ai-cybersecuritytrade-pressNewsThe Broadside2 min read

Pentagon cyber chief says DODIN is a weapon system, finally

Three decades of deferred network maintenance has met AI-enabled attacks that chain mundane vulnerabilities at machine speed, and Lt. Gen. Paul Stanton says the grace period is over.


TL;DR

DISA director Lt. Gen. Paul Stanton told the Billington CyberSecurity Summit on Thursday that the Pentagon has spent three decades treating its networks as IT infrastructure rather than as a weapon system, and that AI-enabled adversaries have made that deferral unsustainable. Stanton said attackers now chain "relatively seemingly insignificant vulnerabilities" to achieve operational effects, and that zero-day discoveries have multiplied tenfold. His remarks land alongside Army Cyber Command's Task Force Lexington, which fields 17 agentic mission elements on DODIN today, and a Senate Armed Services Committee proposal to consolidate DOD's IT and cyber leadership under a single undersecretary, a reorganization driven partly by the friction Stanton described.

Lt. Gen. Paul Stanton's message at Billington Thursday wasn't a budget request disguised as a warning. It was a category correction.

"Readiness is something that we understand in the military: the readiness of a tank, the readiness of an aircraft, the readiness of a ship, we all understand that," said Stanton, who directs the Defense Information Systems Agency and commands the Pentagon's cyber defense forces. "But for some reason, over the past three decades, we have not treated our network and our data in the context of a weapon system, and we have postponed and deferred the sustainment and maintenance of our systems to our potential peril."

"No more," he added.

The timing isn't accidental. Army Cyber Command's Task Force Lexington (established in April) now runs 17 agentic mission elements and cyber protection teams on the DOD Information Network daily, hunting threats at a pace human analysts can't match. Separately, the Senate Armed Services Committee's draft FY2027 NDAA proposes merging the Pentagon CIO and principal cyber advisor roles under a new Undersecretary of Defense for Cyber, Information, and Networks, consolidating authority over IT enterprise, defensive cyber, and CDAO. The reorganization is partly an answer to the same command-and-control friction Stanton identified: the gap between CIO-led network defense and Cybercom-led operational activities has been widening for years.

Stanton's core claim is that AI flips the threat model. "We used to, in cybersecurity, focus on critical vulnerabilities, and we would address them," he said. "But now, with the advent of AI, you can take relatively seemingly insignificant vulnerabilities, chain them together in a meaningful way, and achieve effects." Zero-day volumes, he said, have jumped by an order of magnitude.

He also drew a line on agent autonomy that Task Force Lexington and Project Griffin (the Army's effort to build AI agents that ingest sensor feeds and execute defensive actions) will have to navigate. "Do you know what the agent's doing? Can you code? Do you understand sequence, selection and iteration? Do you understand ports and protocols? If the answers to those questions are 'no,' you don't have the fundamentals," Stanton said. "If you don't know what the agent's doing, you're not unleashing an agent on a network for which I'm responsible."

The question Stanton left unasked is whether a new org chart answers a three-decade maintenance deficit. Treating the network as a weapon system implies reorganizing budget authorities, training pipelines, and command relationships, not just relabeling them. The SASC proposal moves boxes. Stanton's "no more" suggests he thinks the boxes aren't the bottleneck.


Published ·Deep Fathom