Skip to content
SPECIAL

THREATS TO CRITICAL INFRASTRUCTURE IN IRAN CONFLICT

READ MORE

Army says it’s mitigated ‘critical’ cybersecurity deficiencies in early NGC2 prototype

A U.S. Army soldier assigned to 1st Armored Division inspects an antenna as he prepares for Project Convergence - Capstone 5 (PC-C5) at Fort Irwin, Calif., in early March 2025. (U.S. Army photo by Sgt. Kelvin Johnson)

By Mark Pomerleau

The US Army says it has mitigated several cybersecurity risks discovered in an early iteration of its nascent Next Generation Command and Control (NGC2) platform, as detailed in a blunt memo obtained by Breaking Defense.

Penned on Sept. 5 and signed by Army Chief Information Office Chief Technology Officer Gabriele Chiulli, the document said the NGC2 platform “in its current state, exhibits critical deficiencies in fundamental security controls, processes, and governance.”

“These issues collectively create a significant risk to data, mission operations, and personnel by rendering the system vulnerable to insider threats, external attacks, and data spillage,” the document said. Chiulli wrote at the time that the Army “lack[s] the visibility and controls necessary to ensure the security and integrity of the platform. There seems to be a rush to get capabilities into the system without actual oversight or process to do it, putting greater risk as this system further increases this risk.”

Read more at Breaking Defense

Click to listen highlighted text!