NATO Ankara Summit Creates a Call-to-Action for Defense Industrial Base

The Elara Edge

Host: Scott King 

SME: General (Ret) James “Scorch Hecker, Senior Principal Advisor at Elara Nova (JH) 

Brigadier General (Ret) Chad Radeuge, President of the Cyber, Data & Communications sector at Elara Nova (CR) 

Tom Goffus, Executive Partner for Global Security (TG) 

Brad Head, Executive Partner for Global Growth (BH) 

00:02 – 01:46 

Heads of State and Government from 32 nations will gather at this month’s NATO Summit in Ankara, Turkey, looking to accelerate progress toward the goals agreed to at The Hague Summit last year.The Hauge Summit Declaration pledged to strengthen collective defense by committing member nations to spend 5% of annual GDP on defense by 2035, while deepening transatlantic defense industrial cooperation and reaffirming the alliance’s support for Ukraine.  

But now, several factors are also heightening the stakes of the Ankara Summit: Russia’s ongoing invasion of Ukraine, recent conflicts in the Middle East and “NATO 3.0,” or the increased pressure on allies to take on greater defense investment and burden-sharing responsibilities. In response to these factors, there is growing momentum as NATO nations increasingly invest in their defense capabilities, which also presents a call-to-action for the defense industrial base to respond in kind. 

Welcome to The Elara Edge! Today we’ll be looking ahead to the NATO Summit in Ankara and the context and conversations that member nations and the defense industrial base should be paying attention to – both at the summit and in the weeks and months to follow. 

We have four guests today, each with a unique and qualified experience that reflects both the complexity of the challenge NATO faces, as well as the opportunities the alliance has to meet its growing demands. 

Our first guest is retired General James “Scorch” Hecker, a Senior Principal Advisor at Elara Nova. Scorch recently retired after a 36-year military career with the United States Air Force, culminating in roles as Commander of U.S. Air Forces Europe, U.S. Air Forces Africa and Allied Air Command at NATO.  

Sir, welcome to the show! 

01:47 – 01:58 

(JH): Well, it’s great to be here. I really appreciate the opportunity, Scott, to address this very important topic. I think it’s going to be a pretty memorable summit that we have, so I’m looking forward to the outcomes. 

01:59 – 02:19 

(SK): We’re glad to have you. 

Returning to the show is retired Brigadier General Chad Raduege, President of Elara Nova’s Cyber, Data and Communications sector. General Raduege previously served as the Director of the Command, Control, Communications and Computers Cyber Directorate, as well as the Chief Information officer at Headquarters, U.S. European Command. 

Sir, welcome back to the show.  

02:20 – 02:22 

(CR): Scott, great to be here. Thank you.  

02:23 – 02:38 

(SK): Our third guest today is Tom Goffus, Executive Partner for Global Security at Elara Nova. He is the former Assistant Secretary General for Operations at NATO, and previously served as the Policy Director for the United States Senate Committee on Armed Services.  

Tom, thanks for joining us. 

02:39 – 02:52 

(TG): Thanks, Scott.  

02:52 – 03:12 

(SK): And also returning to the show as a familiar voice for our audience, and that’s Brad Head, Executive Partner for Global Growth at Elara Nova. A retired Colonel with the U.S. Air Force, Brad has previously served as the Chief of Defense Planning at the U.S. Mission to NATO and later served as the director of International Affairs at Space Operations Command. 

Brad, welcome back to the show.

03:13 – 03:15 

(BH): Thanks. It’s great to be here. Looking forward to this conversation.  

03:16 – 03:39 

(SK): So let’s jump right in. We’re here to discuss some of the expectations, challenges and the broader environment surrounding this year’s NATO summit in Ankara, Turkey, which will be held on July 7th and 8th, or shortly after we release this podcast. 

Now, Tom you just recently left NATO, from your post as Assistant Secretary General for Operations, so as the guest with the most recent experience at the alliance, I’d like to turn it over to you for some opening remarks.  

03:40 – 09:21 

(TG): Okay. Thanks, Scott. Let me just start with the framing from a NATO perspective. What I think most allies would tell you is that they see a more aggressive Russia, a more unpredictable America, and a more challenging China. And those are the dynamics driving allies to make decisions and take action. 

I should say first that the overall objective of the NATO summit is not to have a major blow up, not to have a fiasco. But overall, this year’s summit, if I summed it up in one word, would be ‘Implementation.’ The three big rocks at the NATO summit in Ankara, will be one: defense spending pledge implementation, two defense industrial production and innovation expansion. And number three, NATO 3.0 execution, also known as burden-shifting by another name. 

So, first: defense spending implementation. The 5% pledge is broken down into two parts, 3.5% on core defense requirements think planes, tanks, ships, and 1.5% on defense-related requirements such as critical infrastructure, defense industrial base and resilience. 

The 3.5% is very precisely defined, while the 1.5% is broad by design. That 3.5% aligns with the capability targets assigned to each ally as part of the NATO Defense Planning Process. And that process works as such: you ID the threats, that drives the building of operational plans, which in turn drives capability targets that are needed to execute those plans. 

The last targets were assigned and agreed in 2025. The next ones won’t be out until 2029. So I expect for 2029, several big new areas. For example, I expect space, autonomous systems, drones that is, and Arctic-specific capabilities. Those are just three areas that we expect to see new capability targets defined in.  

So back to spending for the summit. You can expect positive announcements. Poland and the Baltic nations could be at 5% as early as this year. Germany is shooting for 3.5% by 2029. Sweden is looking at 3.5% by 2030, and the other hard chargers that I expect will hit the line before 2035 are the Nordics and the Netherlands. 

Second, on defense production capacity and innovation: in order to actually translate money into capability, we have to have defense production capacity. And what has been clear is that increased defense spending without increased defense production capacity won’t result in more capabilities. It’ll result in more expensive capabilities. 

As the wars in the Middle East and Ukraine sharply underscore, our defense industrial base is currently not structured to produce what we need at the volume and pace required. And this key dynamic is why NATO has announced that the Defense Industry Forum that is connected with the summit in Ankara will be expanded into the largest industrial event in NATO’s history. At Ankara commensurately, I think NATO is expected to officially launch its front door for industry and that’s a single portal where contractors can upload their potential innovative solutions. Those solutions are then routed to the appropriate NATO point of contact, aimed at connecting industry directly with the alliance procurement needs at speed.  

And a third one – on the 18th of June, Secretary Hegseth brought this up with the allies – and it was called “NATO 3.0.” And what it means is that Europe and Canada will have capability gaps that they need and want to close alongside the money to do so. 

Now, here’s where I would offer a word of caution about rhetoric versus reality. The framing coming out of Washington is that America is forcing a reluctant Europe to finally carry its own weight. That is the political rhetoric. The data tells us a bit more of an interesting story. The Secretary General at that same defense ministerial said that European allies in Canada put in over $90 billion more into defense in 2025 than in 2024. That’s roughly a 20% single year increase. So the step up is not a future ask that the allies are resisting. It’s a present fact that they are already delivering on at a pace that has no precedent in the alliance’s history. 

Now, I want to be very clear that I’m not making a political argument here. I am making a market argument. Strip away the rhetoric and look at where the money, the capability gaps and the durable demand actually sit.  

So if America is generally stepping back from its conventional role in Europe, then Europe and Canada own the gaps and they also own the budget to close them. So your takeaway is Europe defense spending is rising faster than at any point since the founding of the alliance. And that demand is going to be met substantially through industrial production. So I’m going to stop there and conclude. Just a quick summary.  

First, avoid a fiasco. Make the event short and sweet. Second, allies are dealing with a more aggressive Russia, a more unpredictable America, and a more challenging China. And third, three big implementation rocks: defense spending, defense production and innovation and NATO 3.0. That is my framing for the Ankara Summit, and we’re hoping for a successful outcome there. Thanks, Scott. 

09:22 – 10:46 

(JH): Great opening there. Really appreciate you outlining the three big rocks and I think it’s important you mentioned some of the burdens-shifting. Getting an extra $90 billion over just a one year period is very important. But we need to make sure that we spend that money wisely in what I used to call an “integration by design,” and I’ll just use integrated air and missile defense as an example.  

 In the past, each country would buy their individual system. So we ended up having some systems, but unfortunately they didn’t talk to one another and that doesn’t work. So we got to make sure that there’s a force inside of NATO that can take this money, group it together, and buy a system for all of NATO that is interoperable amongst one another.  

Another thing that you talked about was shifting the money, the 5% and those kind of things. In some areas, that’s going very well. Let’s talk F-35. By 2032, we should have around 700 of them in NATO. What people don’t realize is of those 700, only 54 are going to be U.S. So that’s a good positive shift that we’re seeing.  

Now areas where we’re not seeing such a good shift is areas like tankers, AWACS, E-7 Wedgetaill, ISR platforms. So those are areas where we need to improve if we’re going to make this shift happen. So I’ll just pause there.

10:47 – 11:37 

(BH): One nuance that I would add. So I happened to be at the U.S. Mission and NATO in the run up to the Whales Summit, when the first investment pledge was agreed. And that pledge said that allies that were above 2% should stay above 2%, and allies that were below 2% should aim to move towards 2% within a decade, which was not particularly aggressive and hard to hold people to politically. 

And what we see in the updated investment pledge at The Hague Summit and what they expect to see at Ankara are investment plans. The nations are supposed to come with specific plans that show how they’re going to get to 5% by 2035.  

The other nuance in that investment pledge, the kind of why of the investment pledge was in order to fill their capability targets. But the whole point of it was to buy the types of stuff that we collectively need to meet our collective level of ambition, so we’ll unpack that in a little bit.  

11:38 – 12:18 

(TG): And I think really good point on the F-35, Scorch as well.  

The other thing that I emphasized before I left NATO, and this is more in Chad’s lane, and he’ll probably cover some of this later, but that’s a lot of data. A four ship of F-35s in an hour generally will produce four terabytes of data. If you can’t take that data and move it, process it and share it, then that’s a good chunk of your investment that’s on the cutting room floor. 

And so that’s going to be a big challenge is how to move big amounts of data, what gets processed at the edge and what gets pushed around the alliance. But I thought that was a perfect example of the shift in burden-sharing that is ongoing in Europe right now.  

12:19 – 12:41 

(CR): Tom, great point on the data-sharing. And what I would offer is the challenge for the alliance really is having an architecture in place that as you set up these things like a front door for industry to come in, that you don’t just buy a whole bunch of tools, but that you have an architecture that supports interoperability. If you don’t have that, then you’re not going to be able to communicate anyway. It’s a waste of money.

12:42 – 12:55 

(SK): Now, given the three priorities Tom laid out for us: there’s going to be a lot of different capabilities that NATO will be looking for moving forward.  

General Hecker, Sir, what do you see as the main capability gaps that NATO will have to address? 

12:56 – 15:28 

(JH): Yeah. Thanks, Scott. I think one of the ones that really stands out to me, that I struggled with a lot when I was the AIRCOM commander, was air defense  because ever since the Cold War ended, NATO has really kind of taken a knee when it came to investment in air defense. 

We would buy some things, but not near enough. And as an example of that, what we do when we kind of are putting together our air defense plan is we will take a look at what we call the Critical Asset List, and we would determine things that needed to be protected. These would be like airfields, oil production facilities, headquarter buildings, munition storage areas. 

And then there’s also another thing called the DAL, which is what you’re going to actually defend – the Defended Asset List. Well, there was a huge mismatch there. There was a lot more assets that we needed to protect than we actually could protect. 

And then you add the fact that the systems that we had weren’t always interoperable and then the third thing that really made the problem worse was when the Ukraine Russian war started, you had the introduction of these one-way attack vehicles. When I first showed up there, the war was just started about three months, and there would be a couple a day.

When I left, it was up to around a thousand a day from each country going against each other. And then the most recent attack that we just saw from Ukraine, they had basically a thousand of these things in one day, and the production capability has really increased in the country. So that compounds the problem that we have when it comes to defending these assets. 

 And the other thing that we need to think about is how are we going to sense these things? Because a lot of these are at low altitude. So a traditional radar on the ground doesn’t work as well. You know, once you get 10 or 15 miles away, they’re hiding at 500ft just because of the curvature of the Earth.  

So we need to make sure we can detect these things. And there’s capabilities that came out of Ukraine where they can do this with acoustics, which is basically putting up a microphone. And they got somewhere around 20,000 of these in their country now, and then they just take the acoustics that are coming from the noise that is emitted from the UAVs, and then they triangulate and they get a pretty good fixed position, and then they have mobile firing teams that can move out and shoot these things down. And they’re doing it in a cheap way, you know, with Triple-A and EW and things like this, that we just don’t have that capability near to what we need it to be in NATO.

