<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet media="screen" type="text/xsl" href="https://one.sightlinemg.com/federaltimes/wp-content/themes/smg/assets/xslt/rss-xslt.xml"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
xmlns:news="http://www.pugpig.com/news"
>

<channel>
	<title>C2/Comms - Federal Times</title>
	<atom:link href="https://one.sightlinemg.com/federaltimes/c2-comms/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Federal Times</description>
	<lastBuildDate>Sat, 08 Aug 2026 18:05:37 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://one.sightlinemg.com/wp-content/uploads/2026/06/favicon-fed.png?w=32</url>
	<title>C2/Comms - Federal Times</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">255331619</site>	<item>
		<title>Are smartphones the new cyber threat vector?</title>
		<link>https://one.sightlinemg.com/federaltimes/it-networks/2017/10/24/are-smartphones-the-new-cyber-threat-vector/</link>
					<comments>https://one.sightlinemg.com/federaltimes/it-networks/2017/10/24/are-smartphones-the-new-cyber-threat-vector/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Tue, 24 Oct 2017 19:00:33 +0000</pubDate>
				<category><![CDATA[C2/Comms]]></category>
		<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Daily Brief]]></category>
		<category><![CDATA[Home]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<category><![CDATA[Mobility]]></category>
		<category><![CDATA[Newsletters]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2017/10/24/are-smartphones-the-new-cyber-threat-vector/</guid>

					<description><![CDATA[Smartphones are presenting a unique cybersecurity vulnerability, according to panelists at the annual MilCom conference hosted by AFCEA.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/it-networks/2017/10/24/are-smartphones-the-new-cyber-threat-vector/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">11596</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/GettyImages-858906748.jpg.jpg" width="5095" height="3397" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">Recent events have brought to the forefront the vulnerability and threat vector smartphones present.</p>



<p class="wp-block-paragraph">“The very things that make mobile devices such a productivity tool are the exact same things that make them a big target for espionage and for malicious activity,” Kiersten Todt — president and managing partner at Liberty Group Ventures and resident scholar at the University of Pittsburgh Institute for Cyber Law, Policy and Security — said Oct. 24 in Baltimore, Md., at the annual MilCom conference hosted by AFCEA.</p>



<p class="wp-block-paragraph">“We saw most recently [White House] Chief of Staff John Kelly’s phone getting compromised and by all accounts that was likely by a nation-state actor given what he wasn’t able to do.”</p>



<p class="wp-block-paragraph">Mobile devices that are compromised, she said, can be exploited by adversaries to enable the microphone, allowing them to listen into sensitive conversations, access data that’s going through the smartphones or be able to take pictures of a surrounding area.</p>



<p class="wp-block-paragraph">“We typically have looked at smartphones as a peripheral device, but I think we all appreciate right now that smartphones we each hold are really the access points into both our personal and professional lives,” Todt, who previously served as executive director of commission on enhancing national cybersecurity, said. “The data that travels through those devices is critical.”</p>



<p class="wp-block-paragraph">In the military context, <a href="https://www.wsj.com/articles/russia-targets-soldier-smartphones-western-officials-say-1507109402">a report by the Wall Street Journal</a> earlier this month charted how Russia targeted the smartphones of NATO soldiers, with the goal of gaining operational information, gauging troop strength and intimidating soldiers.</p>



<p class="wp-block-paragraph">Personal devices brought onto the battlefield can be exploited allowing adversaries to geolocate positions and direct fires upon their positions.</p>



<p class="wp-block-paragraph">“This might be the clearest example yet of how our reliance on networks and connected devices has created new threats to national security,” retired Rear Adm. Bill Leigher, Raytheon DoD Cyber Programs director, said. “This should make it clearer than ever that nation-states have brought the fight to new terrain — our commercial networks and the devices people use every day.”</p>



<p class="wp-block-paragraph">Complicating matters even further is the combination of social media posting through smartphones. A Russian sailor <a href="http://dailycaller.com/2016/11/06/sailors-selfie-gives-away-position-of-one-of-russias-best-ships/">broadcast the position</a> of his ship’s previously unknown location to much of the world when he posted a selfie off the coast of Syria complete with the geo-tag active.</p>



<p class="wp-block-paragraph">The military is trying to engrain best practices into the ranks of their enlisted soldiers with a recognition that it starts at the highest levels first.</p>



