Modern cyber defense: uniting expertise to strengthen operational capability
Modern military operations rely on a digital infrastructure that has become almost invisible. Behind a ship, an aircraft, a vehicle, a radar system, or a deployed operation lie networks, communications, command and control systems, sensors, software, digital identities, and immense volumes of data. Operational capability now depends directly on the ability to protect this digital environment, to keep it available, and to continue using it when conditions deteriorate or when an adversary is specifically seeking to disrupt it.
This reality explains the growing importance placed on cyber forces and on their ability to work with other disciplines and other organizations. At RIMPAC 2026, more than 30 cybersecurity specialists from Canada, Australia, the United States, Germany, the Philippines, and the Republic of Korea worked together in a continuous cyber training environment. The simulated scenarios allowed them to develop their technical skills, but also to strengthen the communication, trust, and interoperability required for future multinational operations.
The exercise illustrates a far deeper transformation of cyber defense. A defense organization's capability obviously rests on the skills of its own teams, but it also depends on its ability to quickly bring together different areas of expertise, to make them collaborate, and to turn their knowledge into operational capability. In an environment where infrastructures, threats, and technologies evolve continuously, knowing how to mobilize the right ecosystem becomes a strategic skill in its own right.
Cyber is now deeply integrated into military capabilities. Satellite communications are digital, command and control systems depend on software and data, platforms use sensors and networks, and air, naval, land, and space operations rely on information whose integrity and availability can directly influence the mission. In Canada, this institutional shift is visible in the mandate of the Canadian Armed Forces Cyber Command, which brings together cyber operations, joint electronic warfare, and signals intelligence, and supports operations across the various military domains.
This convergence changes the way we think about cybersecurity. Protecting a military organization means protecting a system of systems in which networks, platforms, applications, identities, data, communications, cloud environments, edge infrastructures, and operational equipment become interdependent. The robustness of any one component taken in isolation therefore never guarantees the resilience of the whole. Interactions, dependencies, and the paths that allow a disruption to spread become as important as the individual security of the technologies.
In this environment, internal teams remain at the heart of defense capability. Military personnel, engineers, analysts, cyber operators, architects, and technology specialists know the missions, the procedures, the constraints, and the platforms they have to support. This accumulated operational knowledge is essential to understanding what must be protected, why it must be protected, and what consequences a technology decision can have on the mission. External expertise takes on its value when it complements that knowledge with specialized skills, experience drawn from other environments, or additional analysis and architecture capacity.
It is with this logic in mind that Quantum Beyond shapes its role alongside defense organizations. Our experts can work side by side with cyber, technology, and operational teams when a project calls for complementary expertise in security architecture, identity management, Zero Trust, cyber resilience, sovereign artificial intelligence, governance, cryptography, or post-quantum readiness. Lasting capability remains within the organization; specialized intervention helps to broaden it, to test it, and to strengthen it.
Interoperability becomes particularly important in this model. Contemporary operations are frequently joint, inter-organizational, and multinational. Systems belonging to different organizations must exchange information while maintaining high levels of control, security, and traceability. Identities must be recognized, permissions kept under control, and data made accessible to authorized people and systems without needlessly widening the trust surface. Canadian Defence's 2026-2027 departmental plan reflects this direction, notably by providing for a sovereign open source ecosystem aligned with allied standards, the development of interoperability with NATO and Five Eyes partners, as well as digital infrastructures grounded in Zero Trust principles.
Interoperability must therefore be considered from the architecture stage onward. An extremely well protected infrastructure that becomes unable to communicate effectively with the systems the mission requires can itself create an operational constraint. The real challenge is to enable the required interactions while retaining sufficiently precise control over identities, data, and permissions. In this context, Zero Trust becomes as much an architecture enabling controlled collaboration as a cybersecurity mechanism. A recognized identity does not automatically receive general trust: each access can be evaluated based on the identity, the context, the system being requested, the permissions granted, and operational conditions.
