<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Topic:operational data &#8212; Global Security Review %</title>
	<atom:link href="https://globalsecurityreview.com/subject/operational-data/feed/" rel="self" type="application/rss+xml" />
	<link>https://globalsecurityreview.com/subject/operational-data/</link>
	<description>A division of the National Institute for Deterrence Studies (NIDS)</description>
	<lastBuildDate>Mon, 28 Sep 2026 10:49:27 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.6</generator>

<image>
	<url>https://globalsecurityreview.com/wp-content/uploads/2026/05/cropped-GSR-Chrome-Logo-2026-1-32x32.png</url>
	<title>Topic:operational data &#8212; Global Security Review %</title>
	<link>https://globalsecurityreview.com/subject/operational-data/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Resilience Never Activated, Deters No One</title>
		<link>https://globalsecurityreview.com/resilience-never-activated-deters-no-one/</link>
					<comments>https://globalsecurityreview.com/resilience-never-activated-deters-no-one/#respond</comments>
		
		<dc:creator><![CDATA[Burak Oktenli]]></dc:creator>
		<pubDate>Mon, 28 Sep 2026 12:14:11 +0000</pubDate>
				<category><![CDATA[Archive]]></category>
		<category><![CDATA[Defense & Security]]></category>
		<category><![CDATA[Deterrence & Foreign Policy]]></category>
		<category><![CDATA[Strategic Adversaries]]></category>
		<category><![CDATA[adversary]]></category>
		<category><![CDATA[AI-enabled systems]]></category>
		<category><![CDATA[assurance claim]]></category>
		<category><![CDATA[autonomous systems]]></category>
		<category><![CDATA[BEA]]></category>
		<category><![CDATA[Bureau of Economic Analysis]]></category>
		<category><![CDATA[cascading failures]]></category>
		<category><![CDATA[CISA]]></category>
		<category><![CDATA[continuity costs]]></category>
		<category><![CDATA[continuity plan]]></category>
		<category><![CDATA[continuity planning]]></category>
		<category><![CDATA[continuity target]]></category>
		<category><![CDATA[critical infrastructure]]></category>
		<category><![CDATA[Critical Infrastructure Security and Resilience Agency]]></category>
		<category><![CDATA[cross-sector scenarios]]></category>
		<category><![CDATA[denial]]></category>
		<category><![CDATA[dependency structure]]></category>
		<category><![CDATA[Deterrence]]></category>
		<category><![CDATA[disruption]]></category>
		<category><![CDATA[dynamic resilience]]></category>
		<category><![CDATA[electric power]]></category>
		<category><![CDATA[empirical testing]]></category>
		<category><![CDATA[Federal Continuity Directive 2]]></category>
		<category><![CDATA[Federal Emergency Management Agency]]></category>
		<category><![CDATA[FEMA]]></category>
		<category><![CDATA[governance]]></category>
		<category><![CDATA[inoperability]]></category>
		<category><![CDATA[input-output accounts]]></category>
		<category><![CDATA[interconnected systems]]></category>
		<category><![CDATA[interdependence model]]></category>
		<category><![CDATA[mission essential functions]]></category>
		<category><![CDATA[National Critical Functions]]></category>
		<category><![CDATA[National Institute of Standards and Technology]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[NIST SP 800-82]]></category>
		<category><![CDATA[operational data]]></category>
		<category><![CDATA[operational parameters]]></category>
		<category><![CDATA[recovery rates]]></category>
		<category><![CDATA[service floors]]></category>
		<category><![CDATA[systemic damage]]></category>
		<category><![CDATA[systemic loss]]></category>
		<category><![CDATA[telecommunications]]></category>
		<guid isPermaLink="false">https://globalsecurityreview.com/?p=33083</guid>

					<description><![CDATA[<p>Published: September 28, 2026 Deterrence by denial rests on a practical promise. An attack on a state’s infrastructure will not produce the effect an adversary expects. Resilience contributes to that promise only when continuity measures can reduce losses under the disruptions an adversary can impose. A continuity plan is the plan an agency or operator [&#8230;]</p>
<p><a href="https://globalsecurityreview.com/resilience-never-activated-deters-no-one/">Resilience Never Activated, Deters No One</a> was originally published on <a href="https://globalsecurityreview.com">Global Security Review</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Published: September 28, 2026</em></p>