<p class="wp-block-paragraph">“How do we train our soldiers to understand the vulnerabilities and what our Ukrainian partners are realizing that by using your personal cellphone what that opens you up to,’ Maj. Gen. Patricia Frost, director of the Army’s Cyber Directorate, said during a panel discussion in Augusta, Ga., in August. “If we — this is the leader level — will not recognize the vulnerabilities that we’re bringing into the environment and the threat vector that we’re introducing, how do we expect our soldiers at the most junior level to be disciplined.”</p>



<p class="wp-block-paragraph">She noted that they might being to use the National Training Center as a teaching moment, saying if X number of soldiers brought their personal devices to NTC, leaders could say they targeted them, brought indirect fires on their position as to demonstrate the threat vector they’ve introduced.</p>



<p class="wp-block-paragraph">“I have been at forums at field grade and higher level where we’ve told everyone we’re going to go classified, leave your cellphones in a designated place and we scan the room and more than 50 percent to 75 percent still brought their cellphone into the room,” Frost said.</p>



<p class="wp-block-paragraph">“Right now we have to appreciate the mobile devices are an endpoint priority equal to — or I would argue even more so — important than the laptops and the desktops that we each use,” Todt said.</p>



<p class="wp-block-paragraph">“Being able to develop the policies around protecting the information on our mobile devices and importantly protecting the data is what has to happen. Critical information has to be the priority for looking at how we secure devices, data and how we’re securing our workforce.”</p>
]]></content:encoded>
	</item>
		<item>
		<title>Cyber Flag exclusive: What goes into validating a cyber team?</title>
		<link>https://one.sightlinemg.com/federaltimes/it-networks/2017/07/03/cyber-flag-exclusive-what-goes-into-validating-a-cyber-team/</link>
					<comments>https://one.sightlinemg.com/federaltimes/it-networks/2017/07/03/cyber-flag-exclusive-what-goes-into-validating-a-cyber-team/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Mon, 03 Jul 2017 10:31:56 +0000</pubDate>
				<category><![CDATA[C2/Comms]]></category>
		<category><![CDATA[Cyber]]></category>
		<category><![CDATA[IT & Networks]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2017/07/03/cyber-flag-exclusive-what-goes-into-validating-a-cyber-team/</guid>

					<description><![CDATA[C4ISRNET was provided exclusive access to U.S. Cyber Command’s premier annual training exercise, Cyber Flag, in which 12 teams were used as the capstone toward reaching full operational capability.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/it-networks/2017/07/03/cyber-flag-exclusive-what-goes-into-validating-a-cyber-team/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">21216</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/snagfilms-a.akamaihd.netactive-duty-reserve-and-n-7e165d30ed55735182e357fade8c84a6075f198f-1.jpg.jpg" width="5760" height="3240" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p class="wp-block-paragraph">What goes into validating a cyber team? C4ISRNET was provided exclusive access to U.S. Cyber Command&#8217;s premier annual training exercise, Cyber Flag, in which 12 teams were used as the capstone toward reaching full operational capability.<br/><br/>The entire cyber mission force reached initial operational capability in October 2016. Prior to that, this exercise was partly used to validate teams for IOC.<br/><br/>The full spectrum of cyber teams participated in training — from defensive to offensive. These teams squared up against a live and free-thinking opposing force that operated in the same cyber terrain as blue teams, or friendlies.<br/><br/>The teams are evaluated by an assessment group that certifies teams meet or check off certain events during the exercise. The assessment team lead, who, like many, spoke to C4ISRNET during the exercise on the condition of anonymity, said these assessment teams are made up of no fewer than five individuals who grade the exams given to cyber teams.<br/><br/></p>





<p class="wp-block-paragraph">Within that construct, a team controller sits within what is called the white cell, or the brain of the exercise, understands the team’s objectives and controls the pace of the exam, the team lead said. No fewer than three individuals are embedded with participants to observe their actions and input them into a database. A training analyst works with the opposing force, or OPFOR, to create a visualization to show the blue team how it performed.</p>



<p class="wp-block-paragraph">This visualization — which is a subset taken from a tool in a control room that shows all network traffic and activity in blue (friendly), gray (cyber no man&#8217;s land) and red (adversarial) space — allows assessors a literal playback of how the blue force reacted during a particular event to determine if it was the correct course of action.</p>



