Skip to main content
Geopolitics & DefenseGovernment & Policy

Pentagon Nears Rollout of New Cyber Strategy

Person stands at podium in government briefing room, addressing crowd of military, civilians, and tech equipment.

"the most capable, lethal and agile cyber force in the world,"

Katie Sutton's office and the near-term release

The Defense Department is expected to publish a new, overarching cyber strategy early next week, according to three people familiar with the plan; one of those people predicted a Tuesday release while the others warned the date could change. The blueprint has been developed for months by the office of Katie Sutton, the assistant defense secretary for cyber policy and principal cyber adviser to the secretary, and will be the department’s first overarching cyber framework since 2023. Officials say it will be accompanied by an action plan.

Three priorities: integration across domains, advantage over adversaries, and force reorganization

Officials expect the strategy to center on the three priorities Sutton outlined to Congress: integrating cyber capabilities across every domain of warfare, gaining an advantage over adversaries, and reorganizing the military’s cyber forces to improve their skill and agility. The approach would further move cyber operations into routine military planning so that tools to disrupt an enemy’s communications or computer systems are planned alongside airstrikes and other conventional operations. Officials cited recent Trump-era operations in Venezuela and Iran as examples of such integration.

Translating the White House strategy and the 'defend forward' lineage

The Pentagon document will translate the White House’s March cyber strategy into more specific military priorities and investments. That White House document pledged to deploy the government’s full toolkit of offensive and defensive cyber capabilities, disrupt threats before they reach U.S. networks and impose greater consequences on foreign hackers. The posture reflects continuity with the department’s 2023 strategy and its “defend forward” approach, but the new plan is expected to emphasize delivering cyber options directly to combatant commanders and integrating those options with conventional military power.

Artificial intelligence and access to commercial models

Artificial intelligence is expected to feature prominently. Sutton told lawmakers in June the strategy would set a “clear and specific vision” for enabling AI across the cyber force, supported by coordination among Cyber Command, the Pentagon’s chief information office and its Chief Digital and Artificial Intelligence Office. Separately, the National Security Agency and the Pentagon have been expanding access to commercial models that can find vulnerabilities and automate parts of cyber operations. NSA Deputy Director Tim Kosiba said last week the agency wants access to “all the models” and is holding discussions with leading developers.

Cyber Command 2.0, personnel changes and the Cyber Innovation Warfare Center

The strategy is closely tied to Cyber Command 2.0, the Pentagon’s overhaul of how it recruits, trains and employs cyber personnel. The initiative emphasizes greater specialization and purpose-built teams and includes a Cyber Innovation Warfare Center intended to bring commercial technology directly to operators for testing. A job posting on the website of defense and technology provider Parsons seeks support for the Pentagon’s cyber policy office and indicates the strategy’s action plan contains about nine strategic initiatives and 34 lines of effort, though the posting does not disclose the initiatives’ contents.

How Combatant Commanders, NSA and AI developers, and the departments of Justice, Homeland Security and Defense are positioned

  • Combatant Commanders and military planners: They are positioned to receive integrated cyber options alongside conventional plans, with the strategy explicitly aimed at delivering cyber tools to commanders and embedding cyber in campaign planning.
  • NSA and commercial AI developers: The NSA is expanding access to commercial models for vulnerability discovery and automation; as Tim Kosiba put it, the agency wants access to “all the models” and is in talks with leading developers, which will affect what technologies military cyber teams can employ.
  • Departments of Justice, Homeland Security and Defense: The administration’s recent move to let vetted U.S. companies conduct government-approved operations against foreign cybercriminal groups raises questions the strategy will have to address about how Justice, Homeland Security and Defense divide responsibilities and avoid interfering with one another’s cyber operations.

The strategy reaches decision-makers amid active operational and technical pressures: officials continue to contend with what they describe as an apparently extensive Iran-linked campaign to access U.S. water systems and other infrastructure, and the department has begun an accelerated migration to quantum-resistant encryption with a goal of protecting its highest-impact systems by 2030. The Pentagon’s new framework, once released, will test whether it can reconcile routine operational integration, rapid technological adoption—including AI and commercial models—and interagency lines of authority while the department retools how it fields and trains cyber forces.

Original story