Cyber Commands: Alexander to Nakasone
The U.S. builds CYBERCOM — Keith Alexander to Paul Nakasone's 'persistent engagement.' Russia's GRU units 26165 and 74455 hack and disrupt; China's 61398 prowls. Commanders fight in code, courtrooms, and the feeds on your phone.
Episode Narrative
In the waning days of the Cold War, the world found itself at a monumental crossroads. The year was 1991, and the Soviet Union, a formidable titan of power, had begun to disintegrate, marking the end of an era built on the pillars of nuclear deterrence and geopolitical rivalry. This seismic shift did not merely dismantle the walls that divided East from West; it ushered in a new age in military strategy. The United States and its allies faced a complex new reality. Gone were the days of standoff, of missiles poised and ready. In their place arose new threats in uncharted territories, particularly in the realm of cyber warfare, which would soon lay bare vulnerabilities not in geography, but in technology itself.
As the dust settled on the Cold War, the late 1990s unfolded a transformation within the ranks of the U.S. military. The integration of information and communication technologies took center stage. This was not just an adaptation; it was the groundwork for what would eventually be termed the Revolution in Military Affairs. The emergence of the internet and advanced communication methods began reshaping military doctrines. Strategies that once relied heavily on traditional force now had to account for the burgeoning complexity of information warfare. It was a paradigm shift, with military leaders beginning to envision battles fought not just on land, sea, and air, but within the uncharted territories of cyberspace.
Then, in 2009, the U.S. government took a monumental step toward recognizing this new battleground by establishing U.S. Cyber Command, known as CYBERCOM, under the leadership of General Keith Alexander. This marked a watershed moment, a formal acknowledgment that cyberspace was now a legitimate domain of warfare, standing alongside land, sea, air, and space. It was as if a new theater of war had opened, one where the weapons were lines of code rather than bullets, and the strategies involved disruptions instead of direct confrontations.
However, as the United States turned its attention to this new frontier, it was not alone in this digital arena. By 2013, Russia, through its military intelligence agency known as the GRU, began to make its presence felt. Units like 26165 and 74455 began to loom large, proving adept at traditional warfare while simultaneously conducting disruptive cyber operations against NATO and Western infrastructure. The 2007 cyberattacks against Estonia were a harbinger of things to come. In 2015, they struck again, pulling off a significant hack of the German Bundestag. The message was clear: the rules of engagement had changed, and nations would find themselves in increasingly vulnerable positions without ever setting foot on one another’s soil.
Alongside these developments, China was not far behind. In 2015, the activities of the People's Liberation Army Unit 61398 were laid bare by the U.S. Department of Justice, exposing an extensive web of cyber espionage that reached into American corporations and government agencies. The repercussions reverberated across diplomatic channels, highlighting the global reach and implications of cyber threats. This wasn't the work of rogue hackers; this was state-sponsored warfare, a calculated strategy wielded to exert influence and gain footholds in the chaotic digital landscape.
Amidst this emerging chaos, a new paradigm began to take shape within the U.S. military under General Paul Nakasone. By 2017, the principle of "persistent engagement" had surfaced as a guiding philosophy. It called for continuous cyber operations designed to disrupt adversaries and maintain a strategic advantage. No longer were defensive measures sufficient; the U.S. armed forces were committed to not just guarding against threats, but actively engaging with them. This marked a tactical shift that was as bold as it was necessary, recognizing that the cyber domain demanded a proactive approach rather than a reactive one.
The U.S. Department of Defense articulated this proactive framework further in 2018 with the release of its Cyber Strategy. This document laid out an approach that embraced offensive cyber operations as essential tools for deterrence. The idea was to engage adversaries not merely in a defensive posture but also in a way that placed them on the back foot, ever cognizant of the U.S. capabilities to strike with precision in cyberspace.
As the world moved into 2020, technological advancements began to permeate military operations in unprecedented ways. The integration of artificial intelligence and machine learning into command and control systems became a priority, fundamentally altering how the military assessed threat landscapes and made decisions. Real-time data processing and autonomous systems promised a level of situational awareness that had been unimaginable just a decade earlier. The battlefield was evolving, and with it, the tools of engagement.
