That blunt assessment framed a recent war game run by the Foundation for Defense of Democracies (FDD) in Taiwan in late September. Organizers designed the simulation to test a campaign of cyberattacks and economic pressure that would aim to make daily life unreliable on the island and extract political concessions from Taipei while avoiding a full-scale invasion — a “gray-zone” strategy that, the exercise argued, U.S. planners rehearse far less often than open military conflict.
The FDD Taiwan simulation and who saw it
FDD officials briefed the exercise findings to Taiwanese President Lai Ching-te and his national security team after the event. Craig Singleton, FDD’s China program director, played the role of China during the scenario. Mark Montgomery helped lead the exercise and has urged future runs with congressional staff and federal agencies to improve U.S. preparedness.
How the scenario unfolded: from localized outages to damaged undersea cables
The exercise began with localized cellular disruptions, information manipulation and pressure on satellite connectivity, according to Craig Singleton. A second phase escalated to damaged undersea cables, disabled electrical substations that supported telecommunications, and strained backup networks. The simulated aim was to undermine confidence in Taiwan’s government by making everyday services less reliable without provoking a direct kinetic clash with the United States.
Organizers emphasized cascading effects: communications outages could disrupt payments, slow emergency coordination and make power failures harder to manage. Taiwanese participants rerouted traffic and activated alternatives; the tougher test, Singleton said, was whether backup systems could sustain services for weeks as an adversary studied responses and targeted fallback pathways.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleLessons on planning and recovery times, in Montgomery’s view
Montgomery warned that U.S. planning underestimates how long recovery actually takes when interdependent systems fail. “You know they’re speaking in minutes and hours, and my experience is days or weeks,” he said, describing a recurring problem observed across exercises in multiple countries. The FDD leaders argued that the Department of Defense often treats these campaigns as someone else’s responsibility, while other federal agencies lack the budget and systematic processes to run sustained tabletops focused on civil-sector disruptions.
Salt Typhoon and Volt Typhoon: influences, not literal labels
Organizers told reporters that lessons from prior operations informed the scenario. When asked about Salt Typhoon, a Chinese hacking campaign that breached U.S. and global telecommunications networks, Singleton said that operation informed the exercise but was not named directly in the simulation packets. He also said a separate Chinese hacking collective dubbed Volt Typhoon — which seeks to establish access to critical infrastructure for disruptive or destructive attacks during a major crisis or conflict — was not mentioned by name in the exercise but similarly influenced the war game.
“If an adversary already understands the network, its dependencies and its fallback pathways, then disruption can become much more targeted and adaptive,” Singleton said, explaining the tactical logic the simulation explored.
What this means for Taiwan’s government, U.S. federal agencies, and China-linked threat actors
- Taiwan’s government and emergency managers: The simulation tested rerouting and backup activation; organisers judged short-lived fixes adequate but vulnerable if pressure continued for weeks. The scenario was briefed to President Lai Ching-te and his national security team.
- U.S. federal agencies — the Department of Defense and other federal agencies: FDD leaders contend DoD views cyber coercion as a responsibility of other agencies, and those agencies lack a budgeted, systematic process to run the kind of sustained civil-sector tabletops the simulation found necessary.
- Beijing and Chinese hacking collectives: The exercise modelled a campaign intended to extract concessions without an invasion, drawing from previous operations’ tactics and emphasizing targeted, adaptive disruption of dependencies and fallback pathways.
The simulation and the briefings that followed land against a backdrop of official U.S. intelligence assessments included in the 2026 worldwide threat assessment by the Office of the Director of National Intelligence, which said Chinese leaders did not currently plan to invade Taiwan in 2027 and had no fixed timeline for unification, and that Beijing preferred achieving its goal without force while continuing to develop military options. U.S. officials have also judged an invasion before 2028 increasingly unlikely, citing military readiness delays and China’s interest in Taiwan’s next presidential election.
Montgomery warned of a possible shift in tempo tied to Taiwan’s political calendar: he said early 2028 could bring intensified cyber and economic coercion if Taiwan’s Democratic Progressive Party wins a fourth consecutive presidential election. FDD said it hopes to run future exercises with congressional staff and federal agencies to address the gaps the simulation exposed.
The simulation’s message was pointed: gray‑zone campaigns that degrade civilian services can be calibrated to avoid kinetic escalation, and preparing for them requires budgets, cross‑agency processes and realistic expectations about recovery timelines. Whether those practical steps follow the exercise rests on decisions U.S. agencies and lawmakers have yet to make.




