software baselines and incorporating additional data ingest sources7.
DCO Tools SuiteDCO ToolsPrepositioned, tailorable software packages leveraging COTS, GOTS, and open-source software available from strategic to tactical echelons. It is designed to augment local cyber defense operations, with FY26 market research focused on replacing terrain mapping with more cost-effective solutions aligned with the Army Global Unified Network (AGUN)7.

The Doctrinal Shift: Cyber Persistence Theory and Defend Forward

The integration of offensive and defensive capabilities under PM CW is not merely a bureaucratic reorganization; it is the physical manifestation of a profound doctrinal shift in how the United States conceptualizes strategic conflict in the information age. For the latter half of the twentieth century, strategic military doctrine was overwhelmingly dominated by the logic of nuclear deterrence—specifically, deterrence by punishment. This framework assumed that the credible threat of catastrophic, unacceptable retaliation would dissuade adversaries from initiating an attack, thereby maintaining a state of stable peace4.

The Mismatch of Nuclear Deterrence in Cyberspace

However, the direct application of nuclear-era deterrence theory to cyberspace has proven to be a severe strategic mismatch. Cyberspace is a fluid, low-friction environment characterized by a low barrier to entry, immense attribution challenges, and the continuous execution of operations that purposefully remain below the threshold of armed conflict14. Adversaries—ranging from highly sophisticated state-sponsored intelligence apparatuses in China and Russia to transnational criminal syndicates and proxies—continuously engage in espionage, massive intellectual property theft, ransomware deployments, and the dangerous prepositioning of disruptive malware within critical civilian infrastructure4. In this gray zone of conflict, relying on episodic, reactive responses or waiting for a massive, catastrophic cyberattack to justify a punitive kinetic or cyber response essentially cedes the strategic initiative to the adversary4. The 2011 International Strategy for Cyberspace and the 2015 DoD Cyber Strategy largely relied on a doctrine of restraint and the threat of reactive punishment19. This approach demonstrably failed to dissuade nation-state adversaries from launching persistent, targeted campaigns that eroded U.S. power cumulatively over time20.

The Imperative of Persistent Engagement

To rectify this strategic failure, scholars and military strategists—most notably Dr. Emily O. Goldman, Dr. Michael P. Fischerkeller, and Dr. Richard J. Harknett—developed "Cyber Persistence Theory." This theory posits that cyberspace is structurally defined by a condition of "constant contact" and "interconnectedness"2. Because new vulnerabilities continually arise, targets are never static, and digital terrain frequently shifts, security cannot be achieved through passive defense or the mere threat of future retaliation2. In response to this reality, the Department of Defense formally codified the operational approaches of "Defend Forward" and "Persistent Engagement" in its 2018 Cyber Strategy, the USCYBERCOM Command Vision, and National Security Presidential Memorandum 13 (NSPM-13)4. Persistent Engagement dictates that U.S. cyber forces must continuously interact with and contest adversaries in cyberspace to shape their behavior, introduce tactical friction, and generate strategic advantage2. Defend Forward is the geographic and operational manifestation of this theory: it requires U.S. forces to maneuver seamlessly across interconnected global networks and operate as close to the origin of adversary activity as possible, regardless of physical borders5. As General Paul M. Nakasone articulated, holding cyber forces in reserve as a "response force" for kinetic conflicts resembles obsolete, pre-1945 naval strategies where fleets remained safely in port rather than patrolling the seas5. By defending forward, the military transitions to a "persistence force," actively dismantling adversary infrastructure, seizing command and control (C2) servers, and publishing enemy malware signatures to render their tools ineffective before they ever reach U.S. or allied networks5.

Deterrence by Denial: Recalibrating the Cost-Benefit Calculus

While traditional deterrence by punishment struggles in cyberspace due to the difficulty of timely attribution and the risk of disproportionate escalation, the strategy of Persistent Engagement strongly supports the logic of "Deterrence by Denial"14. Deterrence by denial seeks to prevent aggression by convincing the adversary that their attack will simply fail to achieve its intended objectives, thereby rendering the expenditure of time, capital, and previously unexposed zero-day vulnerabilities pointless15.

