<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet media="screen" type="text/xsl" href="https://one.sightlinemg.com/c4isrnet/wp-content/themes/smg/assets/xslt/rss-xslt.xml"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
xmlns:news="http://www.pugpig.com/news"
>

<channel>
	<title>C4ISRNet - Media for the Intelligence-Age Military | C4ISRNET</title>
	<atom:link href="https://one.sightlinemg.com/c4isrnet/it-networks/cyber-flag/feed/" rel="self" type="application/rss+xml" />
	<link>https://one.sightlinemg.com/c4isrnet/</link>
	<description>Media for the Intelligence-Age Military &#124; C4ISRNET</description>
	<lastBuildDate>Sat, 08 Aug 2026 18:39:37 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://one.sightlinemg.com/wp-content/uploads/2026/06/favicon-c4i.png?w=32</url>
	<title>C4ISRNet - Media for the Intelligence-Age Military | C4ISRNET</title>
	<link>https://one.sightlinemg.com/c4isrnet/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">255331819</site><atom:link rel="next" type="application/rss+xml" href="https://one.sightlinemg.com/c4isrnet/feed/?paged=2" />
	<item>
		<title>EU framework heralds dawn of AI diplomacy with US, China</title>
		<link>https://one.sightlinemg.com/c4isrnet/opinion/2023/12/12/eu-framework-heralds-dawn-of-ai-diplomacy-with-us-china/</link>
					<comments>https://one.sightlinemg.com/c4isrnet/opinion/2023/12/12/eu-framework-heralds-dawn-of-ai-diplomacy-with-us-china/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Tue, 12 Dec 2023 15:55:27 +0000</pubDate>
				<category><![CDATA[AI & ML]]></category>
		<category><![CDATA[Cyber Flag]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT and Networks]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/c4isrnet/uncategorized/2023/12/12/eu-framework-heralds-dawn-of-ai-diplomacy-with-us-china/</guid>

					<description><![CDATA[China is ahead of both Europe and the U.S. with a set of AI regulations implemented this past August - though its laws aren't as comprehensive as the EU's.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/c4isrnet/opinion/2023/12/12/eu-framework-heralds-dawn-of-ai-diplomacy-with-us-china/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">27009</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/AP23305468039042.jpg.jpg" width="8228" height="5485" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">This past week, European Union policy makers agreed to the <a href="https://www.nytimes.com/2023/06/14/technology/europe-ai-regulation.html">AI Act</a>, <a href="https://www.nytimes.com/2021/04/16/business/artificial-intelligence-regulation.html">one of the first significant frameworks</a> to govern the technology. This potential blueprint stands as a guide for European leaders to create the first major regulation governing AI in the western world. </p>



<p class="wp-block-paragraph">While implementation remains <a href="https://cset.georgetown.edu/article/the-eu-ai-act-a-primer/#:~:text=Pending%20final%20EU%20procedures%20(the,the%20regulation%20becomes%20fully%20enforced.">a minimum of two years away</a>, pending ratification, with U.S. leadership, the EU AI Act &#8211; combined with elements from President Biden’s <a href="https://www.whitehouse.gov/briefing-room/presidential-actions/2023/10/30/executive-order-on-the-safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence/">AI Executive Order</a> &#8211; represents a potential groundwork for a global policy linking the People’s Republic of China to the West.</p>



<p class="wp-block-paragraph">The EU AI Act is the most comprehensive set of guidelines for AI regulation to date. The act covers most of the concerning aspects of the technology: the capability for mass disinformation; concerns about self-learning systems developing and then <a href="https://apnews.com/article/ai-act-europe-regulation-59466a4d8fd3597b04542ef25831322c">pursuing their own objectives</a>; and protection of <a href="https://www.forbes.com/sites/forbesbusinesscouncil/2023/10/31/ai-and-intellectual-property-who-owns-it-and-what-does-this-mean-for-the-future/?sh=3b5cf7f43e96">intellectual property</a> absorbed by large language models.</p>



<p class="wp-block-paragraph">The framework also seeks to protect citizens and individuals from the most intrusive elements of AI through <a href="https://apnews.com/article/ai-act-europe-regulation-59466a4d8fd3597b04542ef25831322c">prohibitions on biometric systems</a> that classify individuals based on race or sexual orientation. The guidelines also protect against the unregulated collection of facial data. The legislation does permit law enforcement to employ biometric identification in public areas for specific criminal activities.</p>



<p class="wp-block-paragraph">The EU framework addresses the two opposing impulses that any effective AI regulation must harmonize: safeguarding against potential harm without impeding innovation. The EU proposal manages both risk reduction and technological advancement. Once enacted, companies developing high-risk AI tools &#8211; classified as such due to their potetial for social harm &#8211; must undergo stringent assessments and provide transparency in their operations.</p>



<p class="wp-block-paragraph">Registration will not slow down acceleration. Developers can continue to advance a system once it is under governmental review. Based on the public information released by the EU Parliament, it is unclear what body will determine which tools pose a high enough risk to require this additional scrutiny or what risk threshold will initiate this further review.</p>



<p class="wp-block-paragraph">As Europe emerges as a frontrunner in comprehensive AI regulation, this momentous step offers a unique opportunity to establish a broader framework for AI governance, potentially aligning with the U.S. and China. With China already having enacted <a href="https://www.brookings.edu/articles/the-us-and-its-allies-should-engage-with-china-on-ai-law-and-policy/">sophisticated AI regulations</a> and publicly <a href="https://www.reuters.com/technology/china-willing-enhance-communication-with-all-sides-ai-regulation-vice-minister-2023-11-01/">expressing willingness for international cooperation</a> last month, the EU structure presents a point around which global powers can pivot on a coordinated set of rules.</p>



<p class="wp-block-paragraph">China is ahead of both Europe and the U.S., with a <a href="https://www.reuters.com/technology/china-issues-temporary-rules-generative-ai-services-2023-07-13/">set of AI regulations</a> implemented this past August &#8211; though its laws are not as comprehensive as the EU act. China has been <a href="https://www.reuters.com/technology/chinas-slow-ai-roll-out-points-its-tech-sectors-new-regulatory-reality-2023-07-12/">at the forefront of regulatory development</a> for the<a href="https://carnegieendowment.org/2023/07/10/china-s-ai-regulations-and-how-they-get-made-pub-90117"> past two years</a> while the Biden administration and the EU Parliament struggled to set boundaries around the technology as it advanced exponentially. China’s regulations smartly balance the need for safety and copyright protection while fostering a climate that supports innovation.</p>



<p class="wp-block-paragraph">The new American rules, some of which go into effect <a href="https://www.nytimes.com/2023/10/30/us/politics/biden-artificial-intelligence.html">in the next three months</a>, establishes reporting requirements &#8211; but no binding restrictions &#8211; for the <a href="https://federalnewsnetwork.com/commentary/2023/11/red-teams-watermarks-and-gpus-the-advantages-and-limitations-of-bidens-ai-executive-order/">computing hardware</a> required for advanced AI models. Like the EU rules, the American legislation addresses the technology’s ability to produce massive amounts of disinformation very quickly. The <a href="https://www.europarl.europa.eu/news/en/press-room/20231206IPR15699/artificial-intelligence-act-deal-on-comprehensive-rules-for-trustworthy-ai">press release</a> announcing the EU act offers no details about the control mechanism for this concern. The American rules include <a href="https://www.theverge.com/2023/12/8/23991850/eu-ai-act-artificial-intelligence-regulation-provisional-deal-law-brussels">mandatory watermarking</a> of distorted photos and deep fake videos produced by AI systems.</p>



<p class="wp-block-paragraph">The PRC regulations, formally the <a href="https://www.cnbc.com/2023/07/13/china-introduces-rules-governing-generative-ai-services-like-chatgpt.html">Cyberspace Administration of China Generative AI Measures</a>, are, in some ways, more stringent than those of the EU In contrast to the EU and US approaches, which specifically target only high-risk AI models for government registration, China mandates <a href="https://time.com/6304831/china-ai-regulations/">all AI developers</a> register with a government-established <a href="https://beian.cac.gov.cn/#/index">algorithm registry</a>. This comprehensive registry in China collects detailed information about the training processes of algorithms. Additionally, it obliges AI developers to conduct and pass a security self-assessment.</p>



<h2 class="wp-block-heading">Robust enforcement</h2>



<p class="wp-block-paragraph">Of the three sets of regulations, the PRC’s offer the most robust enforcement mechanism &#8211; likely because this is the only set of laws already in effect. The PRC regulations mandate that generative AI services must not create material that encourages the overthrow of national sovereignty of any state, nor should they promote terrorism, extremism, ethnic hatred, violence or obscenity, including the dissemination of false and harmful content. This puts a cap on the output on PRC large language models.</p>



