Diplomatic Analysis: Prioritising cyber governance structures over force creation is crucial for effective US cyber security.
The debate surrounding the creation of a dedicated US Cyber Force remains intense, with proponents arguing it’s an inevitable step to address shortcomings in force generation and readiness. However, a recent argument gaining traction – as highlighted by recent discussions within the Senate Armed Services Committee and analysis from institutions like the Center for Strategic and International Studies and the Foundation for Defense of Democracies – suggests this approach misplaces priorities. The core issue isn’t how to build a Cyber Force, but who governs cyberspace. This is a critical discussion, as effective cyber security relies not just on technical capabilities, but on clear lines of authority, accountability, and resource allocation. Addressing the governance vacuum will be far more impactful than simply creating a new military branch with currently undefined authorities.
Historical Context
The US military’s engagement with cyberspace has evolved in a fragmented manner. Initially treated as an adjunct to existing IT infrastructure, cyber warfare capabilities were gradually developed within individual Services – Army, Navy, Air Force, and Marines. This resulted in a dispersed system where each Service maintained its own cyber personnel and resources, leading to duplication of effort and challenges with interoperability. The establishment of US Cyber Command (CYBERCOM) in 2010 aimed to centralise military cyber operations, but its authority remained limited. CYBERCOM depended on the Services for “force generation” – the training, equipping, and deploying of cyber personnel. This dependency proved problematic, as cyberspace consistently took a backseat to traditional warfare priorities within the Services. The recurring annual diagnosis from Congress – directing further studies and commissions – underscores the persistent failure of the current construct. This mirrors historical patterns; the creation of the Air Force in 1947 wasn’t simply about creating a new branch, but fundamentally restructuring the broader defense establishment through the National Security Act, establishing clear civilian oversight and defining roles.
Key Actors & Positions
Several key actors are involved in this debate. US Cyber Command (CYBERCOM) desires greater control over force generation to ensure readiness and responsiveness. The Department of Defense (DoD) is grappling with balancing the need for a dedicated cyber capability with the desire to avoid bureaucratic bloat and maintain Service autonomy. Congress is divided. Senator Kirsten Gillibrand (D-NY) champions a Cyber Force within the Army, while Representative Pat Fallon (R-TX) views a Cyber Force as inevitable. A key congressional concern is ensuring accountability and efficient resource allocation. The Services largely resist relinquishing control over their cyber personnel and budgets, fearing a loss of influence and expertise. Additionally, private sector cybersecurity firms and cybersecurity policy think tanks (like CSIS and FDD) are offering their perspectives, largely focused on the need for increased investment and improved organisation, often leaning toward force creation.
Analysis
The argument for a Cyber Force often centres on the perceived technical complexity of cyber warfare and the need for specialised personnel. However, this argument overlooks the fundamental governance issue. Similar technical complexity exists in other domains—nuclear propulsion, for example—without requiring a separate, standalone force. The core problem is not what skills are needed, but who prioritizes, funds, and directs the development and deployment of those skills. Currently, cyberspace is effectively “owned” by no one, creating a diffusion of responsibility and a lack of accountability. CYBERCOM’s inability to compel the Services to prioritize cyber is symptomatic of this broader issue.
Creating a Cyber Force without resolving the governance structure would merely add another layer of complexity to an already fragmented system. It risks creating a bureaucratic entity that struggles to secure the necessary resources and authority, potentially exacerbating existing readiness shortfalls. The recent proposals in the House and Senate represent a more pragmatic approach. The House’s focus on designating a single accountable official for DoD network security, and the Senate’s proposal for a new Undersecretary of Defense for Cyber, Information, and Networks, represent steps towards establishing clear lines of authority and responsibility. The Senate’s proposed dual-hatted role—combining the CIO and Principal Cyber Advisor positions—is particularly promising, as it attempts to bridge the gap between operational requirements and underlying infrastructure. However, this official must be granted directive authority over cyber budgets and resource allocation. Simply designating someone to coordinate without providing them with the power to compel action will perpetuate the existing dysfunction.
Outlook
The creation of a Cyber Force is unlikely to occur in the immediate future. The narrow rejection of the proposal in the Senate and the House’s rejection of including a Cyber Force in their mark suggest a growing recognition that governance reform is the more pressing need. Over the next 12-18 months, Congress is likely to focus on establishing a clear governance structure, potentially adopting the Senate’s proposal for a new Undersecretary of Defense. This will involve a protracted debate over the allocation of authority and resources. The success of this effort hinges on whether Congress can overcome resistance from the Services and empower the new official with the necessary tools to effectively prioritize and oversee cyberspace operations. A more effective, accountable cyber security framework is achievable, but it hinges on fundamentally addressing the governance vacuum, rather than simply adding another layer of organisational complexity.
Sources:
* Hardy, J. (2026, July 24). Before a Cyber Force, Fix Cyber Governance. War on the Rocks. [https://warontherocks.com/2026/07/before-a-cyber-force-fix-cyber-governance/](https://warontherocks.com/2026/07/before-a-cyber-force-fix-cyber-governance/)