7 October 2026

How might future C2 and counter-C2 systems affect strategic stability?

RAND Europe | Henri van Soest, Maria Chiara Aquilino, Scott Warnier, James Black

Emerging non-nuclear command and control (C2) technologies are accelerating military digitisation while introducing critical vulnerabilities that threaten global strategic stability. Rapid integration of artificial intelligence, advanced sensing, and commercial cloud infrastructure expands the cyber attack surface, heightening the risk of crisis miscalculation. Legacy military procurement systems and siloed data structures frequently impede the adoption of these modern capabilities.

Consequently, armed forces increasingly rely on civilian telecommunications networks, commercial satellites, and subsea cables beyond direct state control. This dependency complicates attribution and crisis management during multi-domain operations. Redundant systems can mitigate disruption. However, the opacity of automated decision-making tools and the vulnerability of retaliatory systems create dangerous incentives for pre-emptive strikes. To mitigate these escalation risks, the UK Foreign, Commonwealth and Development Office is exploring soft governance measures, including shared research, interoperability standards, and crisis-communication channels to build trust before technologies become entrenched.

Comment

The integration of commercial space architectures like SpaceX's Starlink into military command and control frameworks exposes a fundamental tension between operational resilience and strategic vulnerability. While distributed low-Earth orbit constellations offer unprecedented redundancy against conventional kinetic anti-satellite weapons, they simultaneously expand the digital attack surface. This reliance shifts the burden of cybersecurity to private corporate entities. Their commercial incentives may not align with national defence priorities during a crisis. Consequently, the integrity of tactical data feeds becomes contingent on the security protocols of non-state actors.

This vulnerability is particularly acute when commercial providers like SpaceX employ proprietary encryption standards that bypass standard military validation protocols. For instance, the integration of commercial off-the-shelf software into the US Army's Unified Network Plan creates blind spots where military cyber defenders cannot actively monitor or patch vulnerabilities. Without direct administrative access to these commercial cloud nodes, joint force commanders utilizing the US Army's Unified Network Plan risk operating on corrupted data streams during high-intensity electronic warfare environments.

Strategic Question for Discussion
If the US Army's Unified Network Plan increasingly relies on commercial space architectures like SpaceX's Starlink, how can military commanders verify the integrity of tactical data feeds without compromising the operational speed that these systems provide?
The trajectory indicates that resolving this tension requires a shift toward zero-trust network architectures that continuously validate data integrity at the tactical edge rather than relying on transport-layer security. My assessment is that military forces will likely adopt automated cryptographic verification protocols to isolate compromised commercial nodes without disrupting the broader command and control network. This approach would allow commanders to leverage commercial bandwidth while maintaining sovereign control over critical decision-making data.
Share your assessment in the comments below.
💬