<p class="wp-block-paragraph">China’s AI legislation is also rooted in Beijing’s program of censorship and propaganda. For example, China forbids AI developers from creating chatbots that criticize the PRC &#8211; a law that <a href="https://www.reuters.com/technology/chinas-slow-ai-roll-out-points-its-tech-sectors-new-regulatory-reality-2023-07-12/">presents challenges</a> with self-learning large language models. These regulations force AI firms in China to enact content moderation as rigorously and subjectively as Chinese social media platforms do.</p>



<p class="wp-block-paragraph">This kind of suppression embedded in the PRC regulations contrasts with the principles upheld in liberal democracies. Engaging with Chinese regulatory authorities toward a global AI law policy could inadvertently validate these severe policies on speech control, creating an international authoritarianism. A global set of standards must navigate the PRC’s internal state control with the democratic value of freedom of expression.</p>



<p class="wp-block-paragraph">The future of AI regulation will depend on the ability to adapt to rapidly evolving technologies and the changing global landscape. The experiences of China, the EU, and the U.S. in regulating AI offer a roadmap for developing adaptable international regulations. In all three cases, the regulations were years in development, modified as the technology advanced. Similarly, A global standard must be open to modification as self-learning systems advance.</p>



<p class="wp-block-paragraph">As with all forms of diplomacy, effective global governance of AI will also require continuous dialogue, exchange of ideas, and a willingness to learn from each other’s experiences.</p>



<p class="wp-block-paragraph">The agreement on the EU AI Act, China’s readiness for international cooperation on AI governance and the new U.S. rules memorialized in the president’s executive order represent a pivotal moment in the history of AI This convergence offers an opportunity to frame the future of a technology that will soon shape every aspect of society.</p>



<p class="wp-block-paragraph"><i>U.S. Army Colonel (retired) Joe Buccino serves as an advisor to the Center for AI Policy, a nonpartisan research organization that develops policy and conducts advocacy to mitigate risks from AI. His views do not necessarily reflect those of the U.S. Department of Defense or any other organization.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>Former soldier charged with trying to give classified info to China</title>
		<link>https://one.sightlinemg.com/c4isrnet/cyber/2023/10/08/former-soldier-charged-with-trying-to-give-classified-info-to-china/</link>
					<comments>https://one.sightlinemg.com/c4isrnet/cyber/2023/10/08/former-soldier-charged-with-trying-to-give-classified-info-to-china/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Sun, 08 Oct 2023 13:59:42 +0000</pubDate>
				<category><![CDATA[Battlefield Tech]]></category>
		<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Cyber Flag]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT and Networks]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/c4isrnet/uncategorized/2023/10/08/former-soldier-charged-with-trying-to-give-classified-info-to-china/</guid>

					<description><![CDATA[A former U.S. Army soldier has been charged with attempting to provide classified information to China's security services.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/c4isrnet/cyber/2023/10/08/former-soldier-charged-with-trying-to-give-classified-info-to-china/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">29959</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/the-gavel.jpg.jpg" width="6978" height="4237" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">SEATTLE — A former U.S. Army soldier has been charged with attempting to provide <a href="https://www.militarytimes.com/news/pentagon-congress/2023/04/13/deputy-defense-secretary-to-troops-dont-share-classified-information/" target="_blank">classified defense information</a> to the Chinese security services during the outbreak of the COVID-19 pandemic — including some listed in a Microsoft Word document titled “Important Information to Share with Chinese Government.”</p>



<p class="wp-block-paragraph">Authorities on Friday arrested former Sgt. Joseph Daniel Schmidt, 29, at San Francisco International Airport as he arrived from Hong Kong, where he had been living since March 2020, the Justice Department said. A federal grand jury in Seattle <a href="https://www.justice.gov/opa/pr/former-soldier-indicted-attempting-pass-national-defense-information-peoples-republic-china" target="_blank">returned an indictment Wednesday</a> charging him with retention and attempted delivery of national defense information.</p>



<p class="wp-block-paragraph">A public defender assigned to represented Schmidt at a brief appearance at U.S. District Court in San Francisco on Friday pending his transfer to Washington state did not immediately return an email seeking comment. U.S. District Court records in Seattle did not list an attorney representing Schmidt on the charges, and neither the U.S. attorney’s office nor the federal public defender’s office had information about whether he had a lawyer, representatives said.</p>



<p class="wp-block-paragraph">An FBI declaration filed in the case quoted Schmidt as telling his sister in an email that he left the U.S. because he disagreed with unspecified aspects of American policy.</p>



<p class="wp-block-paragraph">“I don’t talk about it often, but I learned some really terrible things about the American government while I was working in the Army, and I no longer feel safe living in America or like I want to support the American government,” he was quoted as writing.</p>



<p class="wp-block-paragraph">Schmidt spent five years in active duty in the Army, where he was primarily assigned to the 109th Military Intelligence Battalion at Joint Base Lewis-McChord in Washington state, according to a declaration filed in U.S. District Court by FBI Special Agent Brandon Tower. He eventually became a team leader on a human intelligence squad, and he had access to secret and top secret defense information, Tower wrote.</p>



<p class="wp-block-paragraph">Schmidt left active duty in January 2020 and traveled the next month to Istanbul, where he sent an email to the Chinese consulate trying to set up a meeting, Tower wrote.</p>



<p class="wp-block-paragraph">“I am a United States citizen looking to move to China,” the email said, according to the declaration. “I also am trying to share information I learned during my career as an interrogator with the Chinese government. I have a current top secret clearance, and would like to talk to someone from the Government to share this information with you if that is possible. &#8230; I would like to go over the details with you in person if possible, as I am concerned with discussing this over email.”</p>



<p class="wp-block-paragraph">It was the first of several attempts to share information with the People’s Republic of China, Tower wrote. Two days later, he drafted a Word document titled “Important Information to Share with Chinese Government” that included classified information related to national defense; investigators recovered it from his Apple iCloud account, the declaration said.</p>



<p class="wp-block-paragraph">After returning to the U.S. from Turkey in March 2020, he left a few days later for Hong Kong, where he had been living ever since, the declaration said.</p>



<p class="wp-block-paragraph">Over the next few months, Tower wrote, Schmidt emailed two state-owned enterprises in <a href="https://www.militarytimes.com/flashpoints/china/" target="_blank">China</a>, including a subsidiary of the China Aerospace Science and Industry Corporation Limited that has produced intelligence-gathering software tools.</p>



<p class="wp-block-paragraph">He offered to provide an encryption key he had retained for accessing the Army’s classified information network and related databases, known as the Secret Internet Protocol Router Network, or SIPR, Tower wrote, and he suggested it could be reverse-engineered to help China access the network.</p>



<p class="wp-block-paragraph">“It is a very rare card to find outside of the intelligence community, and if used properly, it can improve China’s ability to access the SIPR network,” the declaration quoted him as writing.</p>



<p class="wp-block-paragraph">The declaration did not describe any response from the state-owned enterprises or China’s security services.</p>



<p class="wp-block-paragraph">Meanwhile, Schmidt was trying to obtain legal immigration status in Hong Kong after overstaying a visitor visa, an effort that may have been hindered by the pandemic, Tower wrote.</p>



<p class="wp-block-paragraph">“Members of our military take a sworn oath to defend our country and the Constitution,” Seattle U.S. Attorney Tessa Gorman said in a news release Friday. “The alleged actions of this former military member are shocking — not only attempting to provide national defense information, but also information that would assist a foreign adversary to gain access to Department of Defense secure computer networks.”</p>



<p class="wp-block-paragraph">The charges carry up to 10 years in prison and a $250,000 fine.</p>
]]></content:encoded>
	</item>
		<item>
		<title>A sensible approach to AI regulation</title>
		<link>https://one.sightlinemg.com/c4isrnet/it-networks/2023/07/14/a-sensible-approach-to-ai-regulation/</link>
					<comments>https://one.sightlinemg.com/c4isrnet/it-networks/2023/07/14/a-sensible-approach-to-ai-regulation/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Fri, 14 Jul 2023 12:40:55 +0000</pubDate>
				<category><![CDATA[Battlefield Tech]]></category>
		<category><![CDATA[Cyber Flag]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT and Networks]]></category>
		<category><![CDATA[IT/Networks]]></category>
		<category><![CDATA[Opinion]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/c4isrnet/uncategorized/2023/07/14/a-sensible-approach-to-ai-regulation/</guid>