15:29 – 16:24 

(TG): So on that Scorch, just curious, you’ve been watching both what’s been going on in Middle East and what’s been going on in Ukraine. Like you said, the threat is much more complex than we ever thought about before. I mean, in Epic Fury, you had two Iranian F-5s and they were just on Iran state TV. The pilots that got in and bombed a base in Kuwait. And to your point about curvature of the Earth, they were flying under power lines when they were doing that.

One of the things that I took away from both Israel and Ukraine is they don’t really do point defense, they do layered defense, thinning the herd, if you will. 

 And Ukraine, like you said, they don’t have all of their sensors around one particular city or one. It’s 20,000 of these things all the way across the country. So for me, one of the things is if you’re going to sit in your one point defense and hope that that’s going to save everything, that’s not how air defense works in the modern battlefield. But having said all that, what do you think, Scorch? What else strikes you that we should be taking away from the Middle East and or Ukraine?

16:25 – 17:30 

(JH): You know, number one is you can’t kill a threat unless you know it’s there. So we need the sensors, whether that’s acoustics, space-based, or radar on the ground or an E-7 Wedgetail up in the air, we need to be able to sense it in order to shoot it. 

And then we need the shooters. The ones that we have are pretty much exquisite ones that cost a lot of money. And we can’t be trading $3 million PAC-3 missiles for a $30,000 drone.  

Ukraine has figured out ways to shoot these things down at relatively cheap and now industry is definitely getting it. But we need to accelerate that to make sure that we’re prepared if something should happen, and then we need to make sure we have the command and control that connects all these things, so that the sensor detects the target, it gets to the shooter, and then the shooter shoots and we don’t want to waste missiles on it.  

So we got to make sure that the right shooter with the right probability of kill shoots that. And then we need operators that are trained to do it. And we need logistics to make sure that they get resupplied. So it’s not an easy problem, but it’s something that’s right in front of us and we just can’t look away from it.

17:31 – 17:45 

(SK): And taking that integrated air and missile defense example, you just spoke to a number of variables within that mission area alone. 

So as NATO looks to better field its integrated air and missile defense system, how does the alliance go about prioritizing which element goes first? 

17:46 – 19:10 

(JH): Yeah. Overall, when I look at the lessons learned from Ukraine and Russia war, the number one thing that stands out is neither side was able to get air superiority. 

So what we saw over the last three years is trench warfare, several casualties, bombings of civilian infrastructure and nothing that we want to be a part of. And if you contrast that with what Israel and the U.S. did against Iran, they were able to establish air superiority fairly quickly by doing counter anti-access aerial denial. So they were able to take those double digit surface-to-air missiles out and take other radar sensors that they had in Iran. And we could basically fly with immunity over Iran and take out high value targets, etc..  

What we weren’t able to do is take out all of their one-way attack vehicles. That’s just going to be a fact that we’re not going to be able to do that in the future, because they produce these things underground, they can set these things up anywhere, and it’s going to be difficult to get all of them. So that’s why we need to make sure that we invest in defensive capabilities for the few that actually get through. And we can’t do this for a long duration using expensive, exquisite shooters. We need to get way cheaper shooters to make that happen.

19:11 – 19:45 

(BH): And if I could add one nuance, Scott, to the way that you framed that question, I think a way a lot of people think about NATO. NATO is a collection of 32 nations that pool their resources to respond to a collective defense. NATO as NATO doesn’t actually own and operate most things.  

So one of the things that NATO can and should do is to provide that overarching framework that would allow countries to invest their resources in a coherent way so that those capabilities [that] come together, are interoperable and additive, and not that there’s gaps and seams. And that’s something I think we’ll talk about here in a minute, particularly as it relates to the space domain and the investments that are being made there.

19:46 – 19:50 

And as it relates to the space domain, what does interoperability look like for NATO? 

19:51 – 23:07 

(BH): Yeah, I think a couple things. One, NATO declared space an operational domain in 2019, but they’re continuing to struggle with defining what does that mean in practice?  

And so we see a lot of activity, but not necessarily the most coherent. For example, there are programs like the Allied Persistent Surveillance from Space, which is looking down like overhead imagery. 3SAS is focused on looking up. There’s a launch capability, there’s a SATCOM capability, there’s a group of nations that are getting together around these various mission areas and working on something.  

But there isn’t an overarching framework that is coherently driving those investments. Like I talked about. It’s not NATO as NATO investing in things. It’s individual nations investing in things. 

And when you get into something like space, which is very expensive and very complicated, that is ripe for these kind of multinational programs or even at the NATO level. Not that it would be a common funded, but the individual nations would be contributing to something. So there’s not a lack of programs, but there is a lack of coherent investment thesis. 

And so I think a couple of things that need to happen over the next period of time are in the NATO Defense Planning Process. In the last cycle, there was nothing for space, specifically. We need to get to a point very quickly that we are articulating those capability targets, which are the things that tell nations. Here’s what you need to go invest in.  

And I look at the Space Force. General Saltzman at the Space Symposium, rolled out the Objective Force baseline, clearly articulating by mission area, by geography. And there’s a classified annex that goes into more detail where we think we need to have those coherent investments.  

So that’s something even the US Space Force is still working on. So it makes sense that NATO would be struggling with that. But again, I think we need to get the right pieces in place, the right capabilities in place. 

And here a dynamic that we see a place is the commercial strategy. So there’s a team over there in the defense investment world that has created a NATO Commercial Space Strategy, which is largely in line with the U.S. strategy. But there’s an acknowledgment that in the same way the U.S. talks about e’ploit what you have, buy what you can and build only what you absolutely must,’ because it will cost billions of dollars and take decades to build capabilities and we have real operational challenges today.   

I think we’ve got commercial providers that are chomping at the bit to provide that. And so as this increase investment comes from the Hague Investment Pledge, and we have individual nations saying, “Hey, I’ve got X many millions of euros that I need to go spend and I’ve got to spend some of that on space, but I don’t have the first idea what is worth investing in.” NATO could help provide that framework so that we are investing those dollars in a coherent way to field real no kidding capabilities.  

And I think the last bit of that is the command relationships. And so once you get those pieces and parts together, NATO and Scorch can talk to this better than literally anybody because he owned that as the AIRCOM commander. He also owned the space function.  

There isn’t really a coherent way to command and control space capabilities that flows back through the U.S. under Operation Olympic Defender. We’ve got Space Force Space out at Vandenberg, which is the operational headquarters that actually deliver space effects on behalf of the U.S. And we coordinate with other nations under the Olympic Defender umbrella. But NATO as NATO does not really have much of an ability to command and control a space fight right now. 

23:08 – 23:45 

(JH): Yeah, Brad, information sharing when it comes to space is so important. The problem is a lot of nations, including ours, don’t share the information with the other countries, or in my case, the commander who is out there. So if I didn’t know what the capabilities were, it’s kind of hard to command and control it.  

So we were starting to tackle that and we released some things from the U.S. that previously we hadn’t released to NATO countries before, and I think that started the ball going, but I think we still got a long ways to go when it comes to information sharing, particularly when we talk about space. 

23:46 – 24:40 

(BH): Absolutely. I remember I went to the space ops commanders conference two years ago when you were still in that position and you said, “Hey, if I don’t know it exists, I can’t ask for it. So if you just want to whisper to I think it was Johnny Stringer. If you just want to tell one guy, tell Johnny, and he’ll be the keeper of all the information. You don’t even have to disclose how you would do stuff.”  

And then I understand. In the last year they actually put out a survey to try and get nations to in a more formal way to provide that input. And I think that that’s still a gap in the knowledge that’s missing. 

I know certainly from a U.S. perspective, that’s something that they’re interested in. And I think from a NATO perspective, the same thing: this idea of like, ‘Hey, what do nations have? What are they in the process of buying? And what would they be willing to do? From a trade-off perspective, would they be willing to invest in this capability as opposed to that capability, if they understood that in the aggregate everything was going to get taken care of? 

And I think that’s still something that we’re struggling with both from a NATO perspective and a U.S. bilateral with all the different nations’ perspectives. 

24:41 – 25:14 

(TG): Yeah, and I’ll just throw in on that. There’s an old policy from 2019 that misses the whole space revolution that basically says, “A couple of us big allies will take care of space for you – don’t worry about it.” But allies are moving out right now with or without capability targets.  

The Bulgarians have two nanosats doing Black Sea overwatch. They have their own satellite manufacturing company there in Bulgaria. So nations are going to move out one way or another in the next three years before those capability targets are there. And we do really need NATO to structure this so that we do it in a logical and effective way. 

25:15 – 25:45 

(SK): And on Brad’s point of NATO facing real operational challenges faced today in the space domain. We have a telling example from the Russian invasion of Ukraine, when one hour prior to the invasion, Russia deployed a cyber attack on a commercial satellite that Ukraine was depending on for their command and control. 

So here is an example of a country that was leveraging a commercial space service, which was then disabled in the context of a pending invasion. So to tie it back to the coming Ankara Summit, what conversation needs to happen today to make sure that NATO, or a NATO nation, doesn’t find themselves in a similar position? 

25:46 – 26:59 

(BH): If I was going to kind of reinterpret that question, I would kind of frame it in the terms of: Can we rely on commercial? If I have my own sovereign national system, I can protect that, and I know it’ll be there in the time of need. A commercial provider, whether it’s they say, “Hey, we’re not comfortable with you using that in a certain way, or they’re vulnerable to things that I’m not responsible for or able to defend them from those sorts of attacks.” 

It does present vulnerabilities. That is a challenge that has been acknowledged, and we’re actively working through that. But I do know that commercial providers in space are doing things that 5 to 10 years ago were the exclusive remit of a handful of nation states. 

And nowadays, if you’ve got a commercial provider who’s going to do on-orbit servicing and refueling, that is the equivalent of what is considered orbital warfare. If I can get up close enough to your satellite to touch it, fix it, refuel it, I can break it and take it where it doesn’t want to go. 

And so now we’ve got commercial providers doing everything up to and including that. It is unrealistic to think that we’re not going to rely on commercial, but there are challenges and risks, and we’ve got to ensure that we’ve got those systems available to us in a time of need. 

So that part of that is the agreements that we put in place. And part of that is, frankly, the agreements between those commercial providers and the government to go, “Hey, to the extent that you rely on these things, then there’s an obligation to protect those assets.”

26:60 – 27:14 

(SK): Thank you, Brad. And so NATO also has their political guidance window coming up in 2027. 

What opportunity does that present the alliance as far as taking a meaningful step towards ensuring NATO has space capabilities available to them at that future time of need? 

27:15 – 28:23 

(BH): This is a critical moment in time, right? So we mentioned the fact that in the last cycle, there wasn’t a demand signal from the political level of NATO to force the system to produce these capability targets that brought coherence to the space domain. 

The 2027 political guidance. If you look at the way the NATO Defense Planning Process operates, the guidance gets signed out that says, here’s what I want you to go do. Here is the level of ambition. Do these two big kind of conflicts, these 5 or 6 smaller conflicts, different geographies, different domains that results in what’s called the minimum capability requirement. 

So the guidance articulates that. And then there’s operational plans. And out of that we come up with here’s how much stuff we need. If there isn’t guidance in this cycle that says you will go develop some space capability targets, and we’ll figure out how we apportion those and how we hold people accountable to those and their kind of effects-based, not specifically platform-based. 

Then you’re going to miss the window of time. And if you miss this window of time, your next window is 2031, which won’t produce capability targets till like 2032-33 timeframe. So NATO has got to figure out in this next round of political guidance, a coherent approach to creating that demand signal for space, which includes the commercial stuff that we’re just talking about. 

28:24 – 28:49 

(SK): Now, moving this conversation forward once more, having 32 nations provide different systems and platforms to the alliance comes with an inherent integration problem that General Hecker referenced earlier. 

And going back to the F-35 example, there’s expected to be over 700 coming available to NATO through its member nations that will have to collect, process, and share massive amounts of data interoperably.  

So this question is for General Raduege. Sir, where does NATO begin to address this challenge? 

28:50 – 30:19 

(CR): Yeah, NATO begins with this by creating a framework of some sort of digital architecture to figure out how to connect those platforms. This modernization challenge where we have these digital assets and capabilities coming in and not having the reliant infrastructure associated with moving those capabilities, that information sharing that General Hecker talked about, it’s really a systemic problem and not the exception of today. 

What we’re seeing is really advanced platforms that are trying to operate on legacy networks, and they’re dependent on communications infrastructure that’s not designed for the contested environment that we’re asking it to fight in. And the big question is why? Well, I would say the digital backbone is harder to fund than the platforms themselves, and that’s simply because it’s a kinetic, non-kinetic discussion. 

What sells – that’s aircraft. What doesn’t sell is investing in your infrastructure. What we’re seeing is that innovation and modernization is indeed happening, and industry is, frankly, leading the way with many cross-cutting and great capabilities. But there’s no funding to put those capabilities in place. 

