Outpacing the Pacing Challenge: Cyber Command's Strategic Scaling
RSA Conference 2024 · Track Session
Overview
Lieutenant General Joe Hartman, Deputy Commander of the United States Cyber Command (US Cybercom), delivered a compelling presentation at RSAC 2024, outlining the command's strategic approach to navigating an increasingly complex and rapidly evolving cyber landscape. Stepping in for General Tim Hawk, the dual-headed Commander of Cybercom and Director of the National Security Agency (NSA), Lt. Gen. Hartman focused on the critical need for speed, agility, and robust partnerships to maintain a decisive advantage against sophisticated adversaries. The talk, titled "Outpacing the Pacing Challenge," underscored Cybercom's commitment to innovation, talent development, and collaborative defense in the face of unprecedented global cyber threats.

Key moments
- 0:00 Introduction and US Cyber Command's mission
- 0:50 Overview of strategic environment, mission, and future
- 2:45 China: The urgent 'today problem' and pacing challenge
- 3:40 Adapting to change: 'The fast eat the slow'
- 3:55 Embracing innovation: 'Move fast and break things'
- 4:40 Speed and agility: Crucial for operations and development
- 5:00 China remains the most formidable cyber threat
Outpacing the Pacing Challenge: Cyber Command's Strategic Scaling
Speakers: Lieutenant General Joe Hartman, Deputy Commander, United States Cyber Command
Conference: RSAC 2024
YouTube: https://www.youtube.com/watch?v=AAWrdDJo1Js
Overview
Lieutenant General Joe Hartman, Deputy Commander of the United States Cyber Command (US Cybercom), delivered a compelling presentation at RSAC 2024, outlining the command's strategic approach to navigating an increasingly complex and rapidly evolving cyber landscape. Stepping in for General Tim Hawk, the dual-headed Commander of Cybercom and Director of the National Security Agency (NSA), Lt. Gen. Hartman focused on the critical need for speed, agility, and robust partnerships to maintain a decisive advantage against sophisticated adversaries. The talk, titled "Outpacing the Pacing Challenge," underscored Cybercom's commitment to innovation, talent development, and collaborative defense in the face of unprecedented global cyber threats.
The core message of the presentation revolved around the concept of a "pacing challenge"—the People's Republic of China (PRC)—and the necessity for the U.S. to adapt faster than its adversaries. Lt. Gen. Hartman articulated how Cybercom is fundamentally transforming its operations, from technology acquisition to talent management and international collaboration, to meet this challenge head-on. The command's strategy emphasizes proactive engagement, rapid technology integration, and leveraging a diverse ecosystem of partners across government, industry, and academia to safeguard national security interests and critical infrastructure globally.
This talk is particularly significant for anyone involved in national security, cybersecurity policy, or critical infrastructure defense, as it provides a candid assessment of the current threat environment and a detailed look into the strategic initiatives Cybercom is undertaking. It highlights the shift from a reactive posture to one of persistent engagement, digital solidarity, and continuous innovation, offering valuable insights into how a major military cyber force is evolving to secure its networks, support joint operations, and protect the nation against malicious state and non-state actors.
Background
▶ Watch: Introduction and US Cyber Command's mission (0:00)
The strategic environment, as described by Lt. Gen. Hartman, is characterized by unprecedented threat and opportunity, shaped by three primary factors: the competitive challenge posed by the People's Republic of China (PRC), accelerating technological change, and the growing empowerment of non-state entities through innovation. Among these, the PRC stands out as the pacing challenge, demonstrating both the intent and the escalating capability to threaten the existing global order. China's cyber forces operate unconstrained by international law or policy, rapidly exploiting opportunities with a high-risk tolerance, and engaging in a deliberate, continuous campaign to steal intellectual property, threaten national security systems, and establish footholds in critical infrastructure. This is not a future problem, but a present one, demanding immediate and sustained contestation below the level of armed conflict, particularly in the cyber domain.