					<description><![CDATA[Humans will use AI as a co-pilot to make them more efficient in unwanted or criminal digital behavior, like cyberattacks or misinformation campaigns.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/c4isrnet/it-networks/2023/07/14/a-sensible-approach-to-ai-regulation/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">33221</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-1080200064-1.jpg.jpg" width="3500" height="2334" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Americans have watched as AI systems <a href="https://www.theverge.com/2018/7/26/17615634/amazon-rekognition-aclu-mug-shot-congress-facial-recognition">incorrectly matched 28 members</a> of Congress to criminal mugshots, <a href="https://time.com/5520558/artificial-intelligence-racial-gender-bias/">demonstrated bias</a> against women and people of color, and caused a lawyer to <a href="https://arstechnica.com/tech-policy/2023/05/lawyer-cited-6-fake-cases-made-up-by-chatgpt-judge-calls-it-unprecedented/">inadvertently cite fake cases</a>.</p>



<p class="wp-block-paragraph">In a recent MITRE-Harris Poll survey, most Americans <a href="https://www.mitre.org/news-insights/news-release/mitre-harris-poll-finds-lack-trust-among-americans-ai-technology">expressed reservations about AI for high-value applications</a> such as autonomous vehicles, accessing government benefits, and healthcare. Only 48% believe AI is safe and secure, and 78% are very or somewhat concerned that AI can be used for malicious intent. And 82% percent are in favor of government regulation for AI.</p>


	<aside class="smg-interstitial-link wp-block-smg-interstitial-link">
		<a href="https://one.sightlinemg.com/c4isrnet/artificial-intelligence/2023/07/05/us-military-calls-for-better-weapons-to-fight-artificial-intelligence/" class="smg-interstitial-link__inner">
							<div class="smg-interstitial-link__media">
					<img decoding="async" width="300" height="225" src="https://one.sightlinemg.com/wp-content/uploads/2026/08/18_special_pentagon.jpg.jpg?w=300" class="smg-interstitial-link__image wp-post-image" alt="" />				</div>
						<div class="smg-interstitial-link__content">
				<span class="smg-interstitial-link__kicker">Related</span>
				<h3 class="smg-interstitial-link__title">US military calls for better weapons to fight artificial intelligence</h3>
									<p class="smg-interstitial-link__excerpt">The fight in Ukraine has underscored just how effective smart tech accessible to anyone may be in neutralizing the elaborate tools of conventional warfare.</p>
							</div>
		</a>
	</aside>
	


<p class="wp-block-paragraph">Even Sam Altman, CEO of OpenAI, the company behind ChatGPT, <a href="https://blog.samaltman.com/machine-intelligence-part-2">has called for regulation</a>.</p>



<p class="wp-block-paragraph">The rapid growth of large language models (LLMs) like ChatGPT have changed how people view AI. It has become anthropomorphized and viewed as a standalone entity with its own agency and objectives. This is very different than only a year ago when AI was understood by most to be smart software that lived inside a digital system. When contemplating an approach to AI regulation, it is helpful to treat these two models differently.</p>



<p class="wp-block-paragraph">For AI as a component within an engineered system, AI assurance–assuring that an AI application does what it’s expected to without unacceptable risks, and in the right context at the right time–is the name of the game. As with any software component, we need testing and validation that verifies things like robustness, security, and correctness. The best equipped to evaluate these attributes are the existing regulators who already have responsibility for relevant industries like healthcare or critical infrastructure. These regulators would be the right group to evaluate risk within the context of their own industry norms.</p>



<p class="wp-block-paragraph">However, this new domain of LLMs with human-like behaviors and understanding requires a different approach. There are a few scenarios to consider.</p>



<p class="wp-block-paragraph">First, humans will use AI as a co-pilot to make them more efficient in unwanted or criminal digital behavior, like cyberattacks or misinformation campaigns. While the LLM here is an enabler, the human ultimately remains responsible for their AI-augmented actions in cyberspace. We must ensure we can prevent, defend, remediate, and attribute these actions— much as we do today—but at what will likely become a larger scale.</p>



<p class="wp-block-paragraph">Second, humans will give agentic AI systems malicious goals. For example, AgentGPT is an instance of GPT with internet access that attempts to execute a high-level task by developing and executing a series of derivative tasks. ChaosGPT is an instance of AgentGPT tasked with exterminating humanity. Fortunately, ChaosGPT has not made much progress in hacking into any national nuclear arsenals, but it represents a hyperbolic example of what may come. Expect criminal ransomware groups to begin using these tools in the near future.</p>



<h2 class="wp-block-heading">Human accountability</h2>



<p class="wp-block-paragraph">Addressing this scenario, solutions include holding accountable the human who gave the system the malicious goal and continuing to increase the assurance level of critical digital infrastructure to prevent AI-orchestrated network intrusions from being successful. Interfaces where AI is deliberately connected to such systems should also be carefully regulated.</p>



<p class="wp-block-paragraph">Third, there is considerable concern around AI systems that inadvertently establish their own sub goals that could be unintentionally dangerous. While this may occur, it is just as, if not more likely, that malicious humans will give AI dangerous sub goals. Thus, the solutions to this scenario are the same as the above example.</p>



<p class="wp-block-paragraph">A few other thoughts on how we can avoid potential dangers with AI technologies without choking innovative research and development:</p>



<p class="wp-block-paragraph">— Best practices and regulatory standards that apply to traditional software should also extend to AI components. However, it’s important to acknowledge that AI software may introduce unique vulnerabilities that demand assurance measures, including testing standards, standardized code development practices, and rigorous validation frameworks.</p>



<p class="wp-block-paragraph">— Regulated industries should develop a response plan based on the National Institute of Standards and Technology (NIST) AI Risk Management Framework. Compliance with the NIST framework should be the starting point for identifying potential regulatory approaches in these industries.</p>



<p class="wp-block-paragraph">— Development of “assurance cases” prior to deployment would provide documented evidence of a system’s compliance with critical assurance properties and behavior boundaries.</p>



<p class="wp-block-paragraph">— For AI intended to augment human capabilities, regulation should prioritize system transparency and auditability. Holding individuals accountable for intentionally misusing AI to cause harm requires documenting their intent and execution of such intent.</p>



<p class="wp-block-paragraph">We can complement regulatory efforts with more investment in research to create a common vocabulary and frameworks for AI alignment that will guide future research efforts, ensuring that advancements in AI align with human values and societal well-being. And it’s essential that we invest more in R&amp;D to automatically detect fake content.</p>



<p class="wp-block-paragraph">The AI revolution is moving so rapidly that we can’t wait long to address these concerns. If we act now, creating the baseline regulations for AI assurance, we can ensure that AI technologies operates in a safe and accountable manner. We need thoughtful regulation that balances innovation with risk mitigation to harness the full potential of AI while safeguarding our society.</p>



<p class="wp-block-paragraph"><a href="https://www.mitre.org/who-we-are/our-people/charles-clancy"><i>T. Charles Clancy</i></a><i> is a senior vice president at MITRE, where he serves as general manager for MITRE Labs and chief futurist. This article is adapted from the recently published paper, “</i><a href="https://www.mitre.org/news-insights/publication/sensible-regulatory-framework-ai-security"><i>A Sensible Regulatory Framework for AI Security</i></a><i>.”</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>Hyper-enabling special ops will transform missions</title>
		<link>https://one.sightlinemg.com/c4isrnet/cyber/2023/05/10/hyper-enabling-special-ops-will-give-transform-missions/</link>
					<comments>https://one.sightlinemg.com/c4isrnet/cyber/2023/05/10/hyper-enabling-special-ops-will-give-transform-missions/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Wed, 10 May 2023 20:13:12 +0000</pubDate>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Cyber Flag]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT and Networks]]></category>
		<category><![CDATA[Newsletters]]></category>
		<category><![CDATA[Robotics]]></category>
		<category><![CDATA[UAS]]></category>
		<category><![CDATA[Unmanned]]></category>
		<category><![CDATA[Unmanned Systems]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/c4isrnet/uncategorized/2023/05/10/hyper-enabling-special-ops-will-give-transform-missions/</guid>

					<description><![CDATA[New tech for language and text translation, as well as secure data transfer, gives operators an edge.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/c4isrnet/cyber/2023/05/10/hyper-enabling-special-ops-will-give-transform-missions/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">36397</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/skyline-spec-ops.jpg.jpg" width="6707" height="4471" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">TAMPA, Fla. — As <a href="https://www.defensenews.com/industry/techwatch/2023/05/09/this-socom-program-has-cut-proposal-to-prototype-timelines-by-half/" target="_blank">special operations teams</a> weave their way across more than 80 countries, they face daunting challenges, often without the <a href="https://www.defensenews.com/smr/sofic/2023/05/09/special-ops-turn-to-data-space-tech-to-gain-decisive-advantage/" target="_blank">high-level support</a> they saw in previous conflicts.</p>



