02 Sep 2026
  • CPT Brittney Andrews

Introduction

Modern military operations increasingly rely on digital systems to collect, process, exploit, and disseminate intelligence. As a result, adversaries use cyber espionage as a primary tool to gain strategic insight into U.S. military operations. State and non-state actors leverage cyberspace capabilities to collect intelligence below the threshold of armed conflict by exploiting the speed, scale, and anonymity of digital networks.1 Over the last five years, the U.S. military has faced persistent cyber espionage targeting its digital systems. Throughout that period, the most significant threat has been the delayed detection of, and response to, foreign adversaries. This persistent risk undermines intelligence reliability and operational security, making it essential for commanders to recognize and adapt to cyber threats to preserve the decision-making advantage. This article assesses the risks of persistent cyber espionage and proposes actionable strategic responses.

The Persistent Threat of Cyber Espionage

The U.S. Cybersecurity and Infrastructure Security Agency defines cyber espionage as “a type of cyberattack in which an unauthorized user attempts to access sensitive or classified data or intellectual property for economic gain, competitive advantage, or political reasons.”2 Common tactics include phishing, malware, and spyware, which state-sponsored actors often use to gain long-term intelligence access.3 Cyber espionage is distinct from other forms of cyberattack because persistence enables long-term exploitation of target networks. While distinct, cyber espionage shares characteristics with generalized cyber collection, such as low visibility, high deniability, global reach without a physical presence, and scalability at a relatively low cost.4 For military organizations, persistent cyber espionage permits adversaries to monitor communications, steal sensitive intelligence, and identify operational patterns over time, often without triggering immediate defensive responses.

Persistence in cyber espionage presents significant challenges for military operations. Adversaries blend into normal network activity, making detection difficult and enabling prolonged exploitation. These actors seek access to operational planning, readiness indicators, logistics and sustainment data, deployment timelines, command relationships, and decision cycles. For example, China has leveraged cyber espionage to compromise U.S. critical infrastructure, including power grids, ports, and transportation systems, demonstrating how this access can enable future operational disruption during conflict.5

The growing use of cyber espionage increases operational and strategic risk by compromising intelligence systems, eroding intelligence integrity and trust, and enabling delayed detection and response. Over time, persistent cyber access can desynchronize operations and support adversaries’ long-term goal of defeating the United States. Historically, the United States has emphasized retaliation and deterrence in response to cyber espionage; however, proactive security measures remain the necessary first step to reduce operational risk.6

From Detection to Action

Addressing persistent cyber espionage requires a shift from reactive defense to proactive, intelligence-driven approaches. Improving the detection of anomalous behavior should include deploying continuous monitoring tools, expanding endpoint detection and response, and implementing automated alerts when unknown devices, accounts, or processes appear on the network. Additionally, tighter access controls and credential management can restrict access to authorized users and block unauthorized attempts.

Enhanced integration between cyber and intelligence functions is also critical: cyber units possess the expertise to combat digital threats, while intelligence operators maintain daily access to sensitive systems and therefore face greater exposure to cyberattacks. Integration enables end users to understand and mitigate cyber threats at the lowest level, allowing battalions to actively reduce cyberspace risk within their formations. These approaches are proactive, emphasizing early detection, coordination, and long-term risk management over one-time incident response.

This article offers two comprehensive recommendations: strategic investment for the future and command-driven action for today. First, the U.S. military should continue investing in advanced capabilities to detect anomalous behavior across networks, as delayed detection remains the primary enabler of persistent cyber espionage. However, these capabilities require significant resources and long-term implementation. Second, in the near term, commanders can take immediate action by integrating cyberspace and intelligence functions at the unit and staff levels. This integration should reinforce an “assume compromise” mindset, extend operational security to everyday digital behavior, and treat nonclassified systems as intelligence collection hotspots. Finally, training end users to recognize, report, and mitigate cyber threats remains one of the most immediate steps commanders can take to disrupt adversary access and reduce risk.

Conclusion

Persistent cyber espionage represents a strategic threat to military intelligence operations. Its covert nature and long-term focus make it difficult to detect and counter. Failure to address this challenge compromises intelligence, erodes decision advantage, and increases operational vulnerability. By adopting proactive, intelligence-driven approaches, military organizations can better defend against persistent cyber espionage in an increasingly contested digital environment.

Acknowledgment

Artificial intelligence supported the development of this paper by assisting with outlining, structuring, and identifying passive voice during proofreading.

Endnotes

1. Constance C. Uthoff, Cyber Intelligence: Actors, Policies, and Practices (Lynne Rienner Publishers, 2021).

2. “Glossary,” Resources, National Initiative for Cybersecurity Careers and Studies, Cybersecurity and Infrastructure Security Agency, updated September 18, 2025, https://niccs.cisa.gov/resources/glossary.

3. Uthoff, Cyber Intelligence.

4. Jorge R. Kravetz, “The Cyber Deterrence Dilemma: Parallels between Cyber and Intelligence Special Operations,” Joint Force Quarterly 119 (4th Quarter 2025): 72-81, https://ndupress.ndu.edu/Media/News/News-Article-View/Article/4367779/the-cyber-deterrence-dilemma-parallels-between-cyber-and-intelligence-special-o/.

5. Ian Mitch, “Watch Out for Physical Sabotage by Chinese Spies in the U.S.” Newsweek, April 11, 2025, https://www.newsweek.com/watch-out-physical-sabotage-chinese-spies-us-opinion-2058610.

6. Kravetz, “The Cyber Deterrence Dilemma.”

CPT Brittney Andrews is a student in the Military Intelligence Captains Career Course at Fort Huachuca, AZ. She previously served as the Brigade Executive Officer, Headquarters and Headquarters Company, 1st Armored Brigade Combat Team, 1st Cavalry Division at Fort Hood, TX. CPT Andrews holds a bachelor of science in psychology.