The Dual Mechanisms of Denial

Deterrence by denial in cyberspace operates on a synchronized dual track: extreme resilience on the defensive side and proactive disruption on the offensive side.

1. Defensive Resilience: Utilizing programs acquired by PM CW, such as the Gabriel Nimbus Big Data Platform, automated User Activity Monitoring, and zero-trust architectures, defenders harden the target surface7. If an adversary calculates that a network is highly segmented, heavily encrypted, and monitored by AI-driven analytics, the perceived probability of a successful breach plummets. Furthermore, if a breach does occur, rapid restoration capabilities—supported by Deployable Defensive Cyberspace Operations Systems (DDS) and advanced live-box forensics—ensure that critical functions continue without interruption, completely blunting the adversary's coercive leverage7.

2. Offensive Disruption: Defend Forward operations actively hunt adversaries in foreign networks. By conducting operations to take down adversary botnets, exposing their customized Foundational Toolkits (FTK), and disrupting their supply chains, the United States imposes heavy operational costs on the attacker33. The attacker must constantly rebuild infrastructure, register new domains, and rewrite code, consuming resources that could have been spent on executing a strategic attack against the homeland5.

The Academic Debate: Cumulative Effect vs. Escalation Risk

The pivot toward Defend Forward and persistent cost-imposition has generated significant debate within academic and policy circles, exposing deep theoretical divides. Proponents argue that cumulative counter-cyber operations generate a stabilizing effect, sharing tenets with the Israeli concept of cumulative deterrence28. Over repeated engagements, adversaries learn the boundaries of acceptable behavior through "tacit bargaining," ultimately realizing that continuous cyber aggression against the U.S. yields diminishing returns and high operational friction2. Conversely, critics raise concerns rooted deeply in the "Stability-Instability Paradox" and Kahn's escalation ladder34. They argue that aggressively operating in foreign networks to impose costs might inadvertently incentivize adversaries to act more recklessly34. If adversaries believe their C2 infrastructure will inevitably be dismantled by USCYBERCOM, they may prioritize speed over stealth, launching rapid, automated, and poorly targeted attacks (such as aggressive ransomware worms) before their tools are discovered and neutralized34. Furthermore, critics argue that persistent engagement blurs the lines between peacetime competition and armed conflict, potentially sparking spiraling, uncontrollable escalation where a cyber operation provokes a kinetic response2. However, defenders of the strategy, including Fischerkeller and Harknett, argue these fears are largely unwarranted. They assert that states recognize cyberspace as a domain of "agreed competition" occurring securely below the threshold of armed conflict. Restraint in the face of continuous adversarial aggression is actually far more destabilizing, as it incentivizes aggressors to operate with absolute impunity and establishes de facto norms that are antithetical to international stability and U.S. national interests2.

The operationalization of Defend Forward and the holistic integration of PM CW portfolios do not exist in a vacuum; they must navigate a highly complex labyrinth of domestic legal authorities, international law, and entrenched bureaucratic cultures. The primary domestic friction point lies at the intersection of Title 10 and Title 50 of the United States Code18.

The Statutory Authority Divide

Historically, cyberspace operations have straddled the ambiguous line between military action and intelligence gathering.

  • Title 10 (Armed Forces): Governs traditional military activities, focusing squarely on the use of force, power projection, and tactical disruption. Under Title 10, USCYBERCOM operates to degrade, disrupt, or destroy adversary capabilities41.
  • Title 50 (War and National Defense): Governs intelligence operations and covert actions. The intelligence community uses Title 50 to conduct espionage, steal data, and maintain persistent, undetected access to foreign networks for long-term monitoring18.

As cyber operations matured in the early 2000s, they originally functioned under an intelligence-driven model prioritizing clandestine collection18. The strategic shift toward Defend Forward represents a definitive militarization of the domain, reclassifying many clandestine cyber operations as "traditional military activity" under Title 1042. Congressional action, such as the National Defense Authorization Act (NDAA), explicitly expanded this, declaring that clandestine military operations in the information environment shall be considered traditional military activity. This statutory maneuver allows military forces to bypass the stringent oversight and formal presidential finding requirements typically associated with Title 50 covert actions, enabling much faster, continuous operational tempos25.