Compounding this challenge is the accelerating pace of technological change, where innovation no longer solely originates from nation-state research and development but from a diverse global ecosystem including academia, corporations, and individuals. The adage "it's no longer the big that eat the small, but now it's the fast that eat the slow" encapsulates the imperative for rapid adaptation. The Department of Defense (DoD), historically not known for its speed in embracing innovation, must fundamentally change its approach, challenging established processes and fostering rapid innovation to prevail. Technologies like Artificial Intelligence (AI) and Machine Learning (ML) are prime examples of waves of innovation that the U.S. must not just ride, but actively leverage.
In response to this dynamic environment, US Cyber Command has adopted a strategy of persistent engagement. This involves continuous, proactive operations conducted in close collaboration with a broad spectrum of partners, including other government agencies like DHS CISA and the FBI, the private sector, academia, and international allies. This collaborative approach is seen as a principal advantage in contesting China during competition and preparing for potential crises. Cybercom's mission framework encompasses four key areas: defending the Department of Defense's networks, data, and weapon systems 24/7/365 through its Joint Force Headquarters Doden (JFHQ Doden); supporting Joint Force Commanders globally with forward-deployed elements; defending the nation against malicious cyber actors in coordination with interagency and industry partners, including critical missions like election security; and supporting allies as they develop their own cyber capabilities. A cornerstone of this strategy is the Cyber National Mission Force (CNMF), which deploys small teams for "hunt forward" operations with friendly governments, assessing networks for vulnerabilities and adversary presence, and then helping to expose and mitigate malicious activity. These operations have matured into an important pillar of national defense, fostering "digital solidarity in action" with like-minded partners.
Key Findings
▶ Watch: China: The urgent 'today problem' and pacing challenge (2:45)
The central finding presented by Lt. Gen. Hartman is that successfully addressing the "pacing challenge" posed by the PRC and the rapidly evolving technological landscape necessitates a radical shift towards speed, agility, and a deeply collaborative, innovation-driven ecosystem. Cybercom's strategy is not merely reactive but proactively seeks to leverage its most critical asset—its people—and expand its reach through strategic partnerships.
Specifically, the talk highlights several key findings and strategic shifts:
- Persistent Engagement is Effective: The hunt forward operations conducted by the Cyber National Mission Force have proven highly effective, with dozens of operations in over 80 friendly networks since 2018. These operations provide crucial insights into adversary tactics, techniques, and procedures (TTPs), enabling broad disclosure and constraining malicious activity while enhancing the defensive posture of both the U.S. and its allies.
- Accelerated Technology Transition is Possible: The Constellation program, a formalized partnership with DARPA, demonstrates a viable model for rapidly translating cutting-edge cyber research from the lab to the operational field. This initiative aims to bridge the "valley of death" between technology development and application, ensuring warfighters receive advanced capabilities at the speed of relevance.
- AI/ML are Transformative for Defensive Operations: Cybercom's internal AI Task Force and AI roadmap are actively developing and prototyping AI/ML solutions to automate mundane tasks in defensive threat hunting. This includes capabilities like multi-language document translation, network anomaly detection, and security alert triage, significantly enhancing the efficiency and effectiveness of cyber analysts.
- Collective Defense Through Exercises is Crucial: Participation in large-scale, live-fire exercises like Locked Shields provides invaluable training and strengthens digital solidarity among allies. The exercise, involving nearly 4,000 participants from 41 nations, allows for the simultaneous honing of capabilities, building of future cyber workforces, and fostering critical partnerships against advanced persistent adversaries.
- Academic Engagement Yields Tangible Intelligence Outcomes: Programs like the National Security Innovation Network (NSIN) and Cybercom's Academic Engagement Network (AEN) demonstrate how tapping into diverse academic thought and research can yield significant intelligence findings, such as the discovery of previously unknown DPRK technology worker entities and operational locations, at low or no cost to the command.
