08/10/2026
THE CASCADE: America Does Not Have to Be Destroyed to Be Defeated
“Therefore the skilful leader subdues the enemy’s troops without any fighting; he captures their cities without laying siege to them; he overthrows their kingdom without lengthy operations in the field.”
— Sun Tzu, The Art of War
More than two thousand years later, that principle may describe one of the greatest vulnerabilities facing a technologically dependent nation. An adversary does not necessarily have to bomb an American power plant, destroy a dam, invade a city or defeat the United States military on a battlefield. It may only have to understand the systems we depend upon, quietly position itself inside them, disrupt the right dependencies at the right moment, and allow cascading failures, public fear and social division to do much of the remaining work.
Americans tend to imagine attacks on critical infrastructure in spectacular terms: explosions, collapsed bridges, destroyed power stations or some cinematic event that makes the beginning of an attack obvious. Modern infrastructure warfare can look very different. Sometimes the buildings remain standing, the generators remain intact and employees still report to work. What disappears is the digital connective tissue allowing all of those people and systems to function together.
Suisun City, California, provided a striking contemporary example in August 2026. Malicious software compromised municipal systems, affecting critical public-safety and government operations. Officials took portions of the city’s digital environment offline as part of the containment effort, while emergency communications were shifted to alternate systems so police and fire response could continue. The incident became serious enough for the city to declare a local state of emergency.
Suisun City did not disappear. The government still existed. Police officers were still on the street. Firefighters still had trucks. Dispatchers were still working. Yet the digital environment connecting those resources had become unreliable enough that officials could no longer safely use it in the ordinary way.
That distinction matters. In a cyber incident, defenders may themselves have to create part of the disruption. Once an organization discovers that its network may be compromised, intentionally disconnecting systems can be the safest course of action. From an operational perspective, however, a system deliberately disconnected because it can no longer be trusted is still unavailable to the person who needs it.
That is how a cyber incident becomes an operational problem, and how an operational problem becomes a governance problem.
The Cybersecurity and Infrastructure Security Agency, commonly known as CISA, is the Department of Homeland Security agency responsible for helping protect the nation’s cyber and physical critical infrastructure. CISA and its federal and international partners have repeatedly warned that hostile state-sponsored actors are penetrating American infrastructure. Some are doing something potentially more consequential than stealing information: they are establishing persistent access.
Perhaps the clearest example is Volt Typhoon, a People’s Republic of China-linked operation that U.S. authorities have described as maintaining access within critical-infrastructure environments in a manner consistent with pre-positioning for potential disruption during a future crisis or conflict.
The phrase “back door” can make this sound almost cartoonishly simple, as though an attacker installs one malicious program and leaves a secret button behind. Persistent access can be considerably more sophisticated. An actor may steal legitimate credentials, compromise routers or other edge devices, create alternate accounts, abuse legitimate administrative tools, map poorly monitored pathways through a network or simply learn enough about an environment to regain access after one route is discovered and closed.
The objective is durability.
An intelligence service that discovers an unlocked door does not always steal everything inside and burn the house down. Sometimes it quietly makes itself another key.
That separates strategic pre-positioning from many financially motivated cyberattacks. A ransomware organization normally wants to turn access into money. A state intelligence service may regard access itself as the valuable asset. It can map the network, learn which systems depend upon which others, understand recovery procedures, identify operational technology and preserve the ability to create effects later.
The lights do not have to go out today.
The strategic advantage lies in possessing the ability to make them go out on the day darkness matters most.
Ukraine provides one of the clearest modern demonstrations of what that capability can become during conflict. Russian cyber operators have targeted Ukrainian government networks, telecommunications, energy systems and civilian infrastructure repeatedly for years. The volume of cyber activity associated with the war became extensive enough that independent researchers created dedicated platforms simply to catalogue and track attacks involving civilian and critical infrastructure.
During periods of intense activity, scrolling through those incident timelines can feel less like reading isolated cyber reports and more like watching a Wall Street ticker tape: incident after incident, target after target, disruption after disruption.
There is something surreal about the underlying concept. Popular culture has played the idea for laughs before: someone sitting thousands of miles away uses the internet to turn another person’s lights on and off or control a remote-control toy on the other side of the world. The joke works because the object is insignificant and the stakes are nonexistent.
In Ukraine, the underlying principle stopped being funny.