<p class="wp-block-paragraph">Leaders such as Army Col. Jarrett Mathews, <a href="https://www.militarytimes.com/smr/sofic/2022/05/18/special-operators-need-counter-drone-counter-ied-tech-in-a-smaller-package/" target="_blank">acquisition </a>director of the SOCOM task force over the “hyper-enabled operator,” seek new tech to give even individuals the assets they need to see, sense, act and react to ever-changing conditions on the ground.</p>



<p class="wp-block-paragraph">Mathews showed the audience here at the Global SOF Foundation’s SOF Week not a bearded, muscled operator kicking in doors and shooting but a business suit-clad “operator” navigating the streets of a foreign nation, deciphering spoken language, signage and even graffiti to sus out threats while running their mission.</p>



<p class="wp-block-paragraph">Prompted by an audience question, Mathews outlined a no-limits picture of what he’d love to put in that operator’s hands.</p>



<p class="wp-block-paragraph">“I would like a fully-capable, human-machine teaming with an information system that had access to the whole of the Internet,” Mathews said.</p>



<p class="wp-block-paragraph">The colonel isn’t delusional, he knows that technology isn’t here yet, but Mathews and his team are looking to industry to make it a reality.</p>



<p class="wp-block-paragraph">“We want these operators to be super users of their environment,” Mathew said.</p>



<p class="wp-block-paragraph">The concept went public nearly three years ago, Defense News sister publication <a href="https://www.c4isrnet.com/battlefield-tech/2020/06/12/making-the-hyper-enabled-operator-a-reality/" target="_blank">C4ISRNET</a> previously reported. Since then, the team that Mathew now leads has advanced the language processing capabilities of its voice-to-voice program and started work on translating text via smartphone photo capture and eventually through other devices.</p>



<p class="wp-block-paragraph">The voice-to-voice program is currently deployed in two undisclosed theaters of operation, Mathews told the crowd. And they’re working now to add languages to the software.</p>



<p class="wp-block-paragraph">The team has also begun development on an augmented reality piece for viewing the environment with layers of data.</p>



<p class="wp-block-paragraph">And he’s got some proof that they’re on the right path. As part of their program, the team set out to create a secure capability that can operate without Internet access called “Voice to Voice Language Translation.” The translation allows the user to speak into a smartphone and the software will translate that speech into the desired language and “speak” it aloud.</p>



<p class="wp-block-paragraph">The team took a calculated risk in trying to demonstrate the software earlier in the day following the morning keynote address. It was clunky, not exactly translating word for word, and required some tech support – a signal that more work is needed.</p>



<p class="wp-block-paragraph">But Mathews later noted that work with the Stanford Research Institute has allowed base-level translation on smart devices disconnected from the Internet with a higher quality than Google Translate.</p>



<p class="wp-block-paragraph">The next phase is the Visual Environment Translation, through which a camera can decipher text, even graffiti, which is still in its nascent stages.</p>



<p class="wp-block-paragraph">Using augmented reality technology, the team also looks to get past tourist-like smartphone photographing, which can draw attention. Instead, they would embed these features into something more inconspicuous, such as a Google Glass-like device that a user could wear, Mathews said.</p>



<p class="wp-block-paragraph">For that operator running in an austere area with little access, or unsecured access to cloud computing, Mathews and his staff are pushing the boundaries of “edge computing” through a combination of radio frequency sensors and secure video/imagery “pipelines” that piggyback on existing WiFi and Bluetooth networks.</p>



<p class="wp-block-paragraph">Working as kind of a second brain for the user, Mathews office is developing an “automate the analyst” program. The program aims to help users have not only those voice and text options but feeds from mapping software, social media and other feeds to have a clear picture on what’s happening around them.</p>



<p class="wp-block-paragraph">The goal is to have all of that without the ever-present hovering “eye-in-the-sky” drones that may not be an option on some of these very small footprint missions.</p>
]]></content:encoded>
	</item>
		<item>
		<title>‘Stone Ghost’ secret intel network may expand to more nations: DIA</title>
		<link>https://one.sightlinemg.com/c4isrnet/cyber/2023/03/29/stone-ghost-secret-intel-network-may-expand-to-more-nations-dia/</link>
					<comments>https://one.sightlinemg.com/c4isrnet/cyber/2023/03/29/stone-ghost-secret-intel-network-may-expand-to-more-nations-dia/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Wed, 29 Mar 2023 14:16:02 +0000</pubDate>
				<category><![CDATA[AI & ML]]></category>
		<category><![CDATA[Battlefield Tech]]></category>
		<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Cyber Flag]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT and Networks]]></category>
		<category><![CDATA[IT/Networks]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/c4isrnet/uncategorized/2023/03/29/stone-ghost-secret-intel-network-may-expand-to-more-nations-dia/</guid>

					<description><![CDATA[The system is used to share intelligence among “Five Eyes” partners, but DIA wants the ability to add and remove other users "on the fly."]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/c4isrnet/cyber/2023/03/29/stone-ghost-secret-intel-network-may-expand-to-more-nations-dia/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">33045</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/230322-D-SG895-0014.JPG.jpg" width="2100" height="1500" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">WASHINGTON — The U.S. Defense Intelligence Agency plans to upgrade its international intelligence-sharing system to allow more seamless collaboration with a broader coalition of allies.</p>



<p class="wp-block-paragraph">DIA uses the top-secret system to communicate with and share intelligence among the U.S. and its Five Eyes partners — the U.K., Australia, New Zealand and Canada. Chief Information Officer Doug Cossa told reporters the agency will begin designing an upgrade to Stone Ghost in fiscal 2024 to allow information to be shared with more countries as needed.</p>



<p class="wp-block-paragraph">“The idea is to add and remove coalitions based on the intelligence problem set that we’re uniquely focused on collectively,” Cossa said during a March 23 briefing at DIA headquarters in Washington. “That’s really where the focus of those modernization efforts will go: [H]ow do you add and remove partners on the fly?”</p>



<p class="wp-block-paragraph">The agency has the ability to share information with other countries, but doing so requires a separate system. As the Defense Department’s lead organization for open-source intelligence, DIA processes an increasing amount of data, Cossa said, and being able to maintain that information seamlessly and quickly within a single network is important.</p>



<p class="wp-block-paragraph">DIA operates more than a dozen international information systems, including Stone Ghost. Cossa said the agency is increasingly applying zero-trust principles to those networks — a cybersecurity approach that emphasizes regular validation that every user, function and piece of hardware that connects to a system is authorized.</p>



<p class="wp-block-paragraph">That work partly relies on artificial intelligence to automate activity logs and evaluate trends, he said.</p>



<p class="wp-block-paragraph">“Traditionally we lock the doors and we lock the windows and we don’t worry about what’s going on inside,” Cossa said. “Zero trust is taking that same principle but applying it to our networks, meaning we’re not just locking the doors and windows, but we’re constantly revalidating and checking.”</p>
]]></content:encoded>
	</item>
		<item>
		<title>Taylor Swift-based passwords harm cybersecurity, report says</title>
		<link>https://one.sightlinemg.com/c4isrnet/cyber/2023/03/14/taylor-swift-based-passwords-harm-cybersecurity-report-says/</link>
					<comments>https://one.sightlinemg.com/c4isrnet/cyber/2023/03/14/taylor-swift-based-passwords-harm-cybersecurity-report-says/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Tue, 14 Mar 2023 16:51:42 +0000</pubDate>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Cyber Flag]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT and Networks]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/c4isrnet/uncategorized/2023/03/14/taylor-swift-based-passwords-harm-cybersecurity-report-says/</guid>

					<description><![CDATA[Swift’s highly anticipated 10th album “Midnights” resulted in many passwords including “taylor,” “swiftie” and “midnights.”]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/c4isrnet/cyber/2023/03/14/taylor-swift-based-passwords-harm-cybersecurity-report-says/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">24686</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/AP110919145463.jpg.jpg" width="4338" height="3036" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">If any of the passwords to your .gov account have a variation of a Taylor Swift song in them, you might want to hit the reset button.</p>



<p class="wp-block-paragraph">According to a new report by <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fspycloud.com%2F&#038;data=05%7C01%7Cjgould%40defensenews.com%7C5b4198d4a09a45fbbcc408db217a5961%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C0%7C638140581613892430%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&#038;sdata=EeFmOyfQEzK2V26eo7eU79%2FLd9LQTs8CPrbPMPEvuD8%3D&#038;reserved=0">SpyCloud</a>, a cybersecurity data analytics company, password reuse and log-in credentials based on words that are trendy in pop culture have the potential to jeopardize millions of data points and personally identifiable information.</p>



<p class="wp-block-paragraph">“The list of the most common exposed passwords associated with government emails is also a cause for concern: the top three are 123456, 12345678, and password,” it said.</p>