- Innovative Talent Management is Imperative: New legislative authorities, including NDAA Sections 1531 and 1535 and Title 10, Section 4092, are critical for attracting, incentivizing, and retaining top-tier cyber talent. These measures allow for financial recognition of innovators, competitive market-based pay supplements, and the hiring of eminent experts, acknowledging that while mission is paramount, compensation matters in the competitive cyber talent market.
These findings collectively underscore Cybercom's strategic pivot towards an integrated, agile, and partnership-centric model designed to outpace adversaries and secure national interests in the cyber domain.
Technical Deep Dive
▶ Watch: Adapting to change: 'The fast eat the slow' (3:40)
US Cyber Command's strategy for "Outpacing the Pacing Challenge" is deeply rooted in several technical and operational innovations, leveraging advanced capabilities, strategic partnerships, and a commitment to rapid deployment.
A cornerstone of Cybercom's proactive stance is Persistent Engagement, primarily executed through hunt forward operations by the Cyber National Mission Force (CNMF). These operations involve deploying small, specialized teams, often at the request of friendly governments, to collaborate directly on their networks. The technical objective is to assess network vulnerabilities, detect the presence of malicious cyber actors, and expose and mitigate their activities. This involves deep dives into network traffic, logs, and system configurations to identify sophisticated tactics, techniques, and procedures (TTPs) that might otherwise go unnoticed. Since 2018, the CNMF has conducted dozens of these operations in over 80 friendly networks worldwide, gathering crucial adversary insights that are then shared broadly, enhancing collective defense and constraining adversary freedom of action.
To accelerate the delivery of cutting-edge cyber capabilities to warfighters, Cybercom has established the Constellation program in partnership with the Defense Advanced Research Projects Agency (DARPA). This initiative is designed as a pipeline and infrastructure to rapidly transition advanced cyber technologies from the laboratory to the operational environment. The program aims to minimize and remove traditional barriers to technology implementation, focusing on specific projects to develop critical capabilities. This partnership, now formalized through a binding agreement, ensures a continuous feedback loop between DARPA's bleeding-edge research and Cybercom's operational needs, maximizing the balance between the "art and science of cyber." An example of DARPA's historical impact includes the development of the internet itself, miniaturized GPS, stealth technology, and automated cyber reasoning systems from the Cyber Grand Challenge. The Constellation program, with key figures like DARPA Program Manager Tejas Patel, seeks to replicate this rapid innovation for cyber defense and offense.
Internally, Cybercom is heavily investing in Artificial Intelligence (AI) and Machine Learning (ML) through its dedicated AI Task Force and a comprehensive AI roadmap. This task force works across the Department of Defense, with the NSA, and international partners to develop and deploy AI/ML pilot projects, particularly supporting defensive threat hunting capabilities. One practical application involves automating mundane, time-intensive tasks for hunt teams. For instance, AI models are being leveraged for local multi-language document translation, which is critical when communicating with diverse international partners. Furthermore, AI/ML is employed for network anomaly detection, sifting through massive amounts of packet capture and log data to identify subtle indicators of compromise that human analysts might miss. It also assists in security alert triage, prioritizing and contextualizing alerts to allow analysts to focus their expertise where it's most needed. These AI models are deployed on specialized GPU-enabled hunt kits that are being prototyped for threat hunting teams, demonstrating a commitment to integrating advanced hardware with intelligent software at the tactical edge.