Once operational technology and industrial-control systems became network-connected, cyber access could cross the boundary between the digital world and the physical one. Someone sitting in another country no longer necessarily needed to enter a power facility physically to create an effect inside it. Russian-linked operations have repeatedly targeted Ukrainian infrastructure, while destructive cyber activity accompanied the opening stages of the 2022 invasion and continued alongside conventional warfare.
Cyber did not replace tanks, missiles or troops. It created friction. It degraded systems, destroyed information, complicated communications, impaired recovery and forced Ukraine to manage another battlefield simultaneously.
That does not mean Russia can arbitrarily turn the entirety of Ukraine on and off like one enormous light switch. Ukraine has demonstrated remarkable resilience, recovery and adaptation. But the cumulative record illustrates something enormously important: connected infrastructure can be reached and manipulated from enormous distances, and cyber effects can be coordinated with events in the physical world.
The old television joke about turning on somebody else’s lights remotely becomes considerably less amusing when the “light” belongs to a city.
Before dismissing that as something that concerns only governments or power companies, however, consider a more uncomfortable question.
How much of your own daily life is accessible through someone else’s network?
How many devices inside your home communicate with Google, Alexa, Apple, Ring or another cloud platform? Could your security cameras establish when you normally leave for work and when you return? Could they show when your children arrive home from school or whether an adult appears to be there? Does your video doorbell document every visitor? Could your thermostat reveal occupancy patterns? Are lights, locks, garage doors, televisions, alarms and cameras all connected through the same home network? How many ultimately depend upon one email account for password recovery or the same phone for multi-factor authentication?
This does not mean smart speakers or voice assistants should be inaccurately described as secretly transmitting every conversation occurring inside a home. The issue is serious enough without exaggeration. We have voluntarily filled homes, vehicles, workplaces and communities with network-connected cameras, microphones, sensors and physical controls.
We already know what unauthorized access to some of those systems can look like.
Families have reported strangers gaining unauthorized access to internet-connected cameras and baby monitors and using built-in speakers to communicate with people inside the home. One particularly disturbing case in Mississippi involved an intruder accessing a camera located in an eight-year-old girl’s bedroom, speaking directly to her, pretending to be Santa Claus and attempting to establish familiarity with the child. Other families have reported unknown individuals talking to or harassing children through compromised connected cameras.
A compromised camera is therefore more than a privacy problem. A device containing video, audio and two-way communication can potentially reveal routines, show whether rooms are occupied and give a stranger a communication pathway into a space a family believed it was monitoring for safety.
That does not mean every compromised baby monitor is being used for grooming or predatory activity, and responsible analysis should not make that leap without evidence. It does demonstrate something deeply uncomfortable: physical distance is no longer necessarily separation.
The question is no longer simply whether someone sitting overseas can reach a switch in another country.
It is how many switches in our own lives have we already connected to the internet?
Scale the same principle upward and the critical-infrastructure problem becomes clearer. The United States does not consist of independent sectors operating neatly beside one another. They are systems of systems whose dependencies continuously overlap. Electricity powers telecommunications. Telecommunications supports utilities, emergency dispatch, transportation and financial transactions. Cloud services host government and private applications. Water systems depend upon electricity, communications and industrial controls. Hospitals rely upon electricity, water, telecommunications, transportation, pharmaceuticals and fuel. Trucking requires fuel, communications, dispatch and payment systems.
The threat therefore is not simply failure.
It is cascade.
Recent malicious activity involving water and wastewater infrastructure reinforces that concern. Internet-accessible programmable logic controllers, or PLCs, have increasingly become targets because they are not simply office computers holding email and spreadsheets. They can participate directly in controlling pumps, valves, pressures and other physical processes.
At the same time, some of the greatest demonstrations of systemic vulnerability have not involved malicious actors at all.
On July 19, 2024, the world woke up to millions of Windows systems crashing after a defective CrowdStrike software update. Airlines, hospitals, banks, governments and businesses experienced disruptions. It was not a hostile cyberattack.
From a resilience perspective, that almost made the incident more instructive.
Organizations that appeared completely unrelated suddenly discovered that they shared a technological dependency. A failure upstream propagated downward through organizations across sectors and national borders.
And I experienced another dimension of that problem firsthand while working in homeland security.
The operational difficulty was not merely getting a computer past the blue screen. Modern government systems depend upon other systems. A restored workstation may still require an identity provider. That identity provider may require network connectivity. The second authentication factor may depend upon an authenticator application, cellular service, cloud connectivity or another digital pathway that is itself degraded.