<p class="wp-block-paragraph">Federal IT systems support a vast array of public services that store information on government personnel, finances, national security and personal health. For several years, as hackers have become more sophisticated and military operations have staked more cyber real estate, the government’s budget has proposed <a href="https://www.whitehouse.gov/wp-content/uploads/2022/03/ap_16_it_fy2023.pdf" target="_blank">billions</a> to shoring up digital security.</p>



<p class="wp-block-paragraph">The White House’s proposed spending plan for fiscal year 2024 outlays $74 billion for IT at civilian Federal agencies — a <a href="https://www.whitehouse.gov/wp-content/uploads/2023/03/ap_14_it_fy2024.pdf" target="_blank">13% increase from 2023</a> that would fund roughly 4,500 investments at 25 agencies.</p>


	<aside class="smg-interstitial-link wp-block-smg-interstitial-link">
		<a href="https://one.sightlinemg.com/federaltimes/federal-oversight/watchdogs/2023/01/10/1-in-5-government-passwords-were-cracked-by-interiors-own-hack/" class="smg-interstitial-link__inner">
							<div class="smg-interstitial-link__media">
					<img loading="lazy" decoding="async" width="300" height="169" src="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-1182226451.jpg.jpg?w=300" class="smg-interstitial-link__image wp-post-image" alt="" />				</div>
						<div class="smg-interstitial-link__content">
				<span class="smg-interstitial-link__kicker">Related</span>
				<h3 class="smg-interstitial-link__title">1 in 5 government passwords were cracked by Interior’s own hack</h3>
									<p class="smg-interstitial-link__excerpt">Find out if you&#039;re using the most common password at the department.</p>
							</div>
		</a>
	</aside>
	


<p class="wp-block-paragraph">Drilling down into that funding pool, the President’s Budget includes approximately $13 billion of budget authority for civilian cybersecurity-related activities.</p>



<p class="wp-block-paragraph">However, cybersecurity can be beefed up with simple, virtually costless measures like fortifying passwords as a first line of defense.</p>



<p class="wp-block-paragraph">Data from SpyCloud shows a nearly 72% password reuse rate for users who were exposed in two or more cyber breaches in the last year, an eight point increase from last year.</p>



<p class="wp-block-paragraph">“Government employees also show the same poor hygiene habits as their peers in the private sector,” it said. “Password reuse by government employees remains high – 61% of users with more than one password exposed in the last year were guilty of reusing passwords across multiple accounts.”</p>



<p class="wp-block-paragraph">Within a sample of government contractors, it also found 24,000 malware infections exposing plaintext passwords and admin credentials.</p>



<p class="wp-block-paragraph">Overall, cybersecurity incidents within government grew by 95% globally in 2022, with China, India and the U.S. as the most targeted. The same year, there were 695 breaches containing .gov emails, up 14% from the year before.</p>



<p class="wp-block-paragraph">Because passwords can play such an outsized role in whether a breach is successful, the report also noted a general phenomenon in the private and public sector wherein passwords reflect whatever is trending in popular culture.</p>



<p class="wp-block-paragraph">For example, what topped the music charts also topped the list of exposed passwords, SpyCloud found. Taylor Swift’s highly anticipated 10th album “Midnights” resulted in many passwords like “taylor,” “swiftie” and “midnights.” Bad Bunny was Spotify’s most-streamed artist in 2022 and inspired passcodes related to his most popular songs.</p>



<p class="wp-block-paragraph">“As expected, top recaptured popular passwords also included russia/russian war, ukraine/ukraine war, and trump,” the report said.</p>
]]></content:encoded>
	</item>
		<item>
		<title>Lessons from tech industry can curb digital fratricide on battlefield</title>
		<link>https://one.sightlinemg.com/c4isrnet/opinion/2022/08/12/lessons-from-tech-industry-can-curb-digital-fratricide-on-battlefield/</link>
					<comments>https://one.sightlinemg.com/c4isrnet/opinion/2022/08/12/lessons-from-tech-industry-can-curb-digital-fratricide-on-battlefield/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Fri, 12 Aug 2022 12:52:04 +0000</pubDate>
				<category><![CDATA[5G]]></category>
		<category><![CDATA[Battlefield Tech]]></category>
		<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Cyber Flag]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[IT and Networks]]></category>
		<category><![CDATA[IT/Networks]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Thought Leadership]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/c4isrnet/uncategorized/2022/08/12/lessons-from-tech-industry-can-curb-digital-fratricide-on-battlefield/</guid>

					<description><![CDATA[There are impactful operating system techniques, like “compute orchestration,” that effectively turn a dozen cell phones into one single supercomputer.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/c4isrnet/opinion/2022/08/12/lessons-from-tech-industry-can-curb-digital-fratricide-on-battlefield/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">9490</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/635588129108039622-arm-bct-shuffle-1jpg.jpg" width="4128" height="2322" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">The more the U.S. military leans on wireless networks, the more congested they become. Unfortunately, the modern battlefield is experiencing critical system outages – with troops increasingly at risk – because we are unintentionally jamming our own networks.</p>



<p class="wp-block-paragraph">This digital fratricide is not a problem that can be solved by radio discipline or rationing commanders’ access to live video feeds.</p>



<p class="wp-block-paragraph">Instead, the solutions need to be baked in from the start by Department of Defense acquisition staff that demand products be designed and built to intelligently sip, not guzzle, precious bandwidth.</p>



<p class="wp-block-paragraph">On America’s frontlines, the internal <a href="https://www.defenseone.com/technology/2019/10/weapons-makers-unveil-herd-robotanks-army-worries-about-battlefield-bandwidth/160618/">battle over bandwidth</a> has reached a critical mass. In response to Russia’s invasion of Ukraine, every military branch is pouring an immense amount of money into high-tech drones with high-definition cameras. Unfortunately, every time a General wants to see the enemy in 4K HD video, mesh networks become so congested that frontline warfighters cannot communicate with each other on conventional radios. Fortunately, American tech companies have already deployed commercial solutions to solve the problem.</p>



<p class="wp-block-paragraph">Self-driving cars, for example, generate far more data than even the most reliable 5G network can handle. In the early days of autonomous vehicles, software engineers had to hand-carry large hard drives on and off the cars on a “sneakernet” just to be able to analyze a day’s route. In time, engineers advanced a concept known as “data decimation” where only the relevant data segments and alerts would have to be extracted from a car, thus becoming more efficient with the network’s scarce resources.</p>



<p class="wp-block-paragraph">Beyond autonomous vehicles, the video game industry has already partnered with hardware manufacturers to bring the power of the Cloud into disconnected devices, which eliminates another tax on networks. Industry calls this method ‘edge computing’ and Pentagon leadership <a href="https://www.defense.gov/News/News-Stories/Article/Article/2665133/dod-budget-request-focused-on-innovations-for-warfighter-hicks-says/">frequently speak about</a> the need for greater intelligence at the tactical edge. But both the defense and tech world are talking about the same solution: the objective is to avoid bandwidth overload by colocating artificial intelligence and machine learning software within handheld devices, robots, and sensors.</p>



<p class="wp-block-paragraph">There are equally impactful operating system techniques, like “compute orchestration,” that effectively turn a dozen cell phones into one single supercomputer when linked on a secure platform. These practices need to be enforced as a technological standard for the battlefield internet of things; however, such techniques are only now being considered in the Department of Defense.</p>



<p class="wp-block-paragraph">There are three major obstacles preventing these solutions from being adopted in time to maintain America’s competitive advantage in the AI arms race.</p>



<p class="wp-block-paragraph">The first is the assumption that old techniques can solve new battlefield problems. Senior leaders and prime vendors <a href="https://breakingdefense.com/2021/11/networks-as-center-of-gravity-project-convergence-highlights-militarys-new-battle-with-bandwidth/">appear surprised</a> that the network is suffering through major bandwidth constraints, and current mitigation measures are focused on the promise of <a href="https://www.cto.mil/5g/">5G</a>. Even so, it is prohibitively difficult and expensive to deploy new cell towers in austere environments. Furthermore, those towers won’t help much when communications are actively contested by a highly effective, $100 radio jammer.</p>



<p class="wp-block-paragraph">The second obstacle is awareness. The Pentagon must have an understanding of the problems already solved by America’s innovative tech experts so the commonplace solutions can be fed into the Defense Department’s requirements process. The National Security Commission on AI’s <a href="https://www.nscai.gov/wp-content/uploads/2021/03/Full-Report-Digital-1.pdf">Final Report</a> made it very clear that the Department is not moving fast enough, and the widening gap between what’s revolutionary in U.S. Defense and what’s common in the tech industry has reached a crisis point.</p>



