There can be little doubt that building a cyber force is without its challenges — There is no doubt building the cyber force has been challenging. from transitioning lessons learned in the signals intel business over the last half century into a military context to operationalizing a new domain and staffing an entire workforce that can integrate with traditional military units.
Col. Paul Stanton, deputy director of Capabilities Development Group at Cyber Command, took command two months ago and, while noting progress, he concedes there is still much work to be done.
“I would submit that we are at an inflection point. Our principle focus to date has been on building the organization, countless challenges and obstacles that the team has overcome in terms of recruiting the right talent, putting them onto the right teams and defining what it means to execute the missions as cyber protection teams. But we have a long way to go,” he said at TechNet Augusta. “We have to be a learning organization and figure out how to, to best transition the talent that we have within the teams towards operational effectiveness in defending — not necessarily protecting — but defending our networks against aggressive adversaries.”
Stanton identified readiness and integration as two lines of effort that forces are initiating within the Cyber Protection Brigade. In terms of integration, Stanton asked a series of rhetorical questions to outline the key focuses and challenges: “How do we integrate our operations, our intelligence and our technical capabilities in a manner that best supports our teams? How do we further integrate our capabilities such that the tactical tools that we have available to us for local analysis and enclave interact successfully and at mission relevance speed with the tools that are arrayed across the depth of the enterprise networks? How do we interact and become interoperable with the sensing capabilities that are deployed on the tactical edge?”
“There are significant challenges that we have to face,” he said, adding: “We’re only going to learn by executing missions. We have to be out executing missions, and we are.”
One of the other key challenges he identified was how forces are faring in realistic environments. “I can’t certify right now is that there’s been an objective, metrics-based assessment that says that [personnel] know how to use our kit as a crew in a realistic environment against a realistic threat,” he said. “My principle mission is to provide trained and ready forces to the operational commands that employ cyber protection teams,” he said, saying he “can promise you using the vernacular of my high school daughters, I can provide wicked smart folks that are really good network engineers and computer scientists and algorithm developers and script writers.”
The force is driving toward these assessments and looking to the expertise from the Cyber Center of Excellence at Fort Gordon, Georgia, “to help us codify the doctrine, help us build the right capability,” according to Stanton.
Cyber operations do not occur in isolation. Military officials are sure to express they run alongside everything the military does, such as maintaining the network to allow for communications or logistics. Part of this effort involves integrating cyber units into traditional military forces.
Chief Warrant Officer 5 Abel Chavez, technical adviser for the Army Cyber Protection Brigade, said part of this effort involves not just educating cyber protection teams (CPT) but education the Signal Corps to fill in capability gaps and provide commanders with more battlefield options.
“We are also educating the Signal Corps on the gaps that are out there [as well as the] electronic warfare folks. We need to bring capabilities into something that … has multiple options on the battlefield. And that’s one of the key things,” Chavez said at TechNet. “When you start looking at the way we distribute our [defensive cyber operations] planners out there, we integrate them in the [cyber, electromagnetic activities] cell and actually exercise how the signal community and the electronic warfare community all converge into one environment and produce a good course of action for that commander to be able to execute his mission.”
Lt. Col. John Hosey, S3 OIC for the Army Cyber Protection Brigade, also noted how, from a combatant command level, it is important to exercise with the joint force. During exercise, “most of the other services’ CPTs [participate] as well,” he said at TechNet. “So Navy, Air Force, Army, we all play in the exercise so we’re all doing coordination to ensure there’s a holistic view for defensive cyber and also interact with other defensive cyber forces.”
The joint nature of the cyber force has engendered unconventional, cross coordination between services. For example, the commander of Joint Force Headquarters — Department of Defense Information Networks (JFHQ-DoDIN), Lt. Gen. Alan Lynn, told an audience in April that Air Force teams have operated in Navy networks. “Matter [of] fact, we’ve had Air Force teams in Navy cyberspace, what would be normally a Navy mission, and we had Air Force people on it, so it’s truly joint,” he said at the AFCEA Defensive Cyber Operations Symposium in Washington.
JFHQ-DoDIN’s deputy director of strategy and plans, Lt. Col. Patrick Daniel, elaborated on this phenomenon during the same conference: “In this particular case, in support of that combatant command’s mission, the Navy had an issue, but the Navy did not have resources to confront that issue. So we from a Joint Force Headquarters perspective … can use an Air Force team here to get at this Navy problem. Was it smooth and easy and perfect? Absolutely not because you have a team from one service trying to operate on a combat platform for another service, and that’s unheard of.”




