Story
October 06, 2026

Protecting military systems where critical information resides requires extending cybersecurity beyond traditional network defense toward architectures designed to preserve classified data after physical compromise. The U.S. National Security Agency (NSA) requirement for two independent encryption layers, together with specific Commercial NSA cryptographic standards, gives engineers concrete design criteria rather than conceptual security objectives. Layered full-disk encryption, independent preboot authentication, and architectures aligned with Commercial Solutions for Classified (CSfC) data-at-rest guidance can protect information even when the network disappears and the hardware itself is lost.
Artificial intelligence (AI), autonomous operations, and distributed command-and-control have transformed military vehicles into mobile computing platforms that store and process unprecedented volumes of sensitive operational data. Yet cybersecurity investment has traditionally concentrated on protecting networks and communications rather than information residing on battlefield endpoints after physical loss or capture.
For modern tactical systems, that distinction is increasingly important. A crewed combat vehicle, unmanned aircraft, autonomous maritime vessel, tactical server, or mobile command post may continue to hold mission data long after it is disconnected from friendly networks. Once that platform is captured, the security problem changes from preventing network intrusion to preventing offline access to the data itself.
Physical capture is an engineering given
Historically, cybersecurity architectures implicitly assumed endpoints would remain under friendly control throughout their operational life cycle. Modern military operations invalidate that assumption: Tactical vehicles become disabled, aircraft are shot down, autonomous systems run out of fuel, command posts are overrun, and equipment is abandoned during maneuver.
As operations move deeper into anti-access/area-denial environments, recovery cannot always be assumed. For autonomous and attritable systems in particular, physical loss should increasingly be treated as a design condition rather than an exceptional event.
The engineering question therefore shifts from whether a platform may be captured and over to what information remains accessible once capture occurs. The confidentiality of mission data, software, and cryptographic material can be as consequential as preserving the physical platform itself. (Table 1.)

[Table 1 ǀ An illustration of how the security model changes when physical possession transfers to an adversary.]
The hidden value resides in the data
The replacement cost of military hardware is relatively straightforward to calculate; quantifying the operational value of the information stored within it is harder because seemingly routine datasets can be combined to produce actionable intelligence.
Today’s vehicle systems may contain mission plans, ISR [intelligence, surveillance, and reconnaissance] collections, navigation histories, terrain databases, sensor calibration parameters, electronic-warfare libraries, software images, firmware, cryptographic credentials, maintenance records, logistics information, and AI models. Collectively, these datasets can expose operational concepts, deployment patterns, command relationships, force disposition, software architectures, pattern of life and coalition interoperability procedures.
AI increases that exposure. Models deployed to tactical platforms can embody years of algorithm development, training, validation, operational tuning, and testing. Associated sensor-fusion methods, autonomy software, and inference techniques may provide an adversary opportunities to reverse-engineer capabilities or develop countermeasures. The result is a different definition of platform survivability: Protecting the vehicle is no longer sufficient if losing the vehicle also exposes the information required to understand how the broader force operates.
Network security stops at the network boundary
Enterprise cybersecurity has invested heavily in zero-trust architecture, endpoint detection and response, identity management, behavioral analytics, continuous monitoring, and software-defined networking. Those capabilities are effective when connectivity to enterprise infrastructure is available.
Battlefield operations present a different operating model, however. Tactical vehicles may operate under emissions control, satellite connectivity may be unavailable, electronic attack may eliminate communications, and autonomous systems may remain disconnected for extended periods.
Once physical possession transfers to an adversary, cloud authentication cannot stop offline forensic analysis, which means that remote-management systems cannot recover inaccessible hardware and endpoint monitoring cannot report compromise. The controls that still matter are the ones engineered into the endpoint: encryption, authentication, key protection, secure-boot processes, and mechanisms that remain effective without a network connection.
Applying NSA CSfC guidance
The National Security Agency (NSA) Commercial Solutions for Classified (CSfC) Data-at-Rest (DAR) Capability Package provides a useful quantitative baseline. NSA requires that CSfC DAR-compliant solutions use two independent layers of encryption to protect stored information while an end-user device is powered off or remains unauthenticated. (The current DAR Capability Package is Version 5.1.0, approved in March 2026 and available here.)
The cryptographic requirements are also specific: CSfC guidance identifies AES-256 for confidentiality and CNSA algorithms, including RSA-3072 or ECDSA P-384 for authentication and SHA-384 for integrity. NSA states that properly configured CSfC solutions using these controls can protect National Security Systems information up to the top-secret level.
The following table summarizes several measurable requirements engineers can use when evaluating a tactical data at rest architecture. (Table 2.)