<p class="wp-block-paragraph">More specifically, it has taken 10 years for the Defense Department to get savvy on the “<a href="https://www.defenseone.com/feature/clouds-of-war/">Clouds of War</a>.” But even though those programs are just starting to get organized on their requirements, the industrial world has already started to shift computing back to the tactical edge, and we cannot afford to wait another 10 years for the Pentagon’s buyers to catch up.</p>



<p class="wp-block-paragraph">The final obstacle is the incongruity of software and the Defense Department’s procurement system. The U.S. government has spent decades optimizing procurement around physical things and billable hours. As a result, the best GovTech software today ends up being bundled in hardware or a “black box” (like a slick new drone).</p>



<p class="wp-block-paragraph">Unfortunately, the natural side-effect has been an explosion of vendor lock-in and data silos, which prevents the best software from getting into the hands of the warfighters at the point of need. Instead, program executive offices tasked by Congress to procure these essential technologies should strive to unbundle hardware and software so that interoperability can liberate the tactical edge from data silos.</p>



<p class="wp-block-paragraph">Everyone close to the Defense Department’s data challenges understands the features of digital fratricide. A solution is within reach if we can build consensus and drive action to deploy industrial techniques like data decimation, edge computing, and compute orchestration to protect the networks that our warfighters rely upon. And it is incumbent on the Pentagon’s acquisition officials to empower those serving at our nation’s frontlines.</p>



<p class="wp-block-paragraph"><i>Ian Kalin is the Chief Executive of TurbineOne. He spent the last twenty years focused on modernizing government technology and was the first Chief Data Officer for the U.S. Department of Commerce.</i></p>
]]></content:encoded>
	</item>
		<item>
		<title>Cyber Flag exclusive: What Cyber Command learns from the annual exercise</title>
		<link>https://one.sightlinemg.com/c4isrnet/cyber/2017/07/05/cyber-flag-exclusive-what-cyber-command-learns-from-the-annual-exercise/</link>
					<comments>https://one.sightlinemg.com/c4isrnet/cyber/2017/07/05/cyber-flag-exclusive-what-cyber-command-learns-from-the-annual-exercise/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Wed, 05 Jul 2017 09:00:00 +0000</pubDate>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Cyber Flag]]></category>
		<category><![CDATA[IT and Networks]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/c4isrnet/uncategorized/2017/07/05/cyber-flag-exclusive-what-cyber-command-learns-from-the-annual-exercise/</guid>

					<description><![CDATA[U.S. Cyber Command is applying lessons learned from operations and training exercises to refine the deployment of cyber teams and effects.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/c4isrnet/cyber/2017/07/05/cyber-flag-exclusive-what-cyber-command-learns-from-the-annual-exercise/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">15247</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/cyber-global.jpg.jpg" width="4752" height="3168" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">U.S. Cyber Command is still a relatively young organization. It was stood up in 2009, and while the organization reached full operational capability in 2010, its workforce isn&#8217;t slated to hit this mark until September 2018.<br/><br/>As such, the command is learning lessons from training exercises and operations pertaining to its structure, the structure of its teams, how to deploy teams and how to conduct operations.<br/><br/>During an <a class="" href="http://www.c4isrnet.com/articles/an-exclusive-peek-inside-cyber-commands-premiere-annual-exercise" target="_blank" title="Link: null">exclusive walk-through of CYBERCOM&#8217;s annual Cyber Flag exercise</a>, the simulation&#8217;s leaders told C4ISRNET that they identified specific, applicable lessons at last year&#8217;s Cyber Flag pertaining to the way defensive teams are deployed to problem sets.<br/><br/><i>[</i><a class="title-link" href="http://www.c4isrnet.com/articles/an-exclusive-peek-inside-cyber-commands-premiere-annual-exercise" target="_blank" title="Link: http://www.c4isrnet.com/articles/an-exclusive-peek-inside-cyber-commands-premiere-annual-exercise"><i><b>An exclusive peek inside Cyber Command&#8217;s premiere annual exercise</b></i></a><i>]</i><br/><br/>Top leaders from CYBERCOM have recently indicated they&#8217;ve discovered it&#8217;s not always necessary to deploy the entirety of a cyber protection team, or CPT.<br/><br/>&#8220;One of the things we found with practical experience is we can actually deploy in smaller sub elements, use reach-back capability, the power of data analytics; we don&#8217;t necessarily have to deploy everyone,&#8221; Adm. Michael Rogers, the commander of CYBERCOM, <a href="http://www.c4isrnet.com/articles/what-defense-leaders-are-now-willing-to-tell-us-about-offensive-cyber-ops" target="_blank" title="Link: http://www.c4isrnet.com/articles/what-defense-leaders-are-now-willing-to-tell-us-about-offensive-cyber-ops">told</a> the House Armed Services Committee in May. &#8220;We can actually work in a much more tailored, focus[ed] way optimized for the particular network challenge that we&#8217;re working. We&#8217;re actually working through some things using this on the Pacific at the moment.&#8221;<br/><br/> <i>[</i><b><i><a class="" href="http://www.c4isrnet.com/articles/what-defense-leaders-are-now-willing-to-tell-us-about-offensive-cyber-ops" target="_blank" title="Link: null">What defense leaders (are now willing to) tell us about offensive cyber ops</a></i></b><i>]</i><br/><br/> &#8220;You would send a smaller group forward and then do whatever analytic work or analysis you need to do back at home base, be it Fort Gordon or San Antonio or Hawaii or reach back and do some of that work there,&#8221; Brig. Gen. Maria Barrett, deputy of operations J-3 at CYBERCOM, <a href="http://fifthdomain.com/2017/06/01/cyber-command-reevaluating-defensive-cyber-tools/" target="_blank" title="Link: http://fifthdomain.com/2017/06/01/cyber-command-reevaluating-defensive-cyber-tools/">said</a> during a keynote address in early June. &#8220;That kind of facilitates us being a little bit more agile and quick.&#8221;<br/><br/> &#8220;From that lesson, our branch at Cyber Command has said now that we&#8217;ve seen that lesson at an exercise, let&#8217;s bring in the mission force experts and figure out how we craft our doctrine to reflect operations,&#8221; said an exercise leader, who like most leaders and participants to which C4ISRNET spoke would only comment on condition of anonymity. &#8220;There&#8217;s real traction that happens from these lessons learned.&#8221;<br/><br/>The command, however, is not necessarily looking to re-evaluate the makeup of teams. Despite the large nature of CPTs, which are typically made up of 39 personnel, even if a subset of that team can deploy to a problem, depending on the nature or difficulty, the entire team might be needed later.<br/><br/>&#8220;You need the full cadre of folks to be able to crate those small reaction forces, and then should they have to go on a full 24/7 mission where there are constant shift changes, you&#8217;re going to need that whole body,&#8221; an exercise lead told C4ISRNET.<br/><br/>A forward element might go out and start working on a mission and determine the whole team is needed to do the mission, the exercise lead continued. Or, the official added, the team might do a lot of reach-back, saying: &#8221; &#8216; Here, take this, help me figure it out,&#8217; and they have that connection.&#8221;<br/><br/>The official noted the model might not be wrong, but what&#8217;s being learned though these exercises is employing it the best way possible.<br/><br/>Teams also bring real kits to this exercise, something they haven&#8217;t done too much prior, one of the exercise leads said.<br/><br/>One kit currently used by CPTs — the Deployable Mission Support System, which consists of laptops, passive and active sensors, and analytic capability provided via either government or commercial off-the-shelf, or free and open software — is being re-evaluated by the command, Barrett said, because the kit&#8217;s requirements document was published in January 2016 before most of the CPTs had reached full operational capability.<br/><br/>Every service has a different type of kit, despite CYBERCOM producing a standard requirements document that all of kits must meet standard baseline requirements, Navy Lt. John Allen, CYBERCOM J35 Department of Defense Information Network operations CPT engagement lead, said during a June conference.<br/><br/>What exists today are four types of kits, each usually with its own specific suite of tools that all meet the requirements, which does present some interoperability challenges, but the command is working toward rectifying those, Allen said.<br/><br/><b><a class="" href="http://fifthdomain.com/2017/06/01/cyber-command-reevaluating-defensive-cyber-tools/" target="_blank" title="Link: null"><i>[Cyber Command reevaluating defensive cyber tools</i></a></b><i>]</i><br/><br/>Based upon ongoing operations and field studies, Barrett acknowledged that this needed to be revisited.<br/><br/>As practice makes perfect, a Cyber Flag exercise lead said one of the critical lessons brought back to leadership involved one of the hardest things they do in real-world missions: the logistics of getting people and kits from one place to another. This is something they actually have to do at Cyber Flag, too, the exercise lead explained. That ends up being a real lesson because of the paperwork and asset movement involved, which may sound mundane but has real consequences if not done correctly, C4ISRNET was told.<br/><br/>Additional lessons provided to leadership helped identify gaps and policy that can feed and inform higher levels as well as discern some of the decisions that can be made to push down to the teams to enable operations, another exercise lead noted.<br/><br/>So what&#8217;s next for Cyber Flag once the cyber mission force reaches full operational capability in 2018?<br/><br/>There were &#8220;some heated discussions about that just the other day because we have to adjust to meet not just certification but readiness,&#8221; one exercise lead said.<br/><br/>The model is different, the official continued, when doing certification and giving the teams tests to evaluate performance as opposed to being able to provide them readiness training so they&#8217;re constantly ready and able to demonstrate performance.<br/><br/>While everybody today is essentially treated the same, they are looking at ways for some folks to perform certification and others to execute collaborative training. &#8220;We&#8217;re trying to figure that out,&#8221; the official said.<br/></p>
]]></content:encoded>
	</item>
		<item>
		<title>Cyber Command leverages acquisition model of special operations group</title>
		<link>https://one.sightlinemg.com/c4isrnet/cyber/2017/07/03/cyber-command-leverages-acquisition-model-of-special-operations-group/</link>
					<comments>https://one.sightlinemg.com/c4isrnet/cyber/2017/07/03/cyber-command-leverages-acquisition-model-of-special-operations-group/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Mon, 03 Jul 2017 02:00:00 +0000</pubDate>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Cyber Flag]]></category>
		<category><![CDATA[IT and Networks]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/c4isrnet/uncategorized/2017/07/03/cyber-command-leverages-acquisition-model-of-special-operations-group/</guid>