Bureaucratic Conflict and Organizational Culture

This statutory shift naturally generates profound bureaucratic friction between the Department of Defense and the Intelligence Community18. Intelligence agencies (operating under Title 50\) possess a highly risk-averse organizational culture in cyberspace. Their primary goal is to infiltrate a network and remain undetected for years to gather strategic intelligence. Conversely, military agencies (operating under Title 10\) possess a risk-acceptant culture. They view cyberspace as a maneuver space where adversaries must be actively disrupted, degraded, and deterred—a process that inherently reveals accesses and frequently "burns" compromised infrastructure44. When PM CW develops tools like the Joint Common Access Platform (JCAP) to execute cyber effects, or relies on Counter Infiltration (C-I) lures, it must carefully coordinate with intelligence stakeholders7. If USCYBERCOM disrupts a foreign server to prevent an impending attack on U.S. critical infrastructure, it may inadvertently destroy an allied intelligence community listening post that was quietly monitoring that same server. Resolving this deconfliction, ensuring mission prioritization, and maintaining agile oversight without stifling operational speed remains one of the most significant governance challenges in modern cyber warfare18.

The "Fog of Law" and International Sovereignty

Internationally, operations below the threshold of armed conflict exploit a persistent "fog of law." The international legal framework governing state-sponsored cyber operations remains in a state of pronounced ambiguity22. The U.S. Department of Defense Law of War Manual maintains a position of "strategic ambiguity," affording the U.S. maximum flexibility but stymieing the development of clear customary international law regarding sovereignty and the non-intervention principle in cyberspace22. As aggressors utilize Gray Zone activities to undercut core aspects of statehood while skirting clear legal red lines, legal entrepreneurs argue for a concept of "legal deterrence by denial"—raising the upfront costs of Gray Zone activities rather than relying on post hoc punishments46. Furthermore, the Cyberspace Solarium Commission highlighted the necessity of layered cyber deterrence, emphasizing that deterrence by denial requires deep public-private partnerships. Because the vast majority of critical infrastructure is owned and operated by private entities, current policies that treat these actors merely as passive victims are insufficient. Enabling trusted private-sector operators to take lawful, risk-calibrated active cyber defense measures is critical to raising adversary costs and denying operational freedom43.

Force Generation and Talent Management: The CYBERCOM 2.0 Mandate

The most sophisticated software architectures and robust legal authorities are ultimately rendered inert without a highly skilled cadre of operators to execute the mission. Despite extensive budget allocations and rhetorical prioritization, the U.S. military has historically struggled with chronic personnel shortages, severe readiness deficits, and abysmal retention rates within the Cyber Mission Force (CMF)48. Since its inception over a decade ago, USCYBERCOM has relied on the individual military branches (Army, Navy, Air Force, Marine Corps) to recruit, train, and equip cyber forces before detailing them to the joint command50. This fragmented "man, train, and equip" model resulted in glaring inconsistencies. Each service prioritized different skills, applied different administrative standards, and subjected highly technical personnel to traditional military promotion processes that rewarded generalist leadership over deep technical competence48. Consequently, highly trained operators frequently left the military for lucrative private-sector roles, leading to the deployment of hollow teams that struggled to achieve Full Operational Capability (FOC)48. For instance, despite plans announced in 2022 to expand the CMF from 133 to 147 teams (adding 14 teams across the Army, Navy, and Air Force), the Navy was forced to delay delivering new teams for several years to focus entirely on improving the dire readiness of its existing personnel48.

The Implementation of CYBERCOM 2.0

To arrest this strategic degradation, the Department of Defense initiated "CYBERCOM 2.0"—a comprehensive overhaul of the cyber force generation model designed to optimize talent management for long-term strategic competition50. Empowered by recent congressional mandates in the NDAA that granted USCYBERCOM enhanced budget control and acquisition authority (effectively giving it service-like powers over training and equipping), CYBERCOM 2.0 seeks to replace compliance-based generalists with deep, technical specialists51. General Timothy Haugh noted that these new authorities allow Cyber Command to set investments in training infrastructure, while services focus on recruiting aligned to a unified standard51. The revised model is built upon fundamental pillars of domain mastery, specialization, and agility50. Key attributes of the reform include:

1. Targeted Recruiting and Tailored Career Paths: Moving away from generalized military assignments, CYBERCOM 2.0 creates dedicated career tracks that allow elite operators to hone their craft at a keyboard for years without sacrificing promotion opportunities50. This cultural shift mirrors the U.S. Navy's recent creation of a specific cyber "rating" (work role) in 2023, a move forced by Congress to remedy readiness issues51.

