Skip to content
    July 21, 2026

    A Workforce Built for Yesterday

    The United States military has built something remarkable in the cyber domain over the last decade. The Cyber Mission Force (CMF) represents a serious institutional commitment to fighting and winning in cyberspace. The doctrine is sound. The intent is right. But beneath the organizational structure, a set of workforce development failures has been quietly compounding, and the gap between the force we are building and the force we need is widening.

    These are not failures of effort. They are structural: the product of a personnel system, a training enterprise, and a force management approach that were designed for a different problem than the one we are actually facing. Naming them precisely is the first step toward solving them. 

    The Pipeline Is Optimized for Volume, Not Depth

    The demand signal for trained cyber operators has consistently outpaced training pipeline capacity. The institutional response has been predictable: increase throughput, train more people faster, fill the billets. But this treats workforce development as a capacity problem when it is actually a depth problem.

    The pipeline produces operators with broad foundational knowledge, but genuine expertise — the kind that allows an operator to adapt against a thinking adversary — requires years of deliberate, focused development. What the current pipeline produces, in too many cases, is functional generalists, not the specialists the mission requires.

    Artificial intelligence (AI) is accelerating this problem in ways the enterprise has not fully reckoned with. AI surfaces findings but does not replace the judgment required to evaluate them. A generalist handed an AI-generated threat assessment can easily misread its significance, miss what is absent from the picture, or act on a false positive with real operational consequences.

    AI is a force multiplier for expertise. In the hands of a generalist, it multiplies the speed of and masks poor judgment.

    The CMF was designed with tiering in mind. Cyber Protection Teams (CPTs), Cyber Mission Teams (CMTs), and National Mission Teams (NMTs) are supposed to represent meaningfully different capability levels. In practice, the training pipeline does not produce the differentiation that tiering implies. The label changes; the depth of expertise often does not. Meanwhile, peer adversaries have been investing in deep, narrow specialization for decades. 

    Exercises Are Producing Compliance, Not Capability

    Every major cyber exercise in the defense ecosystem shares a structural feature that quietly undermines its training value: it is designed to succeed. Scenarios are scoped to be completable, objectives are defined in advance, and injects are sequenced to lead teams toward predetermined outcomes. The exercise becomes a performance review, not a training event.

    This matters because the behaviors that produce real operational capability, including improvisation, lateral thinking, persistence through failure, and genuine problem-solving under ambiguity, are exactly the behaviors that objectives-driven exercise design punishes. When a red team knows the scenario has a scripted path to completion, they stop red teaming. They start facilitating.

    When an exercise has to hit a checklist, the team stops solving the problem and starts performing the solution.

    The consequence is a force that performs well in environments it has seen before and struggles in environments it has not. That is a dangerous profile for a domain defined by novelty. Until exercise design philosophy changes and until we are willing to let teams fail, create conditions that cannot be fully solved, and value adaptation over completion, we will continue producing cyber operators who are well-rehearsed and under-prepared. 

    Specialization Is Collapsing — and Taking Expertise With It

    The defense enterprise has, in some respects, understood the importance of specialization in cyber. The force structure acknowledges that offensive operators, defensive operators, intelligence analysts, and targeteers are distinct disciplines requiring distinct skills. What the force management system has not internalized is that these specializations represent years of deliberate investment, investment that is effectively destroyed the moment the wrong person fills the wrong billet.

    A specialized operator who spent five years developing advanced adversary emulation tradecraft does not transition to another cyber discipline without loss. The tacit knowledge, pattern recognition, and operational instincts that make that operator genuinely dangerous in the cyber domain are not transferable to an unrelated position, and they are not easily rebuilt. When that operator leaves for the private sector, which they will because industry rewards specialization, the loss is permanent.

    The personnel management system does not have a cost model for this. A cyber position is treated as interchangeable with other cyber positions because the system was not designed to distinguish between them at the level of granularity that operational reality demands. The result is a steady transfer of hard-won human capital to the private sector, one mismanaged assignment at a time.

    You might also be interested in: Why Adversary Emulation Must Drive Defensive Change

    The Path Forward Starts With Honest Assessment

    These three failures are not independent. They are expressions of the same root problem: the defense cyber personnel system was inherited largely from the IT and communications world and has never been fundamentally redesigned for the operational realities of the CMF. Volume metrics, objectives-driven training, and interchangeable billet management all made sense when cyber was a support function. They are actively harmful when cyber is a warfighting domain.

    The CMF is now over a decade old. The force is no longer in its formative stage. The persistence of these structural failures is no longer a growing pain; it is a policy choice. Closing the gap requires honest assessment, exercises designed to expose failure rather than prevent it, and personnel systems that protect specialized expertise rather than redistribute it.

    The organizations that get this right will not just build a better workforce. They will field a force that is genuinely prepared for the adversaries they will actually face. 

    Continue the Conversation at TechNet Augusta

    At AFCEA TechNet Augusta 2026, Markon and Millennium will be engaging with military and government cyber leaders on exactly these challenges: workforce depth, training realism, and what it takes to build a force that is ready for real operational conditions, not just the ones we have planned for.

    If these questions are ones your organization is working through, we would like to continue the conversation. Visit our TechNet Augusta event hub to learn more about our presence, explore related insights, and schedule time with our team. 

    Visit our TechNet Augusta event hub to explore additional insights, learn more about our presence at the event, and schedule time to connect with our team.  

     

    Sean Piper

    More from the blog

    View All Posts