The US never stands down

The US and cyber operations as a standing activity rather than a set of strikes

Stuxnet slipping into Natanz, the NSA’s Tailored Access Operations catalogue, the Equation Group and its firmware implants, Flame and Regin surfacing in Middle Eastern and telecoms networks: a run of singular, sophisticated operations, each read as a demonstration of reach. It is the register other states’ actors are given, the virtuoso and the shadowy professional, turned admiring and first-person.

For the routine rather than the showpiece, American cyber power looks less like a sequence of operations than a posture: a standing commitment to stay in continuous contact with other states’ networks, doing the ordinary, unglamorous work of a permanent competition. The important word is not the strike but the standing. The United States runs cyber operations as a normal condition because it can sustain the machinery indefinitely. The doctrine has a name for the posture, and it is unusually candid.

Contact as posture

The substrate is scale and reach: global military commitments, an intelligence establishment built for continuous collection, an alliance network that supplies access and geography, a private technology sector that supplies infrastructure and expertise, and the freedom to operate almost everywhere. What turns that capacity into a signature is a doctrine that treats continuous contact as the default posture. US Cyber Command named it persistent engagement and defend forward: operating continuously to disrupt malicious activity at its source, including below the level of armed conflict, and shifting from reactive to proactive. By the mid-2020s the more current description is campaigning in and through cyberspace, organising that contact into a running sequence of operations rather than a series of separate contacts. NATO’s 2024 policy treats cyberspace as contested at all times, with operations spanning peacetime, crisis and conflict, the posture the United States operationalised. The claim is not that offensive action runs continuously against every adversary. It is continuous readiness, access, observation and opportunity, the default set to contact rather than to wait.

Several machines, one take

The institution is not one machine but several. US Cyber Command is a unified combatant command whose commander is dual-hatted as Director of the NSA, drawing on the intelligence agency’s access; the Cyber National Mission Force and the service cyber components supply the forces; the FBI investigates and disrupts at home; the civilian cyber agency defends critical infrastructure and shares warning; the State Department carries the diplomacy; allies supply networks; and private companies supply infrastructure, telemetry and research. What is distinctive is less any single unit than the ability to move an observation between them.

The clearest case is hunt forward: at a partner’s invitation, American teams deploy onto that nation’s networks to find an adversary already inside, and a single such operation yields several outputs at once, the partner’s defence, US intelligence, malware for public release, warning to allies, and renewed access. Ninety malware samples were released publicly in 2023 alone for the industry to analyse. The intrusion is not the objective. The take is: intelligence yields access, access yields presence, presence yields disruption and further intelligence, and the take feeds partners, industry and the next operation. The signature is that the information does not stay inside the military.

The private sensor

Calling the private sector a supplier of software and patches understates it. The American apparatus runs on private infrastructure at almost every layer: cloud computing, endpoint telemetry, threat intelligence, vulnerability research and incident response. And private companies increasingly see the adversary at scale before the government does. NATO’s deputy secretary general put it bluntly in 2024, that in cyber it is the private sector, not the military, that is in the driving seat, which leaves the state the problem of how to absorb that innovation and intelligence. That produces a second loop nested inside the first. The state shares indicators with vendors, the indicators become detection rules across millions of endpoints, those endpoints generate new observations, and the observations return to the state. The state changes the defensive capability of an enormous civilian ecosystem without owning it. It is national cyber power by diffusion, and it is why military cyber power is too narrow a description.

An alliance property

Allies are not merely geography. They supply legitimacy, access, telemetry, local knowledge and reach, and hunt forward differs from unilateral penetration because the partner invites it. The alliance architecture is itself becoming permanently cyber-operational: in 2024 NATO agreed to establish an Integrated Cyber Defence Centre to improve situational awareness and the ability to operate in cyberspace across peacetime, crisis and conflict. American persistence is partly an alliance property. The capability is extraordinary on its own, but its footprint is amplified because dozens of countries supply observation surfaces and the political relationships that make operating on them legitimate.

