Skip to main content
CybersecurityNetwork Security

Army Seeks Digital Twin to Bolster Network Security, AI Training

Large network operations center with rows of server racks, workstations, and screens on walls under bright fluorescent…

"We get about 1.2 million cyber attacks a day," Maj. Gen. Jacqueline Denise McPhail told an industry audience — a blunt statistic that framed a single, ambitious prescription: build a comprehensive digital twin of the Army’s networks so humans and AI can train, test and harden defenses together.

Maj. Gen. Jacqueline Denise McPhail’s challenge at AFCEA TechNet Augusta

Speaking at AFCEA’s annual TechNet Augusta conference, the two‑star chief of the Army’s Network Command (NETCOM) acknowledged the difficulty of the task but publicly pressed contractors in the room to take it on. McPhail described a model that would be "constantly updated with live data on how the real‑world network is performing," then said the payoff — a realistic environment for training network operators, cyber defenders and AI — was worth the scale of the effort. "It’s a big ask. It’s a big ask! I know it’s a large scale effort," she said, and added: "I think we start small and build it out."

What McPhail means by a "digital twin" — and how that compares to Pentagon doctrine

McPhail used a broader definition of digital twin than the one quoted in Pentagon doctrine, which defines it as "a computerized representation (integrated set of models) that serves as the real‑time digital counterpart of a physical object or process." In defense conversations the source notes, digital twins typically emulate highly detailed physical systems — from aircraft to a supply chain to a virtual wounded soldier used for training medics — so they can be stress‑tested or altered without harming the real system. McPhail’s proposal shifts that ambition toward something already largely virtual: the Army’s networks, where much of the action is at the software and behavioral level.

How a DoDIN‑A digital twin would be used for training, testing and AI

McPhail framed the digital twin as an "ultra‑realistic training ground" in three overlapping roles. First, for human operators and cyber defenders to learn how the network behaves and how to keep it working under attack. Second, for AI algorithms themselves to be trained and tested inside an environment that mirrors the live Department of Defense Information Network – Army (DoDIN‑A). Third, as a laboratory to understand vulnerability, gap and resilience. "That’s where AI comes in," she said. "If we can get a digital twin of the DoDIN‑A, that now enables us to be able to leverage AI in that model to understand our vulnerabilities, where our gaps are, [and] where we do have resilience."

Scale, data volume, and the changing shape of attacks

McPhail stressed that the problem is not only volume but sophistication. Beyond the daily "about 1.2 million cyber attacks," she said, adversaries are shifting away from brute‑force Distributed Denial of Service (DDOS) tactics toward more subtle behavioral changes that are "far harder to detect." "It’s no longer DDOS. Now we have to look at behavior: What behavior has changed?" she asked. The combination of enormous data inflows and nuanced behavioral indicators raises twin challenges: "How do we secure that data? How do we identify what’s just noise and what is a change in behavior?" A digital twin, she argued, would provide the environment to answer those questions by letting defenders and AI test detection and response at scale without risking the operational network.

What this means for contractors, network operators, and AI developers

  • Contractors: McPhail publicly "challenged the contractors in the audience to build it," putting industry on notice that NETCOM seeks partners willing to tackle a live‑data, continuously updated simulation of DoDIN‑A — and to "start small and build it out."
  • Network operators and cyber defenders: They would gain access to an "ultra‑realistic training ground" where human teams can rehearse responses to sophisticated behavior‑based attacks and validate that fixes do not inadvertently break parts of the network. "We need to figure out what’s broken, but we also need to figure out what’s not broken so we don’t break it later," McPhail said.
  • AI developers: A DoDIN‑A twin would create a controlled, high‑fidelity environment to train and test algorithms against realistic traffic, behavioral anomalies and evolving threat tactics — enabling evaluation of both detection accuracy and operational impact before deployment to the live network.

McPhail’s case is straightforward and unapologetic: the Army faces a relentless, evolving threat across hundreds of thousands of events daily, and current practice needs an experimentable, realistic mirror of the network to improve resilience. She conceded the technical and organizational scale — "It’s a big ask" — but closed by urging incremental progress: "I think we start small and build it out."

The core question her remarks leave for industry and NETCOM alike is concrete and immediate: will the contractors in the room answer the challenge to create a continuously updated, behaviorally faithful digital twin of the DoDIN‑A, and can it be grown from modest beginnings into the large‑scale model McPhail describes?

Original story