					<description><![CDATA[With the new acquisition authorities Congress granted to U.S. Cyber Command, the nascent organization is emulating the buying model of U.S. Special Operations Command.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/c4isrnet/cyber/2017/07/03/cyber-command-leverages-acquisition-model-of-special-operations-group/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">15811</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/ready-set-connect.jpg.jpg" width="1000" height="668" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p><i>This is Part IV </i><i>of a four-part series exploring what U.S. Cyber Command will need to operate on its own, separate from the National Security Agency.</i><br/><br/>The Capabilities Development Group is overseeing U.S. Cyber Command’s limited acquisition authority recently provided by Congress.<br/><br/>&#8220;The Command generally lacks NSA’s authorities in acquiring the tools for such initiatives, but Congress recently authorized USCYBERCOM acquisition authority for up to $75 million each year through the end of FY2021 to rapidly deliver acquisition solutions for ‘cyber operations-peculiar’ capabilities,&#8221; Adm. Michael Rogers, the head of CYBERCOM, wrote in congressional testimony in May 2017. &#8220;We look forward to reporting to the Committee soon on how we are executing this authority.&#8221;<br/><br/>Congressional aides have noted that this acquisition model was taken from U.S. Special Operations Command, describing it as a crawl, walk, then run. SOCOM enjoys rapid acquisition authority, which CYBERCOM eventually could get to but must first prove itself.<br/><br/><b><a class="" href="http://www.c4isrnet.com/articles/what-is-needed-to-split-nsa-and-cyber-command" target="_blank" title="Link: null">PART I: What is needed to split NSA and Cyber Command?</a></b><br/><b><a class="" href="http://www.c4isrnet.com/articles/heres-what-cyber-commands-war-fighting-platform-will-look-like" target="_blank" title="Link: http://www.c4isrnet.com/articles/heres-what-cyber-commands-war-fighting-platform-will-look-like">PART II: Here’s what Cyber Command’s war-fighting platform will look like</a><br/></b><b><a class="" href="http://www.c4isrnet.com/articles/the-types-of-tools-an-independent-cyber-command-will-need" target="_blank" title="Link: null">PART III: The types of tools an independent Cyber Command will need</a></b><br/><br/>The Capabilities Development Group&#8217;s three-pronged mission includes planing and synchronizing capability development for the joint cyber force; developing capabilities in order to reduce risk or meet urgent operational needs; and maintaining CYBERCOM’s technical baseline. The group has many different subsections, such as identifying and pulling current resources or government off-the-shelf tools that are already available and in use to assist various elements or subordinate commands, such as the armed forces cyber components.<br/><br/>For example, the mission integration component ingests requirements from subordinate CYBERCOM elements along with the command&#8217;s headquarters, and then identifies capabilities that will potentially meet those requirements or work to get a capability developed and integrated, according to Justin Ball, the technical director at the Department of Defense Information Network Operations and Defensive Planning Division under CYBERCOM.<br/><br/>Ball spoke to C4ISRNET at the Defensive Cyber Operations Symposium in Baltimore, Maryland, on June 15.<br/><br/>The acquisition authority was an important step considering the rapid and evolving nature of the cyber domain. Complicating matters, funding often comes collectively from the individual services, whose cyber components feed into the 133 cyber mission force teams at CYBERCOM.<br/><br/>The secretary of the Air Force position serves as the combatant command support agent, or CCSA, for U.S. Strategic Command and CYBERCOM, which is a sub-unified combatant command under Strategic Command.<br/><br/>The Secretary of Defense has established policy and assigned responsibilities for the administrative and logistical support of combatant command headquarters as well as subordinate unified command headquarters through this CCSA construct, according to information provided to C4ISRNET via a CYBERCOM spokesman.<br/><br/>The Air Force provides funding to certain CYBERCOM resources, to include the military cyber operations platform as referenced in <a class="" href="http://www.c4isrnet.com/articles/heres-what-cyber-commands-war-fighting-platform-will-look-like" target="_blank">Part II</a>.<br/><br/>In many respects, CYBERCOM has been equated to SOCOM in the way its forces — considered high-demand, low-density — are allocated and how it makes purchases.<br/><br/>Michael Hayden, former director of the NSA and the CIA, recently told C4ISRNET in an interview that in order to develop a CYBERCOM of the future, one that is a fully unified combatant command and separate from the NSA, there must be a major force program 12 as SOCOM is MFP-11.<br/><br/>According to a <a href="https://dap.dau.mil/glossary/pages/2192.aspx" target="_blank" title="Link: https://dap.dau.mil/glossary/pages/2192.aspx">DoD webpage</a>, &#8220;<span class="glossarycontent">In the context of the Future Years Defense Program (FYDP), a MFP is an aggregation of program elements that reflects a force or support mission of DoD and contains the resources necessary to achieve an objective or plan. It reflects fiscal time-phasing of mission objectives to be accomplished and the means proposed for their accomplishment.&#8221;</span><br/><br/>Despite the acquisition authorities Congress granted CYBERCOM, it has yet to use them. &#8220;There are some specific technical and oversight and control things I have to make sure are in place, before we start spending the money … that will be finished in the next month or so,&#8221; Rogers told the House Armed Services Committee in late May.<br/><br/>Rogers said the command thought SOCOM offered a good model for acquisition, even hiring two former SOCOM officials to help shepherd the command through this initial process.<br/><br/>Rogers also told the committee that the <a href="http://fifthdomain.com/2017/05/24/cybercom-elevation-at-heart-of-budget-increase/" target="_blank" title="Link: http://fifthdomain.com/2017/05/24/cybercom-elevation-at-heart-of-budget-increase/">first capabilities the command is looking to buy are defensive in nature and slated for cyber protection teams</a>.<br/><br/>Rogers has himself wrestled with the way CYBERCOM develops its offensive tools. The military typically turns to industry for conventional weaponry; but to date, almost all U.S. offensive cyber weapons have been internally developed, he <a href="http://www.c4isrnet.com/articles/cyber-isnt-all-that-special-says-nsa-chief" target="_blank" title="Link: http://www.c4isrnet.com/articles/cyber-isnt-all-that-special-says-nsa-chief">said</a> in February. <br/><br/></p>







<p class="wp-block-paragraph">Rogers, who specifically said he spoke for himself rather than the government, questioned the sustainability of internal development and whether this route neglects access to private sector-made capabilities. &#8220;I’m still trying to work my way through that intellectually,&#8221; he said.</p>



<p class="wp-block-paragraph">In the cyber domain, many cyber tools must be specifically tailored to get after a specific exploit. Vice Adm. Michael Gilday, commander of U.S. Fleet Cyber Command/U.S. 10th Fleet, also noted in February that potential tools brought forth from the private sector might need to be &#8220;tinkered&#8221; because the military could be interested in customization.</p>



<p class="wp-block-paragraph">This is a reality acknowledged by the Defense Science Board in a recent <a href="http://www.c4isrnet.com/articles/dod-scientists-offer-cyber-deterrence-framework-report" target="_blank" title="Link: http://www.c4isrnet.com/articles/dod-scientists-offer-cyber-deterrence-framework-report">report on cyber deterrence</a>. &#8220;Unlike precision-guided munitions, cyber weapons cannot be bought and deployed on a delivery system (or placed in a storage site) with confidence that they will work when needed,&#8221; the report asserted. &#8220;A highly talented cadre of cyber warriors must work together closely with intelligence specialists and technologists in a highly classified environment. And because target systems and software can change, sometimes unexpectedly and at a moment chosen by the adversary, a quick reaction capability with flexible acquisition authorities will be essential.&#8221;</p>