[Table 2 ǀ Selected quantitative characteristics of NSA CSfC architectures. Source: NSA CSfC DAR Capability Package v5.1.0, March 2026, and NSA CSfC FAQ.]
The importance of two layers is not that AES itself is considered inadequate. Layering addresses implementation risk: if misconfiguration, operator error, or an implementation vulnerability compromises one component, an independent second layer remains between the adversary and the classified data.
These principles extend beyond laptops or conventional workstations. Mission computers, vehicle servers, ruggedized storage modules, edge AI processors, ISR recording systems, autonomous vehicle storage, portable solid-state drives, maintenance systems, and mission-planning workstations all represent repositories of operationally significant information.
Engineering the entire tactical data ecosystem
Modern missions depend upon interconnected ecosystems rather than individual platforms. Examples include tactical vehicles that exchange data with planning workstations before deployment; portable storage that distributes intelligence updates, terrain databases, AI models, and software revisions’ maintenance systems that collect diagnostics and operational histories; and edge servers that synchronize information across distributed formations.
Protecting only the primary vehicle, therefore, leaves substantial attack surfaces elsewhere. A captured maintenance workstation or portable storage device may expose many of the same mission datasets as the platform it supports.
Designing for data survivability
Traditional survivability emphasizes preserving platform functionality under hostile conditions. Future systems must also preserve information confidentiality after platform loss.
Data survivability should become a measurable systems-engineering parameter. Design and development must ensure data protection that includes authentication assurance, cryptographic independence, secure key life cycle management, sanitization effectiveness, and resistance to physical compromise. Devices without these technologies risk exposure of sensitive data upon capture by adversaries.
Considering these requirements during architecture development can also reduce the complexity of later integration. Near the end of an acquisition life cycle, adding independent encryption and authentication may require changes to storage interfaces, boot sequences, trusted execution environments, and mission software that have already been finalized.
AI is changing where critical military information resides. More commonly, operational knowledge increasingly lives within vehicles, autonomous systems, tactical computers, and edge-processing platforms operating at the front lines.
Protecting those systems requires extending cybersecurity beyond traditional network defense toward architectures designed to preserve classified data after physical compromise. NSA’s requirement for two independent encryption layers, together with specific CNSA cryptographic standards, provides engineers with concrete design criteria rather than a conceptual security objective. Layered full-disk encryption, independent pre-boot authentication, and architectures aligned with CSfC DAR guidance can protect information even when the network disappears and the hardware itself is lost.
Organizations developing tactical storage architectures are focused on applying these principles to military endpoints operating beyond traditional enterprise environments. As battlefield computing continues moving toward the edge, data survivability should be treated as a fundamental component of platform survivability itself.
Conner Crisafulli is a solutions engineer and cybersecurity professional at Cigent. Before joining Cigent, Conner served six years as a U.S. Air Force combat controller, where he specialized in high-stakes mission planning, communications systems, and joint operations coordination/execution. At Cigent, he focuses on practical applications of self-encrypting drives (SEDs), pre-boot authentication (PBA), and various CSfC [commercial solutions for classified] technologies to safeguard sensitive data.
Cigent