Two-factor authentication can do exactly what it was designed to do: refuse access unless both factors are successfully verified.
The problem arises when the legitimate users cannot satisfy those requirements either.
That creates an extraordinary security paradox. A mechanism designed to keep unauthorized people out can, during systemic failure, also keep authorized personnel out.
Email becomes unavailable. Intelligence databases cannot be reached. Analytical platforms cannot authenticate users. Secure communications degrade. Investigators cannot retrieve records. Intelligence analysts cannot efficiently compare incoming threats against existing holdings. Agencies may know exactly which partners they need to contact while simultaneously losing the normal technological pathways connecting them.
Meanwhile, emergencies do not wait for IT systems to come back online.
School threats still arrive. Missing children still need to be located. Tornadoes still form. Suspicious activity still has to be investigated. Ambulances still need destinations. Intelligence requirements continue accumulating.
The attack at Apalachee High School in Georgia in September 2024 and the waves of copycat threats that followed provide a separate example of how quickly an intelligence requirement can explode following a high-profile event. The school shooting and the July CrowdStrike outage did not occur simultaneously, and conflating the dates would be inaccurate. But viewed as two operational lessons, they create an important question: what happens when a sudden wave of threats arrives at precisely the moment analysts cannot reliably access the systems they normally use to identify, correlate and disseminate threat information?
The amount of information requiring verification can increase at exactly the same moment the government’s ability to verify it decreases.
That is a dangerous asymmetry.
It is not an argument against multi-factor authentication. MFA remains one of the most important defenses against credential compromise. The answer is authentication resilience: protected emergency pathways allowing authorized personnel to perform critical functions when the primary identity infrastructure is unavailable. Depending upon the environment, that may involve carefully controlled break-glass accounts, hardware security keys, segmented emergency systems, offline credentials or alternate identity services.
Security cannot simply mean keeping unauthorized people out.
During a crisis, security must also ensure the right people can still get in.
Large cloud outages reveal the same dependency problem at another layer. AWS disruptions have demonstrated how applications scattered across countless organizations can ultimately rely upon common infrastructure. Telecommunications failures have done the same thing. Nationwide Verizon disruptions have affected voice, text and data services, demonstrating just how many ordinary and emergency functions eventually depend upon commercial communications networks.
CrowdStrike demonstrated concentration around software and endpoint security. AWS demonstrated concentration around cloud infrastructure. Verizon demonstrated telecommunications dependency. Suisun City demonstrated what happens when a municipal government loses confidence in its digital environment. Water-system incidents demonstrate that cyber activity can reach operational technology capable of influencing physical processes.
Those events are not evidence of one enormous coordinated attack.
They are evidence of how the pieces behave when they fail.
And that distinction is critical.
The answer is not abandoning technology.
Modern digital infrastructure is vastly faster, more capable and more efficient than the systems it replaced. Cloud computing, digital dispatch, smart infrastructure, modern authentication and networked operational technology have delivered enormous advantages. Reversing technological progress would not make America safer.
The answer is preserving independent continuity-of-operations capability alongside it.
In some environments, that means alternate cloud regions, separate identity providers, segmented networks, isolated backups or independent communications providers. In others, it may mean radio communications, paper procedures, local maps, manually operable equipment or mechanical systems capable of sustaining essential functions until the primary systems return.
The point is not nostalgia.
It is independence of failure.
Three servers in the same building, connected through the same network, authenticated by the same provider and drawing electricity from the same source are not three resilient systems. They are three copies of the same vulnerability. A backup database reachable with the same compromised credentials as the production environment is not meaningful redundancy.
There is no universal rule requiring every critical system to have exactly three backups. Different sectors employ different resilience models. But critical functions should be designed in layers: a primary capability, a genuinely independent alternate capability and a contingency method capable of surviving failure of the technology supporting the first two.
And increasingly, the least glamorous layer may become one of the most valuable.
A ham radio does not care whether AWS is functioning.
A paper map does not require GPS.
A handwritten dispatch log does not require Microsoft authentication. A manually operable pump does not need the cloud. Properly designed fuel systems can retain manual capabilities where appropriate. Trucking can operate through radio communications and paper manifests when modern logistics platforms are unavailable. Public-safety agencies can maintain independent radio pathways. Emergency contact information can exist somewhere other than a cloud application.
