Pentagon's Top Cyber Official Says Requests Outpace Available Forces
Speaking at DefenseTalks 2026 on September 22, 2026, Katie Sutton — the U.S. Department of Defense's Assistant Secretary for Cyber Policy and principal cyber advisor to the secretary of war — told attendees that military demand for cyber operations has grown well beyond what the current force can deliver. "The demand far exceeds the supply we have," Sutton said, framing capacity expansion as her singular focus: "I'm focused on one single priority, and that is building a more robust set of capabilities for the secretary and the president." Her remarks come eight years after the Pentagon gained authority, in 2018, to conduct cyber operations as a traditional military activity — a shift that opened the door to today's surging appetite for cyber effects across combatant commands.
Details
| Attribute | Value |
|---|---|
| Speaker | Katie Sutton |
| Role | Assistant Secretary of Defense (War) for Cyber Policy; Principal Cyber Advisor to the Secretary |
| Event | DefenseTalks 2026, hosted by DefenseScoop |
| Date of Remarks | September 22, 2026 |
| Key Claim | Requests for military cyber operations "far exceed" current force capacity |
| Historical Context | 2018 authority permitting cyber operations as a "traditional military activity" |
| Related Initiative | Cybercom 2.0 force-generation reform; ongoing Cyber Force debate |
| Source | CyberScoop |
What Was Said
Sutton's core message centered on a widening gap between what combatant commanders are asking for and what U.S. cyber forces can actually deliver. "I'm focused on one single priority, and that is building a more robust set of capabilities for the secretary and the president," she told the DefenseTalks audience, adding plainly: "The demand far exceeds the supply we have."
She traced the department's current posture back to 2018, when the military gained authorities to run cyber operations as a traditional military activity — a policy shift that moved offensive and defensive cyber missions out of a narrowly cabined, case-by-case approval process and into something closer to conventional warfighting authority. Sutton said that in the years since, cyber has "increasingly entered the spotlight" as a tool commanders now reach for routinely rather than exceptionally.
Sutton also described a broadening in how the Pentagon thinks about cyber's role. Rather than treating it purely "as a cyber-on-cyber tool" to counter other malicious actors, she said the department now views cyber "as an integrated tool of cyber warfare" that supports operations across every domain. She underscored data's centrality to that shift: "Data is fundamental to every battle that we fight going forward... Being able to use our cyber tools to deny that to our adversaries as we go into a kinetic fight will ensure our mission success and provide greater safety for our troops." She further framed cyber capabilities as options that give leadership room to act "below the level of armed conflict" before escalating to kinetic force.
Sutton's remarks also touched on artificial intelligence as a natural extension of the cyber mission, while flagging emerging risks such as data poisoning and weakened AI guardrails that will require new tradecraft to manage. Her appearance comes as she continues overseeing development of the Pentagon's first overarching cyber strategy since 2023, expected to be accompanied by an implementation action plan.
The Force-Generation Backdrop
The capacity gap Sutton described did not emerge in isolation. It sits atop a long-running Pentagon debate over how to build and sustain a cyber workforce at scale. Under the Cybercom 2.0 initiative rolled out in November 2025, the department restructured how U.S. Cyber Command generates, trains, and retains cyber operators — an effort Sutton has separately described as addressing a "legacy force generation model" that she called "inconsistent, hindering our ability to adapt at speed and scale to counter threats like Volt Typhoon and Salt Typhoon and quickly integrate emerging technologies like artificial intelligence." That reform effort runs in parallel with a separate congressional and advocacy push to stand up a dedicated Cyber Force as an independent military branch, a proposal a Pentagon-commissioned study previously estimated could cost between $9 billion and $11 billion to stand up. Sutton has argued the two paths are not mutually exclusive — Cybercom 2.0, she has said, was deliberately built to be "agnostic to the organizational model," able to function under the current command structure or a future standalone service.