We can’t afford to just buy those capabilities and hope that interoperability works. So our biggest operational consequence, and really the threat to the alliance, is that every investment is dependent on the digital foundation that has not been proven under attack. If you summarize it in a meaningful way, the comms infrastructure is the limiting factor in this case. 

30:20 – 30:50 

(SK): And so, how does that also factor into the expectation that any system or platform leveraged by NATO is not going to be operating in a benign environment? In any modern day operation, there’s going to be a contested environment where every system is going to be facing jamming, spoofing, and electronic warfare attacks. 

So this question comes back to the command and control aspect, which we saw Russia directly target when it first invaded Ukraine. How does NATO ensure its command and control and the foundational networks you were referring to is resilient to this myriad range of attacks?

30:51 – 32:43 

(CR): Yeah. Resiliency, the word that we often utter, but quite honestly, sometimes misunderstand. When we talk about resilient command and control, we’re talking about having multiple pathways, whether that’s satellite, terrestrial, airborne, HF, what we would call our PACE Plan or Primary Alternate Contingency Emergency communications. It requires some sort of zero-trust architecture that always assumes that the network is compromised. 

It requires that cross-domain solutions allow for appropriate classification sharing at speed, and that there are pre-delegated authorities to allow commanders to act when that connectivity is degraded. And what I would say is that there are indeed pockets of excellence, but there’s an alliance-wide architecture that really remains a very fragile environment. 

The hardest part is not the technology itself, and it’s not the integration of that technology. It’s really the culture. It’s a cultural decision that must be made where we accept that the network is degraded and we design and train to that reality rather than optimizing for some sort of peacetime efficiency.  

The cyber command gap is real and Brad talked about some of that command gap on the space side. But frankly, NATO’s Cyber Operations Center provides coordination and situational awareness right now. They do not have the same authority to employ integrated cyber effects across the allied networks in times of crisis.  

NATO, what they really need is an exercise series that specifically designs to break the command and control under attack, not to test the architecture when it works, but to find where it fails when the crisis begins. Frankly, the days of assumed and exercised exquisite comms is over. We must practice resiliency in this place.

32:44- 33:27 

(JH): Yeah, Scott, I can just throw in when I would do my exercises. There is nothing more frustrating than if I had a team at a certain base and they didn’t even have a classified network, and there’s several bases that don’t. 

So then we built some teams that could go up and set up a classified network and then there’s different levels of classifications. Like when we were talking with space, some it’s just at the secret collateral level and then you need some that go beyond that and that needs to be a lot greater in the NATO countries.  

And I think there’s some good progress being made there. But we need to improve that even more, and then we need backup plans on top of that.  

33:28 – 34:22 

(CR): Yeah. General Hecker, that’s a great point. I had the privilege of serving with you in the European theater under the command of General Cavolli. General Cavolli at the outset of some of the Ukrainian operations, had an observation when he would go into some of the coalition C2 centers and at times there would be 80% of the environment was set up for U.S. secret and above operations, and the remaining 20% was all behind some plywood walls. 

And we’d say, go and do all the Coalition and Alliance comms over there. But never could the two speak. And so he would come to me and he’d say, “Chad, really what we’re looking at is the future fight is not 80% U.S. secret and above. It’s really 80% alliance coordinated activity where we can talk amongst ourselves and maybe you have that exquisite 20% that’s off in the corner, but we need to switch the model of what we currently have in place. 

34:23 – 34:56 

(SK): And another follow-up question for you, Sir. Earlier Brad spoke to the opportunities to leverage the commercial space industry for NATO’s space needs. But what about commercial opportunities in the cyber realm? Things like commercial cloud, commercial communications, data service exchanges, things of that nature. 

So, my twofold question here is this: One – what opportunity exists for NATO and NATO member nations to leverage commercial opportunities in cyber and cyber-related technologies? And two – how does NATO, to Brad’s point earlier about commercial space, ensure that resiliency, in its cyber systems? 

34:57 – 35:54 

(CR): It’s a great question. And what I would offer is that you start with the bottom line up front, which is asking yourself two important questions. 

 First, which commercial services are so operationally critical to your entire operation that their loss would degrade the mission execution? Question two is what is your plan to fight without those capabilities? You ask yourself those two questions and you start building in opportunities and resiliency.  

 There is continued opportunities for commercial providers to integrate into our live operations, and whether that’s some sort of stress testing exercise, simulating attacks, working through physical disruptions, having our commercial partners that are there, providing those capabilities from a cloud environment to cyber tools and techniques, having all of those things in place, I think creates a more realistic environment for us, and it also allows for that resiliency to be learned together.

35:55 – 36:14 

(SK): Thank you, Sir. Now as we look to close our conversation today, I have three remaining questions and I’d like each of you to respond to.  

The first is, given our discussion around the likelihood of the threat coming at the seams, what is the biggest seam NATO should be cognizant of and be prepared to protect against? And how does the alliance go about doing that? 

36:15 – 37:21 

(TG): Scott, I’ll go first on seams. Where Iran in Epic Fury, where we had the leakers come through our air defenses were generally along the seams. One of the biggest ones were the air pictures between the Army and the Air Force and I talked to the Ukrainians who went down with their system to go take a look at it. And they were like,”This is crazy.”  

There are 23 or 25 different air pictures, and they’re not all shared. And to Scorch’s point earlier, when you’re not sharing the air picture, either one you’re going to miss and you’re going to get leakers like what happened, or two, you’re going to fire more weapons at what you’re shooting at, then needed in an already adverse cost-ratio exchange.   

So the seams go right back to what Chad was talking about which is the exchange of information in the most seamless way is necessary. And in missile defense, one of those seams as Scorch brought up is the air and space seam that’s going to get bigger as space plays more in missile defense. 

 We’re going to have to sort that out before we spend the more than 100 billion on Golden Dome, because otherwise we’re just building on a rickety foundation and that’s not going to go well. 

37:22 – 39:31 

(JH): Yeah, Tom, let me talk about another one. This is more on the offensive side, but we do not have the capability to produce in the quantities available of offensive one way attack vehicles that are launched from NATO toward our enemy country that we’re fighting, and they’re cheap. So it’s easily the capability to get some of the nations that can’t afford F-35s, for instance, to buy a bunch and build the capacity to build a bunch of these one way attack vehicles. 

And those one way attack vehicles are not necessarily just going to be used like they are in Russia and Ukraine right now, but they will be part of a larger, coordinated attack for counter anti-access aerial denial. So you’re going to have space providing intel and EW and those kind of things. You’re going to have F-35s with stealth going in. 

You have to have the tankers to refuel all of this. You need your AWACS and those things going in as well. And we saw that they were able to make it happen in Iran with Israel and the U.S. But we need to practice that a lot more and then integrate these one-way attack vehicles at the same time, because that just creates a lot of confusion and the success rate will go way up if you can do that. 

And not only does it do that, it empties the enemy’s magazines. So now they are on the wrong side of the cost curve. They’re spending SA-10’s going after $30,000 drones as opposed to vice versa. So I think that’s a seam on the offensive side that we really need to get after and NATO has the capability to do that, particularly with some of our smaller countries. They would be perfect for doing that. 

And when I would talk to them, they’re more than willing. The biggest thing is when they go ask their defense minister to do it. There’s not a requirement, or at least there wasn’t when I left, I was trying to make it a requirement on the list of what NATO needs for equipment. 

There was nothing in the way of one-way attack vehicles. I don’t know, Tom, if that ever got through in that they’re on the list now. But defense ministers aren’t going to buy something that is not on the list that NATO needs.

39:32 – 40:35 

(TG): It’s a great point. And Brad, chopped down this road with the new political guidance that’s coming out in 2027. They didn’t make the list as far as I can tell. And it’s going to be a hard list because what kind of drones do you want or do you need? Do you specify a number of drones?  

It’s really about the effects. So where they’re going is effects-based kinds of things. And actually what they’re sitting on for 2029 is a disposition that is like if normally your country got told you need four fighter squadrons and you can come back to them and go, really, all I need are two fighter squadrons and four different squadrons of drones, and I can achieve the same effects. I’m just giving you a hypothetical.  

Nobody knows how to do that yet. And basically what NATO has done is go, “We’re open. Give us the argument, prove it to us, and we’ll accept it. More than likely.” 

So there’s going to be a real need for operational analysis to kind of come up with that and figure out what those capabilities are to do that. So it’s a really good point on the drones. And you’re right, it’s a big gaping hole in what NATO capabilities we have right at this minute.  

0:36 – 41:25 

(CR): Scott, I’d come in and talk about the digital seam. When we think about NATO communications architectures, faced with simultaneous jamming, cyber intrusions, physical attacks, and that those information sharing gaps between the Allied networks, that’s where we need to invest our time and our resources. 

We should be celebrating the fact that we found gaps, and that we’re closing those gaps through technology or processes. We should not be white carding these exercise environments. We should be recognizing that finding those gaps is exactly what the future fight is all about and we have to figure out a way of fighting through that.  

So it’s no longer a lost training environment because you can’t send the email. It’s no longer that the network is down and so everybody goes home. Now you have to figure out how to work through that and fight through that at the digital seam.

41:26 – 42:20 

(BH): And I think so I’ll end this off with sounding like a broken record. But on the space side, I think clearly articulating what the collective set of requirements that we need so that we have coherence in the investments that 32 individual nations are making, and then having the ability to command and control those effects. 

I mean, space is critical to any future battlefield in the same way cyber is. And so they’re going to have to figure out how to command and control those effects, particularly in the space domain. You think about like electromagnetic warfare capabilities, who’s doing PNT and SATCOM jamming, and what can I do about it? If I had some systems in the same way that we have like Patriots that do defense, we’re going to have those sorts of systems.  

And so even if it just starts with that regional EW kind of capability, getting those capabilities chopped to NATO and then having somebody with the authority to command and control those on behalf of General Grynkewich, as SACEUR, and then having the actual tools and systems that are able to do that kind of work, I think is something that needs to be sorted out over the next period of time.

42:21 – 42:30 

And as far as the Ankara Summit itself, what will you be looking for both at the summit and in the weeks and months to follow? What will be your metrics for success coming out of it? 

42:31 – 45:41 

(TG): I’ll lead off again on that. I’m focused primarily on the defense production and innovation follow through. And then on NATO 3.0, the only way that’s going to get fixed is by producing a lot more capabilities for European and Canadian allies. 

And I’m looking for two aspects out of that. You know, the cost exchange ratio of a $3 million PAC-3 against a $30,000 drone. This came up with the Ukrainians interestingly enough.  

In 2023, at the Munich Security Conference, he was the minister of Strategic Industries Commission. The Ukrainian asked to see me. And so I walk up and I say, “Hey, what’s going on?” And he goes, “Well, because here’s my issue. I have three different anti-tank weapons. I know how much each one of them cost by going on the internet. And I know from the battlefield how many it takes on average to kill a tank. So I’m doing cost-ratio analysis.” 

And he said, “Tom, I’d like to talk to the people at NATO that are doing this.” And I said, “Yeah, I’d like to too.” It’s not how we thought before, but it’s what we need to get at. So I’d like to see some progress on cost-ratio analysis. We’re talking about it more, but something needs to be done there. 

And then the other piece is on the acoustic sensors that Scorch mentioned, 20,000 of them. I talked to the guy that put that architecture together, and I said, “So was this some kind of requirement that the Ukrainian government gave you to fill to put acoustic sensors out here?” He goes, “No, there was no requirement when we saw that our friends and our relatives were dying and getting hurt and so we wanted to do something about it. So we made this up as we went to figure out how to do that.”  

They did not wait for an RFP and a full blown set of requirements to move forward. And it’s a different ecosystem than what we’re used to and we got a lot to learn from commercial. 

And one of the things that we were trying to and Chad will appreciate this. I was trying to get cloud solutions for NATO before I left and they said, “Oh boy.” Well, if you started tomorrow to get approval to pursue one of those kind of things, by the time you go through all the committees, it’s 54 months before you can spend the first euro.” 

54 months. That’s the process to get all the approvals done. And I said, “You got to be kidding me? Everything will be in a rearview mirror by then.” And they said, “Nope, that’s how the process works.” So we need to fix the process. And the folks at NATO headquarters know that. And this is the process of acquisition and what I think it needs to go down is there are a couple things that the Ukrainians do. 

They don’t let the perfect be the enemy of good. They have the operators talking directly to the innovators. When I went to Ukraine in March, I talked to one drone manufacturing company and she said, you know, “We set up 1-800 hundred number for the operators.” I go, “What do you mean?” She goes, “Well, you know, the guys on the front lines every night flying the drones. We gave them 1-800 fix it number so they can call in 24/7 directly to the engineers to get a patch made on the drone. When they see something not work, they just pick up the phone and call. And that next day they have a patch that tries to fix whatever they highlighted.”  

