Skip to main content
Research BriefCyber StrategyEvidence Pack· 4 min read· in Defense & Security

Evidence Pack: The Architecture of U.S. Cyber Strategy and the Shift to Persistent Engagement

A comparative analysis of the doctrinal frameworks—Defend Forward, Persistent Engagement, and Deterrence by Detection—that govern modern military operations below the threshold of armed conflict.

By Aarav Khanna

Doctrinal Proponents 40%Escalation Skeptics 30%Deterrence Realists 30%
Doctrinal Proponents
Argues that continuous friction is the only viable way to defend a domain where adversaries are perpetually active.
Escalation Skeptics
Warns that operating inside adversary networks risks miscalculation and unintended escalation into conventional war.
Deterrence Realists
Questions whether detection and friction actually change adversary strategic goals or merely force them to alter their tactics.

Perspectives this story doesn't cover

  • Allied nations whose networks may be utilized as neutral ground during Defend Forward operations
  • Private sector infrastructure operators who bear the collateral impact of state-level cyber friction
2018
Year DoD officially adopted Defend Forward
0
Conventional wars triggered by cyber engagement to date
100%
Theoretical visibility goal of detection networks

In 2018, the United States Department of Defense fundamentally altered its cyber posture, publishing a vision document that replaced a historically reactive stance with a mandate to operate continuously against adversaries. This pivot acknowledged a structural reality of the digital domain: it is not a dormant battlefield awaiting a conventional war, but an environment of constant, daily contact where state actors maneuver for strategic advantage.[1]

This shift codified two distinct but interlocking concepts that now define U.S. military cyber operations: Defend Forward and Persistent Engagement. While often used interchangeably in public discourse, they represent different nodes in the operational architecture. One dictates where forces operate, while the other dictates the tempo of those operations.[1][3]

Defend Forward is the geographic and network-topological mandate. It dictates that U.S. forces must operate outside their own networks—specifically within adversary or neutral networks—to halt malicious activity before it reaches domestic infrastructure. The evidence supporting this approach rests on the premise that waiting for an attack to hit domestic firewalls cedes the initiative entirely to the attacker.[1][2]

Persistent Engagement, conversely, is the operational tempo. It argues that because adversaries are constantly probing, mapping, and exploiting vulnerabilities below the threshold of armed conflict, the only effective defense is continuous, reciprocal friction. By imposing tactical costs on a daily basis, defenders aim to disrupt the adversary's operational rhythm.[3][6]

The three pillars of modern proactive defense strategies.

The mechanics of this friction are highly specific. They include exposing adversary malware to public cybersecurity vendors, disrupting command-and-control servers, or publicly attributing attacks to specific state intelligence units. The goal is to force attackers to expend their resources rebuilding infrastructure and developing new tools rather than executing their primary strategic missions.[1][6]

The evidence supporting the efficacy of Persistent Engagement is largely drawn from the absence of catastrophic cyber events since its implementation, though academic literature notes the inherent difficulty of proving a negative. Analysts point out that while low-level intrusions continue, the continuous friction model has arguably prevented these intrusions from coalescing into larger, systemic attacks.[3][6]

A third, parallel framework—Deterrence by Detection—operates on a similar logic of continuous presence but relies on pervasive Intelligence, Surveillance, and Reconnaissance (ISR) rather than active network disruption. This concept extends beyond the cyber domain, encompassing space-based sensors, maritime patrols, and signals intelligence.[4]

This concept extends beyond the cyber domain, encompassing space-based sensors, maritime patrols, and signals intelligence.

Deterrence by Detection posits that if an adversary knows they are being continuously observed by a network of sensors, they are less likely to initiate an aggressive act because the element of surprise is eliminated. The theoretical foundation is that transparency itself acts as a deterrent mechanism, denying the adversary the benefit of anonymity.[4][5]

However, the evidence for Deterrence by Detection is highly contested within the strategic community. Critics argue that visibility does not equal deterrence; an adversary may simply accept that they are being watched if they believe the observing party lacks the political will or the rapid-response capability to intervene effectively.[5]

The Center for Strategic and International Studies (CSIS) analysis highlights this limitation explicitly, noting that perfect attribution and detection do not automatically translate to behavioral change. Highly motivated state actors, particularly those operating in their own geographic spheres of influence, may proceed with operations regardless of whether they are detected.[5]

When analyzed as a unified system, these three frameworks reveal a fundamental shift in how military power is applied in the 21st century. They move away from the Cold War model of "deterrence by punishment"—which relies on the threat of massive retaliation—toward "deterrence by denial" and "deterrence by friction."[2][3][7]

The integration of Defend Forward and Deterrence by Detection creates a theoretical operational loop: pervasive ISR identifies the adversary's preparations, and forward-deployed cyber elements disrupt those preparations before they mature. This requires a seamless flow of intelligence from collection platforms to tactical cyber units.[1][4][7]

Yet, the empirical evidence regarding escalation risks remains thin and heavily debated. A primary concern among scholars is that operating continuously in adversary networks (Defend Forward) could be misinterpreted as preparation for a kinetic strike, inadvertently triggering the very conflict the strategy aims to prevent.[3][6]

How surveillance and forward operations integrate to disrupt adversary campaigns.

The Taylor & Francis study on permanent engagement underscores this uncertainty, questioning whether continuous tactical friction actually alters long-term strategic behavior or merely accelerates the cycle of cyber capability development on both sides. If the latter is true, the strategy may inadvertently drive a rapid arms race in stealth and counter-detection technologies.[6]

Ultimately, the architecture of modern military cyber operations relies on the assumption that continuous, low-level engagement is safer and more effective than episodic, high-intensity retaliation. While the operational data from the past several years supports this hypothesis, the long-term stability of a perpetually contested domain remains an open question.[3][6][7]

What we don’t know

  • Whether continuous cyber friction actually deters long-term strategic campaigns or merely forces adversaries to develop better stealth capabilities.
  • The exact threshold at which an adversary might interpret a Defend Forward operation as an act of war.
  • How effectively Deterrence by Detection can be maintained against peer adversaries with advanced counter-ISR capabilities.

Sources

Source coverage

7 outlets

3 viewpoints surfaced

Doctrinal Proponents 40%Escalation Skeptics 30%Deterrence Realists 30%
  1. [1]U.S. Cyber CommandDoctrinal Proponents

    CYBER 101 - Defend Forward and Persistent Engagement

    Read on U.S. Cyber Command
  2. [2]Model DiplomatDoctrinal Proponents

    Defend Forward: U.S. Cyber Strategy Explained

    Read on Model Diplomat
  3. [3]CSS ETH ZürichEscalation Skeptics

    US Cyber Strategy of Persistent Engagement and Defend Forward

    Read on CSS ETH Zürich
  4. [4]Model DiplomatDoctrinal Proponents

    deterrence by detection — Definition & Meaning

    Read on Model Diplomat
  5. [5]CSISDeterrence Realists

    Bad Idea: Deterrence by Detection

    Read on CSIS
  6. [6]Taylor & Francis OnlineEscalation Skeptics

    The implications of persistent (and permanent) engagement in cyberspace

    Read on Taylor & Francis Online
  7. [7]Factlen Editorial TeamDeterrence Realists

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team

Comments

Stay informed

Every angle. Every day.

Get Defense & Security stories with full source coverage and perspective breakdowns delivered to your inbox.