Cyberwall Blog · September 10, 2026

What Military Doctrine Teaches Blue Teams: Fighting Smarter, Not Just Harder

Strategic theory, intelligence tradecraft, and the doctrinal foundations of network defense

By Ebrahim Rahnama, Cyber Threat Intelligence Analyst

What Strategic Theory Offers the Network Defender

Cybersecurity is a discipline that borrowed its lexicon from the military and its epistemology from almost nowhere. We speak of kill chains, red teams, and defense in depth, yet the doctrinal and theoretical literature behind those terms remains largely unread within the profession. This is more than an aesthetic gap. Network defense is a contest between adaptive, intelligent adversaries operating under uncertainty, and that problem has been studied with rigor for two centuries across strategic theory, international relations, and intelligence studies. This article argues that five bodies of doctrine, read together with contemporary threat intelligence practice, offer defenders something scarce in our field: a coherent theory of the defensive fight, rather than an accumulation of controls.

The argument rests on a premise drawn from Clausewitz: that war, and by extension any adversarial contest, is not the action of a living force upon a lifeless mass but “the collision of two living forces” (Clausewitz, 1832/1976). Security architectures designed as if the adversary were static weather rather than a reacting opponent will fail in predictable ways. Doctrine exists precisely to discipline thinking about reacting opponents. What follows applies that discipline to the operational level of cyber defense.

I. Elastic Depth and the Offense-Defense Balance

The conventional reading of defense in depth as a static layering of controls misrepresents its doctrinal lineage. The elastic defense developed on the Western Front and elaborated in Soviet deep operations theory was a temporal concept before it was a spatial one: the defender trades ground for time, absorbs the attacker’s momentum within prepared terrain, and counterattacks at the culminating point of the offensive, the moment Clausewitz identified as the point at which attacking strength is exhausted (Clausewitz, 1832/1976; Glantz, 1989).

This reframing intersects directly with one of the livelier debates in security studies: the offense-defense balance in cyberspace. The prevailing assumption that cyber conflict is offense-dominant has been persuasively challenged by Slayton (2017), who demonstrates that the balance is governed less by the technology itself than by the relative organizational costs each side bears. Her analysis carries an operational implication that practitioners rarely draw out: defenders can shift the balance by raising the adversary’s costs of operating inside the environment rather than only the costs of entry. An interior architected for observation converts attacker dwell time from a defender’s failure metric into an intelligence collection window. The empirical stakes are visible in Mandiant’s current M-Trends data, which places global median dwell time at 14 days, with espionage-linked intrusions persisting for a median of roughly four months (Mandiant, 2026). Under an attrition paradigm those figures describe defeat. Under an elastic paradigm they describe fourteen days of adversary contact with instrumented terrain, provided the instrumentation exists.

The threat intelligence corollary is the Pyramid of Pain (Bianco, 2013): detections keyed to hashes and infrastructure impose trivial replacement costs, while detections keyed to tradecraft force the adversary to re-tool. Elastic depth and pain-based detection are the same idea expressed at different levels of analysis, and both descend from the culminating-point logic.

II. Tempo, the OODA Loop, and the Intelligence Cycle

Boyd’s observe-orient-decide-act construct is routinely cited and routinely flattened into a slogan about speed. Osinga’s (2007) reconstruction of Boyd’s thought makes clear that the decisive element is orientation: the side whose model of reality degrades slower, and who can operate inside the opponent’s process of re-orientation, generates paralysis without requiring superior force. Boyd’s intellectual debt to maneuver theory and to epistemology, rather than to aerial tactics alone, is what makes the loop portable to network defense.

Two applications follow. The first is organizational: every mandatory approval between detection and containment lengthens the defender’s loop, and in an environment where ransomware operators routinely progress from initial access to encryption within a day, approval latency is functionally a control failure.

The second is analytical, and it connects Boyd to intelligence studies. Heuer’s (1999) work on cognitive bias in analysis is, in Boydian terms, a study of corrupted orientation: analysts anchor on prior hypotheses, and adversaries exploit precisely this through the denial and deception practices that Soviet maskirovka doctrine systematized (Glantz, 1989). Structured analytic techniques such as the analysis of competing hypotheses are best understood as orientation hygiene, protecting the SOC’s decision loop against an opponent who is actively feeding it noise. A threat intelligence function that only produces indicators has automated observation while leaving orientation undefended.

III. Maneuver, Centers of Gravity, and the Diamond Model

Attrition and maneuver represent distinct theories of victory. Attrition seeks cumulative destruction and rewards the side with cheaper force generation; maneuver, as formalized in MCDP 1, seeks the systemic incapacitation of the opponent by striking critical vulnerabilities and centers of gravity (U.S. Marine Corps, 1997). Alert-by-alert triage commits the defender to an attrition contest in which adversary force generation, in the form of commodity malware and phishing infrastructure, is nearly costless, while defender force generation is constrained by a well-documented labor market shortage. This is a structurally losing exchange ratio, and no quantity of tuning changes its structure.

