Skip to main content
Geopolitics & DefenseNational Security

US Cyber Arsenal Depleted Fast in Modern Conflict

A dimly lit industrial room with a slightly ajar metal cabinet and a worn leather briefcase nearby.

"Your cyber magazine of these exquisite fires is empty pretty damn quick," Vice Adm. Heidi Berg said, framing a problem few outside the military cyber community have had to reckon with in public.

Vice Adm. Heidi Berg on the vulnerability of cyber munitions

Speaking at HammerCon, hosted by the Military Cyber Professionals Association, Vice Adm. Heidi Berg, commander of Fleet Cyber Command/10th Fleet, drew a direct line from recent operations to a strategic constraint: cyber capabilities that deliver high-value effects can be consumed rapidly. She cited lessons from Russia’s invasion of Ukraine and U.S. operations in Venezuela, the Middle East and elsewhere, and asked sharply, "How are you going to regenerate and continue to develop accesses and effects to be able to deliver over the course of what will almost always be against a peer competitor, a longer-term sustained conflict?"

The limits of bespoke exploits and sustained access

The crux of Berg’s point is technical and operational: exploits and bespoke hacking tools are finite and often non-reusable. The source material notes that once a vendor, operator, or adversary patches a flaw, that tactic may become obsolete; development of new exploits requires time and skill and cannot be replenished like physical munitions by opening factory lines. A former senior Pentagon official, speaking on background, warned that China is likely observing how U.S. cyber operators perform and is studying their tactics.

Jason Kikta, a former cyber operator with CYBERCOM, reinforced the operational reality: access is the "real asset" in cyber operations and is "quickly expended and slow to replenish." That reality drives a recurring operational dilemma: after gaining access to a target, should operators continue to collect intelligence or strike and thereby close that avenue of influence and intelligence for future operations?

Operation Epic Fury: a new tempo for sustained cyber combat

The United States has, according to service commanders quoted at the event, entered a prolonged period of cyber operations. Lt. Gen. Christopher Eubank, commander of Army Cyber Command and the officer charged with running cyber operations in the Middle East, said of Operation Epic Fury (OEF), "From an OEF perspective, just to put in perspective, so 28 February, and it hasn’t stopped. Probably for the first time for the cyber force at large, it’s been this constant."

Berg placed earlier actions on the same spectrum: she described Absolute Resolve — the operation to capture Venezuelan leader Nicholas Maduro — as "the largest and most complex cyber operation that had ever been executed." In episodic operations, perpetual access may be a secondary concern; in Epic Fury, sustaining effects, regenerating accesses, and adjusting missions as priorities evolve are central challenges.

CYBERCOM’s funding request to scale capacity and munitions

Recognizing the mismatch between demand and the current ability to sustain effects, U.S. Cyber Command placed a funding ask before Congress earlier this year. In an unfunded priorities list, CYBERCOM requested an additional $229 million "for scaling cyber operational capacity and the development and deployment of cyber munitions," the reporting cites InsideDefense. Those funds are framed as addressing limitations in CYBERCOM’s ability to generate and sustain cyber effects "at speed and scale."

The request underscores a policy and resourcing question that mirrors Berg’s operational query: how to replenish capabilities and maintain persistent operational tempo when cyber tools and accesses are inherently perishable.

How Jason Kikta, Lt. Gen. Eubank, and CYBERCOM are responding

  • Jason Kikta (former CYBERCOM operator): Kikta’s assessment — that access is the "real asset" and is expended fast — suggests former and current operators will continue prioritizing reconnaissance and selective use of access, weighing intelligence value against the one-time strike potential of an exploit.
  • Lt. Gen. Christopher Eubank (Army Cyber Command): With Epic Fury running since 28 February and described as unrelenting, Eubank’s command faces the immediate operational problem of sustaining mission tempo, adapting priorities as the battlefield and cyberspace environment shift, and rotating or regenerating operator capacity.
  • U.S. Cyber Command (CYBERCOM): The $229 million unfunded request positions CYBERCOM to expand its ability to generate and sustain cyber effects; if funded, it would aim to address "limitations in CYBERCOM’s ability to generate and sustain cyber effects at speed and scale," per the reporting.

The facts on the record point to a blunt operational truth: cyber effects are powerful, but they are also consumable. Commanders who wage sustained campaigns in cyberspace must reconcile a tempo of operations that can burn through access with the limited and time-intensive process of finding new vulnerabilities. The service and command statements, the former operator’s warning, and CYBERCOM’s explicit budget ask together leave a concrete question: can the force replace what it expends fast enough to sustain prolonged, high-tempo operations — and how will witnessing adversaries adapt in response?

Original reporting at Breaking Defense