In 2018, United States test teams evaluating weapon systems under development repeatedly uncovered mission-critical cyber vulnerabilities. In some cases, they gained control of systems using relatively simple techniques and operated largely undetected.
The platforms involved were not publicly identified, and the tests did not replicate every possible threat. The findings therefore do not demonstrate that an aircraft, warship, or military vehicle could easily be remotely hijacked under real-world operational conditions.
The findings expose a broader problem. Software is no longer confined to peripheral functions. It supports communications, sensors, targeting, maintenance and data exchanges between systems. The question is no longer only how to keep an attacker out. It is what the weapon system can still do when part of its digital architecture is compromised or unavailable.
From the United States to Japan: testing what still works under attack
The vulnerabilities uncovered during U.S. testing were not necessarily sophisticated. In one system, unencrypted internal communications allowed a low-privilege user to obtain an administrator’s credentials and use them to gain additional privileges. In another case, only one of 20 previously identified vulnerabilities had been fixed before a subsequent assessment. The test team was able to exploit the remaining weaknesses and take control of the system.
Detection was another problem. During one assessment, testers remained inside the system for several weeks without being detected, even though they made no particular effort to conceal their presence.
United States testing doctrine has since moved beyond simply finding vulnerabilities. Operational testing guidance published in February 2025 no longer focuses solely on identifying vulnerabilities. It defines cyber survivability around four capabilities: preventing an attack, limiting its effects, recovering from it, and adapting in order to preserve mission-essential functions.
Japan has framed the requirement even more explicitly around continuity of operation. The Acquisition, Technology and Logistics Agency is researching technologies for equipment systems operated by Japan’s Ministry of Defense and armed forces. The stated objective is to contain the spread of damage during a cyberattack while keeping the affected system operational.
This work is not new. A Japanese technology roadmap describes research underway since 2017 aimed at making maximum use of infrastructure that remains available after a system or network is damaged, allowing critical systems to continue operating. It specifically distinguishes between manual and automated measures for operational continuity.
The operational logic is straightforward: losing part of the digital system should not automatically mean losing the military function it supports.
KA-SAT: disrupting the system without attacking the weapon
The attack on the KA-SAT satellite network on February 24, 2022, illustrates another aspect of the problem: a military function can depend on equipment located far beyond the combat platform itself.
At around 3:00 a.m., Viasat detected significant malicious traffic originating from modems in Ukraine. Its investigation concluded that the attacker had exploited a misconfiguration in a remote-access device to enter a trusted management segment. The attacker then moved through the network until reaching the infrastructure used to manage customer terminals.
The attacker did not need to develop an exotic command for each modem. Once inside the management network, legitimate administrative commands were used to overwrite critical data stored in the devices’ memory. Tens of thousands of terminals were knocked off the network, forcing Viasat to ship tens of thousands of replacement modems.
Yet according to the operator, the KA-SAT satellite itself was not compromised. Neither was its satellite ground infrastructure.
That distinction is what makes KA-SAT relevant to weapon-system resilience: the attacker never had to compromise a weapon platform. The operational effect came through a digital service on which those users depended.
A military capability can therefore be disrupted without an attacker ever reaching the weapon’s onboard systems.
Iron Dome: survivability across an integrated architecture
This external dependence is particularly visible in air defense architectures.
Iron Dome is more than an interceptor. Its operation combines detection, battle management, launch, and interception. Recent developments are pushing this integration further.
In June 2026, the Israeli Ministry of Defense and Rafael completed a new series of Iron Dome tests against scenarios involving rockets, cruise missiles, and uncrewed systems. The upgrades incorporated operational lessons from the war and were also intended to improve the system’s ability to cope with large volumes of incoming threats.
More importantly, the trials included joint scenarios involving Iron Beam, the high-power laser system designed to complement Iron Dome. These scenarios were integrated through Iron Dome’s battle management center.
The architecture illustrates a basic cyber-resilience problem: the military effect depends on several components exchanging data and functioning together.
The survivability of an integrated capability therefore cannot be assessed solely by looking at the physical resilience of an interceptor or launcher. It also depends on whether the overall system can continue to detect, decide, and engage when some functions are degraded.
Weapon-system resilience extends into the supply chain
The digital boundary also extends into the industrial base that develops, upgrades and sustains the system.
Japan provides a useful example. Japanese companies manufacture and locally maintain components for some U.S.-acquired equipment, including the F-35 Lightning II. Japan also participates with the United States in the development and production of the Standard Missile 3, while working with the United Kingdom and Italy on the future fighter aircraft under the Global Combat Air Programme, an international future combat aircraft program.
Japan’s acquisition agency explicitly links this growing internationalization to the need for stronger industrial security against cyberattacks and foreign intelligence activities. Comparable levels of protection among partner nations become essential when classified information moves across international programs.
Japan has consequently consolidated its requirements in the Defense Industrial Security Manual, which is intended in part to harmonize the protection of information required for international defense cooperation.
The United Kingdom applies a similar approach to its suppliers. Its cybersecurity model sets requirements according to the level of contractual risk and provides for those requirements to flow down to relevant subcontractors.
This industrial dimension is particularly significant for multinational programs. A future combat aircraft may be physically assembled in one country while relying on software, components, technical data, and maintenance activities originating in several others. Cyber exposure therefore follows the software, technical data, components and maintenance activities across the supply chain.
Survivability now extends beyond the platform
These cases point to the same conclusion: cyber resilience does not stop at the platform boundary. A vulnerability may sit in onboard software, communications infrastructure, system-management tools or the industrial base that develops and sustains the weapon.
The objective is therefore not to assume that every compromise can be prevented. It is to stop a local failure from producing a disproportionate loss of military capability: contain the attack, isolate affected functions, preserve those that remain trusted and restore those that do not.
For highly digitized weapon systems, survivability is increasingly about continuity of military function. The decisive measure is not whether the system contains vulnerabilities, but what it can still detect, decide, transmit and engage when part of its digital environment is degraded.
Cyber survivability begins where protection fails: with the ability to keep performing the mission despite that degradation.