I don't get your message......You're going to "defend" a network and don't know the difference between UDP and TCP?
Having recently worked with an Army Cyber Protection Team, they need all of the help they can get. You're going to "defend" a network and don't know the difference between UDP and TCP?
Cyber, please....
Decisions on architecture, implementation, design, and training pipelines are made by commanders and leaders - not technical experts brought in. All of those decisions are structural in nature - meaning they are going to impact significantly on infrastructure, contracting, and budget - all of which require more buy-in than a single leader.
One of the benefits of the business world is being able to structure authority and organizations to meet business goals. Market competition helps to weed out failure as measured by profit margins. Government and especially the military and IC don't have the same structure - for good and for ill. If the NSA does a shitty job at SIGINT they don't go out of business in favor of a start-up SIGINT section at the FBI. Similarly, the head of the NSA doesn't get to re-organize against EO 12333 because SIGINT coverage is spotty in a target area.
There's a reason ATO is so hard to get. It's because the people who wrote the processes for gaining ATO didn't understand the real world of IT. They went out and did a bunch of research on best practices and then took every single one of them and stuffed them into a series of regulations without any regard to the mission. It's the difference between theoretical and practical knowledge. Then you add in the military's insane need to put everything in a process to the smallest detail and you end up with a set of criteria that is nearly impossible to meet in any type of short time frame. Institutionally that results in a culture where finding ways around the regulations is a path to success rather than having a culture where working within the framework allows for success while still maintaining control. It's a cultural issue, not a technical one. The military will NEVER solve that issue without bringing in outside perspective. Its own institutional practices will hamstring any effort to do so. Sometimes you just need a fresh set of eyes that have dealt with similar issues in other organizations that have a similar scale.Medical professionals are brought in at a high rank to execute their specialty - not to run hospitals. An O-6 thoracic surgeon is brought in to be a surgeon - and they do that under very clear guidelines of professional medical standards (that are the same as the civilian world), in a clear structure (the hospital setting). None of those are present in cyber, where authorities to operate are even more important frequently than the technical skills to operate themselves.
There's NO excuse for that one....
Zoom or Skype for Business?@Teufel , I need to get back up there for a chat. I’ll send you stuff related to the shit show I’m going through:
@AWP will enjoy this
unit: ”We need a X!”
feds: “mmm, I dunno. Why?”
bigger unit: “Cute, when can we expect a fed to arrive at the unit?”
feds: “We have a highly qualified candidate who arrives soon.”
unit: happy dance
me @ unit: “I’m here to fuck shit up. Feds, I need all this stuff.”
feds : “mmm, I dunno. Why do you want that? What do you do for the unit there?”
me: “counterparts @bigger unit say it need it. Wait, what? You’re asking what I do here?”
feds: “Yes, why do you need it? what mission does that unit have?”
me: “ You phuxers didn’t think to ask that shit and figure it out before I arrived?”
feds: “relax. You won’t get promoted talking like that. Let’s VTC to discuss.”
me: “You phuxing rocket surgeons didn’t allocate VTC equipment for our network. So we can’t VTC.”
feds: “hmmm. Ok, let’s polycom.”
me: “same rocket surgeons didn’t allocate a phone for our net.”
feds: “submit a request.”
me to SAME Fed supe: “I need a phone & VTC to commo.”
I shit you not the reply went along lines of...
feds: “Yes, why do you need it? I honestly don’t think this will be approved. what mission does that unit have?”
![]()
Such a diva.@Teufel , I need to get back up there for a chat. I’ll send you stuff related to the shit show I’m going through:
@AWP will enjoy this
unit: ”We need a X!”
feds: “mmm, I dunno. Why?”
bigger unit: “Cute, when can we expect a fed to arrive at the unit?”
feds: “We have a highly qualified candidate who arrives soon.”
unit: happy dance
me @ unit: “I’m here to fuck shit up. Feds, I need all this stuff.”
feds : “mmm, I dunno. Why do you want that? What do you do for the unit there?”
me: “counterparts @bigger unit say it need it. Wait, what? You’re asking what I do here?”
feds: “Yes, why do you need it? what mission does that unit have?”
me: “ You phuxers didn’t think to ask that shit and figure it out before I arrived?”
feds: “relax. You won’t get promoted talking like that. Let’s VTC to discuss.”
me: “You phuxing rocket surgeons didn’t allocate VTC equipment for our network. So we can’t VTC.”
feds: “hmmm. Ok, let’s polycom.”
me: “same rocket surgeons didn’t allocate a phone for our net.”
feds: “submit a request.”
me to SAME Fed supe: “I need a phone & VTC to commo.”
I shit you not the reply went along lines of...
feds: “Yes, why do you need it? I honestly don’t think this will be approved. what mission does that unit have?”
![]()
@Teufel , I need to get back up there for a chat. I’ll send you stuff related to the shit show I’m going through:
@AWP will enjoy this
unit: ”We need a X!”
feds: “mmm, I dunno. Why?”
bigger unit: “Cute, when can we expect a fed to arrive at the unit?”
feds: “We have a highly qualified candidate who arrives soon.”
unit: happy dance
me @ unit: “I’m here to fuck shit up. Feds, I need all this stuff.”
feds : “mmm, I dunno. Why do you want that? What do you do for the unit there?”
me: “counterparts @bigger unit say it need it. Wait, what? You’re asking what I do here?”
feds: “Yes, why do you need it? what mission does that unit have?”
me: “ You phuxers didn’t think to ask that shit and figure it out before I arrived?”
feds: “relax. You won’t get promoted talking like that. Let’s VTC to discuss.”
me: “You phuxing rocket surgeons didn’t allocate VTC equipment for our network. So we can’t VTC.”
feds: “hmmm. Ok, let’s polycom.”
me: “same rocket surgeons didn’t allocate a phone for our net.”
feds: “submit a request.”
me to SAME Fed supe: “I need a phone & VTC to commo.”
I shit you not the reply went along lines of...
feds: “Yes, why do you need it? I honestly don’t think this will be approved. what mission does that unit have?”
![]()
I'm also a huge fan of using the warrant officer program to recruit cyber talent. We could easily use the 160th warrant officer pilot model and apply it to this field. It takes almost two years to train and certify some of the more technical work roles. Some people can jump right in and make it through the assessment and training programs. Some need more time. I would propose to make the cyber analysis work roles in the enlisted ranks and offer the warrant officer program as an ascension program or direct entry.As @Teufel said, the best model is just to give these people a GS position with all the benny's. Otherwise you're bringing them in at O4/5/6 and giving them instant authority but little understanding of the culture. I admit my attitude has changed a little bit on this since I've been out and thought about it a little more. Direct commission works for a lot of fields, but even direct commission in the medical and nursing fields have to go through a lot of the standard Navy leadership courses, they're just not given the rank and authority without a strong support network. But it's been that way for how many hundred years now?
Can it work? Sure but with a metric shit-ton of growing pains. I don't know if you can take the medical model or the JAG model or new the others and just apply it to the field.
I suppose another idea is to bring them in as a warrant with big buck contracts and incentives and keep them out of the leadership structure and let them do the voodoo they do so well.
I just (this week) had a run in with an O-5. Tomorrow when I'm sober I'll explain why this cyber stuff us a bad idea...