Pentagon Creates New Subcommand to Defend U.S. Infrastructure From State-Sponsored Cyber Threats
The Department of Defense has established the Defense Cyber Defense Command (DCDC) as a sub-unified command under U.S. Cyber Command to centralize control of military cyber defenses and protect critical infrastructure. Officials say the move responds to mounting evidence that state-backed actors, particularly from China, have been pre-positioning inside U.S. systems and could launch disruptive or destructive attacks during a crisis.
By Blake Marriott
921 views
The Pentagon has taken a major step to centralize responsibility for defending U.S. networks and critical infrastructure by elevating the Defense Cyber Defense Command (DCDC) as its own sub-unified command under U.S. Cyber Command (CYBERCOM). The reorganization, made official in May 2025 and codified in the 2025 National Defense Authorization Act, is intended to provide clearer command-and-control authority and a focused mission: protect the United States from digital threats that could undermine national security.
DCDC — formerly known as the Joint Force Headquarters-Department of Defense Information Network — now has a mandate that extends to the defense of power grids, water systems and transportation networks, officials say. Col. Adolph Rodriguez, director of Defense Critical Infrastructure at DCDC, described the organizational challenge in an interview at the TechNet Cyber conference, saying, “I’m currently assigned there to build out a … framework and command and control footprint, because the most important thing, besides understanding the technology, the people, the processes, is who’s in control, who’s executing, what’s the common rail amongst all the authorizations that we have between CISA (Cybersecurity and Infrastructure Security Agency), FBI, Coast Guard, Department of War writ large.”
The Pentagon’s move comes amid repeated official warnings that state-sponsored cyber actors — notably those linked to the People’s Republic of China — have sought to establish footholds inside U.S. information technology networks. A CISA report from Feb. 7, 2024, warned that PRC state-sponsored actors were “seeking to pre-position themselves on IT networks for disruptive or destructive cyberattacks against U.S. critical infrastructure in the event of a major crisis or conflict with the United States.” The National Security Agency has also cited specific Chinese-sponsored groups, including Volt Typhoon, as compromising infrastructure systems and positioning to strike.
Advocates for the new command argue that unified military leadership is necessary to plan and execute resilient cyber campaigns before, during and after attacks. “Given the dynamic nature of cyber capabilities, fast and continuous, once again addressing these questions is welcome, absolutely essential, and will not be [the] last time it happens,” said Steven Bucci, a Heritage Foundation visiting fellow and former Pentagon official. Bucci emphasized that complacency would be dangerous: “If we get to the point that we think we have ‘solved’ this challenge, we will be [in] grave danger. So, are we prepared? Yes. Do we need to be constantly endeavoring to become more prepared? Absolutely.”
Officials at DCDC are also exploring how existing authorities can be linked into enduring campaign plans for cyber defense. Rodriguez suggested developing an enduring cyber campaign plan that leverages NORTHCOM authorities with Cyber Command’s authorities and organizes sectoral defenses in a way “very similar to FEMA” so that training, assessments and infrastructure protections become routine and resilient.
Not all experts agree that the new structure is the optimal solution. Piero Tozzi, senior director of China policy at the America First Policy Institute, argued that the People’s Liberation Army treats infrastructure and civilian systems as an “asymmetric battlespace” and that military commands such as NORTHCOM and CYBERCOM, rather than civilian agencies like CISA, should be the primary leads. “Infrastructure, cyberspace, and civilian systems are treated by the PLA as an asymmetric battlespace that can escalate up to and including kinetic warfare. As these are war plans, NorthCom and Cybercommand should be the lead—not CISA,” Tozzi said, adding concerns about reliance on foreign-origin technology that has created long-standing structural vulnerabilities.
The Pentagon and CYBERCOM did not immediately respond to requests for comment about the DCDC reorganization, and the White House referred inquiries to the Department of Defense. Breaking Defense has reported on DCDC leaders’ focus on operational questions such as continuity of operations “before, during, and after the attack,” and DCDC officials are reportedly working to define the common lines of authority that will govern interactions with other federal agencies and private-sector owners of critical infrastructure.
The heightened attention to cyber defense underscores the broader strategic risks posed by cyber operations. The NSA has warned that some cyber actors have been living inside targeted systems for years, waiting for the opportunity to cause disruptive or destructive effects. Bucci warned of cascading economic consequences from large-scale attacks, saying, “Such an attack could also trigger disruptions of the wider global economy that would ultimately do irreparable damage to China given our [economic] interconnectivity.” As adversaries continue to probe and occasionally outpace U.S. defenses, Pentagon officials and outside experts agree that the United States must keep adapting its structures and capabilities to stay ahead in the digital battlespace.
All content created by the Daily Caller News Foundation, an independent and nonpartisan newswire service, is available without charge to any legitimate news publisher that can provide a large audience. All republished articles must include our logo, our reporter’s byline and their DCNF affiliation. For any questions about our guidelines or partnering with us, please contact licensing@dailycallernewsfoundation.org.