Advertisement
Advertisement
Advertisement
17 September 2026·9 min read·By Erik Vanderwall

US Cyber Strategy Overlooks Military Logistics Links

US cyber strategy overlooks the civilian infrastructure links that keep the military moving, a Navy intelligence veteran argues.

US Cyber Strategy Overlooks Military Logistics Links

US cyber strategy has a blind spot. It sits between a commercial rail yard and a defense plant floor. For years, the conversation about protecting America from foreign hacking has centered on hardening individual networks, securing classified systems, and defending the most visible pieces of critical infrastructure. But a sustained conflict with Iran wouldn't test any single network in isolation. It would test the connective tissue that keeps the military moving, and that means railroads, ports, power lines, telecom links, and the smaller manufacturers that feed the defense industrial base. We can't ignore that.

A War Without a Clean Ending

There is little reason to believe the war with Iran will end anytime soon. Even as diplomatic efforts continue, Tehran remains unpredictable, with a durable ability to disrupt shipping and energy markets through actions in the Strait of Hormuz. That reality should push U.S. agencies to prepare for sustained Iranian cyber operations and to run defensive wargames now, before the pressure escalates further.

A career spent in Navy intelligence supporting expeditionary and special warfare operations teaches a specific lesson: look past the individual attack and ask what larger objective it serves. Iran's objectives are relatively straightforward. Impose enough pain on critical infrastructure, businesses, and public services to increase pressure on Washington. Disrupt the industrial and civilian systems that let the U.S. sustain military operations abroad.

Iran may not be a top-tier cyber power like China or Russia. It doesn't have to be.

One recent mapping effort cataloged 130 documented attack techniques used by five Iranian threat groups. That's a lot. Much of that playbook leans on well-known, repeatable methods rather than exotic capabilities, the kind of stuff that's been around for years and that defenders keep seeing again and again. Success doesn't require extraordinary skill. It really doesn't. The ability to create enough disruption, uncertainty, and delay is enough. America's greatest vulnerability may not be any single network or piece of critical infrastructure, but the links in between.

Prepare for Volume, Not Just Catastrophe

When Americans imagine a cyberattack on critical infrastructure, the mental image tends to be catastrophic: a large-scale blackout, a poisoned water supply, a digital Pearl Harbor. But that's not the whole story. In an extended conflict, the more realistic possibility is persistent attacks across many targets at once, a steady grinding pressure that never lets up. Small water systems, manufacturers, transportation providers, energy infrastructure, and local governments all become disruptive targets. They're everywhere. And we can't defend them all.

Smaller water utilities got hit. That recent string of attacks across 12 states is a prime example. So is the four-day outage of a small-scale power plant in the UK. Attackers don't need to destroy these systems. Any intrusion that manipulates industrial systems, interrupts operations, or forces operators to determine whether equipment can still be trusted consumes valuable time and resources, and that's the point.

Multiply that across dozens of organizations. Federal, state, local, and private-sector response capacity will be stretched thin. The cumulative strain on the country's ability to respond may matter more than any single attack, because when you pile pressure on dozens of groups at once, the system that's supposed to absorb every blow starts to bend in ways no single strike could ever manage. Iran doesn't need the world's most sophisticated cyber force. Its affiliated hacking groups just have to generate problems faster than defenders can investigate and remediate them.

Defense Contractors Face a New Calculus

Defense contractors have long faced espionage threats targeting military secrets. That threat remains. But the war has significantly changed Iran's motives and risk calculus. The same access used to steal information from the defense industrial base can also be used to destroy data and disrupt operations.

Destructive malware such as wipers and ransomware could destroy engineering files, disable production systems, or force manufacturers offline, directly affecting the military's ability to replenish equipment and supplies. An attacker does not have to shut down production to disrupt it.

Consider a compromised calibration setting, altered test result, or unauthorized change to engineering data. Discovering that an adversary had persistent access to a manufacturing environment raises difficult questions: Which files were touched? Which designs can still be trusted? Which components were manufactured from them?

The incident quickly becomes a production problem. Parts must be quarantined, engineering data re-validated, products retested. NIST SP 800-171 and CMMC set a core security baseline, which makes the current pause in CMMC implementation particularly concerning. But contractors must also be prepared to operate through destructive attacks and establish that their systems, data, and products can still be trusted. That preparedness has to extend down the supply chain, where a smaller manufacturer, software provider, or managed service provider may present a greater vulnerability than a well-defended prime.

The Attack Surface Doesn't Stop at the Fence Line

The U.S. military is extraordinarily capable at defending its own networks. Its operations depend on infrastructure it doesn't own or control. Troops and equipment move on commercial railroads. Materiel flows through commercial ports. Military airlift can depend on commercial carriers. Installations and defense contractors also depend on commercial power, telecommunications, and other infrastructure.

red and blue cargo containers

In an ongoing conflict, those dependencies become part of the attack surface. That's the problem. An adversary like Iran does not have to penetrate military command-and-control to interfere with these operations, because it's the quieter, softer edges of the system that give way first. At a time when speed matters most, cyberattacks that disrupt port scheduling, corrupt logistics information, or degrade power and communications can introduce critical delays and uncertainty.