<p>Deterrence by denial rests on a practical promise. An attack on a state’s infrastructure will not produce the effect an adversary expects. Resilience contributes to that promise only when continuity measures can reduce losses under the disruptions an adversary can impose.</p>
<p>A <em>continuity plan</em> is the plan an agency or operator uses to preserve or restore functions that must continue during a disruption. For federal agencies, The Federal Emergency Management Agency (FEMA) document <a href="https://www.fema.gov/sites/default/files/2020-07/Federal_Continuity_Directive-2_June132017.pdf">Federal Continuity Directive 2</a> formalizes the identification and business-process analysis of mission essential functions. An <em>interdependence model</em> describes how the loss of capability in one sector propagates to sectors that depend on it. The National Institute of Standards and Technology (NIST) document <a href="https://csrc.nist.gov/pubs/sp/800/82/r3/final">NIST SP 800-82</a> describes U.S. critical infrastructure as highly interconnected and mutually dependent, warning that failures can cascade across systems. This is referred to as a <em>continuity target, </em>which is one that must be kept above a specified service level or restored within a specified time. It is not a formal FEMA term. The distinction matters because identifying an essential function verses proof that a target reduces systemic damage, otherwise known as a continuity target, are different tasks.</p>
<p><strong>An illustrative Example: The U.S. Economy</strong></p>
<p>Consider an illustrative cascade model using the U.S. economy. The model receives a service-integrity failure: a sector remains physically online, but the output other sectors depend upon can no longer be trusted. The disturbance runs for six time increments using stylized dependency coefficients. Inoperability represents the fraction of useful service loss, while total systemic loss is a cumulative inoperability across all modeled sectors.</p>
<p>If telecommunications is the origin, the struck sector reaches 63 percent inoperability. Yet 71 percent of cumulative systemic loss occurs outside telecommunications, in sectors that depend on it. Much of the damage from a sector failure may therefore emerge elsewhere. Now add a continuity target. Suppose each sector can cap its own inoperability at 30 percent. Applying that target to telecommunications reduces total systemic loss by 44 percent. Applying the same target to any downstream sector does not reduce the total systemic loss.</p>
<p>This is the point. Downstream sectors never lose more than 6 to 23 percent of their service, so their 30 percent continuity targets are never reached. In operations-research terms, the constraint never binds. An organization can spend substantial resources maintaining a target that appears prudent on paper but changes nothing in the scenario being tested.</p>
<p>Now, lower the modeled target to 5 percent and some downstream measures begin to matter. The best produces a 14 percent reduction in systemic loss. The specific percentages are illustrative. The structural result matters more because a continuity target can be demanding in isolation, yet irrelevant once cross-sector propagation is considered.</p>
<p>Upon further analysis, if one changes the origin of the failure, the result changes again. When the same disturbance begins in electric power rather than telecommunications, total systemic loss rises by 15</p>
<p>percent even though the originating sector peaks lower, because damage spreads more evenly. The ranking of which continuity measures provide the greatest reduction also changes.</p>
<p>A continuity target therefore has no deterrent meaning in the abstract. Its value depends on the disruption&#8217;s origin, dependency structure, severity, and duration.</p>
<p><strong>From Resilience to Deterrence</strong></p>
<p>Natalie Treloar and Jean-Claude Meledje recently <a href="https://globalsecurityreview.com/the-impossibility-of-strategic-stability-in-a-multipolar-era-from-brittle-walls-to-dynamic-resilience/">argued</a> that dynamic resilience should replace the pursuit of brittle stability. The argument is compelling, but resilience becomes deterrence by denial only when it measurably reduces the damage an attacker expects to inflict. A declared capacity to endure is not the same as a tested capacity that changes an attacker&#8217;s expected payoff.</p>