Maneuver logic asks instead where the adversary’s cohesion resides. The Diamond Model provides the analytical machinery: every intrusion event links adversary, capability, infrastructure, and victim, and campaigns cluster along those axes (Caltagirone, Pendergast, & Betz, 2013). Read through a maneuver lens, the model is a center-of-gravity map. Dependencies on valid credentials, resilient command-and-control, and permissive egress are load-bearing; collapsing one defeats a class of operations rather than an instance. Phishing-resistant authentication, in this framing, is not a control among controls but a maneuver against the adversary’s critical requirement, which is why its adoption alters campaign economics in a way that incremental detection cannot (CISA, 2022). ATT&CK-informed defensive planning (Strom et al., 2018) serves the same function at the tradecraft level: it identifies the techniques an adversary cannot cheaply abandon, which is where defensive investment purchases disproportionate effect.

IV. Deception, the Security Dilemma, and Imposing the Attacker’s Dilemma

Jervis’s (1978) security dilemma describes how defensive preparations are read by opponents as threatening because capabilities are ambiguous and intentions are opaque. Cyberspace intensifies the dilemma to a degree Jervis could scarcely have anticipated: the reconnaissance required for defense is indistinguishable from the reconnaissance that precedes attack, and attribution is slow, probabilistic, and contestable (Rid & Buchanan, 2015). Defenders cannot resolve this ambiguity, but they can exploit its local form. Inside the defended environment, it is the attacker who suffers from opacity: every credential, share, and host is of uncertain authenticity.

Deception doctrine converts that uncertainty into a cost. Maskirovka’s central insight was integration: deception planned continuously and woven into genuine operations, rather than deployed as an isolated stratagem (Glantz, 1989). The contemporary translation is an environment seeded with honeytokens, canary credentials, and decoy infrastructure as a matter of architecture, for which MITRE Engage now supplies a structured planning vocabulary (MITRE, 2023). The strategic effect is an inversion of the canonical defender’s dilemma. Where the defender ordinarily must be right everywhere and the attacker once, a deceptive environment requires the attacker to make correct authenticity judgments at every step of discovery and lateral movement, under time pressure, with any error producing a detection of near-perfect fidelity. Deception is thus the rare defensive investment that degrades adversary orientation (Section II) while generating high-confidence intelligence, and its marginal cost approaches zero.

V. Mission Command and the Epistemics of Delegation

Mission command doctrine holds that in fluid conditions, decision authority must sit with the echelon in contact, because information decays as it moves up a hierarchy and the situation changes faster than reporting cycles (U.S. Army, 2019). The doctrine is, at bottom, an epistemological claim: the person at the point of contact possesses the least-degraded picture of reality, and command structures that centralize decisions systematically act on stale information. Schelling’s (1966) analysis of commitment supplies the complementary logic: pre-commitment to a course of action, established before the crisis, is itself a strategic capability, because it removes decision latency at the moment latency is most expensive.

A security operations center that requires managerial authorization to isolate a host has inverted both principles: it has centralized the decision away from the freshest information and forfeited the value of pre-commitment. The doctrinal remedy translates with almost no modification. Leadership articulates intent in advance and in writing, specifying the conditions under which analysts act first and report after; the analyst inherits authority bounded by that intent; and the organization measures escalation frequency as a diagnostic of misallocated authority. Persistent engagement theory makes an analogous argument at the strategic level, holding that in a domain of constant contact, initiative accrues to actors structured to operate continuously rather than episodically (Fischerkeller & Harknett, 2017). The SOC is the tactical instantiation of that claim.

Conclusion: Toward a Theory of the Defensive Fight

These five threads share a single premise: the adversary is a reasoning system, and defense is therefore a problem of competitive adaptation rather than of accumulation. Strategic theory supplies the concepts — elastic depth, tempo, centers of gravity, integrated deception, and delegated authority; threat intelligence practice supplies the empirical machinery — the Diamond Model, ATT&CK, and the Pyramid of Pain — that makes those concepts operational against observed tradecraft. Neither is sufficient alone. Theory without collection is speculation; collection without theory is inventory.

The practical program is deliberately modest. Instrument the interior and treat dwell time as contested terrain. Audit decision latency as seriously as detection coverage. Map defensive investment to adversary dependencies rather than alert taxonomies. Integrate deception architecturally. Write down commander’s intent. Each is testable within a quarter, and each rests on lessons for which prior generations paid in considerably harder currency than breach disclosures. The discipline that borrowed the military’s vocabulary would do well, finally, to borrow its thinking.

References

About the Author

Ebrahim Rahnama is a cybersecurity analyst whose work bridges security operations, cyber threat intelligence, cybercrime, forensic psychology, behavioral analysis, and strategic studies. His interests focus on the intersection of technology, human behavior, ideology, and emerging security threats.


Originally published in Cyber Defense eMagazine, September 2026 Edition. Copyright © 2026, Cyber Defense Magazine.

Not ready to wait on a blog post?

Book a preparedness call and get a straight answer for your specific situation, no searching required.