2. Specialized Mission Sets and Agile Training: Leveraging platforms like the Rapid Capability Development Network (RCDN), the military will provide continuous, mission-specific advanced training adapted to countering rapidly evolving, embedded threats like China's Volt Typhoon7.

3. Establishing Enabling Organizations: The Department established the Cyber Talent Management Organization to attract and retain elite talent, and the Advanced Cyber Training and Education Center to build domain mastery through tailored education50.

While some critics and prominent think tanks (such as the Center for Strategic and International Studies) argue that these reforms are insufficient and advocate for the creation of an entirely independent, standalone "Cyber Force" (akin to the Space Force established in 2019\)48, CYBERCOM 2.0 represents the most aggressive attempt to date to forge a warrior ethos built specifically for the digital domain50. By optimizing unit phasing to maintain sustainable operational tempos and presenting fully functional tactical headquarters, the model aims to directly support the proactive "Defend Forward" posture led by figures like Katie Sutton, Assistant Secretary of War for Cyber Policy, and Elbridge A. Colby, Under Secretary of War for Policy50.

The Joint Cyber Warfighting Architecture (JCWA) and Allied Integration

Bringing together the capabilities of PM CW, the strategic doctrine of persistent engagement, and the specialized workforce of CYBERCOM 2.0 requires a comprehensive command and control matrix. This is realized through the Joint Cyber Warfighting Architecture (JCWA), USCYBERCOM’s premier platform that enables the Cyber Operations Forces to conduct full-spectrum operations globally and at scale55. JCWA serves as the organizing paradigm for the cyber enterprise, integrating previously disparate systems into a unified architecture56. It is comprised of interconnected elements, including Cyber Weapons and Tools (such as FTK and JCAP), Data and Sensors (supported by platforms like Gabriel Nimbus), Robust Infrastructure, and Cloud environments57. The Unified Platform acts as the foundational data hub of JCWA, providing the analytic infrastructure necessary to deploy, manage, and secure petabytes of data critical to Information Advantage and Decision Dominance55. The integration of JCWA ensures that Service Components—such as ARCYBER, Fleet Cyber Command (FLTCYBER), Air Forces Cyber (AFCYBER), Marine Forces Cyberspace Command (MARFORCYBER), and the DoD Cyber Defense Command (DCDC)—operate in a standardized, interoperable environment53. As Congress and DoD leadership push for tighter integration across the cyber architecture, JCWA dictates the interface control documents and data exchange formats that allow tactical tools, like the Deployable Defensive Cyberspace Operations System (DDS), to communicate seamlessly with strategic national assets60.

Extended Deterrence and Allied Coordination

This technological integration extends beyond domestic borders to support extended deterrence and allied coordination. In regions like the Indo-Pacific, where highly capable state actors such as China and North Korea routinely work in opposition to U.S. strategy, defending forward requires combined operational concepts with bilateral alliances26. How Beijing and Pyongyang perceive signals sent by U.S. and allied persistent engagement will ultimately decide the deterrent value of the strategy26. Similarly, in the European theater, NATO has historically relied on forward defense to keep the balance between deterrence by denial and deterrence by punishment62. NATO’s recent transition from defense by reinforcement to forward defense in all domains, including cyber, mirrors the U.S. shift30. Initiatives such as the deployment of U.S. "Hunt Forward" cyber squads to Lithuania to defend against Russian aggression exemplify this integration27. Establishing information warfare fusion cells across allied commands ensures that the U.S. and its partners can present a united, interoperable front that generates cumulative strategic effects against common adversaries5.

