Officials have previewed a blueprint emphasizing offensive operations, AI adoption and closer industry ties as the military reorganizes its cyber forces. #
The Defense Department is expected to release its anticipated cyber strategy early next week, according to three people familiar with the plans for the blueprint that officials argue will more tightly integrate digital operations into U.S. military campaigns.
One of the people predicted the strategy would be released Tuesday. All three spoke on the condition of anonymity to discuss the release timing, with two noting its exact release could still be subject to change.
The strategy has been under development for months by the office of Katie Sutton, the assistant secretary of defense for cyber policy and principal cyber adviser to the secretary. It will be the department’s first overarching cyber framework since 2023 and is expected to be accompanied by an action plan.
Officials initially said it would be completed during the summer. Sutton told lawmakers in April that the strategy would seek to build “the most capable, lethal and agile cyber force in the world,” able to defend military networks, gain strategic advantage and give the president more options to deter or defeat adversaries.
The plan is expected to center on three priorities Sutton outlined before Congress: integrating cyber capabilities across every domain of warfare; gaining an advantage over adversaries; and reorganizing the military’s cyber forces to improve their skill and agility.
A job posting on the website of defense and technology provider Parsons seeks support for the Pentagon’s cyber policy office and says the strategy’s action plan contains approximately nine strategic initiatives and 34 lines of effort. It’s not clear when the role was posted, and the specific initiatives’ contents are not disclosed in the description.
The approach would aim to further move cyber operations into routine military planning, meaning tools that can disrupt an enemy’s communications or computer systems would be planned alongside airstrikes and other conventional operations. Officials have cited recent Trump-era operations in Venezuela and Iran as examples of this integration.
The strategy will also translate the White House’s March cyber strategy into more specific military priorities and investments. That document pledged to deploy the government’s entire toolkit of offensive and defensive cyber capabilities, disrupt threats before they reach U.S. networks and impose greater consequences on foreign hackers.
The posture is not entirely new. The Pentagon’s 2023 strategy embraced “defend forward,” an approach that calls for confronting malicious cyber threats closer to the source of their operations. The new strategy is expected to emphasize delivering cyber options to combatant commanders and integrating them with conventional military power.
Artificial intelligence is also expected to feature prominently. Sutton said in June that the strategy would set a “clear and specific vision” for enabling AI across the cyber force, supported by coordination among Cyber Command, the Pentagon’s chief information office and its Chief Digital and Artificial Intelligence Office.
The Pentagon and National Security Agency have been expanding access to commercial models that can find vulnerabilities and automate parts of cyber operations. NSA Deputy Director Tim Kosiba said last week that the agency wants access to “all the models” and is holding discussions with leading developers.
The efforts, broadly, are closely tied to Cyber Command 2.0, the Pentagon’s overhaul of how it recruits, trains and employs cyber personnel. The initiative emphasizes greater specialization and purpose-built teams, along with a Cyber Innovation Warfare Center intended to bring commercial technology directly to operators for testing.
The strategy arrives as officials continue grappling with myriad cyber threats to U.S. systems, including an apparently extensive Iran-linked campaign to access water systems and other critical infrastructure around the nation. The Defense Department has also begun an accelerated migration to quantum-resistant encryption, with a goal of protecting its highest-impact systems by 2030.
The administration separately moved last month to let vetted U.S. companies conduct government-approved operations against foreign cybercriminal groups. The initiative also raises questions about how the departments of Justice, Homeland Security and Defense will divide responsibilities and avoid interfering with one another’s cyber operations.
To securely contact the reporter for this story, he can be reached on Signal via username did.99