This logic becomes particularly important when an environment brings together several organizations. A legitimate partner may need to access a very specific portion of a system without having access to the entire infrastructure. An authenticated device may be authorized to communicate with only a few services. An application may use certain data without needing access to its full source. Least privilege thus makes it possible to collaborate without turning a trust relationship required by the mission into generalized access.
Added to this evolution of architectures is a transformation that must be prepared over a much longer horizon: the cryptographic transition. Defense systems often have considerably longer life cycles than commercial technologies. Platforms, embedded equipment, and infrastructures can remain in service for several decades, while the cryptographic mechanisms they use may have to evolve several times over their existence. The problem is therefore not only knowing which algorithms are currently in use. It requires understanding the systems that depend on them, the libraries that implement them, the certificates that use them, the vendors that control them, and the equipment whose upgrade could become complex.
The Harvest Now, Decrypt Later risk adds a temporal dimension to this issue. Information encrypted today can be intercepted and retained in the hope that future capabilities will make it possible to decrypt it. When the sensitivity of a piece of information must be preserved for several years, its confidentiality horizon therefore becomes an element of the security decision. Post-quantum readiness must make it possible to know the cryptographic assets, their dependencies, and their exposure in order to prioritize transitions according to actual risk rather than waiting for a migration to become urgent.
This line of thinking leads directly to crypto-agility. Algorithms will continue to evolve, implementations will have to be corrected, new vulnerabilities will appear, and different requirements may be imposed depending on systems, classifications, and partners. An architecture whose cryptography is deeply buried in equipment that is difficult to modify accumulates a technology debt that may one day become an operational constraint. Crypto-agility therefore seeks to preserve the ability to evolve certain security mechanisms without having to entirely rebuild the systems that depend on them. In an environment where the lifespan of platforms can far exceed that of the security technologies used when they were designed, this capability becomes strategic.
Artificial intelligence now adds another dimension to this transformation. In 2026-2027, Canadian Defence plans to continue implementing its AI strategy, to develop secure and standardized environments, to put risk management frameworks in place, and to support the development of trustworthy and sovereign AI solutions. Its plan also provides for the use of integrated infrastructures combining AI, edge, and Zero Trust, among others.
The value of AI for cyber defense extends well beyond conversational models. It can help analyze large volumes of information, correlate certain signals, detect anomalies, accelerate incident analysis, and support decision-making. As AI agents gain the ability to consult document repositories, use APIs, interact with various systems, or trigger actions, however, they become a new population of operational identities. Each one must have a clear identity, permissions suited to its role, and sufficient traceability to understand the actions carried out. These accesses must be able to evolve and be revoked quickly when the context changes.
This governance becomes even more important when artificial intelligence interacts with equipment, autonomous systems, or edge infrastructures. A digital decision can then produce an operational consequence. Military AI must therefore be designed jointly with identity, cybersecurity, sovereignty, governance, and the levels of authority granted to systems. The ability to use AI cannot be separated from the ability to determine what it can consult, what it can decide, the actions it can trigger, and the circumstances in which human intervention remains necessary.
Digital sovereignty connects directly to this pursuit of control. For a defense organization, it cannot be limited to the location of data or the nationality of a vendor. An infrastructure can be hosted nationally while depending on components, technologies, or vendors that are extremely difficult to replace. Operational freedom therefore also depends on the options the architecture preserves: the ability to change vendors, to replace a cryptographic mechanism, to move a workload, to operate in a disconnected environment, to maintain the necessary skills, and to have documentation sufficient to evolve the systems.
This conception of sovereignty takes on its full meaning when infrastructures must remain operational for several decades. It is impossible to predict with precision the vendors, technologies, standards, and threats that will exist at that horizon. An architecture can, however, be designed to retain an adaptive capability. Modularity, interoperability, knowledge of dependencies, reversibility, and mastery of knowledge then become strategic properties. In concrete terms, sovereignty translates into the ability to choose, to adapt, and to continue operating when the technological or geopolitical environment changes.
