Clicky

Content gathering dust?

Put your content front and center with the industry leaders you care about.

New White House Funding Request Prioritizes Endpoint Security 

Become an Insider.

Get Modern Integrated Warfare news and updates in your inbox.

Get started by entering your email below.

Related Content

More Content

The way wars are fought is changing. Massive troop deployments have been superseded by a growing tech presence on the battlefield. From AI to the connected warfighter and autonomous and unmanned systems defending the national interest, how the Pentagon approaches warfighting and battlefield readiness is changing. Recently, on our Government Technology Insider community, we published an article from Brett Hansen, CEO of Cigent about this evolution and what this new era means for the recent defense spending request from the White House. Keep reading to learn more. 

In June, the White House requested $87.6B in supplemental funding to support the Defense Department, including $2.4B for drones and $5.1B for cybersecurity and autonomy. From AI to the connected warfighter to autonomous systems and unmanned vehicles across air, sea and land, thousands of new endpoints are entering the force, pushing more compute power to the edge and carrying sensitive intelligence into contested environments. Edge devices now sit at the center of how missions are planned and executed

But this investment leaves a critical gap: deploying more edge systems expands the attack surface and increases the risk that classified data will be exposed if an adversary gains control of a device. Through its Commercial Solutions for Classified program, the NSA has established requirements for protecting classified data on endpoints. These requirements combine hardware- and software-based encryption with strong authentication to preserve data confidentiality and integrity. Yet despite the mandate and the proven effectiveness of the approach, investment in protecting sensitive data at the endpoint still lacks urgency.  

Historically, tactical edge modernization focused on connectivity: moving data faster, sharing it across intelligence domains, and connecting sensors to shooters in contested environments. Those priorities remain vital to the Joint All-Domain Command and Control strategy. But the tactical edge is not only a networking challenge. It is also a data-at-rest (DAR) challenge, and that means moving beyond network-centric security to include device-level assurance. 

When we talk about data at rest, we are talking about information on devices that are disconnected, physically exposed, or deployed where recovery is impossible. As distributed mission architectures push more compute to the edge, more classified data lives outside protected boundaries. Drones, UxVs, deployable kits, vehicle systems, forward servers, mission workstations, removable storage and edge processors all carry sensitive mission data into contested, disconnected or hostile environments. A tank, rugged laptop, mobile phone or ISR node starts out connected to a controlled enterprise network, and traditional cybersecurity assumes the network stays in control. That assumption fails the moment communications are lost, or the device is powered off. Nor is the risk limited to overseas deployments. A laptop left in a hotel room or rental car during a training exercise or temporary duty assignment carries the same exposure as a device abandoned in theater. DAR protection has to occur on the device itself. 

The stakes are concrete. Mission plans, communication logs, authentication credentials, AI models, and the algorithms, software and firmware supporting autonomous capabilities could all be used by an adversary to understand U.S. military strategies and target our forces. 

Physical capture of devices by adversaries is no longer hypothetical. Over the past several years, up to 35 MQ-9 Reaper drones have been lost, including seven shot down over Yemen in the spring of 2025. During Operation Epic Fury against Iran, which began in February 2026, the U.S. lost 24 MQ-9, and Iranian officials claimed captured drones were handed to engineers for reverse-engineering. Just recently, Russia claimed it seized U.S. AI-powered drones. Every one of those airframes represents more than lost hardware. The technical data, mission applications and algorithms on board are what adversaries value most. And these are only the incidents we know about. 

The timing of the funding request underscores the urgency. It arrived alongside the White House’s National Security Presidential Memorandum NSPM-12, which raises the compliance and accountability bar government-wide just as the volume of classified data on edge devices reaches unprecedented levels. 

The government already has an approved path forward. Commercial Solutions for Classified (CSfC), an NSA program, governs how agencies protect classified national security systems using commercial hardware with a two-layered approach to encryption. For data-at-rest protection, devices need both an encrypted drive and pre-boot authentication. A common oversight made during requirements development and acquisition is purchasing a self-encrypting drive (SED), regardless of its certification, and assuming the SED alone provides protection. However, the term self-encrypting drive is somewhat misleading, without an authentication platform such as pre-boot authentication (PBA), the SED does not provide protection. Without PBA, all an attacker needs to do to access sensitive mission data is power on the device. 

Yet data-at-rest protection, specifically the inclusion of certified PBA, is too often left out of requirements until late in the acquisition process. It must be treated as a mission-critical requirement, built into acquisition, integration, and platform design decisions before they are finalized. Before procurement begins, program officers must answer critical operational risk questions: How sensitive is the data the system will hold? Who can access it? What assurance level does it require? And who owns the consequences if the system is compromised and the data exposed? When these questions are answered early, the people executing the mission can operate without fear of compromising our security posture. 

Investments in AI, autonomy, drones, CJADC2, cyber modernization and tactical edge infrastructure should include specific funding for data-at-rest protection across the edge systems that will carry the mission toward success. 

It is critical to prioritize funding for: 

  • Tactical edge devices and deployable systems
  • Forward servers and mission workstations 
  • Autonomous and unmanned platforms 
  • Vehicle-based compute and storage 
  • Disconnected and intermittently connected systems
  • Systems storing classified, controlled operational or mission-sensitive data 
  • Programs supporting CJADC2 and distributed command and control 

This is not an unsolved problem. NSA’s CSfC Data-at-Rest Capability Package is the government’s approved architecture for protecting classified data at rest using layered, independent encryption and pre-boot authentication. More devices will be lost or captured; that much is certain. What remains within our control is what those devices reveal when it happens. 

The Pentagon’s own funding priorities confirm that the edge is central to the future of warfare. The next step is ensuring the data at the edge remains protected when devices fall outside of friendly control. Data-at-rest protection belongs in every edge modernization program as a funded requirement. 

The author, Brett Hansen, is CEO of Cigent.