Security1 publisher2 min readPublished
Pentagon cyber policy chief says demand for cyber options outruns the force's supply
Katie Sutton told DefenseTalks that her one priority is building more cyber options for the president and the defense secretary. She dated the department's current posture to the 2018 authorities and credited the past year with the change.
The Watch · Security desk

What happened
- Katie Sutton, the Pentagon's assistant secretary of defense for cyber policy, said Tuesday that her single priority is expanding the cyber options available to the president and the defense secretary.
- She put the gap between what commanders ask for and what the department can deliver in one line: "The demand far exceeds the supply we have."
- Sutton dated the current posture to 2018, when the military gained authorities to run cyber operations as a traditional military activity.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint If demand outruns supply, requests from commanders queue behind options that already exist. What a president can be offered is limited by the inventory.
- contradiction The showcase case is unsettled. Officials asserted a cyber effect on Venezuela's power; the experts CyberScoop asked said the visible physical attacks could account for the same outages, so nobody outside can grade the capability.
- exposure Sutton places cyber below the level of armed conflict and ahead of kinetic options. Infrastructure and logistics operators on both sides of any confrontation sit inside that pre-conflict window.
- decision Naming data poisoning and weakened guardrails as the AI risks puts the Pentagon on record that security has to be decided before deployment this time. Its own AI programs will be measured against that test.
The demand she means comes from commanders and civilian leaders. The supply is what the department has already built and can put in front of a decision-maker. Sutton described the build in the past tense. "We've built up the capabilities, we've built up our force, we have the operational experience," she said [7]. By her own count the 2018 authority to run cyber operations as a traditional military activity is eight years old, and she credits only the most recent of those years with cyber entering public view, which leaves seven years of buildout that happened out of sight [5][6][19].
She pointed to one operation as an example of that visibility. It is contested. President Donald Trump and other public statements said power outages during the operation to apprehend former Venezuelan president Nicolas Maduro were the result of a cyberattack [8]. Experts who spoke to CyberScoop afterwards said cyber operations may have been involved, and also that the visible physical attacks in the same operation could plausibly explain the outages on their own [9].
Sutton described the shift as a change in the use case. Cyber is now used "not just to counter other malicious cyber actors as a cyber-on-cyber tool, but actually as an integrated tool of cyber warfare," she said [10]. She named data as the target. "Data is fundamental to every battle that we fight going forward," she said, adding that "being able to use our cyber tools to deny that to our adversaries as we go into a kinetic fight will ensure our mission success and provide greater safety for our troops" [11][12]. She also described cyber as something leaders can use "below the level of armed conflict to provide options before having to move forward to our kinetic options" [13].
On AI she argued the department has to be "an AI-first organization," on the grounds that cyber is a digital domain built on zeros and ones [14]. She named data poisoning and weakened guardrails as the risks that make AI different [15]. "We've spent a long time chasing cybersecurity and dealing with decisions that we made in moving quickly to creating an internet," she said, noting that security came second in that era [16]. At the same conference, Gen. Randall Reed, who heads U.S. Transportation Command, said the military's predictable supply chains have become vulnerable to AI-enabled adversaries, and suggested AI could make Transcom less predictable [17].
Anyone reading this as a procurement or hiring signal is working from intent alone. Sutton did not disclose a force size, a budget or a timeline for the expansion [18].
What to watch
- A budget request or force-structure document that puts a number on the capability expansion Sutton described.
- Any official attribution of the Venezuela outages that separates cyber effects from the physical attacks in the same operation.
- Whether the "AI-first organization" language turns into acquisition requirements for data poisoning and guardrail testing.