When officials consider U.S. Cyber Command’s critical cybersecurity mission, the conversation typically focuses on the state of its technology — the hardware and software and systems and networks that together represent the command’s ability to successfully conduct offensive and defensive operations in cyberspace.
To be sure, those technical capabilities are vitally important, but I would argue that they pale in comparison to something even more fundamental: the capability of CYBERCOM’s “wetware.”
What’s “wetware”? It’s CYBERCOM’s human capital; that is, the combined force of uniformed and civilian personnel that support the command’s mission, including its Cyber Mission Forces. And as its commander, Adm. Mike Rogers has argued they’re far more important than the other “-wares” we usually think off when it comes to our cybersecurity. Unless the command can recruit, develop, deploy and retain the wetware it needs to take full advantage of its state-of-the-art technologies, it (and we!) are at risk.
To be sure, CYBERCOM’s mission teams and the individuals who comprise them are as technically capable and committed as our nation can make them — but while the command may have the very best technological tools to accomplish its cybersecurity mission, I would argue that when it comes to the rules and policies it must use to manage its military and civilian personnel, it’s stuck with a toolkit that was developed in the last century. And that’s problematic.
On the military side, CYBERCOM and the services that provide it troops know they have a challenge. They’ve had to try to acquire, train and (most importantly) retain uniformed cyber talent in a labor market that is hypercompetitive, especially for military-grade cyber expertise. And they are handcuffed by a set of traditional military force management tools that are no longer up to that task. Twentieth century personnel policies like up-or-out promotions, a one-size-fits-all compensation system, frequent geographic relocations, the requirement for “broadening” command and staff assignments, and prematurely truncated careers all make it difficult to build and sustain a cadre of highly specialized military cyber ninjas.
That’s not the way that the Defense Department manages similarly specialized, elite forces. For example, it has sought and received legislative authority to treat its doctors and lawyers and even its special operators (to name a few) differently from the rest of its regular troops. And as part of its innovative Force of the Future initiative, DoD has proposed legislation that would give it even more flexibilities (ironically, the challenge of recruiting and retaining military cyber talent has often been used as justification for them). However, Capitol Hill has just begun to consider these proposals, with their ultimate fate in doubt.
In the meantime, CYBERCOM and the services will continue to lose uniformed cyber talent; they may not (yet) be hemorrhaging that talent, but their leadership has reported that they still suffer what they call individual “regrettable losses” from the ranks of their very best cyber warriors. Thus, they desperately need better tools to manage their own Force of the Future … as soon as possible.
The tools available to CYBERCOM to recruit and retain civilian cyber experts is just as problematic, but also a bit further along. When it comes to winning the war for civilian cyber talent, CYBERCOM’s sibling, the National Security Agency, is one of the more successful federal agencies, in part because it enjoys extraordinary civilian personnel management flexibilities, and it has been able to leverage those flexibilities to get and keep top-end cyber wetware even in today’s talent market.
And because of its unique relationship to NSA, CYBERCOM has had access to that civilian talent — via day-to-day collaboration and/or longer-term rotational assignments between the two organizations. However, it does not have access to the flexibilities that helped NSA acquire and keep that talent on a more permanent basis. And as a consequence, it continues to lose its best and brightest civilians to permanent positions with its three-letter neighbor. This issue will become even more acute if NSA is ever organizationally divorced from the command.
The good news is that in last year’s National Defense Authorization Act, DoD was given authority to extend the NSA’s civilian “excepted” personnel flexibilities to CYBERCOM and part of the Defense Information Systems Agency, and according to published reports, the department is well on its way to issuing an internal regulation that will do so. Indeed, it could happen as soon as this month.
The not so good news: That regulation establishes a brand-new personnel system for CYBERCOM’s civilians, and even though their neighbors at the NSA are familiar with it, the command and the services are not. Thus, it will still likely require some months — and additional implementing regulations, supporting systems and infrastructure, and above all, training for those who will administer it and be affected by it — to achieve final operating capability. So even if CYBERCOM leverages everything the NSA can teach it about how to use these new authorities, it may be as much as a year or two before the command can stand alone in that regard.
The bottom line: While CYBERCOM has all the technical tools to perform its mission, it (and the services) are not in the same place when it comes to the wetware that drives those technologies, and that may be the most important consideration of all. The command and its various supporting elements do not yet have all the military and civilian personnel management tools they need to win the war for cyber talent, and while they have been able to use their compelling mission to put up a good fight in that war, that will only get them so far.
Ron Sanders is a vice president and fellow at Booz Allen Hamilton and former chief human capital officer for the intelligence community.




