"The demand far exceeds the supply we have," said Katie Sutton, the Pentagon’s assistant secretary of defense for cyber policy, summing up a shortfall she framed as urgent and institution-wide.
Katie Sutton: one priority — more cyber options for the secretary and the president
Speaking at DefenseTalks, hosted by DefenseScoop, Sutton described a single, focused mission: "building a more robust set of capabilities for the secretary and the president." She repeatedly returned to the mismatch between commanders’ requests and the tools the department can currently provide, saying bluntly, "I’m focused on one single priority, and that is building a more robust set of capabilities for the secretary and the president."
Posture change rooted in 2018 authorities
Sutton traced the department’s current posture to 2018, "when the military gained authorities to run cyber operations as a traditional military activity." She framed the period since then as a learning curve: "In those last eight years, we’ve learned a lot, but I feel like the last year has really been the year that cyber has sort of entered the limelight." Sutton said the department has "built up the capabilities, we’ve built up our force, we have the operational experience."
She pointed to prior public attention on operations such as the reported attempt in Venezuela to apprehend former president Nicolás Maduro. Sutton noted that "various public statements, including those made by President Donald Trump, stated that power outages during the operation were the result of a cyberattack." Sutton acknowledged competing analysis: experts told CyberScoop that cyber operations "may have been involved," while the visible physical attacks linked to that operation "alone could plausibly explain the outages."

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleData as a center of gravity and cyber as an integrated tool of warfare
Sutton placed data at the heart of future combat: "Data is fundamental to every battle that we fight going forward," and she argued for using cyber capabilities to deny adversaries access to that data as U.S. forces enter kinetic fights. She also cast cyber as more than a defensive, cyber-on-cyber mechanism, calling it "an integrated tool of cyber warfare" and arguing it can be used "below the level of armed conflict to provide options before having to move forward to our kinetic options." The framing ties capability development directly to mission assurance and troop safety: denial of adversary data, she said, will "ensure our mission success and provide greater safety for our troops."
AI integration: "an AI-first organization" — and new operational risks
Sutton described artificial intelligence as a natural fit for cyber operations. "Cyber is a digital domain; it’s all based on zeros and ones," she said, and the department must work to be "an AI-first organization." At the same time she highlighted AI-specific vulnerabilities that demand fresh approaches: "data poisoning and weakened guardrails" and a need to "fundamentally think about that differently from AI," given long-standing trade-offs where security lagged behind rapid internet development. She said, "We’ve spent a long time chasing cybersecurity and dealing with decisions that we made in moving quickly to creating an internet," and added that security "came second in that era."
Gen. Randall Reed, head of U.S. Transportation Command, presented a complementary view at the conference. Reed warned that the military’s "predictable supply chains have become vulnerable to AI-enabled adversaries" and suggested AI could also be part of the remedy, helping Transcom "become less predictable" and demonstrating how military officials are leveraging AI "across multiple operational domains."
What this means for the secretary, the president, and commanders
- For the secretary and the president: Sutton’s stated priority is a clearer menu of cyber options — more tools to choose from when weighing kinetic versus non-kinetic responses.
- For commanders requesting cyber support: the reported gap—"the demand far exceeds the supply"—means some requests may go unmet until capability growth accelerates.
- For U.S. Transportation Command and logistics planners: Gen. Reed’s remarks signal simultaneous exposure and opportunity — AI increases vulnerabilities in predictable supply chains while offering techniques to introduce unpredictability into logistics.
Sutton framed a steady, substantial effort: authorities granted in 2018 have produced "capabilities," a built-up "force" and "operational experience," but she emphasized that the current year marked a turning point in public attention and institutional focus. Her public prescription is precise: expand the capacity to supply commanders and senior leaders with more cyber options, and do so while reckoning with AI-specific threats such as data poisoning and eroding guardrails.
The department’s next steps, by Sutton’s account, are practical and immediate in outline but open in scale and timing. Translating a single priority into a demonstrably larger supply of cyber tools — and doing so in ways that manage the new risks of AI-enabled operations — is the concrete task she set before the Pentagon at DefenseTalks.