The vulnerability as resource

A state that wants continuous access has a different relationship to software flaws than one interested only in defence. A vulnerability can be disclosed, patched, retained, exploited, shared with an ally, handed to a vendor, used for collection or used for disruption, and the same flaw cannot be all of these at once. The Vulnerabilities Equities Process exists because the government has to decide, case by case, whether a flaw it holds is disclosed or retained. The existence of the process is the revealing thing, whatever the balance of its decisions: the same state that wants everyone else’s systems secure has standing reasons to keep some systems exploitable. The tension is not unique to the United States, but the scale of its intelligence and military ecosystem makes it unusually consequential.

The unseen half

The doctrine may not do what it claims. Its own architects argue that deterrence is not a credible strategy for cyberspace, that the domain is one of constant contact whose end-state is not cessation but agreed competition. Persistent contact, on that account, is less a way of stopping adversaries than a way of living permanently beside them, and whether it raises their costs, thins their intrusions, or merely produces a stable contest both sides get better at is asserted by the command and, in open sources, close to unmeasured. That last possibility is the live one, and it is compatible with the doctrine: the state may not expect cyber conflict to end, only to manage its position within it.

There is also an observability problem that bends the whole picture. Hunt forward is public because it is defensive, invited and shareable; the offensive operations the dual-hat structure enables, the ones that would test whether contact changes anyone’s behaviour, are the least visible of all. MITRE, which names the sponsoring government for many states’ actors, labels the American-linked tools descriptively and declines to attribute them, and carries no entry for Tailored Access Operations. The record that can be read is not lying; its visibility is structurally biased. Any account assembled from open sources will disproportionately see the sharing and undersee the operating.

Recurring business, not a strike

The memorable operation is the wrong thing to count. A strike has a beginning and an end; a standing apparatus has neither in the same sense. It holds access, watches adversary behaviour, builds tooling, shares findings, alters the adversary’s environment, and uses what it learns to set up the next operation. The unit of capability is not the implant or the intrusion. It is the cycle, and much of it is routine enough that the state has built standing authority for it. Where a spectacular operation once needed an extraordinary presidential decision, continuous cyber activity runs under standing military and intelligence authorities, with congressional notification and rules of engagement, conducted as recurring government business. That bureaucratisation is part of the standing. The distinctive feature is not persistence as duration. It is persistence as the absence of a terminal state.

A diagram of effects for American cyber power, drawn as two reinforcing loops that close and one edge that does not. The operational loop turns intelligence into access, access into persistent presence, presence into disruption, disruption into the shared take, and the take back into intelligence. A second loop, the information ecosystem, runs off the shared take: the take reaches partners and industry, becomes defensive products across many endpoints, generates new telemetry, and returns to the shared take. Both loops are drawn solid, meaning documented, and both are reinforcing, marked R. A single open edge leaves disruption toward adversary networks degraded and then rises, dashed, to a question mark without closing: whether continuous contact deters, degrades, contains, or merely sustains a contest both sides get better at. The two loops close; the strategic edge does not.

The adversary is in the loop

If the posture works by continuous contact, then adversary adaptation is not an external disturbance to it. It is part of the system. American operations reveal something, alter the adversary’s calculations or capabilities, and provoke adaptation; the apparatus then observes that adaptation and adjusts in turn. USCYBERCOM’s own doctrine treats the environment in roughly these terms: no target remains static, no capability remains indefinitely effective, and advantage is continually contested.

The adversary is therefore not outside the American cyber system. It is one of the variables that keeps the system moving. That is also why the contest has no obvious end state. Each side changes the conditions under which the other operates, so the thing being maintained is not victory but contact, adaptation and the capacity to act again.

Ordinary by doctrine

American cyber power is not, at bottom, a gallery of spectacular operations. It is the treatment of access, intelligence, disruption and defence as one standing activity, maintained across military, intelligence, government, private industry and allies. The operational loop closes: intelligence produces access, access produces presence, presence produces disruption and information, and the take returns to the system. The strategic loop does not. Whether that permanent contact deters, degrades, contains or simply reproduces competition remains the question the machinery cannot answer for itself.

The doctrine that made the operation ordinary is the capability.