Beyond direct operational deployments, Cybercom emphasizes collective defense through large-scale, live-fire exercises. The Locked Shields exercise, hosted by NATO's Cooperative Cyber Defense Center of Excellence (CCDCOE) in Tallinn, Estonia, is the largest and most complex international cyber defense exercise globally. This annual event brings together nearly 4,000 participants from 41 nations, including civilian, government, military, industry, and academic partners. In a recent iteration, Cybercom's JFHQ Doden, in collaboration with the National Center of Excellence for Cyber Security and Critical Infrastructure Collaborators (West Virginia University and Marshall University), led Blue Team 9. This team included international partners from Norway and Montenegro, as well as experts from the Department of Defense, Homeland Security, Treasury, and representatives from the electrical and financial sectors. The exercise simulates defending critical infrastructure against an advanced persistent adversary, providing invaluable real-world training and fostering interoperability among diverse partners. Notably, this year marked the first time Ukraine participated, joining forces with the Czech Republic, highlighting the exercise's role in building digital solidarity and sharing experiences against modern cyber threats.
Finally, Cybercom actively engages with academia to foster innovation and research. The National Security Innovation Network (NSIN), a DoD program, facilitates collaborations between universities, military academies, and the venture community. Cybercom's intelligence section (J2) submits topics of interest to NSIN, which then identifies academic partners. For example, a year-long capstone project with George Washington University, mentored by Cybercom intelligence analysts, focused on malicious cyber actors from North Korea (DPRK). This collaboration resulted in the discovery of numerous previously unknown DPRK technology worker entities, shell companies, and operational locations, providing actionable intelligence for the broader U.S. intelligence community. These academic operations are part of Cybercom's broader Academic Engagement Network (AEN), which connects with over 126 schools to inspire future cyber workforces and address critical challenges, including through its Cyber Recon program focused on research and education.
Demo / Proof of Concept
▶ Watch: Speed and agility: Crucial for operations and development (4:40)
While the talk itself did not feature a live, interactive demonstration, Lieutenant General Hartman described several initiatives that serve as practical applications and proofs of concept for Cybercom's strategic scaling efforts.
The hunt forward operations by the Cyber National Mission Force are, in essence, continuous proofs of concept for proactive defense. These deployments, numbering dozens in over 80 friendly networks globally since 2018, demonstrate the tangible impact of embedding U.S. cyber teams with allies to actively detect and mitigate adversary presence. The success of these operations in exposing malicious cyber activity and sharing critical insights validates the persistent engagement strategy.
Within the AI Task Force, the development and prototyping of GPU-enabled hunt kits for threat hunting teams serve as a direct demonstration of how advanced AI/ML capabilities are being integrated into operational tools. The description of a team led by "Jack" leveraging open-source information, academic research, and industry expertise to deploy AI models for tasks like multi-language translation, network anomaly detection, and security alert triage illustrates a practical application of AI in enhancing analyst effectiveness. These kits are not merely theoretical but are actively being tested and refined for immediate assistance to CNMF teams in defending critical networks.
Furthermore, large-scale exercises like Locked Shields function as a comprehensive proof of concept for collective cyber defense and international partnership. The participation of nearly 4,000 individuals from 41 nations, including the integration of U.S. teams (such as Blue Team 9) with international partners and representatives from critical infrastructure sectors, demonstrates the viability and effectiveness of multilateral collaboration in a live-fire scenario. These exercises validate interoperability, hone defensive skills against advanced threats, and build the foundational relationships necessary for real-world cyber solidarity.
Defensive Implications
▶ Watch: China remains the most formidable cyber threat (5:00)
The insights shared by Lt. Gen. Hartman carry profound implications for cybersecurity defenders across all sectors, emphasizing the urgent need for a paradigm shift in approach.
- Embrace Proactive Defense and Persistent Engagement: Defenders can no longer afford to be purely reactive. The success of Cybercom's hunt forward operations underscores the value of proactive threat hunting within networks, not just waiting for alerts. Organizations should actively seek out vulnerabilities and adversary presence, sharing insights with trusted partners to build a broader defensive picture.
- Prioritize Speed and Agility in Innovation: The "fast eat the slow" mantra applies universally. Defenders must challenge established, slow-moving processes for technology adoption and capability development. Rapid prototyping, iterative development, and a willingness to "move fast and break things" (within acceptable risk parameters) are essential to integrate new defenses faster than adversaries can develop new attacks.
