Diplomatic Analysis 5 min read

Before a Cyber Force, Fix Cyber Governance

Diplomatic Analysis: Effective cyber defence hinges on establishing clear accountability and ownership, not solely force creation.

This analysis examines the ongoing debate within the United States Department of Defense regarding the creation of a dedicated Cyber Force. While the impetus for such a force – addressing persistent readiness shortfalls and complexities in manning, training, and equipping cyber personnel – is understandable, this piece argues, based on Justin Hardy’s assessment, that a fundamental prerequisite remains unaddressed: comprehensive cyber governance. The focus on structuring a new force risks exacerbating existing dysfunction without resolving the core issue of who truly ‘owns’ cyberspace within the US defence apparatus. This has implications not only for US cyber capabilities but also for international alliances reliant on a robust and coordinated American cyber posture.

Historical Context

The US approach to cyberspace has been characterised by a gradual, largely reactive evolution rather than deliberate design. Initially treated as an extension of information technology, cyber quickly emerged as a distinct warfighting domain with unique challenges. This realisation led to the establishment of US Cyber Command in 2010, but its authority remained limited, heavily reliant on the Services – Army, Navy, Air Force, and Marine Corps – for force generation. These Services, understandably, prioritise their traditional domains, leaving cyber consistently under-resourced and under-prioritised. Decades of attempted “patches” – congressional studies, commissions, and legislative direction – have failed to fundamentally alter this dynamic. The situation echoes the pre-1947 landscape, before the National Security Act established the modern US defence structure, creating the Secretary of Defence and fundamentally restructuring governance. The creation of the Air Force itself, often cited by Cyber Force advocates, followed this initial governance overhaul. The parallel with the establishment of US Special Operations Command (USSOCOM) and its dedicated funding line (Major Force Program 11) is also relevant, underlining the importance of budgetary control for effective operational command.

Key Actors & Positions

The primary actors in this debate include:

* US Cyber Command (CYBERCOM): Advocates for improved force generation but constrained by its dependence on the Services.

* The Services (Army, Navy, Air Force, Marine Corps): Reluctant to fully dedicate resources to cyber, viewing it as a supporting function rather than a core warfighting domain.

* Congress: Divided, with some members actively pushing for a Cyber Force (e.g., Rep. Pat Fallon), while others, like Senator Kirsten Gillibrand, initially sought a Cyber Service within the Army but ultimately failed. The House Armed Services Committee and the Senate have presented differing approaches, with the House focusing on accountability and the Senate proposing an Undersecretary of Defense for Cyber.

* Department of Defense (DoD) Leadership: Navigating a complex landscape, attempting to balance competing priorities and address persistent shortfalls.

* Cybersecurity Industry & Think Tanks: (e.g., Center for Strategic and International Studies, Foundation for Defense of Democracies) – Providing analysis and recommendations, often favouring a Cyber Force, but now acknowledging the centrality of governance.

Each party acknowledges the need to improve US cyber capabilities, but they diverge on how to achieve that. The core disagreement centres on whether creating a new force before resolving governance issues is the correct approach.

Analysis

The central argument presented by Hardy is compelling: the focus on force generation obscures a deeper, more fundamental problem. Simply creating a Cyber Force without establishing clear ownership, budgetary control, and accountability will likely perpetuate existing inefficiencies and shortfalls. The danger is creating another siloed organisation operating within a fragmented ecosystem, inheriting the problems it was intended to solve.

The proposed Undersecretary of Defense for Cyber, consolidating the roles of Chief Information Officer and Principal Cyber Advisor, represents a promising step toward establishing this necessary accountability. However, merely designating an official isn’t sufficient. This position must be endowed with directive authority over cyber budgets and systems – the authority to compel the Services to prioritise cyber defence and investment. Without control of the “purse strings”, the role risks becoming a largely advisory one, lacking the leverage to enact meaningful change.

Rushing towards a Cyber Force mirrors a common pitfall in defence reform: focusing on structure before addressing underlying systemic issues. The analogy to the Air Force’s creation is often cited, but overlooks the crucial governance reforms that preceded the establishment of a new service. Failing to address the governance gap risks replicating the current predicament, effectively building a new house on a faulty foundation. The hesitancy to directly task organisations within the cyber enterprise, preferring instead consensus-building, highlights a cultural aversion to accountability – a culture that must be actively challenged through clear lines of authority.

Outlook

The debate within Congress signals a growing recognition of the governance challenge. The recent passage of Section 1502 in the House, mandating the identification of a single accountable official, and the Senate’s proposal for a new Undersecretary suggest a shift away from a purely force-centric approach. While a Cyber Force remains a possibility, its creation is now less inevitable.

The next 12-24 months will be critical. Congress must focus on establishing a robust governance framework – defining clear lines of authority, budgetary control, and accountability – before seriously considering the creation of a new service. This will likely involve difficult negotiations between the Services, CYBERCOM, and Congress. A successful outcome will not be measured by the creation of new uniforms, but by a demonstrable improvement in US cyber readiness and resilience – and a more coherent, accountable approach to defending critical infrastructure, both at home and abroad.

References:

Hardy, J. (2026). Before a Cyber Force, Fix Cyber Governance. War on the Rocks. [https://warontherocks.com/2026/07/before-a-cyber-force-fix-cyber-governance/](https://warontherocks.com/2026/07/before-a-cyber-force-fix-cyber-governance/)

About the Author

Gregory Halloran

Geopolitics analyst on US–China–Russia competition and the Middle East.

×
×
Install Merlows Add to your home screen for the full app experience.