Evidence Pack: The Architecture of U.S. Cyber Strategy and the Shift to Persistent Engagement
A comparative analysis of the doctrinal frameworks—Defend Forward, Persistent Engagement, and Deterrence by Detection—that govern modern military operations below the threshold of armed conflict.
By Aarav Khanna
- Doctrinal Proponents
- Argues that continuous friction is the only viable way to defend a domain where adversaries are perpetually active.
- Escalation Skeptics
- Warns that operating inside adversary networks risks miscalculation and unintended escalation into conventional war.
- Deterrence Realists
- Questions whether detection and friction actually change adversary strategic goals or merely force them to alter their tactics.
Perspectives this story doesn't cover
- Allied nations whose networks may be utilized as neutral ground during Defend Forward operations
- Private sector infrastructure operators who bear the collateral impact of state-level cyber friction
In 2018, the United States Department of Defense fundamentally altered its cyber posture, publishing a vision document that replaced a historically reactive stance with a mandate to operate continuously against adversaries. This pivot acknowledged a structural reality of the digital domain: it is not a dormant battlefield awaiting a conventional war, but an environment of constant, daily contact where state actors maneuver for strategic advantage.[1]
This shift codified two distinct but interlocking concepts that now define U.S. military cyber operations: Defend Forward and Persistent Engagement. While often used interchangeably in public discourse, they represent different nodes in the operational architecture. One dictates where forces operate, while the other dictates the tempo of those operations.[1][3]
Defend Forward is the geographic and network-topological mandate. It dictates that U.S. forces must operate outside their own networks—specifically within adversary or neutral networks—to halt malicious activity before it reaches domestic infrastructure. The evidence supporting this approach rests on the premise that waiting for an attack to hit domestic firewalls cedes the initiative entirely to the attacker.[1][2]
Persistent Engagement, conversely, is the operational tempo. It argues that because adversaries are constantly probing, mapping, and exploiting vulnerabilities below the threshold of armed conflict, the only effective defense is continuous, reciprocal friction. By imposing tactical costs on a daily basis, defenders aim to disrupt the adversary's operational rhythm.[3][6]
The mechanics of this friction are highly specific. They include exposing adversary malware to public cybersecurity vendors, disrupting command-and-control servers, or publicly attributing attacks to specific state intelligence units. The goal is to force attackers to expend their resources rebuilding infrastructure and developing new tools rather than executing their primary strategic missions.[1][6]
The evidence supporting the efficacy of Persistent Engagement is largely drawn from the absence of catastrophic cyber events since its implementation, though academic literature notes the inherent difficulty of proving a negative. Analysts point out that while low-level intrusions continue, the continuous friction model has arguably prevented these intrusions from coalescing into larger, systemic attacks.[3][6]
A third, parallel framework—Deterrence by Detection—operates on a similar logic of continuous presence but relies on pervasive Intelligence, Surveillance, and Reconnaissance (ISR) rather than active network disruption. This concept extends beyond the cyber domain, encompassing space-based sensors, maritime patrols, and signals intelligence.[4]
This concept extends beyond the cyber domain, encompassing space-based sensors, maritime patrols, and signals intelligence.
Deterrence by Detection posits that if an adversary knows they are being continuously observed by a network of sensors, they are less likely to initiate an aggressive act because the element of surprise is eliminated. The theoretical foundation is that transparency itself acts as a deterrent mechanism, denying the adversary the benefit of anonymity.[4][5]
However, the evidence for Deterrence by Detection is highly contested within the strategic community. Critics argue that visibility does not equal deterrence; an adversary may simply accept that they are being watched if they believe the observing party lacks the political will or the rapid-response capability to intervene effectively.[5]
The Center for Strategic and International Studies (CSIS) analysis highlights this limitation explicitly, noting that perfect attribution and detection do not automatically translate to behavioral change. Highly motivated state actors, particularly those operating in their own geographic spheres of influence, may proceed with operations regardless of whether they are detected.[5]
When analyzed as a unified system, these three frameworks reveal a fundamental shift in how military power is applied in the 21st century. They move away from the Cold War model of "deterrence by punishment"—which relies on the threat of massive retaliation—toward "deterrence by denial" and "deterrence by friction."[2][3][7]
The integration of Defend Forward and Deterrence by Detection creates a theoretical operational loop: pervasive ISR identifies the adversary's preparations, and forward-deployed cyber elements disrupt those preparations before they mature. This requires a seamless flow of intelligence from collection platforms to tactical cyber units.[1][4][7]
Yet, the empirical evidence regarding escalation risks remains thin and heavily debated. A primary concern among scholars is that operating continuously in adversary networks (Defend Forward) could be misinterpreted as preparation for a kinetic strike, inadvertently triggering the very conflict the strategy aims to prevent.[3][6]
The Taylor & Francis study on permanent engagement underscores this uncertainty, questioning whether continuous tactical friction actually alters long-term strategic behavior or merely accelerates the cycle of cyber capability development on both sides. If the latter is true, the strategy may inadvertently drive a rapid arms race in stealth and counter-detection technologies.[6]
Ultimately, the architecture of modern military cyber operations relies on the assumption that continuous, low-level engagement is safer and more effective than episodic, high-intensity retaliation. While the operational data from the past several years supports this hypothesis, the long-term stability of a perpetually contested domain remains an open question.[3][6][7]
What we don’t know
- Whether continuous cyber friction actually deters long-term strategic campaigns or merely forces adversaries to develop better stealth capabilities.
- The exact threshold at which an adversary might interpret a Defend Forward operation as an act of war.
- How effectively Deterrence by Detection can be maintained against peer adversaries with advanced counter-ISR capabilities.
Sources
[1]U.S. Cyber CommandDoctrinal ProponentsCYBER 101 - Defend Forward and Persistent Engagement
Read on U.S. Cyber Command →
[2]Model DiplomatDoctrinal ProponentsDefend Forward: U.S. Cyber Strategy Explained
Read on Model Diplomat →
[3]CSS ETH ZürichEscalation SkepticsUS Cyber Strategy of Persistent Engagement and Defend Forward
Read on CSS ETH Zürich →
[4]Model DiplomatDoctrinal Proponentsdeterrence by detection — Definition & Meaning
Read on Model Diplomat →
[5]CSISDeterrence RealistsBad Idea: Deterrence by Detection
Read on CSIS →
[6]Taylor & Francis OnlineEscalation SkepticsThe implications of persistent (and permanent) engagement in cyberspace
Read on Taylor & Francis Online →
[7]Factlen Editorial TeamDeterrence RealistsSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
Comments
More in Defense & Security
See all →Acoustic Stealth
Silencing the Hull: How Anechoic Tiles, Isolation Mounts, and Pump-Jets Suppress Submarine Radiated Noise
9 sources
CBRN Defense
Survival, Sustainment, and Reconstitution: The Three Phases of CBRN Decontamination
5 sources
Space-Based SIGINT
Mapping Dark Fleets: The Accuracy and Limits of Commercial RF Satellite Geolocation
8 sources
Information Security
U.S. Information Classification: The Statutory Boundaries Between Top Secret, Secret, and Confidential
8 sources
Every angle. Every day.
Get Defense & Security stories with full source coverage and perspective breakdowns delivered to your inbox.