Conclusion

The transition of cyberspace from a supporting technical domain to a primary arena of strategic, continuous competition has forced a fundamental reckoning within the United States military. The paradigm of treating cyber defense as a passive IT function and cyber offense as a highly classified, episodic intelligence-gathering mechanism is obsolete. The modern battlespace is characterized by relentless ingenuity, where adversaries continuously probe, infiltrate, and preposition within critical infrastructure, exploiting the gray zone below the threshold of armed conflict. The establishment of Project Manager Cyber Warfare (PM CW) represents a visionary, organizational response to this reality. By fusing offensive and defensive portfolios, the U.S. Army has institutionalized the operational truth that cyberspace operations are a continuous feedback loop1. This organizational synergy, supercharged by agile acquisition pathways like BA-08 funding and Other Transaction Authorities, ensures that cyber operators are equipped with cutting-edge tools—from the Gabriel Nimbus analytics platform to the Joint Common Access Platform—at the speed of relevance, bypassing decades-old bureaucratic inertia7. Concurrently, the strategic embrace of Cyber Persistence Theory, Persistent Engagement, and Defend Forward aligns U.S. doctrine with the structural, unyielding realities of the domain2. By abandoning the flawed framework of deterrence by punishment and fully committing to deterrence by denial and proactive cost-imposition, the United States is actively contesting adversaries, introducing profound tactical friction, and seizing the strategic initiative5. Executing this comprehensive strategy requires expertly navigating profound legal friction between Title 10 and Title 50 authorities, harmonizing the competing risk cultures of military and intelligence operations, and relentlessly focusing on talent management to cure readiness deficits18. Initiatives such as CYBERCOM 2.0 and the continuous maturation of the Joint Cyber Warfighting Architecture (JCWA) are essential, non-negotiable components of this effort, ensuring that the Cyber Mission Force possesses the domain mastery, specialized training, and technological interoperability required to dominate the information environment50. Ultimately, the best offense in cyber warfare is indeed a powerful, proactive defense intimately linked to continuous offensive pressure1. By treating the cyber domain as a cohesive battlefield, continuously contesting adversaries abroad, rapidly deploying integrated capabilities, and cultivating an elite technical workforce, the United States military is securing the digital high ground, ensuring national security, and guaranteeing warfighting readiness for the complex conflicts of the twenty-first century.

Works cited

1. Cyber Warfare: Best Offense Is Powerful Defense \- USAASC, https://asc.army.mil/web/cyber-warfare-the-best-offense-is-a-powerful-defense/

2. Persistent Engagement, Agreed Competition, and Cyberspace Interaction Dynamics and Escalation \- The Cyber Defense Review, https://cyberdefensereview.army.mil/Portals/6/CDR-SE\_S5-P3-Fischerkeller.pdf

3. Constant Modernization: The Establishment of Project Manager Cyber Warfare \- CPE ISW, https://cpeisw.army.mil/2026/08/03/constant-modernization-the-establishment-of-project-manager-cyber-warfare/

4. Paradigm Change Requires Persistence \- A Difficult Lesson to Learn \- The Cyber Defense Review, https://cyberdefensereview.army.mil/Portals/6/Documents/2022\_winter/12\_Goldman\_CDR\_V7N1\_WINTER\_2022.pdf

5. A Cyber Force for Persistent Operations \- NDU Press \- National Defense University, https://ndupress.ndu.edu/Media/News/News-Article-View/Article/1736950/a-cyber-force-for-persistent-operations/

6. 20150122-C2-Cyber-EWID.pdf \- AFCEA Quantico-Potomac |, https://www.afcea-qp.org/wp-content/uploads/2015/01/20150122-C2-Cyber-EWID.pdf

7. PM CW \- Capability Program Executive \- Intelligence and Spectrum Warfare \- CPE ISW, https://cpeisw.army.mil/pm-cw/

8. Better, faster, cheaper \- USAASC, https://asc.army.mil/web/news-alt-jfm18-better-faster-cheaper/

9. PM Defensive Cyber Operations Aligns with Continuous Transformation \- USAASC, https://asc.army.mil/web/pm-defensive-cyber-operations-aligns-with-continuous-transformation/

10. PM Defensive Cyber Operations Aligns with Continuous Transformation | Article \- Army.mil, https://www.army.mil/article/288894/pm\_defensive\_cyber\_operations\_aligns\_with\_continuous\_transformation