By 2021, the military's commitment to modernizing its approach bore fruit as AI-driven tactical communications systems were deployed. This not only enhanced secure data exchanges but also provided real-time situational awareness, a crucial edge for soldiers in the field. Secure communication channels were no longer merely fortifications but dynamo systems that could adapt to the chaos of the battlefield, ensuring that information flowed with the agility required by modern conflicts.
The momentum continued into 2022, as more advanced cyber defense systems were developed, including initiatives that employed blockchain technology to safeguard communications against tampering. Resilience became a watchword; the goal was not only to fend off attacks but to ensure that systems remained operational even in the face of sustained onslaughts.
As the years rolled into 2023, the focus shifted towards even more innovative strategies. Initiatives to enhance cyber resilience included the exploration of quantum-resistance encryption algorithms. These cyber fortifications were designed to withstand threats from quantum computing, an emerging technology that could render traditional encryption methods useless. This forward-looking approach illustrated a profound understanding: the battlefield of tomorrow was already being shaped by technological advancements that we could barely comprehend.
By 2024, collaboration became a cornerstone of military strategy. The U.S. armed forces established partnerships with private sector companies, incorporating commercial cybersecurity innovations. This collaboration not only broadened the military’s capabilities but fostered an environment of innovation that was critical in the rapidly evolving cyber landscape. The synergy between military rigor and private sector agility proved invaluable.
Continuing into 2025, the military refined its cyber structure further, integrating cyber operations into every domain of warfare. This shift was holistic, recognizing that threats were no longer confined to cyberspace alone but intersected with land, sea, air, and space operations. The emergence of new technologies, particularly autonomous systems and drones, escalated the precision and speed of cyber-related operations, making engagements more complex and multifaceted.
By the same year, training programs for cyber personnel expanded significantly. A new generation of cyber warriors began to prepare for the complex and dynamic threats of the future. These individuals were not merely technicians; they were strategists capable of navigating the uncharted waters of cyberspace.
As the U.S. military grew in sophistication, so too did its capabilities in cyber forensics. Advanced analysis tools enabled rapid attribution of cyber attacks, allowing military and governmental officials to respond effectively, both legally and diplomatically. This marked a maturation in understanding cyber warfare — not just as an ephemeral realm of bits and bytes, but as a crucial aspect of national security that required rigorous forensic analysis.
At the same time, a robust cyber intelligence network gradually emerged, harnessing the power of big data and AI. This real-time monitoring brought with it the potential for predictive power; cyber threats could be anticipated, and proactive actions could be initiated before any significant damage occurred.
The realization of the gravity of cyber hygiene became paramount. Strict protocols were implemented across all branches of the military to protect against common vulnerabilities. The principle was simple but profound: a well-informed personnel base, coupled with rigorous systems, made for a resilient military structure. Cyber hygiene became an ongoing responsibility, one that all ranks needed to embrace.
Not to be overlooked was the establishment of comprehensive cyber incident response plans. These frameworks had been designed to ensure that in the event of a significant cyber attack, a rapid and coordinated response would be executed. This foresight indicated a maturing understanding of warfare, where preparation met adaptability — a crucial balance in an increasingly unpredictable digital world.
In this atmosphere, international partnerships began to flourish, providing avenues for sharing threat intelligence and coordinating global responses to emergent cyber threats. A realization took root: cybersecurity could not be an isolated endeavor; it required collaboration on a global scale. Nations found themselves bound by shared vulnerabilities, as well as by a collective responsibility to safeguard digital landscapes.
As we reflect on this sweeping evolution — from the dissolution of the USSR to the present day — we are reminded that the battles of tomorrow will not be fought solely in traditional war zones. Instead, they will unfold in the vast expanse of cyberspace, where the stakes are high, and the landscape is obscured by a digital fog. The story of U.S. Cyber Command, spanning from General Keith Alexander to Paul Nakasone, illustrates not only a response to threats but a profound transformation in understanding the nature of warfare itself.
This journey challenges us to consider a future where our greatest vulnerabilities may not lie in our military might, but rather in our digital infrastructure. As we stand at this crossroads, we grapple with fundamental questions: How prepared are we for battles yet unseen? And what will the legacy of this new form of engagement be for generations to come? The era of cyberspace has dawned, but what shadows await us as we continue to navigate this intricate landscape? These questions echo, urging us to stay vigilant as the storm of change rumbles on the horizon.