That’s not how our system works, in general. So if we’re going to get somewhere operators talking to innovators, don’t let the perfect be the enemy of good. Build it, try it, fix it, and rinse, lather, repeat. It’s more of the commercial operation than waiting on an RFP and doing a 30-day campaign to try and get a program a record going.

45:42 – 46:38 

(JH): What I’ll be looking for is, you know, last year they had the five-fold increase in IAMD commitment. What are they going to do this year to follow through with that? Because there needs to be a named force package review with measurable readiness standards to push this thing forward or otherwise we’re going to be here on this podcast next year talking about the same thing, right? So that needs to happen.  

How much we talk about the 5% GDP? That is 100% necessary. And the system that we need, needs to be integrated by design from the get-go. So everything’s talking to everything else, and we need to take advantage of all NATO countries capabilities, whether it’s exquisite capabilities like a Patriot or a simple triple-A on the back of a pickup truck that can shoot down a one way attacks, we need all of them. So we just need to get after it. So that’s what I’m going to be looking at, at the outcome of this.

46:37 – 47:06 

(CR): Well, I’m going to be looking to see whether a coalition digital backbone initiative is in fact directed with the specific architecture requirements that we’ve talked about, or whether the cyber and comms resiliency efforts will remain at the 1.5% category level. 

We do have a precedent for this in the alliance. We have NATO interoperability standards. On the communications protocol side. We need the same on the digital and data side as well and that’s what I’m going to be looking for.

47:07 – 47:53 

(BH): Yeah. And I think I would say the specific concrete plans for getting to 5% and investing those things in a coherent way, particularly as it regards the space domain, getting those capability targets in the NATO Defense Planning Process and the political guidance agreed, and then providing that coherence, updating the NATO space policy. When you talk to people over there, they go. “It’s still fit for purpose because it doesn’t keep us from doing anything that we want to do.” That’s certainly one way to look at it, but it also doesn’t tell you where you’re going and what you need to be able to do.  

So I would prefer if it was much more aggressive and forward leaning and driving things, as opposed to just looking and go, “oh, it doesn’t keep us.” That would be my pitch, is that we have a much more coherent way forward on the space domain to take advantage of the increased resources that are coming in as a result of the political moment that we find ourselves in.

47:54 – 48:11 

(SK): Now, our audience is made up of leadership across government and industry, who will also be paying attention to the conversations and actions coming out of the Ankara Summit. 

Can you share a little bit about Elara Nova and how the strategic advisory firm is positioned to support them as they respond to NATO’s needs?

48:12 – 49:02 

(TG): I think that what we’re seeing in Europe right now, the desire to grow the defense industry production pie means partnerships are going to win, despite the political shin-kicking that’s going on, companies still want to work with American companies. American companies have a lot that they can do with European companies. 

There’s a real opportunity here. And one of the things that Elara Nova can do is help companies navigate the partnership landscape. Who should you be partnering with? What countries are most forward leaning in the areas that you want to work in? 

That’s something that Elara Nova can be really good at helping companies in a bit of a matchmaking regime in order to get to the point where we can produce enough to, as Scorch said, to spend that money smartly rather than just spend that money. Scorch? 

49:03 – 49:32 

(JH): Tom talked about the 90 billion increase. Hopefully we get another 90 billion next year, and it looks like we might be on the U.S. side to 1.5 trillion. So there’s lots of money out there.  

And what Elara Nova can do is help you get partners and make sure that we spend that money wisely, like Tom said. So that’s with the operational backgrounds that we have with a lot of the folks that are on board, they can make that happen and we can do it smartly and your company can make money out of it as well.

49:33 – 50:05 

(CR): What I would offer from an Elara Nova perspective is that our value proposition is working at those seams. And we talked about seams in this conversation quite a bit, but what takes place in space and aerospace and cyberspace and how those things are interoperable together, that’s where Elara Nova is built, is to have these remarkable people that we have an opportunity to work with, with the relationships that we have around the world to integrate all those in a very meaningful way and so it’s that integration between multiple domains.  

50:06 – 51:16 

(BH): And I think I would say a couple of things. One, as we see nations going through these transformations, helping nations navigate those institutional capacity building, we have an unrivaled team of experts who have been there and done that at the very highest levels that can come alongside our allies, partners and friends and help them to navigate those transitions to say, “Hey, we learned lessons and you don’t want to go down this road. Here’s something you need to start thinking about early.” So we have the ability to kind of help in that regard from a national perspective.  

And I think with our commercial clients, whether it is European providers in this case who are trying to penetrate the U.S. market, or U.S. companies who are trying to penetrate the NATO market, the days of waiting for an RFP to then compete for a program of record and then be the company that wins that, and you’re going to have that business for the next 10 or 20 years. That moment is passing.  

And so understanding where the requirements are emerging and skating to where the puck is going. We’ve got the ability to provide some very unique insights in that regard, because we have deep understanding at the highest levels of where those enterprises are moving. And so I think we can help clients on both sides of that house understand where they should be going and where they should be investing that would be something that Elara Nova is fairly uniquely positioned to help with.

51:17 – 51:54 

This has been an episode of The Elara Edge. Elara Nova is the trusted global security partner delivering decisive advantage.  

As a strategic advisory firm, Elara Nova builds expert teams uniquely tailored for client needs to deliver actionable results. With the trusted insight to deliver your decisive edge, Elara Nova is your source for expertise and guidance in global security. 

If you liked what you heard today, please subscribe to our channel and leave us a rating. Music for this podcast was created by Patrick Watkins of PW Audio. I’m your host, Scott King, and join us next time at the Elara Edge.

NATO Ankara Summit Creates a Call-to-Action for Defense Industrial Base

Alliance Seeks Meaningful Progress on Last Year’s Defense Spending Pledge

Heads of State and Government from 32 nations will gather at this month’s NATO Summit in Ankara, Türkiye, looking to accelerate progress toward the goals agreed at The Hague Summit last year. The declaration pledged to strengthen collective defense by committing member nations to spend 5% of annual GDP on defense by 2035, deepen transatlantic defense industrial cooperation and reaffirmed support for Ukraine. Now, several factors are also heightening the stakes of the Ankara Summit: Russia’s ongoing invasion of Ukraine, recent conflicts in the Middle East and “NATO 3.0,” or the increased pressure on and intention of allies to take on greater defense investment and burden-sharing responsibilities. In response, there is growing momentum as NATO nations increasingly invest in defense capabilities, which presents an unprecedented call-to-action for the defense industrial base to respond in kind. 

“At this critical intersection, NATO nations see a more aggressive Russia, a more unpredictable America and a more challenging China, and those dynamics are driving allies to make decisions and take action,” said Tom Goffus, Executive Partner for Global Security at Elara Nova and the former Assistant Secretary General for Operations at NATO. “There will be three big focus areas at the NATO Summit in Ankara: implementing last year’s defense spending pledge, expanding defense industrial production and executing the NATO 3.0 concept.” 

In Washington DC at the Atlantic Council on 25 June, NATO Secretary General Mark Rutte summarized the key themes of the Ankara Summit as: “Transformation in defence investment; revolution in defence industry; and affirmation of our enduring support to Ukraine.”  

Within this construct, he asserted that the major overhaul of defense spending and defense industry will deliver a stronger Europe in a stronger NATO – his NATO 3.0 definition.   


The Defense Spending Challenge

The Hague Summit’s 5% defense spending pledge can be broken down into two parts: 3.5% of spending for core defense requirements like plans, tanks and ships, and 1.5% on defense-related requirements like critical infrastructure, the defense industrial base and resilience.  

NATO’s framework for defense spending is known as the NATO Defense Planning Process (NDPP), a five-step process that occurs every four years in which threats are identified, operational plans are developed and capability targets are determined. The NDPP was most recently updated in 2025, which means the next set of capability targets won’t come until 2029. 

But as the conflicts in Ukraine and the Middle East have shown, capability needs are rapidly evolving as technologies advance. 

“There will be several new capability targets for 2029, that I believe will include space, autonomous systems and Arctic-specific capabilities,” Goffus said. “And at the Ankara Summit, we can expect positive announcements on spending plans for several NATO nations. Poland and the Baltic nations could be at 5% as early as this year, Germany and Sweden are looking to reach 3.5% years ahead of the 2035 timeline.”  

Defense spending by NATO nations is accelerating. According to the Secretary General of NATO, Mark Rutte, European allies and Canada have invested $90 billion more in defense spending in 2025 compared to 2024, a roughly 20% single year increase.  

Defense Industrial Production and Integration by Design 

Along side growing calls for greater investments under the NATO 3.0 concept and these substantive increases in defense spending, the defense industrial base must also expand to be able to accommodate this increased demand with greater production. One acute example is air and missile defense, a mission area where Secretary General Rutte called for a 400% increase in investment by NATO nations. 

“Our defense industrial base is not currently structured to produce what NATO needs at the volume and pace required for the threat,” Goffus said. “So NATO has announced that the Defense Industry Forum connected to the Ankara Summit will be the largest industrial event in NATO’s history. But increasing transatlantic defense production capacity takes time, that’s why NATO is also expected to officially launch its ‘Front Door’ for industry at the summit which will be a single portal where contractors can upload their innovative solutions.”  

This is one of many initiatives designed to answer the Secretary General’s call “To scale up production, spark innovation, and outsmart our competitors.” 

There’s also an inherent challenge of coordinating investments made by NATO nations in a cohesive way, so members are not duplicating capabilities or investing in ones that don’t directly benefit the alliance. 

“NATO needs to spend that money wisely in a way that’s integrated by design,” said Gen (Ret) James “Scorch” Hecker, a Senior Principal Advisor at Elara Nova and the former Commander of U.S. Air Forces Europe, U.S. Air Forces Africa and Allied Air Command at NATO. “To use the air and missile defense example, when each NATO nation would traditionally buy an individual air defense system, they often weren’t integrated with one another. This created a huge disparity between NATO’s ‘Critical Asset List’ of things that need to be defended, compared to its ‘Defended Asset List’ of what was actually defended.” 

Complicating matters further is the growing complexity and urgency of the air and missile threat. But even still, NATO can address this complexity if the alliance coordinates their investments appropriately.   

“We need to make sure that all 32 nations providing air and missile defense systems can address three different threats: ballistic missiles from space, air threats like fighters and cruise missiles and one-way attack vehicles like drones,” Hecker said. “While not every nation can afford a PAC-3 battery, several nations can buy the less exquisite anti-aircraft artillery necessary to respond to one-way attack vehicles. Yet all of these capabilities must still be integrated with a resilient space-based ISR and command and control architecture.” 

Calls for a Space Investment Framework 

Coherent space capability invesmtent and development is another emerging imperative for NATO, which first declared space an operational domain in 2019. This coincides with growth to a projected $1.8 trillion space economy by 2035. This presents an opportunity for NATO nations to meet their defense spending pledge by investing in space capabilities necessary for the alliance.  

“NATO nations are coming to the Ankara Summit with specific plans that show how they’re going to get to 5% by 2035,” said Brad Head, Executive Partner for Global Growth at Elara Nova and the former Chief of Defense Planning at the U.S. Mission to NATO. “But NATO as a collective defense alliance doesn’t actually own and operate most of its capabilities, which are instead provided to the alliance by the individual NATO nations. So what NATO can and should do is provide that overarching framework that would allow countries to invest their resources in a coherent way, so that the capabilities provided to the alliance are interoperable and additive.” 

While NATO released its own commercial space strategy in 2025, the alliance has yet to articulate capability targets for space in the NATO Defense Planning Process. But that’s also where NATO can look to recent actions from the United States Space Force to create a vision and a demand signal that the commercial space economy can respond to. 

“The NATO Commercial Space Strategy is largely in line with the Space Force’s Commercial Space Strategy, whose approach is to exploit what you have, buy what you can and build only what you must,” Head said. “General Saltzman also recently unveiled the Space Force’s Objective Force 2040 baseline to clearly articulate its capability needs by mission area and geography, with a classified annex, to coherently drive the service’s investments. NATO could provide a similar framework to coordinate Allied investment dollars in a coherent way and develop real value-add space capabilities. There are real operational challenges in space today, and commercial providers are preparing to respond.” 

The Digital Foundation Imperative 

Underpinning all of the capability investments of NATO nations, from air and missile defense to space capabilities, is a digital architecture to synchronize and coordinate the exchange of data and information that has become foundational to any modern fight.  

One primary example that puts this challenge into context is Secretary General Rutte’s projection that NATO will have over 700 F-35 fighter jets available to the alliance by 2032. A single F-35 can generate around a terabyte of data during every flight, which is equivalent to 500 hours of high definition video

Consequently, this creates an imperative for NATO to ensure that the hundreds of F-35s provided by its member nations can operate together and exchange data in an integrated fashion. 