11. Cyber Maneuver and Schemes of Maneuver \- The Cyber Defense Review, https://cyberdefensereview.army.mil/Portals/6/Documents/2020\_fall\_cdr/CDR%20V5N3%2006\_Allen.pdf

12. Cybertest and Evaluation of Defensive Cyberoperations in the U.S. Army \- CSIAC, https://csiac.dtic.mil/state-of-the-art-reports/cybertest-and-evaluation-of-defensive-cyberoperations-in-the-u-s-army/

13. Cyber Tasking Order Specialist @ Dice | Jobright.ai, https://jobright.ai/jobs/info/6a5d5256c8e3a473cb8b3f8f?visit=cyber-tasking-order-specialist-jobs-in-united-states

14. Deterrence by denial in cyberspace | Request PDF \- ResearchGate, https://www.researchgate.net/publication/367957765\_Deterrence\_by\_denial\_in\_cyberspace

15. Deterrence by Denial vs. Deterrence by Punishment: Evaluating the Effectiveness of US Cyber Deterrence Strategy \- ResearchGate, https://www.researchgate.net/publication/411995885\_Deterrence\_by\_Denial\_vs\_Deterrence\_by\_Punishment\_Evaluating\_the\_Effectiveness\_of\_US\_Cyber\_Deterrence\_Strategy

16. A Hypothetical Command Vision Statement for a Fictional PLA Cyber Command \- Lawfare, https://www.lawfaremedia.org/article/hypothetical-command-vision-statement-fictional-pla-cyber-command

17. Power of Beliefs in US Cyber Strategy: The Evolving Role of Deterrence, Norms, and Escalation | Journal of Cybersecurity | Oxford Academic, https://academic.oup.com/cybersecurity/article/9/1/tyad006/7097988

18. U.S. Cyber Policy: Offense, Deterrence, & Strategic Competition, https://mccraryinstitute.com/app/uploads/2025/12/U.S.-Cyber-Policy-Offense-Deterrence-and-Strategic-Competition.pdf

19. Deterrence is Not a Credible Strategy for Cyberspace | Request PDF \- ResearchGate, https://www.researchgate.net/publication/317245213\_Deterrence\_is\_Not\_a\_Credible\_Strategy\_for\_Cyberspace

20. From Reaction to Action: Adopting a Competitive Posture in Cyber Diplomacy, https://tnsr.org/2020/09/from-reaction-to-action-adopting-a-competitive-posture-in-cyber-diplomacy/

21. Offensive Cyber Operations: Failure to Dissuade Nation-State Adversaries in Cyberspace, https://search.proquest.com/openview/72b4a0630dfd2c036b38505c619deea3/1?pq-origsite=gscholar\&cbl=18750\&diss=y

22. Toward Clarity in Cyber's “Fog of Law”, https://cyberdefensereview.army.mil/Portals/6/Documents/2025-vol10-iss1/V10N1\_06\_Sullivan\_2025.pdf

23. Bridging the Gap Ser.: Cyber Persistence Theory : Redefining ... \- eBay, https://www.ebay.com/itm/335927743285

24. The Cyber Defense Review \- Army.mil, https://cyberdefensereview.army.mil/Portals/6/CDR%20V5N1%20-%20FULL\_WEB\_1.pdf

25. Answering the Cyber Oversight Call \- Insight @ Dickinson Law, https://insight.dickinsonlaw.psu.edu/cgi/viewcontent.cgi?article=1341\&context=fac-works

26. Bilateral Alliances in an Interconnected Cyber World: Cyber Deterrence and Operational Control in the US Indo-Pacific Strategy \- Project MUSE, https://muse.jhu.edu/article/881960

27. UNCLASSIFIED 1 UNCLASSIFIED POSTURE STATEMENT OF GENERAL JOSHUA M. RUDD, USA COMMANDER, UNITED STATES CYBER COMMAND BEFORE THE, https://www.armed-services.senate.gov/download/testimony/04/28/2026/rudd-opening-statement