<p>An adversary also sees infrastructure differently from an individual operator. An operator plans from inside its own organization; an adversary selecting an origin point can evaluate the network as a whole. Public data already make part of that assessment possible. The <a href="https://www.bea.gov/data/industries/input-output-accounts-data">Bureau of Economic Analysis (BEA) publishes input-output accounts</a> showing direct and indirect production relationships among U.S. industries. These accounts do not reveal operational vulnerabilities by themselves, but they provide a public starting map of economic interdependence.</p>
<p>An adversary does not need access to every continuity plan to exploit that asymmetry. It needs to identify nodes with disproportionate downstream effects and disruptions likely to be long-lived. Sophisticated adversaries can estimate dependency structures and test alternative origins even when detailed performance targets remain protected.</p>
<p>Also, duration matters as much as depth. In the illustrative model, the health sector ranks only fifth by peak inoperability but recovers last because it combines heavy dependence on other sectors with slow restoration. A triage scheme based only on immediate loss would therefore underrate a function whose prolonged degradation could create greater coercive leverage.</p>
<p><strong>What Should Change</strong></p>
<p>Continuity targets should be tested against cross-sector scenarios before being treated as evidence of denial. A useful target should answer four questions:</p>
<ol>
<li>From which disruption origins was it tested?</li>
<li>Does it bind to relevant sectors?</li>
<li>How much cumulative system loss does it avert?</li>
<li>How much does it shorten degradation or recovery?</li>
</ol>
<p>The Critical Infrastructure Security and Resilience Agency (CISA) already provides a cross-sector framework through its <a href="https://www.cisa.gov/national-critical-functions">National Critical Functions</a> work, while <a href="https://csrc.nist.gov/pubs/sp/800/82/r3/final">NIST guidance</a> recognizes physical and logical interdependencies among operational systems. CISA could sponsor a protected pilot combining public BEA input-output structures with nonpublic operational data on recovery rates, service floors, and continuity costs.</p>
<p>The purpose would not be to publish exploitable thresholds. Detailed targets can remain protected. The public result should instead be an assurance claim that “continuity measures were tested against multiple failure origins, became binding where expected, and produced measurable reductions in cumulative loss and recovery time.”</p>
<p>None of the numerical results above describes the real U.S. economy. The coefficients are illustrative, the disturbance is simplified, and detection delay sits outside the model. That is precisely why the next step should be empirical rather than rhetorical. The public economic accounts exist. Sector operators hold the missing operational parameters, and the question is testable.</p>
<p>Dynamic resilience is a stronger deterrent concept than a promise to return to yesterday&#8217;s equilibrium. But resilience that never activates to counter the damage an adversary is positioned to inflict does not deny anything. It documents preparation without demonstrating effect.</p>
<p>The standard should therefore be stricter and more useful. Do not just ask whether an essential function has a continuity plan. Ask whether its performance target becomes binding in the scenarios that matter and how much adversary-imposed loss it prevents.</p>
<p><em>Burak Oktenli is an independent researcher conducting work on the governance of authority in autonomous and AI-enabled systems. His writing has appeared in Dark Reading, RealClearDefense, the Modern War Institute at West Point, and the Lieber Institute&#8217;s Articles of War. Views expressed in this article are the author&#8217;s own.</em></p>
<p><a href="http://globalsecurityreview.com/wp-content/uploads/2026/09/Resilience-Never-Activated-Deters-No-One.pdf"><img decoding="async" class="alignnone wp-image-32906 size-full" src="http://globalsecurityreview.com/wp-content/uploads/2026/07/@-Download-Button-2026.png" alt="" width="250" height="80" /></a></p>
<p><a href="https://globalsecurityreview.com/resilience-never-activated-deters-no-one/">Resilience Never Activated, Deters No One</a> was originally published on <a href="https://globalsecurityreview.com">Global Security Review</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://globalsecurityreview.com/resilience-never-activated-deters-no-one/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