“There’s a modernization challenge NATO has where advanced platforms are trying to operate on legacy networks,” said Brig Gen (Ret) Chad Raduege, President of the Cyber, Data and Communications sector at Elara Nova and former Chief Information Officer at Headquarters, U.S. European Command. “NATO needs to create a framework for a digital architecture that will connect all of these platforms. At the same time, NATO’s communications infrastructure is not designed to operate in a contested digital environment that defines modern warfare. So NATO’s biggest operational vulnerability, and threat to the alliance, is that every investment NATO makes is dependent on its digital foundation.” 

Likewise, NATO will require a command and control architecture that will be resilient in the face of the threat. This reality is evident in light of Russia’s cyberattack on a commercial satellite system Ukraine relied upon for command and control at the onset of its 2022 invasion. 

“As it stands today, NATO’s alliance-wide command and control architecture remains fragile,” Raduege said. “Resilient command and control means multiple pathways, such as satellite, terrestrial, airborne or radio frequency means as part of the Primary Alternate Contingency Emergency (PACE) communications plan. This PACE plan requires a zero-trust architecture that always assumes the network is compromised and has pre-delegated authorities for commanders to act upon when connectivity is degraded.”  

As the operating environment evolves across domains, the NATO Summit in Ankara will be a surefire indication of how the alliance intends to respond. It will then be up to the defense industrial base to position themselves accordingly, and that’s where Elara Nova is similarly prepared to support. 

“Right now, there’s a real opportunity because Europe has a desire to grow its defense industrial production,” Goffus said. “So despite the political shin-kicking that’s going on, there’s a lot of American companies that can work with European companies and support NATO nations in achieving their capability targets. One of the things Elara Nova can do is help companies determine which countries and companies to partner with so that NATO nations can spend their growing defense investments wisely.” 

Elara Nova is the trusted global security partner delivering decisive advantage. Learn more at elaranova.com  

Cyber Resilience On-Orbit a ‘Nervous System’ for Detecting Threats

SBIR Funding Demonstrates Growing Imperative for ‘Space Cyber’

In response to an evolving threat landscape where cyberattacks can manipulate and compromise a satellite’s data, the United States Space Force is heightening its focus on “space cyber,” or the cybersecurity of space systems on-orbit. One emerging solution toward this effort is the Cyber Reslience on-Orbit (CROO) tool, a software program that focuses on not just securing the links between satellites and the terrestrial networks, but on the cybersecurity of the satellite itself. Funded in part by an AFWERX Small Business Innovation Research (SBIR) Direct-to-Phase II contract, the CROO tool will leverage innovative technologies like artificial intelligence (AI), machine learning (ML) and digital twin modeling and simulation in a way that demonstrates how the Space Force is adapting to a more dynamic and contested ‘space cyber’ environment.  

“CROO essentially acts as a ‘nervous system’ to indicate that something isn’t right with the satellite,” said Maj Gen (Ret) Kim Crider, the former Chief Technology and Innovation Officer with the Space Force and Founding Partner at Elara Nova. “It starts with building a complete digital model of a satellite, including its subsystems and components to learn the normal behavior of the system. CROO then uses AI and synthetic data to model attacks against one or more subsystems or components. By learning how the digital twin satellite reacts to simulated attacks, the CROO tool can learn to detect or infer real attacks on real satellite systems by knowing what attack indicators to look for. This ultimately will give satellite operators more ways to diagnose when an anomaly is in fact an attack.”  

CROO is being designed to recognize and detect the broad range of current and emerging cyber threats.

“CROO is a next generation cybersecurity tool specifically designed for space systems,” said Brig Gen (Ret) Chad Raduege, the former Chief Information Officer with U.S. European Command and President of Elara Nova’s Cyber, Data and Communications sector. “By using the digital twin model to explore how the satellite might behave under a cyberattack CROO indicates what may happen when an intrusion or unauthorized access is taking place, where a bad actor is making malicious commands or tampering with the code in a way that results in an abnormal behavior. It’s also looking at its signals for software compromises like the different spoofing techniques an adversary or hacker can employ.”  

In doing so, CROO both embodies the convergence of emerging technologies like AI/ML and digital twin modeling and simulation and reinforces the inherently integrated and operationally vital relationship between the space and cyberspace domains. 

Ensuring Cybersecurity Across Domains 

While the United States government has been putting satellites on-orbit for decades, it’s only been in relatively recent history that it’s had to protect those assets from cyberattacks. But protecting satellites from cyberattack isn’t as easy as protecting networks on the ground.  

“Different strategies are required beyond our traditional cybersecurity approaches,” Gen Raduege said. “Cyber defenses for terrestrial networks like firewalls, patching and perimeter defenses, don’t necessarily translate well into space. You can’t just plug and play with different assets like you can on the ground, so cybersecurity defenses have to be designed and built in before the system is even launched. You have to have redundant and resilient systems in space, and that’s why other types of defensive approaches like AI/ML, digital twins and the automation activities of CROO will be important.” 

Further complicating matters is the inherent interconnectedness of space and cyber technologies, which means the Department of War must consider how it will protect its networks across its whole system of systems.  

“We have to keep in mind that when it comes to space cyber, the ground infrastructure and their data links to on-orbit assets create a complex, interconnected ecosystem across domains,” Gen Raduege added. “Terrestrial network defenses can be regularly accessed and updated with patches or fixes, whereas we don’t have direct access to space cyber networks that exist in a hostile and distant space environment. Space cyber is an end-to-end system across a distributed environment that blurs the boundaries of operational and information technologies. That’s a unique challenge to have to protect.” 

It’s also where a cybersecurity tool like CROO will play an outsized role, particularly as satellites function as physical, control-oriented systems that rely heavily on IT for complex software, data processing, communication and data transport. 

“CROO becomes incredibly important when it comes to monitoring a satellite’s behavior because satellites are just one set of endpoints in the entire system of systems,” Gen Crider said. “These satellites are assets we can’t afford to lose, and they’re operating thousands of miles away and traveling at incredibly fast speeds. So we’ve got to think through how we’re going to deal with potential compromises, delays or anomalous behaviors with that satellite and protect the rest of this system it’s connected to.”  

Space Force Investing in Cybersecurity Solutions 

As the nation’s newest military service, the Space Force recognizes its role beyond a facilitator and enabler of joint force operations. Its leaders understand that the service was stood up to protect and defend strategic assets on-orbit in response to a growing counterspace threat environment, which specifically includes cyber threats. 

That’s why the government is creating avenues for companies to cross the ”Valley of Death” and bring innovative, dual-use solutions to the fight. CROO is one such example of this emerging public-private investment.  

“This example demonstrates the government sees operational value in the CROO concept, because these Direct-to-Phase-II SBIR contracts are intended to transition a credible idea into an operational prototype as quickly as possible,” Gen Raduege said. ”The AFWERX SBIRs program and other innovation contracting approaches in general, are explicitly designed to attract startups with operationally feasible and relevant ideas, even from non-traditional defense contractors. These programs enable researchers to develop solutions that can close an operational gap.” 

The influx of funding dollars capabilities like CROO also reflects the emerging priority that is “space cyber.” 

“CROO signals that the Space Force is serious about ‘space cyber’ and is willing to put money behind it,” Gen Crider said. “The Space Force wants a framework for equipping a space system and monitoring it for threats and anomalous behavior. CROO now creates an opportunity that’s not just a one-off capability, but one that can be expanded across the Space Force’s mission areas over time.” 

Leveraging Commercial Innovation and Collaboration 

The successful development of CROO further demonstrates how the government is using the SBIR program to initiate high-level conversations about its needs and its willingness to explore commercial solutions to meet those needs. This can be an innovative break from traditional approaches, when the government oftentimes would receive different capabilities from different industry partners and would ultimately be responsible for integrating them together into a comprehensive solution themselves.  

Instead, the SBIR program is creating an opportunity for industry partners to contribute their own respective strengths to deliver the most advanced capability – already fully integrated – to the warfighter.  

“CROO is an example of the power of collaboration between innovative commercial companies, where Proof Labs, BigBear.ai and Redwire Space all came together to develop a solution,” Gen Crider said. “Proof Labs focuses on cybersecurity testing and analysis, while BigBear.ai delivers modern AI/ML techniques, and RedWire Space understands how satellite systems are developed and integrated into end-to-end systems. This resulted in a capability that incorporates all three of these strengths: cybersecurity, AI/ML technologies and space systems.” 

An Evolving ‘Space Cyber’ Threat 

The space environment, and particularly the space cyber environment, will only continue to evolve rapidly as technologies and adversarial threats advance. Therefore, the need to secure and protect space systems, and other systems across operational domains, becomes an increasingly significant imperative.  

That’s why Elara Nova is also evolving to meet this emerging requirement, by standing up its new Cyber, Data and Communications business sector to ensure the cybersecurity resiliency of technologies and systems across operational domains.  

“The Cyber, Data and Communications sector is focused on what our warfighters need across multi-domain operations,” Gen Raduege said. “Data exchanges through communication nodes that connect one domain to another require the right cybersecurity applications. Our objective is to help government and industry alike translate commercial technologies into solutions that meet the government’s needs, and can be integrated into the current operational environment.” 

For Gen Crider, as one of the four Founding Partners at Elara Nova, the new CDC sector demonstrates a natural evolution for the strategic advisory firm.  

“Elara Nova’s core focus from the start has been: ‘How do we help advance the national defense and security capabilities of the United States and its allies?’” Gen Crider said. “This requires a team of experts with deep experience across the specific domains of military, commercial and civil operations that are becoming more and more complex, interconnected and integrated together through data networks. We need the appropriate software and cybersecurity constructs to assure this spectrum of technologies can perform with assured protection across domains. So Elara Nova’s CDC sector is a natural evolution of how we help our industry partners satisfy and meet government requirements for operating in these complex environments and supporting how the government thinks about leveraging the capabilities industry brings forward.” 

Elara Nova is a trusted guiding partner that builds tailored teams to illuminate unseen opportunities and deliver impact across every domain. Learn more at https://elaranova.com/ 

Episode 34: Cyber Resilience On-Orbit a ‘Nervous System’ for Detecting Threats

The Elara Edge Podcast

Host: Scott King 

SME: Maj Gen (Ret) Kim Crider, Founding Partner at Elara Nova (KC) 

Brig Gen (Ret) Chad Raduege, President of Cyber, Data & Communications at Elara Nova (CR) 

00:02 – 01:17 

In response to evolving cyber threats that can manipulate and compromise a satellite’s data, the United States Space Force is heightening its focus on “space cyber,” or the cybersecurity of space systems on-orbit. One emerging solution toward this effort is the Cyber Reslience On-Orbit tool, or CROO, a software program that focuses on not just securing the data links between satellites and their terrestrial networks, but on the cybersecurity of the satellite itself. Funded in part by an AFWERX Small Business Innovation Research Direct-to-Phase II contract, the CROO tool will leverage innovative technologies like artificial intelligence, machine learning and digital twin modeling and simulation in a way that altogether demonstrates how the Space Force is adapting to a more dynamic and contested ‘space cyber’ environment.  

Welcome to ‘The Elara Edge.’ Our topic today is the Cyber Resilience On-Orbit tool and the broader emergence of the space cyber imperative. We have two guests returning to the show today.

First, we have retired Major General Kim Crider, the first Chief Technology and Innovation Officer with the United States Space Force and a Founding Partner at Elara Nova.  

Ma’am, welcome back to the show.

01:18 – 01:20 

(KC) Thank you. Scott. It’s a pleasure to be here.  

01:20 – 01:48 

It’s a pleasure to have you. 

Also returning to the show, albeit in a different capacity than before, is retired Brigadier General Chad Raduege, the former Chief Information Officer at Headquarters U.S. European Command. While General Raduege has been with Elara Nova for several years, he joins us now as the President of Elara Nova’s new Cyber, Data and Communications business sector, which we’ll get into a little more later on in the show. 

Sir, welcome back! 

01:49 – 01:54 

(CR) Yeah. Scott, it’s great to be back and thank you for pulling together this important conversation.  

01:55 – 02:12 

Now, we’ll kick-off today’s discussion with the story at-hand, which is the Space Force has recently contracted with Proof Labs, a national security space startup, and two other industry partners to deliver the Cyber Resilience On-Orbit tool.  

What is this software program and how is it designed to work? 

02:13 – 03:38 

(CR) Yeah. Thanks, Scott.  I’ll jump in and, and take this first question and come out of the chutes. The Cyber Resilience On-Orbit, what we would call CROO. 

It’s really one of those next generation cybersecurity tools specifically built for space systems that integrates in a very meaningful way – advanced AI and machine learning. And essentially what it does is it provides continuous monitoring, the ability to learn to detect cyber threats for the ongoing challenges of the on-orbit environment. 

I think there’s a couple of important aspects associated with CROO. One is the on-orbit monitoring. What CROO does – is it watches the operational behavior of what is going on in the satellites and instead of just protecting the terrestrial networks or those encrypted links that we think about, it actually monitors the actual system in space and so I think that that’s a unique role of CROO.  