28. 'Cumulative Deterrence' as a New Paradigm for Cyber Deterrence \- ResearchGate, https://www.researchgate.net/publication/292071882\_'Cumulative\_Deterrence'\_as\_a\_New\_Paradigm\_for\_Cyber\_Deterrence

29. Operationalizing Deterrence by Denial in the Cyber Domain \- Digital Commons @ USF, https://digitalcommons.usf.edu/cgi/viewcontent.cgi?article=1093\&context=mca

30. Deterrence and defence | NATO Topic, https://www.nato.int/en/what-we-do/deterrence-and-defence/deterrence-and-defence

31. Twenty-first Century Threats Require Twenty-first Century Deterrence \- Connections: The Quarterly Journal, https://connections-qj.org/article/twenty-first-century-threats-require-twenty-first-century-deterrence

32. CyberThreats 2025 – Federal, State & Local – 2 Day Summit | Webinar | FedInsider, https://www.fedinsider.com/cyberthreats-2025-federal-state-local-2-day-summit/

33. The Gray Zone: Changing our Understanding of National Security in the Information Age, https://www.researchgate.net/publication/383720717\_The\_Gray\_Zone\_Changing\_our\_Understanding\_of\_National\_Security\_in\_the\_Information\_Age

34. Preparing the next phase of US cyber strategy \- Atlantic Council, https://www.atlanticcouncil.org/in-depth-research-reports/issue-brief/preparing-the-next-phase-of-us-cyber-strategy/

35. Cyber Deterrence: The Past, Present, and Future \- ResearchGate, https://www.researchgate.net/publication/347341001\_Cyber\_Deterrence\_The\_Past\_Present\_and\_Future

36. Integrated Deterrence and Cyberspace \- NDU Press, https://ndupress.ndu.edu/Portals/68/Documents/strat-monograph/Integrated-Deterrence-and-Cyberspace.pdf

37. Army Support of Military Cyberspace Operations, https://www.files.ethz.ch/isn/187504/pub1246.pdf

38. (PDF) PERSISTENT ENGAGEMENT AND ESCALATION RISK 1 Persistent Engagement and Escalation Risk: Assessing the Stability- Instability Paradox in Cyberspace Operations \- ResearchGate, https://www.researchgate.net/publication/412011120\_PERSISTENT\_ENGAGEMENT\_AND\_ESCALATION\_RISK\_1\_Persistent\_Engagement\_and\_Escalation\_Risk\_Assessing\_the\_Stability-\_Instability\_Paradox\_in\_Cyberspace\_Operations

39. (PDF) LEGAL AND SOVEREIGNTY IMPLICATIONS OF BELOW-THRESHOLD CYBER OPS 1 The Legal and Sovereignty Implications of Offensive Cyber Operations Below the Threshold of Armed Conflict \- ResearchGate, https://www.researchgate.net/publication/411994494\_LEGAL\_AND\_SOVEREIGNTY\_IMPLICATIONS\_OF\_BELOW-THRESHOLD\_CYBER\_OPS\_1\_The\_Legal\_and\_Sovereignty\_Implications\_of\_Offensive\_Cyber\_Operations\_Below\_the\_Threshold\_of\_Armed\_Conflict

40. Congressional Oversight of Modern Warfare: History, Pathologies, and Proposals for Reform \- W\&M Law School Scholarship Repository, https://scholarship.law.wm.edu/cgi/viewcontent.cgi?article=3914\&context=wmlr

41. Defense Primer: Cyberspace Operations \- National Security Archive, https://nsarchive.gwu.edu/sites/default/files/documents/3534796/Document-07-Congressional-Research-Service.pdf

42. Policy Roundtable: Cyber Conflict as an Intelligence Contest, https://tnsr.org/roundtable/policy-roundtable-cyber-conflict-as-an-intelligence-contest/

43. Testimony of Frank Cilluffo Director McCrary Institute for Cyber and Critical Infrastructure Security Auburn University House Co, https://homeland.house.gov/wp-content/uploads/2026/01/2026-01-13-CIP-HRG-Testimony.pdf

44. Bureaucratic Politics of Cyber Strategy | Journal of Global Security Studies, https://academic.oup.com/jogss/article/10/3/ogaf007/8104758

