Decades of delayed maintenance has left Pentagon networks in ‘potential peril’ for the AI age, cyber defense commander says: ‘no more.’
The top general in charge of securing and defending the Pentagon’s cyber infrastructure said Thursday that decades of delayed maintenance has left DOD networks increasingly vulnerable in the AI age, adding to the drumbeat of warnings across the field about agent-instigated hacks.
Lt. Gen. Paul Stanton, commander of the Pentagon’s cyber defense command and director of the Defense Information Systems Agency, told an audience at the annual Billington CyberSecurity Summit in Washington that the ways in which an adversary could employ cyber agents is “mind-boggling in terms of the complexity.”
He likened the cyber playing field to maneuver warfare, comparing enemy hacks to the way an opposing ground force would identify and exploit physical entry points on the battlefield. The military cyber community needs to adopt such a “maneuverist” mindset, he said, including in the way operators treat the systems they use to combat an enemy force.
“Readiness is something that we understand in the military: the readiness of a tank, the readiness of an aircraft, the readiness of a ship, we all understand that,” Stanton, a former infantry officer, said. “But for some reason, over the past three decades, we have not treated our network and our data in the context of a weapon system, and we have postponed and deferred the sustainment and maintenance of our systems to our potential peril.”
“No more,” he added. Stanton said that cyber operators can no longer afford to defer patching or upgrades to operating systems when new versions are released, and that those digital troops need to train on cyber systems the same way combat arms troops train with their own weapons.
His comments come after the Army’s cyber command established an AI task force to develop agents for the DOD’s information network, and as multiple frontier AI companies continue to disclose that their own agents escaped testing environments to hack third-party organizations.
Anthropic — which is anticipated to launch a massive initial public offering this fall — reported a fourth incident Wednesday it had missed on an initial review and as multiple AI researchers, spurred by the resignation of an Anthropic employee, warned of the disruptive technology’s dangers to humanity.
At the heart of the AI-cyber upheaval is agents’ ability to identify and exploit digital vulnerabilities faster than humans, leading to fears across the field about how devastating a mass-coordinated, agentic attack could be on critical infrastructure, companies, the military and other entities.
“We used to, in cybersecurity, focus on critical vulnerabilities, and we would address them,” Stanton said. “But now, with the advent of AI, you can take relatively seemingly insignificant vulnerabilities, chain them together in a meaningful way, and achieve effects.”
He said the number of zero day vulnerabilities has soared, having multiplied “by a factor of ten, a changed order of magnitude, and that’s what we’re up against currently.”
Several top cyber officials have said the military needs to integrate AI into network defense to combat these “machine-speed” attacks, including the Army, which recently asked industry to help the service create such a capability under Project Griffin.
“Static defenses will not work in a[n] era of AI-enabled cyberspace warfare,” said Stanton. But he also cautioned that agentic-led cybersecurity is not the end-all for network defense, which he said requires a human, fundamental understanding of the systems and the risks that network-integrated AI could pose to troops in combat.
“Do you know what the agent’s doing? Can you code? Do you understand sequence, selection and iteration? Do you understand ports and protocols? If the answers to those questions are ‘no,’ you don’t have the fundamentals,” he said. “And if you don’t know what the agent’s doing, you’re not unleashing an agent on a network for which I’m responsible, the network for which I’m responsible has a warfighter on the end of it.”
While the military must automate cyber work, he said, human operators have to understand how those agents are employed and the third-order impacts they may cause ahead of their deployment. He suggested that digital twins could help forecast those effects.
“There’s a[n] infantryman with a software-defined radio in contact on the other end of that circuit. If an agent makes a configuration change inside the operating environment that I don’t understand, I cannot accept the risk that you’re severing communications while we’ve got troops in contact,” he added. “That’s an unacceptable risk.”
Stanton previously spoke about standardization and needing to better maintain the network during the annual TechNet August conference last month, reiterating that cyber operators need to adopt a combat arms culture. Failing to adequately patch vulnerabilities or fix systems can impose risk on other network functions, he said at the time.
The standardization of those weapon systems for cyber operators is a requirement, Stanton said at the Billington summit, just like it would be for a tank or aircraft. In turn, they have to be fluent on those like-made systems to employ them in the “operational context” those troops are responsible for.
“We’ve got to build the qualification concept such that as you deploy something new, we take our service members to the range,” he said. “We validate that they can execute effectively, and now I have the confidence as the commander issuing orders that they can execute.”