- Invest in AI and Machine Learning for Automation and Augmentation: AI/ML are not future technologies; they are present-day necessities. Organizations should explore how AI can automate mundane tasks like log analysis, alert triage, and even multi-language intelligence processing. Investing in GPU-enabled hardware and data science talent can significantly enhance the efficiency and effectiveness of security operations centers, allowing human analysts to focus on complex problem-solving.
- Foster Broad Partnerships and Information Sharing: No single entity can tackle the global cyber threat alone. Defenders should actively cultivate partnerships across government, industry, and academia. Participating in industry threat intelligence groups, engaging with academic researchers, and collaborating with government agencies (like DHS CISA, FBI) can provide invaluable threat intelligence, shared best practices, and collective defensive capabilities. Exercises like Locked Shields highlight the immense value of multilateral collaboration for critical infrastructure defense.
- Focus on Talent Development and Retention: The "win with people" philosophy is paramount. Organizations must aggressively recruit, develop, and retain skilled cyber talent. This includes exploring innovative compensation models, fostering a culture of continuous learning and innovation, and providing opportunities for professional growth. Mechanisms like Cybercom's new financial incentives and market-based pay adjustments offer a glimpse into how to compete for top talent.
- Understand and Counter the "Pacing Challenge": The PRC poses a unique and pervasive threat. Defenders need to understand the scope, scale, and sophistication of nation-state actors, particularly those operating unconstrained by international norms. This requires staying informed about their TTPs, their objectives (e.g., intellectual property theft, critical infrastructure pre-positioning), and adapting defenses accordingly.
- Emphasize Digital Solidarity: For organizations with international operations or supply chains, fostering "digital solidarity" with global partners is crucial. This involves not just sharing information but actively collaborating on defensive strategies and capability building, recognizing that a threat to one partner can quickly become a threat to all.
Key Takeaways
- China is the Pacing Challenge: The People's Republic of China (PRC) represents the most formidable and immediate cyber threat, necessitating a shift to proactive, continuous engagement to counter its global ambitions.
- Speed and Agility are Paramount: The Department of Defense and all defenders must accelerate innovation and adaptation, moving faster than adversaries to leverage emerging technologies like AI/ML and overcome traditional bureaucratic inertia.
- Partnerships are Force Multipliers: Collaboration across government agencies, the private sector, academia, and international allies is critical for scaling defenses, sharing intelligence, and building collective resilience against global threats.
- Talent is the Ultimate Competitive Edge: Attracting, developing, and retaining highly skilled cyber personnel through innovative incentives, competitive compensation, and a mission-driven culture is fundamental to maintaining a technological advantage.
- Proactive Operations are Essential: Strategies like Persistent Engagement and hunt forward operations are proven methods to actively detect, expose, and mitigate malicious cyber activity on partner networks, moving beyond reactive defense.
- Innovation Ecosystem Integration: Programs like Constellation (with DARPA) and Academic Engagement Network (with NSIN) provide vital pipelines for rapidly transitioning cutting-edge research into operational capabilities and generating actionable intelligence.
About the Speaker(s)
Lieutenant General Joe Hartman is the Deputy Commander of the United States Cyber Command (US Cybercom). With a distinguished career spanning approximately 35 years in the Army, Lt. Gen. Hartman has held numerous significant leadership positions. Notably, he previously served as the commander of the Cyber National Mission Force (CNMF), a critical component of US Cybercom responsible for conducting defensive and offensive cyber operations. His extensive experience in cyber operations and national security positions him as a key leader in shaping the U.S. military's strategy in cyberspace. He operates under the leadership of General Tim Hawk, who serves as the dual-headed Commander of Cybercom and Director of the National Security Agency, a unique structure designed to enhance speed, agility, and unity of effort in defending American interests.