Permanent contact¶
The US and cyber operations as a standing activity rather than a set of strikes
The American cyber story is told in set pieces. Stuxnet slipping into Natanz, the NSA’s Tailored Access Operations catalogue, the Equation Group and its firmware implants, Flame and Regin surfacing in Middle Eastern and telecoms networks: a run of singular, sophisticated operations, each read as a demonstration of reach. It is the register other states’ actors are given, the virtuoso and the shadowy professional, turned admiring and first-person.
Read for the routine rather than the set piece, American cyber power looks less like a sequence of operations than a posture: a standing commitment to stay in continuous contact with other states’ networks, doing the ordinary, unglamorous work of a permanent competition. The doctrine has a name for the posture, and it is unusually candid.
The doctrine that makes it ordinary¶
The substrate is scale and reach: global military commitments, an intelligence establishment built for continuous collection, an alliance network that supplies access and geography, a private technology sector that supplies infrastructure and expertise, and the freedom to operate almost everywhere. What turns that capacity into a signature is a doctrine that makes using it continuously the default. US Cyber Command calls it persistent engagement and defend forward: operating continuously to disrupt malicious activity at its source, including activity below the level of armed conflict, and shifting posture, in the command’s own words, from reactive to proactive. The doctrine’s purpose is that there is no waiting for an intrusion to arrive. Contact is constant by design.
The coupling: operations as a standing campaign¶
The coupling is institutional before it is technical. US Cyber Command is a unified combatant command whose commander is dual-hatted as Director of the NSA, drawing on the intelligence agency’s access; the Cyber National Mission Force and the service cyber components supply the forces; allies supply the networks to operate from; and private companies supply the software and the patches. The most visible edge is hunt forward: at a partner’s invitation, American teams deploy onto that nation’s networks to find an adversary already inside, and the findings are routed to the FBI and the domestic cyber agency and to private software vendors, with more than ninety malware samples released publicly for the industry to analyse. Intelligence yields access, access yields presence, presence yields disruption and further intelligence, and the take feeds partners, industry and the next operation. It is a machine for staying in contact, built to keep running.
That makes a clean contrast with China. China’s signature is a procurement pipeline, where the state buys operations from a contractor market. America’s is an operational network, where the state conducts them continuously through an apparatus that never quite stands down.
The signature is the machinery, not the operation¶
Read this way, the spectacular operation is almost incidental. Stuxnet is the piece everyone remembers, and it is a single expensive strike, but the doctrine is the opposite of a strike: it is the institutionalisation of doing this every day, below the threshold that would make any single act a strike at all. The signature is not one capability. It is a standing apparatus that treats access, disruption, intelligence and defence as a single continuous activity rather than separate phases.
Where the tidy version breaks¶
Two things complicate it, and both cut at the word engagement.
The first is that the doctrine may not do what it claims. Its own architects argue that deterrence does not apply in cyberspace at all, that the domain is one of constant contact whose honest end-state is not cessation but agreed competition, a continuous friction with tacit bounds. Persistent contact, on that account, is less a way of stopping adversaries than a way of living permanently beside them. Whether the friction raises their costs or thins their intrusions is asserted by the command and, in open sources, close to unmeasured.
The second is an observability problem that bends the whole account. Hunt forward is public precisely because it is defensive, invited and shareable; the offensive operations the dual-hat structure enables, the ones that would test whether contact changes anyone’s behaviour, are the least visible of all. MITRE, which names the sponsoring government for many states’ actors, labels the American-linked tools descriptively and declines to attribute them, and carries no entry at all for Tailored Access Operations. So the record that can be read tilts heavily toward the cooperative, defensive face, and away from the part that would answer the hard question. Any account assembled from open sources overstates the sharing and understates the operating.
What stays open¶
The operational cycle can be traced a surprising distance, from adversary activity through intelligence, access, disruption and back to renewed access. The strategic return edge, whether continuous contact deters, degrades, or merely sustains a contest both sides grow better at, does not close on the available evidence, and by the design of the secrecy it is the edge least visible from outside. That is the awkward part: the most consequential operations are the least observable, so any public reading of American cyber power is drawn from the half of the doctrine that can be discussed.
What survives is a single normalisation. American cyber power is not, at bottom, a gallery of spectacular operations. It is the treatment of access, disruption, intelligence and defence as one standing activity, a permanent contact the state has built the institutions to maintain and the doctrine to call routine. The memorable operation was always the exception. The doctrine that made the operation ordinary is the capability.