It also provides what we would call intrusion detection and anomaly detection. And it does this by comparing what’s normal versus some of those threats that can come in. So you’re going to start hearing terms like digital twin technology. That’s how it does it. It establishes a digital twin model to allow those systems to test how they behave. I think an important note for CROO is while it’s being built for military application, it’s certainly going to have some dual-use.  

03:39 – 05:25 

(KC) It really is, as Chad said, kind of the next generation of what we need to be doing in securing our space assets. 

What’s so powerful about it, is its application and use of artificial intelligence and machine learning and being able to understand and assess how a satellite system is supposed to be working and how it’s supposed to be responding to contacts from the ground and then what some of the anomalous behavior signals might be indicating, some of the potential on-orbit system compromises. If that system is not performing as expected, if the responses to ground contacts and engagement are not as expected, or if there’s an anomaly that occurs on orbit that creates some sort of alert, the system of CROO essentially acts as like a nervous system to provide an indication that something just isn’t right. Something isn’t performing the way it’s supposed to.  

And if we have a digital twin, as Chad described, and we can talk about that a little bit more, we can compare that on-orbit activity, that on-orbit behavior, to what normal behavior would look like and really start to pinpoint where the problem is in a way that is much more comprehensive than what we can do today.  

And as Chad mentioned, the other thing that I think is very powerful about this capability, is its ability to be able to support both military applications, government applications, commercial applications across the board. 

So I think it’s going to be a very powerful capability and it’s very exciting to see the Space Force getting behind this.

05:26 – 05:33 

I’d like to dig further into the idea of a digital twin model. Can you speak a little bit more to what that means and why it presents an advantage? 

05:34 – 06:36 

(KC) The idea of a digital twin is that you would use artificial intelligence to be able to describe a digital version of an asset, whether it’s a static asset where you wanted to create a digital representation of that asset, and you might use different sensors to understand what that asset looks like. 

If there are certain operational parameters that you would expect or behavioral parameters, if you will, that you would expect that specific asset to accomplish and you would create a digital representation of the asset. 

And that specific twin is then continuously updated and maintained to represent how that asset is changing in the environment within which it is operating. 

And then in this case, of the CROO, might be compared to an anomalous activity of that asset that is outside of the norm, outside of the established performance parameters of the digital asset. 

Let me turn it over to Chad for additional thoughts.

06:37 – 07:17 

(CR) Yeah. Kim, I like the word that you used or the phrase that you used about operational parameters. And digital twins are being used to enable the operators to experiment a little bit to see what the art of the possible with the different sensors and tools and technologies and processes really would look like.  

They’re able to learn, they’re able to apply different ideas, different hardware and software configurations to learn and really develop a best practice list of capabilities and how the live operational environment should look and so digital twins, as alluded to, have been around for a while, but I think we’re going to see more and more of this because it’s just such a powerful concept. 

07:18 – 07:29 

Now, the U.S. government has had assets on orbit for decades. But what does the continued development and maturation of artificial intelligence and machine learning technologies enable now that wasn’t possible before? 

07:30 – 09:08 

(KC) With artificial intelligence, we have so much more capability to create an understanding of a system in its environment without actually being there. We can capture data about the real world environment in space, and how a particular asset that we may have created a digital version of is performing, is responding to that environment with real world data. 

But if we want to understand the possible scenarios, the possible attacks, the possible challenges that might impact an asset in the environment, we have to create synthetic data. We have to synthesize what that potential attack might look like, or what that potential reaction might look like in an environment that we might have to emulate through synthetic data and artificial intelligence can allow us to do that.  

It can allow us to envision and establish: here is the asset. Here is the digital version of that asset in its established operational environment, and we would feed that synthetic version with realistic attack data once we have that in a range sort of scenario where it can be compared to what an attack might do to the asset. So it’s a process of using data and models to not just represent what is, but to represent what could be and to represent responses and actions that could be taken if and when an anomalous behavior or an anomalous activity occurs.

09:09 – 09:14 

And Sir, what are some of the anomalous behaviors or cyber attacks that CROO is being designed to detect and prevent? 

09:15 – 10:54 

(CR) I love the way that, that Kim described the use of data, both with what we currently have [with] the large data models that are out there of what does a normal operation look like, but also that infused with synthetic data of what might an attack look like so that you can you can look at that data and learn from that and anticipate.  

 And so, Scott, to your question specifically of what types of cyber attacks CROO is designed to look at and developed to prevent. There’s a couple of things. 

One would be intrusions and unauthorized access. So detecting when some sort of outside infiltration of the systems are taking place. It could be spotting malicious commands or any tampering or deviations in the code that are part of the normal behavior. 

Kim used the term “the nervous system.” And I think that that’s a very good grab on the type of thing the CROO is designed to prevent. It’s looking at full signals and different spoofing techniques that an adversary or a hacker may be employing. It’s looking for things like software compromise. What is actually on board and what corrupt software states come in. It could be kind of the engine light warning in your car that’s popping up saying, ‘Hey, alert, there’s something going on here.’  

And then finally, I would say that it detects some of those anomalous operational patterns. So things like changes in real time, things that are outside the norm – going back to the data that it has been fed, things that create what a normal environment would look like and what would a simulated attack look like and it can pick up on that. So that’s where I think CROO is going to help us prevent. 

10:55 – 11:09 

Now Charleen Laughlin, the Space Force’s Deputy Chief of Space Operations for Cyber and Data, has noted in the past that there is an inherent difference between defending terrestrial networks and on-orbit networks.  

Can you elaborate on the difference between the two? 

11:10 – 13:57 

(CR) Yeah. Scott, I love that question. And I’d like to start by just acknowledging it’s great to have Char Laughlin, as the first stand alone S6, if you will, for our Space Force. I think her placement on the U.S. Space Force front office staff focused directly on cyber and data is a strong indicator of the type of talented leader she is. 

She comes from a very strong joint and coalition experience in her previous role down in the Joint Staff, J6. And so she comes in and has been able to pinpoint in a very succinct way the difference between what you’re talking about of terrestrial, where we think about focusing on the network and how you physically control it, how you regularly update it.  

Whereas, space cyber defenses, what I’ll call ‘space cyber,’ must protect things that we can’t necessarily touch. Once you put that in orbit, it’s operating in an area that we don’t have direct access to. Often in a hostile environment and it’s very complex given the distance that it is from us. So there’s a couple of things that I think feed into that ‘space cyber’ definition, if you will. 

One is just the complexity and the architecture. Think about this. You know, it’s not just the ground infrastructure and not just the data links that we’re used to on the terrestrial side. But now you add in that orbital asset, and the interconnected ecosystem that that creates. So now you have different endpoints in different domains where you can get one by hand, but you can’t get the other and so that creates complexity.  

It also limits the physical access as you can’t touch that once that’s already been launched. So those satellites and those orbiting systems are really out of our control. It also creates a very distributed environment. There are vast differences. I mean, we’re talking a long way up into space to even have that ability to work with it.  

Final point that I will make is that there is a unique role that this ecosystem creates when you have those ground stations, those uplinks and downlinks and then all of those connections that are taking place. We’re really seeing a real blurring of the terrestrial IT environment. So the things that we can touch. Now, it’s on an asset that’s in space and so that begins blurring in and bringing in the boundary of operational technology and that’s really where the hardware and the software is processing. It’s the control, it’s the physical environment that is operating in space and so a real blurring of IT and OT and so that’s unique as well. So Char Laughlin’s description I think is spot on. It’s different and more complex.

13:56 – 14:13 

And given these differences, the imperative to have the appropriate cybersecurity measures in place remains ubiquitous across operational domains.  

So can you speak to how the government must take different defensive approaches to account for the cyber threat across these different operational domains? 

14:14 – 16:00 

(CR) I think there’s a couple of things that come to mind when you talk about that defensive approach and the way that we’re thinking about space cyber. One is that it’s an imperative to be built in from the start. This is one of those things that cybersecurity is built-in by design, before it is even launched into space and so that’s unique.  

Different strategies are required beyond our traditional IT security. What we talked about with things like firewalls, or patching, or perimeter defense, all of those things that we are very involved in and very deliberate upon on the terrestrial side, once you get up into space that doesn’t necessarily translate well. 

Now you’re having to think about things like remote detection and built-in resiliency. You can no longer just plug and play different assets like you could on the ground. You’re now having to have built-in, redundant systems and resilient systems in the event that something happens.  

You also happen to figure out, even before you deploy what sort of hardening activities, you put on those systems. 

We spent quite a bit of time already talking about AI and ML and I think that that is another example of the types of defensive approaches that the digital twins and automating activities like CROO is doing. And then finally, I would just say that I think that there is a role in this of thinking about the whole of system and what that integration looks like. 

Earlier I used the term the ecosystem, but I think that that is a foot stomp to this whole conversation. It’s not just the exchange of data by way of uplinks and downlinks. It’s the spacecraft, it’s the ground systems. It’s all of that and you can’t treat those all individually. You have to think about the entire data flow, from ground to space and back. 

16:01 – 18:31 

(KC) You really do need to, more than ever, think about the engineering up front, and emphasizing the resilience up front, really working through the architecture of that entire space system as Chad’s talking about not just the on orbit asset, but the the links and the connections and the ground system and how it all works together and where and how the resilience is going to be built-in and across that entire entity, that entire end-to-end system. 

And this is where something like CROO becomes so important is when you’re thinking about the end-to-end system [and] the monitoring of its behavior. How do you expect this system to behave across the board? And where are you going to be potentially seeing compromises in that system? We’re talking about endpoints, these space satellite systems that are operating at thousands of miles, tens of thousands of miles away, whether they’re in LEO about 1,200 miles away or in GEO 22,000 miles away. These assets are far away. They’re moving around very, very quickly in space and they’re entities that we can’t afford to necessarily lose.  

So we have to be really mindful, even before the asset is launched. How could that system potentially be compromised? And what are we going to do if it is, what’s going to be the playbook on dealing with remediation? How are you going to get to the last normal mode of operation? And roll back in some manner to a level of operation that you can control and command the spacecraft with.  

And so you’ve got to be able to think through how you’re going to deal with potential compromises, potential delays, potential needs to rekey or reconfigure and remediate any potential anomalous behavior in that on-orbit system and the entirety of this system that it’s connected to.  

I’ll add one more point. I mean, oftentimes, as much as we’re concerned about the on-orbit asset and I’m glad that we’re thinking through this and how to be able to understand it better and assess anomalous behavior – we can’t overlook the ground system. The ground system is connected to the terrestrial network and it has so many potential attack vectors associated with it. 

We need to be thinking about the entirety of the network, the entirety of the system, and the entirety of where the ground system could potentially be compromised as well, because quite frankly, that is still a very, very vulnerable point in our overall space end-to-end system.  

18:32 – 18:53 

Now, getting back to CROO. This software tool was partially funded through an AFWERX Small Business Innovation Research or SBIR, Direct-to-Phase II contract. 

What does this demonstrate about SBIR as a contract vehicle for a capability the government is interested in? And further, what does this example signal about the government’s emerging cyber priorities? 

18:54 – 20:37 

(CR) I think what’s unique about the Direct to Phase Two SBIR contract that was put in place: the government doesn’t mess around on this stuff. Often, we’ll have an idea. We’ll get started with research by giving out some funds to allow researchers to go and be curious to look at the types of solutions that we could provide and then really bring it back to the government for us to evaluate. 

I think in this case, when we’re talking about directly to a phase two, what this is signaling is that the government already sees strong operational value and relevance and credibility in this CROO concept. And so that’s a salute to CROO, that we’ve already bought into the idea. Now it’s just bringing it to light.  

From our innovation societies in general – AFWERX, the SBIRs program – those are explicitly designed to attract startups with great ideas, nontraditional defense contractors. We’re looking for agile companies with innovative ideas. Innovation often is more important than anything. Speed matters. We’re trying to close an operational gap that we are seeing.  

In this case, I think the Department of War is probably saying, ‘Hey, we’re willing to take some calculated risks on this.’ There’s enough vulnerability to what we’re seeing in space and down on the ground that we’ve got to get after this right now. 

And so the whole idea about those phase two SBIRs is transitioning to a program of record as quickly as possible. And so for industry this is a real pipeline to real contracts. And so that’s a little bit of the incentive and a little bit to your second question of how industry should look at this.

20:38 – 22:08 

(KC) Yeah, I’ll just add that I think that with what this signals, is that the Space Force in this particular case is very serious about space cyber. It’s willing to put some money behind it. It wants to see what can be done. It really wants to see a real prototype of what can be done in this area of digital twin of a space asset and using artificial intelligence and machine learning as we talked about, to be able to not only build out the digital twin and understand its performance parameters under normal conditions, but be able to detect anomalous behavior and have a framework for doing that.  