Why It Matters
A senior DoD cyber policy official publicly acknowledging that operational demand outstrips available capacity is a notable admission from an administration that has otherwise emphasized offensive cyber posture as a deterrent. It signals that the bottleneck constraining U.S. cyber operations is not primarily legal authority or policy — those questions were largely resolved by the 2018 shift — but personnel, training pipelines, and force structure. That distinction matters for how Congress, industry, and allied partners interpret the Pentagon's cyber posture going forward: authority without throughput does not translate into deterrent capability. It also reinforces the urgency behind the Cybercom 2.0 versus Cyber Force debate, since both proposals are, at their core, competing answers to the same capacity problem Sutton described.
Impact Assessment
| Impact Area | Description |
|---|---|
| National Cyber Deterrence | A persistent capacity shortfall limits how many concurrent cyber options the president and secretary of war actually have available, potentially narrowing response choices during a crisis |
| Force Generation Policy | Adds pressure to resolve the Cybercom 2.0 versus independent Cyber Force debate, since both are aimed at closing the same demand-supply gap |
| Workforce & Recruiting | Signals sustained, likely growing demand for cyber operators, engineers, and AI-integration specialists across DoD components and the private contractor base that supports them |
| AI Integration | Sutton's emphasis on AI as a capacity multiplier suggests the department will lean on automation and AI-assisted tooling to offset personnel shortfalls, introducing new risks (data poisoning, guardrail failures) that require dedicated oversight |
| Interagency & Industry Demand | A capacity-constrained DoD cyber force may increasingly lean on NSA, CISA, and cleared industry partners to fill operational gaps, raising coordination and oversight considerations |
| Congressional Oversight | Puts renewed pressure on lawmakers to resolve funding and structural questions (NDAA authorization, Cyber Force cost estimates) that have stalled amid the ongoing organizational debate |
Recommendations
For Policy Makers
- Prioritize force-generation legislation in upcoming NDAA cycles rather than continuing to defer the Cybercom 2.0 versus Cyber Force decision, since Sutton's remarks indicate the capacity gap is a present operational constraint, not a future hypothetical
- Fund training pipeline expansion explicitly, since the bottleneck Sutton described is about trained personnel and mission-ready teams, not legal authority
- Establish AI governance guardrails for cyber operations before AI-assisted capacity expansion scales, addressing the data-poisoning and guardrail-erosion risks Sutton flagged
For the Cyber Security Workforce
- Cyber professionals with DoD-adjacent clearances or backgrounds should expect continued strong demand for offensive and defensive cyber roles, both in uniform and through cleared contractor positions supporting Cyber Command
- Track Cybercom 2.0 career-pathway changes, including new talent-acquisition and tailored-training tracks, as these may open non-traditional entry points into military and DoD-adjacent cyber careers
- Build AI-adjacent cyber skills (secure model deployment, data-integrity validation, adversarial ML defense) given the department's stated intent to integrate AI more deeply into cyber operations
For Industry Partners
- Defense contractors and cyber vendors should anticipate increased demand for tools and services that extend DoD cyber capacity, particularly automation, AI-assisted analysis, and managed cyber-effects platforms
- Monitor the Pentagon's forthcoming cyber strategy (the first update since 2023) for procurement and partnership signals tied to closing the capacity gap
- Prepare for scrutiny on AI supply-chain integrity, as DoD's AI integration plans will likely come with heightened vendor security and data-provenance requirements
Key Takeaways
- Katie Sutton, DoD's Assistant Secretary for Cyber Policy, told DefenseTalks 2026 on September 22 that demand for military cyber operations "far exceeds" the Pentagon's current supply of forces.
- The capacity gap traces back to 2018, when the military first gained authority to conduct cyber operations as a traditional military activity — meaning the current constraint is operational capacity, not legal authority.
- Sutton described cyber increasingly being used as an integrated warfare tool across domains, not just a cyber-on-cyber countermeasure, with data denial framed as central to future kinetic operations.
- The demand-supply gap reinforces the urgency of the ongoing Cybercom 2.0 versus independent Cyber Force debate, two competing structural answers to the same underlying problem.
- Artificial intelligence is positioned as a key capacity multiplier for future cyber operations, alongside new risks such as data poisoning and weakened AI guardrails that will require dedicated oversight.
- A new DoD cyber strategy — the department's first comprehensive update since 2023 — is expected soon and will likely address force generation, AI integration, and capacity expansion in more detail.