<p class="wp-block-paragraph">Participants and OPFOR are playing on a synthetic network or range that has to be developed prior to the exercise. One range lead told C4ISRNET during a walk-through at the exercise that they build all the networks — to include virtual networks for members playing in remote locations — and vulnerabilities, meaning they purposefully built in vulnerabilities for the OPFOR to exploit. The network was only patched up to December 2016, affording the OPFOR all the vulnerabilities that were relevant and unpatched at that time. Moreover, the range can also take down security measures if they want to simulate bad business practices or bad systems administrators.</p>



<p class="wp-block-paragraph">Teams are assessed against certain criteria. And while being tested to the point of failure makes it an unfair fight by design, teams do debrief with the OPFOR every evening to provide limited insight for the next day’s exercises. The OPFOR and exercise leads are &#8220;bending over backwards&#8221; for the participants to ensure the right training is occurring, a blue team lead said.</p>



<p class="wp-block-paragraph">This means teams can request to run through particular scenarios again if they feel they need additional practice.</p>



<p class="wp-block-paragraph">For example, the OPFOR team lead pointed out that perhaps a blue team never experienced or didn’t have much training on a data exfiltration operation, so they’ll run such a mission. If the team didn’t catch it, they’ll rerun that again in coordination with all involved and maybe make it easier the next time, if necessary, or provide a little bit of extra intelligence.</p>



<p class="wp-block-paragraph">It could be the team’s skill sets of dealing with data exfiltration are spot on, C4ISRNET was told, but maybe the intel lead wasn&#8217;t paying attention. There are multiple factors that could be blamed for a failed data exfiltration response, and the OPFOR in conjunction with exercise planners and assessors must pinpoint where the failure occurred, try to correct it and see how they perform again.</p>





<p class="wp-block-paragraph">&#8220;If we don’t hear chatter over the course of the day, we’ll generally encourage that: Take a break and do like a mini catch-up so everyone’s on the same page to give us a pulse of how things are going,&#8221; a blue team lead said. &#8220;At that point, it&#8217;s: Take a deep breath; it’s OK; what else do you want to focus on today? Some of the guys have been up front to say: &#8216;I want to dig into this tomorrow.&#8217; OK, we will work with the mission owner to get you that time to do what you want to do.&#8221;</p>



<p class="wp-block-paragraph"><b>Going off script</b></p>



<p class="wp-block-paragraph">While there is a script, so to speak, to which the the exercise tries to follow, there are specific things everyone must learn and experience, according to a blue team lead.</p>



<p class="wp-block-paragraph">However, the script isn’t structured like: &#8220;A,&#8221; then &#8220;B,&#8221; then &#8220;C,&#8221; then &#8220;D,&#8221; another blue team lead said. &#8220;A&#8221; might happen and the team must react. &#8220;So they’re like: Well, &#8216;B&#8217; doesn’t really follow, but we have &#8216;A&#8217; sub one and hopefully we’ll get them back on track to what we want to see from them.&#8221;</p>



<p class="wp-block-paragraph">There also are specific injects available to assessors and the OPFOR that can be used to force the blue teams to perform a certain action. &#8220;I didn’t really see this out of you, but I want to see</p>



<p class="wp-block-paragraph"><i>this</i></p>



<p class="wp-block-paragraph">out of you, so how do I make that happen?&#8221; the team lead said.</p>



<p class="wp-block-paragraph">&#8220;I don’t feel like I’m being attacked by OPFOR. I feel like I’m being presented with potential scenarios I might really face,&#8221; another blue team lead told C4ISRNET. &#8220;I don’t feel like I’m being personally attacked by anybody, I feel like I’m very much in a scenario where I’m being presented with as much realism as possible. OPFOR isn’t there to attack you — they’re providing opportunity for things to react to.&#8221;</p>



<p class="wp-block-paragraph">While an extremely tactically focused exercise, teams might be asked in a scenario to provide mission assurance to the mission owner, who needs to make sure team members can communicate with other assets, be it a naval vessel or otherwise.</p>



<p class="wp-block-paragraph">&#8220;There’s one thing or two things that are absolutely critical for the mission to be successful. The rest of it is just a mitigation effort by the teams,&#8221; an exercise leader said. &#8220;We have to make sure this stuff is working, then do damage control on the rest of it. That’s the problem set they’re given.&#8221;</p>