 Have a framework for really, tooling the system, monitoring the system, assessing anomalies, and then being able to use that as a basis for: how do you really defend against those challenges? And providing a basis, as I said earlier, for what we might be able to do with any type of mission system. This becomes an opportunity to create a capability that’s not just a one-off. 

We can reuse these methods that are being built out here, to be able to expand and extend into all of the mission areas of the Space Force over time. So I think it’s a very powerful way to use the Small Business Innovative Research program to have a capability developed, to get a real usable prototype that can be extended and expanded across a variety of different mission sets.  

22:09 – 23:06 

(CR) Yeah. Hey, Scott, if I can just piggyback on Kim’s great response. Often the government is put in the role of integrator. We have stovepipe solutions that are delivered to us and then we in the government are forced to try and figure out how to bring those capabilities together. 

In this particular case, with this SBIR, it’s really forcing a higher level conversation about solving the system of systems problem set and and being the integrator. And so for the example of CROO, we had three different companies that came together and said, ‘We’re going to take that integrator role off of you, and our engineers are going to tackle this and look at it from end-to-end and figure out how to how to bring in AI and ML and bring in cybersecurity aspects of things and bring in our engineering design, all of that together in a whole of system approach.’ And so that’s just a real kudo in this case. 

23:07 – 24:03 

(KC) It’s so interesting. In this particular case, you’ve got Proof Labs, Big Bear AI, and Redwire, all coming together. Again, the power of that collaboration, the power of that teaming of commercial innovative companies, a company very much focused on the application of AI and ML testing and assessing from a cybersecurity standpoint in Proof Labs. A leading AI company in Big Bear AI that is bringing modern AI techniques and machine learning. 

And then a company that understands the space environment and the space components, and how satellite systems are developed and built out and the end-to-end system and particularly the on-board asset’s space components that RedWire brings to bear. So three really important capabilities coming together: cybersecurity, and the testing and analysis of it. 

It’s a very powerful collaboration here.

24:04 – 24:30 

CROO was also a topic of conversation at The Value of Space Summit, an event hosted last fall by the Space ISAC (or Space Information Sharing and Analysis Center).  

 The Space ISAC also recently announced that it’s expanding its watch center operations to the United Kingdom and other Allied countries. We’ve discussed the Space ISAC on the show before, but to briefly reiterate, can you share the role of the Space ISAC and its watch centers, particularly in context of the cyber threat? 

24:31 – 25:41 

(CR) I’ll take a first go at this and I’ll tell you that ISACs in general. So you described it: information sharing and analysis centers. These are stood up all over the environment. There’s sector specific threat sharing organizations that are meant to improve the cyber resilience by indicating when there are compromises, sharing best practices, sharing information between each other, [and] getting stronger as a group. 

Typically these are member-based organizations, as is the case of the Space ISAC, which is one of those again, specific sectors. So our Space ISAC is headquartered in Colorado Springs. It’s a nonprofit industry consortium, but it’s also a membership. And so you can choose to be part of this. And, when you come in, you’re part of the broader space ecosystem that includes space companies, different government partners that are there. There are higher education research institutes and now, as you alluded to, there’s some allied contributions, and it’s all about sharing information about the security threats and vulnerabilities that are out there against our space systems.  

25:42 – 27:25 

(KC) Yeah, the Space ISAC has been around for a while now and I think they’ve really started to figure out ways to expand and grow into the international community with the expansion to the UK and Allied countries. They’ve found that it not only is important to bring those industry partners in, but as Chad mentioned, bring other countries in so that they can be able to leverage the information and insights, threat intelligence that Allied partners can provide around the globe on specific threats to the space domain. 

What the Space ISAC does is it collects threat information. The members share information about vulnerabilities that they are observing to their space assets, threats to their space assets, and incidents occurring in space, whether those be cybersecurity incidents or environmental space anomalies that are impacting their systems. 

And if you expand that to take advantage of the global reach of Allies and partners around the world, now you’re starting to really understand, how those assets might be impacted anywhere, from any vantage point of those assets from the globe, and from the perspective of different types of members who have assets operated from their different countries. 

It provides a much broader understanding of what’s happening, much more potential threat vectors, against those space assets. And a lot of collaboration and coordination reinforcement, between U.S. commercial partners, international commercial partners, and U.S. and Allied government partners that are all interested in and collaborating on the Space ISAC. 

27:26 – 28:29 

(CR) You know, Scott, my last duty assignment was with European Command, so I had an opportunity to work quite a bit with our Allies and partners in the NATO environment. 

We used to have a saying called ‘Stronger Together.’ And that was really a foot stomp of what these multinational Ally and partner cooperations look like. And so, thinking back to the Space ISAC and now that they’re going global, I think there’s some very easy takeaways for our audience to understand. Now you have more regions and more time zones that threat intelligence is flowing from and to, you have a ‘follow the sun’ monitoring model. 

And so there may be something that you see happen in one part of the globe and through the interconnectivity of the Space ISAC they’re able to see that and perhaps even get the word out for others to protect themselves. I also think that it helps from an international perspective of dialing in, not only the response for anything that’s been detected, but building in some resiliency through some of the best practice programs that are out there.  

28:30 – 28:46 

Also at around this time, the Department of War announced a new cybersecurity framework, known as the Cyber Security Risk Management Construct, or CSRMC. Can you introduce us to this new construct and what does it aim to do differently from its predecessor: the Risk Management Framework? 

28:47 – 31:13 

(CR) Oh, Scott, you said the bad word of ‘risk management framework.’ RMF has been, one of those four letter words that I’ve known most of my career as I was in, different senior level jobs, near the end of my career, it was – I won’t say the bane of my existence – but it was a tough environment, as innovative and agile leaders at the Pentagon were trying to drive us to be more cyber secure through RMF, which was just a tough model.  

RMF had its role. It was based in industry standards and NIST standards. It provided a framework to get to your authority to operate or your authority to connect. And so it did have an important role. But what I like about this new cybersecurity risk management construct is this is a new framework that’s built on a different set of values. 

They have five different phases associated with this framework where they’re designing, building, testing, on-boarding and then operating. And so what does this look like?  

RMF used to be one that was more of a compliance focus, [whereas] the new model was one of continuous operational risk management. Exactly what our warfighters are looking for, exactly what commanders are looking for when they employ systems. The RMF model used to be one where you have periodic assessments. We used to be on a schedule every year or two years or three years, depending on your authority to connect and authority to operate. 

Now, this new framework, this new construct is built on real-time monitoring and dashboards. So now it’s not a static PowerPoint chart. Now it’s a live operational dashboard that’s showing you the true cybersecurity presence in real time.  

What used to be a snapshot in time is now continuous and dynamic. It allows for real-time risk evaluation. It used to be limited and now there’s a real central emphasis on coming together and thinking about and managing our cyber risk as a community. Those that are responsible for evaluating it and those that are responsible for fielding and operating it. And so, I’m excited to see where this is going to go. I think it’s a real indicator that there is a shift, again, in the cybersecurity culture of our department. And I’m cautiously optimistic – how about that? 

31:14 – 33:46 

(KC) And Chad’s exactly right in terms of everything he described with regards to what’s different about the Cyber Security Risk Management Construct. [It] certainly puts us in a position to emphasize some of the things that we’ve been talking about here all along. The continuous assessment, the monitoring, versus, the sort of checking the boxes, paperwork-based approach that we had before. 

And I think this is really what industry needs to think about when it comes to this new approach. That it really is about ‘show me the data,’ prove that there is a continuously measured security posture in place for a particular system or asset, and do that through evidence, through providing these digital twins that we talked about before that can really demonstrate how secure a system will be in the face of threats and how that system will be monitored and how that system will react in the face of threats.

It doesn’t call specifically for digital twins, but that is one way to certainly present a continuously measured and secure posture for an asset that can be supported with some evidence, with some data, with some provability. Industry needs to ensure that systems are built for reciprocity, that they are providing information and evidence and controls that show how they’re leveraging established controls and established secure methods for monitoring those systems that will reinforce its posture. 

And then it’s communicating specific risk to mission, not just specific risk from a cyber perspective, from a technology perspective. But what does that risk mean? What is that cybersecure vulnerability that that system is designed to protect against? How is that reinforcing the mission security? The mission posture? And so how does that system design understand, and account for protecting the mission and assuring that the controls that are in place are oriented around a mission focus, versus just a focus on a specific component of the system. 

Those would be some of the things that I think industry should be taking away from this new approach, and be leaning into as it looks to seek to support the Cyber Security Risk Management Construct. Chad, what would you add to that?

33:47 – 34:11 

(CR)  I think mine would just be a footstomp. This is going to become the new norm and industry needs to understand that. I was just reading an article this morning where we now have a confirmed DoD CIO, who is very interested in this new construct and what that will look like for weapons systems across the Department of War. 

So, it’s going to be the norm, get used to the buzzwords and deliver accordingly.  

34:12 – 34:32 

So we’ve covered a lot of recent changes in the “space cyber” realm of national security. But here at Elara Nova, there have also been some recent developments.  

General Raduege, you are now spearheading a new line of business for Elara Nova, the Cyber, Data and Communications sector, as its new president.  

What are some of the goals and objectives of Elara Nova’s new CDC effort? 

34:33 – 37:48 

(CR)  Scott, I’d be happy to. First of all, let me just say I’ve been with the Elara Nova team for several years now. Always been impressed with the way that they operate, the types of people that they have assembled as part of the Elara Nova family. I am just thrilled and honored to now pick up a more expanded role in this.  

So we’re calling it the Cyber, Data and Communications sector. I’m very excited to see how those three things interact.  

First of all, I would tell you that I’m thinking in terms of multi-domain. There is, there’s some real things that our warfighters are in need of, we have the terrestrial environment, we have air, we have space. And how do you tie all those things together to exchange data from one location to another through the communications nodes that we’ve assembled, and then make sure that you’ve got the right cybersecurity applications applied to that? So I mean, really, that’s going to be the focus moving forward. 

We really do have an objective as we initially get started to help industry and government alike cut through the complexity of everything that’s out there. We’ve spent a lot of time today talking about systems of systems and architecture and cutting down on silos. This is a way of getting after that. We’re really thinking in terms of creating a strategic edge for our warfighter.  

We’re focused in this new sector on industry: helping them understand really, what are the government requirements looking for? What are they asking? How do you interpret that? How do you enable your technology toward that? How do you message the capabilities that you have put together? 

You have great tech, but it requires somebody that can help translate that great tech and that great vision into the requirements that the government is looking for. And then it’s figuring out how to engage the right leaders at the right time. Where does the acquisition community fit in this? Where does the Combatant Commander fit into this? How about the services? Where are the authorities? Who are the right people to get visibility and get that capability recognized?  

But we’re also focusing on, on the government as well. How do we help them in the very demanding environment that they have? It’s just a look across the environment right now to see all of the military operations that are ongoing around the world and those that are in uniform and serving in the Department of War currently have a lot to figure out how to employ the capabilities of today, while trying to envision the future.  

And Elara Nova will have a role in that: helping them think about that future construct, aligning the right capabilities, with the right technology and helping figure that out, interpret what industry has out there and how that may plug into the current environment. 

So I’ll stop there, Scott, and just say, I’m really excited to see how this Cyber, Data and Communications play will all come together. You’re going to be amazed at the type of experts that we’ve been able to assemble into this new sector and we’re just really looking forward to making a difference for our nation. 

37:49 – 38:07 

And Ma’am, as one of the Founding Partners at Elara Nova, can you take us behind the scenes on what prompted the decision to stand up the CDC sector? 

And how does expanding Elara Nova’s services in this way reflect the growing imperative to ensure government and commercial systems are cybersecure not only in space, but across operational domains? 

38:08 – 41:14 

(KC) These questions go hand in hand, really. You know, Elara Nova’s core focus from the start, is and continues to be: how do we as a company help advance the national defense and security capabilities of the United States and its Allies? And in doing so, how do we bring our team of experts who have deep and wide backgrounds and experience in and across specific domains of military operations, intelligence community operations, commercial operations, civil operations? How do we bring that expertise to bear so that we can ensure that the United States and her Allies have the absolute best capabilities that industry can bring forward and apply?  

And in doing so, we recognize that those operations that I mentioned across the board are becoming more and more complex. They’re becoming more and more interconnected. They’re becoming more and more integrated. They’re becoming more and more multi-domain across space, air, ground and cyber. And the application of technology has to be able to perform in those very complex environments. And what connects all of those environments is, in fact, software, networks, data, and the cybersecurity constructs that assure protection in and across those domains. 

It’s a natural outcome for us as a company to be thinking about having a sector that’s going to focus on not only advancing space capabilities for our nation and her Allies, but the cybersecurity components that go along with that: the data architectures, the interconnected communication systems in space, from space, to space, and with all domains that goes along with that. 