Highlights
- In 1991, the breakup of the USSR marked the beginning of a new era in global military strategy, with the U.S. and its allies shifting focus from Cold War deterrence to managing regional conflicts and emerging cyber threats. - By the late 1990s, the U.S. military began integrating information and communication technologies (ICT) into its operations, laying the groundwork for what would become the Revolution in Military Affairs (RMA), fundamentally changing military doctrines and strategies. - In 2009, the U.S. established U.S. Cyber Command (CYBERCOM) under General Keith Alexander, marking a formal recognition of cyberspace as a domain of warfare alongside land, sea, air, and space. - By 2013, Russia’s GRU units, notably 26165 and 74455, were identified as key players in cyber operations, conducting disruptive attacks on NATO and Western infrastructure, including the 2007 cyberattacks on Estonia and the 2015 hack of the German Bundestag. - In 2015, China’s People’s Liberation Army Unit 61398, known for its cyber espionage activities, was publicly exposed by the U.S. Department of Justice for hacking into American companies and government agencies, highlighting the global reach of cyber threats. - By 2017, the U.S. military adopted the concept of "persistent engagement" under General Paul Nakasone, emphasizing continuous cyber operations to disrupt adversaries’ networks and maintain strategic advantage. - In 2018, the U.S. Department of Defense released its Cyber Strategy, outlining a proactive approach to cyber operations, including the use of offensive cyber capabilities to deter and respond to threats. - By 2020, the integration of artificial intelligence (AI) and machine learning into military command and control systems became a priority, enhancing situational awareness and decision-making processes. - In 2021, the U.S. military began deploying AI-driven tactical communications and networking systems, improving secure data exchange and real-time situational awareness on the battlefield. - By 2022, the U.S. military had developed advanced cyber defense systems, including the use of blockchain technology to secure communications and prevent data tampering. - In 2023, the U.S. military launched several initiatives to enhance cyber resilience, including the development of quantum-resistant encryption algorithms to protect against future quantum computing threats. - By 2024, the U.S. military had established partnerships with private sector companies to leverage commercial cybersecurity technologies and expertise, fostering innovation and collaboration. - In 2025, the U.S. military continued to refine its cyber command structure, with a focus on integrating cyber operations into all domains of warfare, including land, sea, air, and space. - By 2025, the U.S. military had also expanded its cyber training programs, preparing a new generation of cyber warriors to operate in an increasingly complex and dynamic threat environment. - In 2025, the U.S. military began exploring the use of autonomous systems and drones for cyber operations, enhancing the speed and precision of cyber attacks and defenses. - By 2025, the U.S. military had also developed advanced cyber forensics capabilities, enabling rapid attribution of cyber attacks and supporting legal and diplomatic responses. - In 2025, the U.S. military had established a robust cyber intelligence network, leveraging big data and AI to monitor and predict cyber threats in real-time. - By 2025, the U.S. military had also implemented strict cyber hygiene protocols, ensuring that all personnel and systems were protected against common cyber threats. - In 2025, the U.S. military had also developed a comprehensive cyber incident response plan, enabling rapid and coordinated action in the event of a major cyber attack. - By 2025, the U.S. military had also established international partnerships to share cyber threat intelligence and coordinate responses to global cyber threats.
Sources
- https://gjeta.com/node/2492
- https://ojs.lgu.edu.pk/nooretahqeeq/article/view/2319
- https://militaryhealth.bmj.com/lookup/doi/10.1136/bmjmilitary-2025-NATO.12
- https://militaryhealth.bmj.com/lookup/doi/10.1136/bmjmilitary-2025-NATO.10
- https://wafml.wildapricot.org/2025-September-Issue-Vol-44-(3)
- https://pubs.aip.org/aip/acp/article/813/1/1224-1231/814050
- https://pogledi.cimoshis.org/wp-content/uploads/2022/11/14.-Hikmet-Karcic-82022.pdf
- https://www.semanticscholar.org/paper/c7108d5244212ba4069ba68398ed6f73c0bd204c
- http://link.springer.com/10.1057/9781137336910_14
- https://zenodo.org/record/1266896/files/article.pdf