<p class="wp-block-paragraph">The operational tempo for the exercise stresses participants to the point where they are left with nothing but the ability to rely on their basic skills, a participant said. If there’s one super star that might carry things, this situation kind of highlights that, C4ISRNET was told. The exercise is compressing what might occur in a month’s time into six days.</p>



<p class="wp-block-paragraph">Officials provided less details regarding offensive team activities and validation efforts. Their activity is tailored differently because their play is somewhat unique, one exercise leader said. &#8220;There’s one team, and that aspect of it is it’s highly tailored to them, but they’re being assessed against their objectives and mission sets. That’s an aspect of the exercise,&#8221; an official explained.</p>



<p class="wp-block-paragraph">&#8220;What’s unique about how they’re doing it in this exercise is they’re doing it together,&#8221; another lead said. Protection teams, support teams — which provide analysis and intelligence — and mission teams — which conduct offensive ops — are all working against the same adversary in conjunction.</p>



<p class="wp-block-paragraph">&#8220;They’re feeding one another, which is hard to do,&#8221; an official said. &#8220;But the value they get out of it is hard to beat.&#8221;</p>
]]></content:encoded>
	</item>
		<item>
		<title>Cyber, electronic warfare blur tactical, strategic lines</title>
		<link>https://one.sightlinemg.com/federaltimes/cyber/2017/06/29/cyber-electronic-warfare-blur-tactical-strategic-lines/</link>
					<comments>https://one.sightlinemg.com/federaltimes/cyber/2017/06/29/cyber-electronic-warfare-blur-tactical-strategic-lines/#respond</comments>
		
		<dc:creator><![CDATA[migration]]></dc:creator>
		<pubDate>Thu, 29 Jun 2017 09:30:50 +0000</pubDate>
				<category><![CDATA[C2/Comms]]></category>
		<category><![CDATA[Cyber]]></category>
		<guid isPermaLink="false">https://one.sightlinemg.com/federaltimes/uncategorized/2017/06/29/cyber-electronic-warfare-blur-tactical-strategic-lines/</guid>

					<description><![CDATA[The Army is working to test new technologies to help inform requirements, doctrine and operational concepts in the cyberspace domain.]]></description>
		
					<wfw:commentRss>https://one.sightlinemg.com/federaltimes/cyber/2017/06/29/cyber-electronic-warfare-blur-tactical-strategic-lines/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">11636</post-id><media:content medium="image" url="https://one.sightlinemg.com/wp-content/uploads/2026/08/cyber-quest-ew-soldier.jpg.jpg" width="5000" height="2813" type="" />
<news:push>0</news:push>
<content:encoded><![CDATA[
<p>One of today&#8217;s frequently emerging adages is that the character of war is changing. The rapid pace of technologies and nascent domains of war such as cyberspace are turning what used to be <a href="http://www.c4isrnet.com/articles/army-takes-strategic-cyber-capabilities-to-the-tactical-edge" target="_blank" title="Link: http://www.c4isrnet.com/articles/army-takes-strategic-cyber-capabilities-to-the-tactical-edge">tactical issues</a> into issues of <a href="http://www.c4isrnet.com/articles/secure-software-is-of-strategic-importance-to-the-army" target="_blank" title="Link: http://www.c4isrnet.com/articles/secure-software-is-of-strategic-importance-to-the-army">strategic importance</a>.<br/><br/> &#8220;If we don’t win the cyber/[electronic warfare] fight, then the maneuver fight may not matter because we may not get to it,&#8221; Maj. Gen. Wilson Shoffner, director of operations at the Army&#8217;s Rapid Capabilities Office, said in early June, noting that the decisive fight may well be the electromagnetic spectrum as opposed to maneuver.<br/><br/>Moreover, if communications are disrupted via <a href="http://www.defensenews.com/story/defense/policy-budget/warfare/2015/08/02/us-army-ukraine-russia-electronic-warfare/30913397/" target="_blank" title="Link: http://www.defensenews.com/story/defense/policy-budget/warfare/2015/08/02/us-army-ukraine-russia-electronic-warfare/30913397/">jammed radios</a> — which are increasingly more susceptible to cyber and electronic attacks as demonstrated in Ukraine — then campaign plans could be significantly affected.<br/><br/>To help close operational gaps and harness the evolution of commercial technology, the Army recently held its second Cyber Quest exercise, which is a cyberspace and electronic warfare experimentation and collaboration event held at the Army Cyber Center of Excellence in Fort Gordon, Georgia. It involves a search for emerging technology, ideas and concepts that could yield solutions for future requirements in realistic and replicated operational environments.<br/><br/><img decoding="async" alt="Cyber Quest room" data-alignment="center" data-object-id="0000015c-f3ab-de2f-a95c-f3eb170c0000" data-type="image" src="http://snagfilms-a.akamaihd.net/81/d9/1e9c9dd44892a963c43b6fd81179/cyber-quest-room.jpg"/><figcaption> <span>The Army is working to test new technologies to help inform requirements, doctrine and operational concepts in the cyberspace domain.</span></figcaption><figcaption> <span>Photo Credit: U.S. Army</span></figcaption><br/>This exercise works to inform future Army planning, said Maj. Gen. John Morrison, commanding general of the Army Cyber Center of Excellence, during a June 28 media call.<br/><br/>The Army identifies operational gaps that get passed to industry, academia and acquisition teammates who come to Cyber Quest with capabilities that are put in the hands of soldiers, Morrison said. The soldiers handling the equipment help to determine how these solutions might inform future requirements, doctrine and operational concepts, he added. <br/><br/></p>