Market Context: According to IBM's 2023 Cost of a Data Breach Report, critical infrastructure organizations experienced an average cost of $5.04 million per data breach in 2023.

This is why the line blurs. Civilian and military infrastructure merge in conflict. A commercial railroad carrying military equipment to a strategic port may be civilian infrastructure administratively, but operationally it's part of the nation's ability to operate its military power, and that distinction matters more than any administrative label ever could. The same holds for utilities and communications providers. And for other civilian infrastructure supporting military installations and defense production. Their resilience can quickly become a matter of military readiness.

Who Owns the Links Between Sectors?

American cybersecurity is organized around sectors, organizations, and authorities that make administrative sense. It's tidy. They're built for paperwork, not for war. And when you take a system that's designed to keep budgets and jurisdictions and chains of command clean and legible in peacetime, you shouldn't be surprised that it doesn't hold up when someone is actually shooting at it. The boundaries between them can become a serious liability. We've seen it. They can't hold.

Adversaries in Tehran do not care about administrative boundaries. They care about weak spots. A vulnerability anywhere in the chain connecting civilian infrastructure, industrial production, transportation, communications, and military operations can affect everything downstream.

That raises hard questions. Who's responsible for the cyber resilience of a commercial railroad that a military deployment depends on, and who answers when that railroad, or the utility serving a critical defense manufacturer, can't withstand a sustained nation-state campaign? Who identifies the supplier whose failure could disrupt multiple defense programs? And who coordinates the response when several are attacked at once? Nobody knows.

  • Critical infrastructure exercises should assume simultaneous incidents across multiple sectors and regions.
  • We should also be extremely cautious about weakening incentives driving cybersecurity improvements across the defense industrial base, including the current pause on CMMC.
  • Defense manufacturers should test their ability to operate through destructive attacks and determine whether engineering data, production systems, and finished products can still be trusted.
  • DoD exercises should treat civilian infrastructure, including rail, ports, energy, and communications, as a routine part of the operating environment and an attractive target for adversaries.

Small Attacks, Big Consequences

Catastrophic scenarios deserve attention. But exercises should also account for lower-level attacks that are less spectacular yet still highly consequential. Iran does not need overwhelming cyber capability to impose serious costs. Persistent disruption at home can increase political and economic pressure surrounding the war. Disruption of defense production and military logistics can make it harder for the U.S. to sustain operations abroad.

Frequently Asked Questions

What is the blind spot in US cyber strategy described in the article?

The article states that US cyber strategy has a blind spot sitting between a commercial rail yard and a defense plant floor. It explains that the conversation about protecting America from foreign hacking has centered on hardening individual networks, securing classified systems, and defending the most visible pieces of critical infrastructure, but a sustained conflict with Iran would test the connective tissue that keeps the military moving, including railroads, ports, power lines, telecom links, and smaller manufacturers that feed the defense industrial base.

Why does the article argue that Iran does not need to be a top-tier cyber power like China or Russia?

The article explains that one recent mapping effort cataloged 130 documented attack techniques used by five Iranian threat groups, and much of that playbook leans on well-known, repeatable methods rather than exotic capabilities. It states that success doesn't require extraordinary skill, and that the ability to create enough disruption, uncertainty, and delay is enough.

How does the article say defense contractors' risk calculus has changed in the war with Iran?

According to the article, defense contractors have long faced espionage threats targeting military secrets, but the war has significantly changed Iran's motives and risk calculus. The same access used to steal information from the defense industrial base can also be used to destroy data and disrupt operations, with destructive malware such as wipers and ransomware potentially destroying engineering files, disabling production systems, or forcing manufacturers offline.

When should U.S. agencies run defensive wargames, and what should those exercises assume?

The article states that the reality of a sustained conflict with Iran should push U.S. agencies to prepare for sustained Iranian cyber operations and to run defensive wargames now, before the pressure escalates further. It adds that critical infrastructure exercises should assume simultaneous incidents across multiple sectors and regions, and that DoD exercises should treat civilian infrastructure, including rail, ports, energy, and communications, as a routine part of the operating environment and an attractive target for adversaries.

Who does the article say is responsible for the cyber resilience of commercial infrastructure that military operations depend on?

The article raises hard questions about who's responsible for the cyber resilience of a commercial railroad that a military deployment depends on, and who answers when that railroad, or the utility serving a critical defense manufacturer, can't withstand a sustained nation-state campaign. It also asks who identifies the supplier whose failure could disrupt multiple defense programs, and who coordinates the response when several are attacked at once, concluding: "Nobody knows."

Erik Vanderwall
Written by
Security and Privacy Correspondent

Erik Vanderwall reports on information security, data breaches and the defenders working to keep systems safe. He follows the constant contest between attackers and the people trying to stop them.

💬 Comments (0)

Sign in to leave a comment.

No comments yet. Be the first!

Advertisement