Resilience is the operational extension of this logic. In a conventional commercial infrastructure, a major outage can lead to a service interruption. In a defense environment, one must also consider that an adversary is deliberately seeking to cause that interruption. Resilience must therefore be built into the architecture. Systems must be able to operate with reduced connectivity, isolate certain compromised components, maintain essential functions, recover effectively, and retain enough information to understand the incident. Distributed and edge architectures can play an important role by allowing certain capabilities to keep functioning locally when central communications are degraded.
Cyber defense therefore no longer consists solely of preventing an intrusion. It must also help preserve the mission once a defense has failed. This perspective changes the nature of the questions put to architects and security teams. What happens if this component is compromised? How far can the incident spread? Which functions can keep operating? Which dependency would prevent a rapid recovery? What knowledge is missing to rebuild or reconfigure the environment? The ability to contain, withstand, recover, and adapt becomes as important as the ability to protect.
It is also from this perspective that an external specialized team can bring a useful point of view. Internal teams have a deep knowledge of their environment, but every organization develops over time certain assumptions that become so familiar that they are less often questioned. Complementary expertise can examine trust relationships, dependencies, permissions, compromise scenarios, and recovery options from a different angle. It can help test assumptions, simulate certain scenarios, and identify the places where an improvement to the architecture could increase resilience. This contribution adds a perspective to internal expertise and gives it new ways to put its own systems to the test.
The experience of multinational exercises ultimately shows that this logic extends beyond any individual company or vendor. At RIMPAC 2026, specialists from six countries did not merely exercise their technical skills: they worked on the ability to collaborate, communicate, and operate together. Other Canadian initiatives in 2026 point in the same direction, notably exercises with Five Eyes partners and cyber training and cooperation activities in the Indo-Pacific.
Cyber defense thus becomes a collective capability. Digital environments evolve too quickly and bring together too many disciplines for a single team to permanently maintain leading-edge expertise in each of them. Strategic capability also lies in the ecosystem the organization can mobilize: allied forces, internal teams, research centers, universities, industrial partners, and specialized technology companies. The quality of that ecosystem then depends on its ability to turn a diversity of expertise into coherent architectures, procedures, and decisions.
The digital transformation of defense goes well beyond the modernization of IT systems. It directly affects operational readiness, interoperability with allies, data protection, artificial intelligence, edge infrastructures, digital identities, cryptography, and the ability to continue a mission in a contested environment. In Canada, this transformation is already visible in the development of the Canadian Armed Forces Cyber Command as well as in the planned investments in Zero Trust, sovereign AI, interoperability, secure digital infrastructures, and cyber skills development.
Quantum Beyond aims to contribute to this ecosystem as a specialized technology partner alongside the professionals who already carry these responsibilities. Our skills in security architecture, IAM, Zero Trust, cyber resilience and sovereign digital defense, private and sovereign AI, AI governance, post-quantum readiness, and cryptographic transition can be mobilized when internal teams need complementary expertise, additional capacity, or a cross-cutting view of environments that have become particularly complex.
This approach can also apply to allied defense organizations facing the same transformations: protecting distributed infrastructures, preparing systems whose lifespan is measured in decades, integrating artificial intelligence in a controlled manner, preserving interoperability, and retaining enough technological freedom to evolve in a constantly changing environment.
Modern cyber defense relies on advanced technologies, but its true capability rests on the people who know how to understand them, integrate them, and make them work together. Multinational exercises such as RIMPAC are therefore a reminder of a reality that holds as much for organizations as for their allies and partners: no single area of expertise can be considered in isolation once the systems themselves have become interdependent.
In an environment where technologies, missions, and threats evolve continuously, a team's strength also lies in its ability to bring together, at the right moment, the expertise needed to understand what it could not see on its own.