<p class="wp-block-paragraph">&#8220;This is key in a space that is ever-changing,&#8221; Morrison noted. &#8220;Cyberspace today is not going to be what cyberspace is tomorrow.&#8221;</p>



<p class="wp-block-paragraph">Cyber Quest will assist the Army in its requirements process. Morrison pointed out that the service is in the midst of developing requirements for a number of operational gaps identified for the exercise.</p>



<p class="wp-block-paragraph">This will allow the Army to have solid operational concepts that underpin requirements and better inform the acquisition process.</p>





<p class="wp-block-paragraph">One of the areas of which the Army will focus is the world of cyber and the electromagnetic spectrum. &#8220;The traditional acquisition model will not work. I’ll be that definitive,&#8221; Morrison said, adding that the service is trying to shorten the timeline here.</p>



<p class="wp-block-paragraph">&#8220;If we develop requirements today, and seven years from now we’re trying to field a capability in the cyberspace domain, it simply will not work. We’re behind before we even start.&#8221;</p>



<p class="wp-block-paragraph">The 40 capabilities brought to Cyber Quest by 27 vendors this year were tested in scenarios developed by Army Training and Doctrine Command that incorporated many of the threats that would originate from near-peer adversaries.</p>



<p class="wp-block-paragraph">Everything was done with an eye toward the near-peer adversary, according to Lt. Col. Stephen Roberts, the lead project officer for this year&#8217;s Cyber Quest exercise. Capabilities and measures were made to look like those seen in the battlefield, he said, so they could be assessed against specific real-world threats.</p>



<p class="wp-block-paragraph">Morrison said some scenarios were built in where critical systems were &#8220;spoofed,&#8221; meaning the adversary was actually trying to make forces think something was happening inside the operational environment that wasn&#8217;t actually occuring.</p>



<p class="wp-block-paragraph">Solutions for defensive cyber operations capabilities were also tested. Some of these solutions &#8220;are things that would be utilized to defend our networks and provide an operational edge for us to not only detect new attacks against our network but then also remediate those attacks in a rapid fashion,&#8221; Roberts said.</p>



<p class="wp-block-paragraph">Currently, it takes hours or days to detect or remediate these issues at the tactical edge. he noted. The service is trying to get that time frame down to minutes.</p>



<p class="wp-block-paragraph">The exercises also served to conduct risk-reduction efforts for government-developed solutions and programs. Program managers and program executive offices put forth programs of record while labs such as the</p>



<p class="wp-block-paragraph"><a href="http://fifthdomain.com/2017/06/05/army-relying-on-situational-understanding-to-secure-legacy-devices/" target="_blank" title="Link: http://fifthdomain.com/2017/06/05/army-relying-on-situational-understanding-to-secure-legacy-devices/">Communications-Electronics Research, Development and Engineering Center</a></p>



<p class="wp-block-paragraph">provided four separate systems within the EW space, Roberts said.</p>



<p class="wp-block-paragraph">Morrison said these government solutions were undergoing operational assessments of capabilities being examined by acquisition teammates deeper than where current programs of record are. This, he said, allows soldiers to get their hands on kits to provide feedback and take the right risk-reduction direction.</p>
]]></content:encoded>
	</item>
	</channel>
</rss>