And the interconnectivity, if you will, across those three assets: cybersecurity, data and communications. It’s only natural for us to think about the air domain and how air and space have to work well together to reinforce and enhance operations for each domain, across each domain, and with all the other domains of operation that our joint warfighting Combatant Commanders need to be able to assess and therefore also the cybersecurity data and network communications that needs to occur in the air, from the air, and between air and the other domains. 

It’s just a natural evolution of what we, as Elara Nova, bring to bear and the expertise that we want to assure can be brought forward to help our industry partners satisfy and meet government demands of operating in those complex environments and help our government think about what kinds of capabilities are needed and how to leverage those capabilities most effectively with and in support of, all the other capabilities that they’re bringing forward.

41:15 – 41:54 

This has been an episode of The Elara Edge. As a strategic advisory firm, Elara Nova is the trusted guiding partner that builds tailored teams to illuminate unseen opportunities and deliver impact across every domain. 

With the trusted insight to deliver your decisive edge, Elara Nova is your source for expertise and guidance in cross-domain security. 

If you liked what you heard today, please subscribe to our channel and leave us a rating. Music for this podcast was created by Patrick Watkins of PW Audio. This episode was edited and produced by Regia Multimedia Services. I’m your host, Scott King, and join us next time at the Elara Edge. 

Episode 5: CMMC 2.0 and The Zero-Trust Strategy: How the DOD is Accelerating Cybersecurity Across the Defense-Industrial Base

The Elara Edge: Expert Insights on Space Security

The Elara Edge: Expert Insights on Space Security

Episode 5: CMMC 2.0 and The Zero-Trust Strategy: How the DOD is Accelerating Cybersecurity Across the Defense-Industrial Base

Host: Scott King

Subject Matter Experts: Lieutenant General (Ret.) Harry Raduege, Senior Partner at Elara Nova; Brigadier General (Ret.) Chad Raduege, Senior Partner at Elara Nova

00:00 – 01:42

In the waning years of the Cold War, the Department of Defense launched its Advanced Research Projects Agency Network, or ARPANET, one of the earliest iterations of the modern day Internet. In the decades since, cyberspace has become essential to streamlining decision-making up and down the kill chain.

Now, the threat landscape in the cyber domain is more malicious than ever. Nation-states, hacktivist groups, and individual actors are launching incessant cyberattacks against our military services, federal agencies, critical infrastructures and even commercial entities. In response, the DOD is implementing its Zero-Trust Strategy by 2027 to secure its cyber operations.

As part of this process, the DOD rolled out the Cybersecurity Maturity Model Certification 2.0 – or CMMC – providing a requirement framework for its defense-industrial base to follow. 

Welcome to “The Elara Edge: Expert Insights on Space Security.” I’m your host – Scott King. And joining us today to discuss how the DOD is securing its cybersecurity practices across its military services and defense-industrial base is Elara Nova Senior Partners Retired Lieutenant General Harry Raduege and his son – recently Retired Brigadier General Chad Raduege. 

Throughout each of their respective military careers, the Radueges have emerged as leaders in ensuring critical DOD information and operations are protected and secure. 

Sirs, thank you for joining me at the Elara Edge today. Can you begin by describing the modern cyber threat the DOD and its defense industry partners face today?

01:42 – 03:08

Yeah, Scott, thanks for the question. I’m going to take lead on this and then let my dad pile on with his perspective. 

There are three words that come to mind. One is constant. We are under constant attack in our DOD systems, the cyber capabilities that our adversaries are employing against us. We’ve had somewhere between, well, about 12,000 different cybersecurity attacks against our DOD systems since 2015. And that’s probably meeting a threshold of big cyber attacks and not just nuisances. 

The second word is complexity. We are seeing our adversaries employ something that we call ‘Advanced Persistent Threats.’ This is them working over not just days and weeks, but really months and years to gain a foothold into our DOD systems and having the capability that they can activate at a time of their choosing. That complexity is what challenges our cybersecurity professionals on a daily basis.

The third word that I would use is one of determination. Our adversaries are determined. Our DOD systems are very elaborate. But where they’re finding the soft underbelly is really in our contract workforces, in our program offices. And so they’re targeting those particular avenues of approach. So they’re very determined to get in and then sit and wait.

03:08 – 03:48

Yeah. Thanks, Chad. Let me add a little bit there to what my son has mentioned. The threats that we’re seeing in the cybersecurity world have just continued to grow in intensity, sophistication and even approaches. 

Successful breaches are conducted every day against all critical infrastructures, that being government, industry, banking and finance institutions, oil and gas companies, health care, retail, supply chain, etc., etc. Bottom line is no one is exempt from cybersecurity attacks these days. 

03:49 – 04:07

Thank you. And so it appears the DOD is laying out two solutions in response to these threats: the Cybersecurity Maturity Model Certification 2.0 – CMMC – and its Zero-Trust Strategy.

Let’s begin with CMMC 2.0. What is the DOD attempting to do with this framework?

04:08 – 04:56

It’s all about establishing baseline security, really some expectations for companies. Anyone that’s part of our defense industrial base that is providing capabilities to our Department of Defense – this gives them the rules of the game.

This began with CMMC 1.0 back in about the 2020 timeline, and this was trying to identify the intersection between military and commercial capabilities and organizations. And so this was really a methodology of trying to get after protecting our supply chain.

We fully expect that the CMMC 2.0 criteria will give those companies, those members of the defense industrial base an idea of what are the rules of the game? What are the expectations in providing baseline security for our systems?

04:57 – 05:25

Yeah, let me just mention one quick thing: This 2.0 really does streamline the requirements from 1.0, which had five levels down to three levels of cybersecurity. And it also aligns the requirements at each of these three levels with well-known and widely accepted National Institute of Science and Technology – or NIST – cybersecurity standards.

05:26 – 05:33

How does CMMC 2.0 factor into the DOD’s approach to establishing its Zero-Trust Strategy by 2027?

05:34 – 06:43

The zero-trust really can be boiled down to ‘Never trust and always verify.’ So DOD requires an enhanced cybersecurity framework that’s built on these zero-trust principles, including the very important aspect of developing a zero-trust mindset among every employee. And so education and training in the cybersecurity area is really key to the success of any organization going forward.

We’re actually having some standardized level one CMMC self-assessments which adds an entry level self-assessment that you can do for gaining higher levels of CMMC performance and certification. 

And this is particularly important I think for the small and medium businesses out there that don’t have the internal resources to either buy the cybersecurity expertise through personnel, or training or even consultants.

06:43 – 08:04

I think that’s a great point – that idea of mindset and education and training. Really, I think, Scott, what we need to remember with really both CMMC 2.0 as well as zero-trust – cybersecurity is a culture and it’s not a product. 

It requires a commitment of building the culture through education and training, through funding, through investment. Cybersecurity is that culture and not just the product.

Just last fall, the Department of Defense released their ‘Zero-Trust Strategy.’ And in that strategy, it acknowledged that each of the services are different in the way that they operate, maintain and fund zero-trust strategies in the way that they’re building their cybersecurity culture.

And so they’re holding each of the services accountable for turning in a review of where you are. What does your zero trust strategy now look like? And DOD plans to review those over the next several months.

But still, what DOD is recognizing and acknowledging is that their timeline is 2027. And so we’ve been on an eight year journey to get zero-trust in not a unified fashion, but by service, implemented into the DOD – that’s optimistic. We’ll remain hopeful that that comes to fruition. But that’s where I think we are right now.  

08:05 – 08:22

Space and cyberspace are inherently interconnected as warfighting domains. This is reflected in the Space Force’s founding as the military’s first fully “digital service.” So what role can the Space Force serve as a cybersecurity leader for the DOD and its defense-industrial base?

08:23 – 09:41

There are three things that come to mind when I think about the role that the Space Force is playing and could play moving forward. One is their size, because of their size, because of the way that they have streamlined their processes. I believe they have the agility to quickly and rapidly field capabilities and shape processes, tools, tactics, techniques and procedures.

The second one is they have unity of action. There is a unique thread that is being pulled through our Space Force right now from young Guardian to senior leader, where there is unity of effort in the way that they’re thinking about their role in the future, their role as a digital service. 

The third thing that comes to mind when I think about the Space Force and their digital service capabilities – their relationships between the U.S. Space Force and industry. There is this collaboration, these relationships that take place between those that have the requirements and those that are delivering upon the requirements. And so if we could figure out some way to harness that relationship, tie together the military and our commercial providers, I believe there’s huge power moving forward.

09:42 – 10:09

I believe that digital services that are provided by the space and cyberspace domains and specifically U.S. Space Force and U.S. Cyber Command. These serve all the other operational domains: land, air, sea and themselves. So these digital services are critical to proper and efficient Department of Defense operations going forward.

10:10 – 10:48

I would just chime in and offer a perspective, as I went through a two year experience in the European theater and got to witness firsthand the initial stages of Russia’s drive into Ukraine.

The Russian attack into Ukraine was started by taking down ViaSat. They attempted to blind the Ukrainian people, Ukrainian command and control military forces and they attacked the ground stations. So that’s a real-world example of the way that kinetic and non-kinetic threats come together by, not only the space front but also on the cybersecurity front.

10:49 – 11:06

Why is it important for the Space Force to collaborate with its industry partners, through a framework like CMMC 2.0, to not only ensure appropriate cybersecurity protections are in place across the defense-industrial base, but also to adapt commercial cybersecurity solutions for the national security mission?

11:06 – 12:09

Yeah, me start with, if we don’t have this, then we can lose control, forfeit assets and experience manipulation by others, and that is across the space, government, the industry partners in particular. You must establish a comprehensive cybersecurity risk management plan. The CMMC 2.0 is a really great start of government and industry and academia, frankly, working together. 

It’s essential that the Space Force and all of our military forces continue to leverage what they see and can gain from commercial cybersecurity measures and practices and innovation. We have the best commercial capabilities available and the capabilities that we have available to us are targets for other nations to gain access to and to leverage themselves.

12:10 – 13:50

We must remember that we’re all part of one big team and our adversaries are looking for the weakest link and so there’s what drives our commitment. The impacts of what space provides not only what my dad referenced before of the impact to every one of the other services and all of the domains – when you start talking about precision, navigation and timing, these are the things that drive all of our military capabilities and robustness.

Scott, I think this is the importance of establishing a relationship. All too often we sometimes in DOD point to the commercial industry in Silicon Valley and say, ‘They’re so much faster and they’re doing it so much better, let’s just adopt everything that they’re doing.’

In their line of business, that may work for them. In reality, as you start raising those risk calculus conversations to the national security level and implementation across our Department of Defense, that’s where I think that it is – at times – a little bit of an apples and oranges comparison. That doesn’t mean that we cannot learn an enormous amount from Silicon Valley in their agility, in their practices, the way that they harness speed to implementation. Those are all great things. 

So what I would offer for the Space Force and learning from the commercial entity is the idea of a relationship, have the conversations, see what works and what doesn’t. But I think it’s a bridge too far to just say we’re going to scrap everything that we have done to maintain national security and implement a process without any further questions. It requires a dialogue.

13:51 – 14:06

Considering the depth and breadth of each of your experiences in cybersecurity and the service of our nation – how can Elara Nova facilitate the adoption of Zero-Trust principles for both the DOD and its industry partners?

14:07 – 14:47

The Elara Nova team has partners with years and years of unequaled experience across the space and cyberspace areas of operation. Chad and myself, we have years of experience working in space operations, network operations, cybersecurity, command and control, communications. Chad, having just short of 30 years. Myself, having over 35 years of military experience. So that’s 65 years experience total between just the two of us.

14:48 – 16:08

I would offer that there are two things that kind of come to mind as I look at the team of experts that Elara Nova has brought together and what we can offer by way of facilitating those stronger relationships and principles and partnerships moving forward. 

One of those is just taking advantage of all of that expertise that my dad referenced. That expertise will translate into identifying best practices across a number of different areas and domains and capabilities and organizations and units. And so you have the opportunity of leveraging all of those best practices that we’ve seen over years of our time together for the benefit of our nation. 

The second is really, I think, the power of Elara Nova and that’s in relationships and really the capability of being an integrator between our military, our commercial capabilities and academia as a whole. That ability to have established relationships over many, many years in uniform, out of uniform, at conferences, on real-world missions, the ability to leverage that relationship and be the integrator and facilitator of great talks is really the power of Elara Nova.

16:08 – 17:00

If you’re interested in learning more about the DOD’s approach to establishing and implementing a Zero-Trust Strategy across its services and defense-industrial base – visit our Insights page at www.elaranova.com.  

This has been an episode of The Elara Edge: Expert Insights on Space Security. As a global consultancy and professional services firm focused on helping businesses and government agencies maximize the strategic advantages of the space domain, Elara Nova is your source for expertise and guidance in space security.

If you liked what you heard today, please subscribe to our channel and leave us a rating. This episode was edited and produced by Regia Multimedia Services. Music for this podcast was created by Patrick Watkins of PW Audio. I’m your host, Scott King, and join us next time at the Elara Edge.