Applying Warfighting Principles to Cyber Resilience


By Lt. Col. Vince Holloway, USA (Ret.)

Engineering teams can strengthen cyber resilience within military infrastructure by applying warfighting principles to their cybersecurity practices while ensuring full integration into systems and maintenance cadences.
In an increasingly connected and complex cyber domain, defense organizations must integrate cybersecurity practices with other core practices of infrastructure engineering. Photo by David Grim, U.S. Space Force Combat Forces Command.

Throughout the defense enterprise, military installations rely on a complex web of infrastructure systems to sustain training, logistics, manpower, and force projection. The realms of water, energy, communications, and operational technology are no longer just support functions; they are mission-critical elements that are being increasingly targeted by sophisticated cyber adversaries.

Recent reporting highlights a shift in adversary intent. To enable disruption, nation-state actors are now pre-positioning within infrastructure environments. Campaigns such as Volt Typhoon, a China-linked cyber campaign targeting U.S. infrastructure, demonstrate how attackers exploit legitimate system tools and avoid traditional malware, making detection difficult while maintaining persistent access to critical systems.

For installation engineers and mission assurance leaders, this evolving threat landscape requires a fundamental shift. Cybersecurity must be treated not as a technical overlay, but as an engineering and operational discipline essential to readiness. The integration of infrastructure systems has to be deliberately designed to operate through disruption. They must maintain critical functions under degraded conditions rather than relying solely on prevention or rapid restoration.

An approach that has shown to be effective is to adapt proven military operational principles to cyber defense. The principles of war provide a practical framework for strengthening resilience across information technology (IT) and operational technology (OT), both now-kinetic environments that support the warfighter at the strategic, operational, tactical, and installation levels.

Coordinated Action

In military operations, command and control ensures coordinated action under a clear authority structure. The same construct applies to cyber defense across base infrastructure and reflects the principle of unity of command.

Many cyber incidents exploit gaps between IT and OT, where responsibility and visibility are fragmented. Both engineers and cybersecurity leaders must synchronize their actions, whether through a centralized authority or tightly coordinated teams, to ensure that defensive actions are executed consistently across interconnected systems. For garrison environments, this requires clearly defined roles across engineering, cybersecurity, and operations, supported by a shared situational awareness of priorities. Mission-type orders can further enable local teams to act decisively within defined objectives. This improves response speed during incidents while maintaining alignment with installation-wide goals. The result is reduced confusion, faster decision-making, and more effective coordination when systems are under attack.

Security and Surprise

Military planners rely on intelligence preparation of the battlefield to understand terrain, anticipate threats, and reduce uncertainty. A similar approach is essential for cyber resilience.

At the installation level, this begins with engineering-driven mapping of critical infrastructure systems across IT and OT environments. Users must understand system dependencies, normal operating conditions, and which assets are essential to mission execution. This foundation enables organizations to anticipate adversary behavior. Techniques such as credential misuse, remote access exploitation, and living off the land activity should be expected and actively monitored.

Vulnerabilities need to be identified and prioritized as part of ongoing system management.

Implementing scenario-based planning is equally important. By war-gaming potential cyber incidents, such as disruption of utility control systems or loss of communications, both engineering and operations can evaluate how systems will perform under stress and identify where additional resilience or redundancy must be designed in. This intelligence-driven approach reduces uncertainty and ensures that teams focus defensive efforts where they matter most.

Proper Preparation

Modern military success depends on combined arms, which integrates multiple capabilities so that no single failure leads to defeat. In cybersecurity, this translates to layered, coordinated defense strategies embedded directly into infrastructure design and operations. Such an approach reflects the principles of mass and maneuver by concentrating defensive effects and limiting adversary movement.

For installation environments, these strategies should be engineered as part of the system architecture rather than applied as afterthoughts. Effective defense begins with identity-based access controls that restrict interaction with critical systems to authorized users. This is reinforced by network segmentation between IT and OT, which limits the spread of intrusions and prevents adversaries from moving laterally across systems. At the same time, continuous monitoring and detection capabilities provide early visibility into anomalous behavior, including subtle techniques that blend into normal operations. When intrusions occur, resilient response and recovery capabilities, supported by well-practiced procedures and tested backups, help contain damage while maintaining or rapidly restoring essential functions. Proactive testing, including red and purple team exercises that simulate adversary behavior, further strengthen defenses by identifying weaknesses before adversaries can exploit them.

Maintaining a proactive posture is crucial. Engineering teams should incorporate threat hunting, adversary-focused testing, and attack path analysis to identify and disrupt adversary activity before it can impact mission-critical systems.

These strategies are most effective when designed as an integrated system rather than isolated controls. Increasingly, automation plays a key role in enabling this. Automated correlation, detection, and response workflows provide near real-time visibility and reduce the burden on personnel, allowing teams to respond with speed and precision.

Lifecycle Management

In military operations, logistics determine whether forces can sustain combat effectiveness. Outracing supply lines leaves units vulnerable. In cyber defense, the same principle applies to infrastructure readiness and reflects the principle of economy of force by efficiently allocating resources to sustain critical functions.

Many successful cyber incidents exploit routine gaps, including unpatched systems, incomplete asset inventories, or misconfigured devices. Addressing these issues requires disciplined sustainment practices embedded into system lifecycle management.

  • Proper patch and configuration management ensures that known vulnerabilities are addressed in a timely manner.
  • Accurate asset inventories provide visibility into all connected systems, including legacy and OT assets that are often overlooked but still remain mission-critical.
  • Likewise, backup and recovery capabilities are essential to mission continuity. In the event of ransomware or destructive attacks, the ability to rapidly restore systems from clean backups enables installations to sustain or quickly reconstitute operations without prolonged disruption.

Supply chain security is another key consideration. Installation infrastructure increasingly depends on third-party vendors and connected systems. This makes vendor risk management an integral part of system design and sustainment.

From a cost perspective, these practices reduce lifecycle risk and help avoid the far greater costs associated with mission disruption, emergency response, and system recovery.

Continuous Improvement

Military organizations continuously refine tactics through after-action reviews and regular training cycles. Cyber resilience requires the same discipline. Every incident, or near-miss, should be analyzed to identify lessons learned and inform improvements to system design, operational procedures, and defensive strategies. Regular training exercises reinforce readiness and validate that systems and teams can perform under realistic conditions.

Establishing a consistent operational rhythm ensures that cybersecurity remains an ongoing engineering and operational function rather than a one-time effort. Routine reviews, threat briefings, and system assessments create a feedback loop that strengthens preparedness over time. For installation environments, this continuous improvement cycle enhances decision-making under pressure and ensures that engineered systems and operational teams are prepared to respond.

Sustaining Performance

Cyber threats to infrastructure systems will continue to evolve, and no defense can prevent every intrusion. The objective is not absolute security, but sustained mission performance under degraded or contested conditions.

By applying warfighting principles and aligning cyber defense with the principles of war, installation engineers and mission assurance leaders can design and operate systems that anticipate threats, withstand disruption, and continue functioning under even degraded conditions.

Lt. Col. Vince Holloway, USA (Ret.), is Vice President, Federal IT Division, Tetra Tech Inc.; vince.holloway@tetratech.com


The Military Engineer archives