45. Emerging Technology and U.S. Presidential War Powers \- BearWorks \- Missouri State University, https://bearworks.missouristate.edu/cgi/viewcontent.cgi?article=5114\&context=theses

46. Legal Deterrence by Denial: Strategic Initiative and International Law in the Gray Zone, https://tnsr.org/2025/06/legal-deterrence-by-denial-strategic-initiative-and-international-law-in-the-gray-zone/

47. layered cyber deterrence \- Journal on Emerging Technologies, https://ndlsjet.com/wp-content/uploads/2024/06/01\_Hance.pdf

48. United States Cyber Force \- FDD, https://www.fdd.org/analysis/2024/03/25/united-states-cyber-force/

49. Evaluating Alternative Models for Organizing U.S. Cyber Forces, https://cyberdefensereview.army.mil/Portals/6/Documents/2025-vol10-iss3/CDR\_V10\_N3\_A11\_Arnold.pdf

50. Department of War Establishes CYBERCOM 2.0 \- Revised Cyber Force Generation Model, https://www.war.gov/News/Releases/Release/Article/4330204/department-of-war-establishes-cybercom-20-revised-cyber-force-generation-model/

51. Following new authorities, Cybercom says it's making progress on correcting readiness, https://defensescoop.com/2024/07/31/following-new-authorities-cybercom-says-making-progress-correcting-readiness/

52. CYBERCOM 2.0 Seeks to 'Deny Adversaries Freedom of Maneuver', https://govciomedia.com/cybercom-2-0-seeks-to-deny-adversaries-freedom-of-maneuver/

53. Bacon: We're in a New Era of Cyber Warfare | House Armed Services Committee, https://armedservices.house.gov/news/documentsingle.aspx?DocumentID=6527

54. The Cyber Defense Review \- Army.mil, https://cyberdefensereview.army.mil/Portals/6/Documents/2025-vol10-iss3/CDR\_2025\_Full\_Issue\_V10\_N3.pdf

55. The Cyber Defense Review \- Army.mil, https://cyberdefensereview.army.mil/Portals/6/Documents/2024\_Summer/CDRV9N2\_Summer\_2024-SE-Web.pdf

56. Creating Selective Overmatch: An Approach to Developing Cyberspace Options to Sustain U.S. Primacy Against Revisionist Powers \- RAND Corporation, https://www.rand.org/content/dam/rand/pubs/research\_reports/RRA1900/RRA1943-1/RAND\_RRA1943-1.pdf

57. cybercom op-5 \- Fiscal Year 2026 Budget Estimates, https://comptroller.war.gov/Portals/45/Documents/defbudget/FY2026/budget\_justification/pdfs/01\_Operation\_and\_Maintenance/O\_M\_VOL\_1\_PART\_1/CYBERCOM\_OP-5.pdf

58. Examination of United States Cyber Command and Service Cyber Components Cyber Workforce Development Programs \- ProQuest, https://search.proquest.com/openview/9452d3e86afbe298b050274a07b1872a/1?pq-origsite=gscholar\&cbl=18750\&diss=y

59. United States Cyber Command \- Fiscal Year 2025 Budget Estimates, https://comptroller.war.gov/Portals/45/Documents/defbudget/FY2025/budget\_justification/pdfs/01\_Operation\_and\_Maintenance/O\_M\_VOL\_1\_PART\_1/CYBERCOM\_OP-5.pdf?utm\_source=chatgpt.com

60. The Cyber Defense Review \- Army.mil, https://cyberdefensereview.army.mil/Portals/6/Documents/2023\_Spring/CDR\_V8N1\_Spring\_2023\_r5.pdf

61. Army putting offensive and defensive cyber portfolios under a single office \- DefenseScoop, https://defensescoop.com/2023/05/24/army-putting-offensive-and-defensive-cyber-portfolios-under-a-single-office/

62. NATO Approaches to Forward Defence and Contemporary Deterrence and Defence Adaptation \- Generolo Jono Žemaičio Lietuvos karo akademija, https://journals.lka.lt/journal/lasr/article/2278/file/pdf

63. Modern Deterrence \- per Concordiam, https://perconcordiam.com/modern-deterrence/