<p class="wp-block-paragraph">The board recommended the establishment of a small and temporary task force, or so-called tiger team, on acquisition. This team would develop options and recommendations for improved and accelerated acquisition of scalable offensive cyber capabilities.</p>



<p class="wp-block-paragraph">Following the NSA-CYBERCOM split, the latter will require its own tools and infrastructure to perform its Title 10 war-fighting duties, which are different — albeit similar — to the former&#8217;s Title 50 espionage mission. The bottom line is that for the divorce to be a success, it must be done in a way where each organization&#8217;s mission is not degraded.</p>



<p class="wp-block-paragraph">As CYBERCOM continues to gain in capacity and capability, the split will become more inevitable and necessary. As many involved in the original stand up of this structure have articulated, the co-location was never intended to be permanent.</p>
]]></content:encoded>
	</item>
		<item>
		<title>An exclusive peek inside Cyber Command’s premiere annual exercise</title>
		<link>https://one.sightlinemg.com/c4isrnet/cyber/2017/06/30/an-exclusive-peek-inside-cyber-commands-premiere-annual-exercise/</link>
					<comments>https://one.sightlinemg.com/c4isrnet/cyber/2017/06/30/an-exclusive-peek-inside-cyber-commands-premiere-annual-exercise/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Fri, 30 Jun 2017 18:02:07 +0000</pubDate>
				<category><![CDATA[C2/Comms]]></category>
		<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Cyber Flag]]></category>
		<category><![CDATA[IT and Networks]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/c4isrnet/uncategorized/2017/06/30/an-exclusive-peek-inside-cyber-commands-premiere-annual-exercise/</guid>

					<description><![CDATA[C4ISRNET got an exclusive look at Cyber Flag, a military exercise focused on training and validating the Cyber Mission Force’s capabilities and readiness.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/c4isrnet/cyber/2017/06/30/an-exclusive-peek-inside-cyber-commands-premiere-annual-exercise/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13042</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/cyber-flag-17-1.JPG.jpg" width="5000" height="3333" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Practice makes perfect. For America&#8217;s cyber teams, the last stage of their validation and certification to achieving full operational capability occurs at the annual Cyber Guard and Cyber Flag training exercises.<br/><br/>While Cyber Guard games whole-of-nation defense in a simulated disaster. Cyber Flag is &#8220;a joint and combined military exercise focused on training and validating the Cyber Mission Force&#8217;s capabilities and readiness to execute all phases of conflict across defensive and offensive capabilities of USCYBERCOM&#8217;s assigned mission area responsibilities in support of Combatant Commands,&#8221; according to U.S. Cyber Command.<br/><br/>Coast Guard Rear Adm. David Dermanelian, director of exercises and training with CYBERCOM J7, detailed for C4ISRNET the four primary training objectives at Cyber Flag this year during an exclusive walk-through of the exercise:<br/><br/></p>



<ul class="wp-block-list"><li>Identify how the military can include cyber effects in an operation.</li><li>Determine if teams can identify characteristics of the terrain — either in an offensive or defensive environment, depending on the team&#8217;s mission set.</li><li>Find out how teams react when critical infrastructure is compromised.</li><li>Identify how the military can share information with partners and allies.</li></ul>



<p class="wp-block-paragraph">This year, 12 teams from the cyber mission force participated in order to reach full operational capability, but there were 19 teams at the event. This runs the gamut of Cyber Commands’ capabilities to include defensive cyber-protection teams to analytical- and intelligence-focused support teams to offensive-minded national-mission and combat-mission teams, the latter of which are allocated to combatant commands to get after commander’s objectives.</p>





<p class="wp-block-paragraph">The exercise, now in its seventh year, is &#8220;not a game environment where there is a winner and a loser,&#8221; Dermanelian said. &#8220;It’s really about adjusting the training value to get the maximum out of training for each of the teams.&#8221;</p>



<p class="wp-block-paragraph">With that in mind, officials told C4ISRNET that there are 19 mini exercises or operations taking place for each of the teams. The ultimate goal for the teams is ensuring they have been given all the opportunities to demonstrate their proficiency as required — an exam of sorts.</p>



<p class="wp-block-paragraph">Rather than playing part of a major war game or campaign plan, the exercise is very tactical. Dermanelian equated some of the events to wrestling practice where a coach places wrestlers on their back, has opponents prepare to pin them and has them fight it out when the coach says: &#8220;Begin.&#8221;</p>



<p class="wp-block-paragraph">The cyber equivalent is when the real, live opposing force takes control of critical intrastate, and cyber protection teams must react. &#8220;How do I fight out of this really bad situation?&#8221; Dermanelian said.</p>



<p class="wp-block-paragraph">There is a global scene-setter who carefully choreographs scenarios. U.S. Pacific Command personnel might participate in a scenario in the South China Sea, or U.S. European Command in the Baltics, Dermanelian explained. But mostly these scenarios provide context to operators at the micro-tactical level.</p>



<p class="wp-block-paragraph">&#8220;If you were to distill a storyline down to a task order [that] was given [for] a team to deploy &#8230; to do this mission — that’s what we’re doing,&#8221; said Col. Michael Frymire, Cyber Guard and Cyber Flag exercise director for CYBERCOM.</p>



<p class="wp-block-paragraph">Or, for example, a base commander has a command-and-control system that needs to work 100 percent of the time, and maybe the commander had some reports that there had been some bad guys in the area, so cyber forces will work to maintain the integrity of that system.</p>



<p class="wp-block-paragraph">One of the things that sets this exercise apart from others is a real, live, thinking opposing force, or OPFOR, rather than automated injects. Moreover, exercise planners and assessors evaluate how teams are doing toward their validation. The planners are the brain of the exercise and can dial up or down the intensity of the injects depending on how teams are performing.</p>





<p class="wp-block-paragraph">While teams are tested to the point of failure, which is where learning occurs, thus making this an unfair fight for friendly, or blue, forces by design, officials noted they don’t want negative training to occur. Teams are pushed as hard as they can so when they are on a mission, they have the experience. This is done through intense training. &#8220;We compress what these guys might do over a month into six days,&#8221; an exercise leader said.</p>



<p class="wp-block-paragraph">The OPFOR, for its part, is made up of 100 aggressors from 38 different professional organizations across the military, U.S. government, coalition partners and commercial industry, the OPFOR mission commander told C4ISRNET on condition of anonymity. OPFOR team members are also hand-picked to ensure they have the skills necessary to provide the right level of training.</p>



<p class="wp-block-paragraph">They emulate tactics, techniques and procedures from an amalgam of actors ranging from nation-states to hacktivists to provide as realistic an environment as possible. There are &#8220;bad guys&#8221; playing the same terrain as blue forces.</p>



<p class="wp-block-paragraph">Another real-world factor added in this year based on previous year’s feedback was the addition of a cybersecurity service provider, or CSSP. These are the mission owners — the local system administrators that defend their networks. Cyber protection teams, as quick-reaction forces that respond to incidents, must work with these CSSPs in the event of an incident.</p>



<p class="wp-block-paragraph">Teams that are tasked to defend a bases’ network will have to work with the mission owner like they would if they were deployed to that location to defend that base. There is a local network defender cell that does the wrench turning on the network with which they also must.</p>



<p class="wp-block-paragraph">&#8220;If I get tasked to go support a mission owner, no matter who it is, they’re not going to give me the keys to the kingdom,&#8221; an exercise participant told C4ISRNET. &#8220;I’m going to have to go through the local defender, their network owner to get my recommended changes.&#8221;</p>



<p class="wp-block-paragraph">&#8220;Really, I don’t want the keys to the kingdom. I wouldn’t want to become their system administrator,&#8221; a blue team lead said. &#8220;Eventually, I’ve got to leave&#8221; their network.</p>



<p class="wp-block-paragraph">For the cyber protection teams, this is a new environment into which they&#8217;re entering, another blue team lead said. They look to the local administrators to see what normal on their network might mean or what might be anomalous behavior.</p>



<p class="wp-block-paragraph">The CSSPs, moreover, don’t have to act on the recommendations of cyber protection teams.</p>



<p class="wp-block-paragraph">Offensive teams such as national mission teams and combat mission teams are also being assessed at Cyber Flag, but their mission set is different and highly tailored. Officials declined to offer significant details.</p>
]]></content:encoded>
	</item>
	</channel>
</rss>