Those systems are slower. They are less efficient. They are not supposed to replace modern digital infrastructure.
They are supposed to survive it.
A technologically sophisticated system is resilient only if it can continue performing its essential purpose after one of the technologies supporting it disappears.
Now follow the cascade.
Imagine telecommunications fails first. Cellular voice and data become unreliable. Utility personnel lose normal communications. Businesses lose connectivity. Emergency call centers become congested as frightened citizens overwhelm the pathways that remain.
Then cloud infrastructure fails. Authentication services and hosted applications disappear. Dispatch tools, scheduling systems and databases become unavailable. Employees still occupy the buildings, but the information connecting the organization has vanished.
Then electricity becomes unstable. Generators start. Generators require fuel. Fuel has to be pumped, transported and delivered. Transportation requires drivers, dispatch, communications and functioning routes. Fuel terminals increasingly depend upon computerized control and authorization. Gas stations may physically possess thousands of gallons underground but lack electricity to operate pumps. Then payment systems begin degrading. The truck exists. The diesel exists. The food exists. The hospital exists. But the digital machinery used to authorize, coordinate and record modern transactions is failing. Transportation slows. Food deliveries slow. Medicine deliveries slow. Repair crews encounter delays. Hospitals consume generator fuel while simultaneously receiving more patients. Water facilities enter emergency operating modes. Police and fire resources become stretched. 911 volume rises at precisely the moment dispatch capacity is impaired.
Then another battlefield opens.
Information.
Foreign influence operations do not necessarily need to manufacture hatred, racism, political anger or distrust of government from nothing. It is much easier to find divisions already existing within American society and widen them. Russian influence operations aimed at American audiences have historically exploited political polarization, racial tension, resentment and distrust of institutions.
The goal does not necessarily need to be convincing Americans to support Russia.
Convincing Americans that other Americans are their enemy may be considerably more useful.
Now introduce that capability during a critical-infrastructure emergency.
The lights are out. Cellular service is intermittent. Government websites are unreliable. Officials cannot immediately explain what happened because investigators themselves are still establishing the scope of the incident. Analysts may be struggling to authenticate into systems ordinarily used to determine whether emerging threats are genuine.
That gap between the public’s demand for immediate answers and government’s ability to produce verified answers becomes exploitable terrain. Rumors appear that the government deliberately disabled particular neighborhoods. That the other political party caused the outage. That a particular racial, religious or political community is being given preferential treatment. That the drinking water is poisoned. That banks are confiscating deposits. That police have abandoned neighborhoods. That the military is preparing to impose martial law.
The narratives do not need to remain believable forever. They only need to remain believable long enough to change behavior. Tell frightened citizens fuel will disappear tomorrow and they buy all the fuel today.
The false shortage becomes a real shortage.
Tell people grocery distribution has collapsed and they empty stores faster than an already stressed logistics system can replenish them.
Tell communities the police have abandoned them and some residents flee while others arm themselves. Rumor becomes behavior. Behavior becomes operational demand. Police resources shift toward crowd management. Emergency rooms see additional patients. Dispatch volume increases. Repair crews require security. Government resources that should be devoted to restoring infrastructure are diverted into managing the social consequences of the infrastructure failure.
The information operation does not merely accompany the disruption.
It amplifies it.
Every secondary effect makes recovery from the original failure more difficult. The cascade begins feeding itself. History repeatedly demonstrates that catastrophe rarely begins with one enormous failure. More often, several smaller failures align.
The Deepwater Horizon disaster offers one of the clearest examples. Eleven workers died in the April 2010 explosion, and the Macondo well subsequently released enormous quantities of oil into the Gulf of Mexico, creating one of the largest environmental and financial disasters in modern American history.
Investigations did not uncover one absurdly simple mistake that explained everything. There were technical problems, misunderstood warning signs, failed barriers, poor risk decisions and ultimately failure involving systems intended to stop the catastrophe.
One safeguard failed. Another should have caught the problem. It did not. Signals were misinterpreted. Another protection proved weaker than assumed. Operators worked with incomplete situational awareness. The final defensive system failed under the very conditions it existed to control.
A collection of individually survivable problems became catastrophe.
That is cascade.
The 2003 Northeast blackout demonstrated the same principle within the electrical grid. It was not a cyberattack, but a localized sequence of transmission problems, equipment trips and inadequate situational awareness propagated across an interconnected system and left tens of millions of people without electricity.
The lesson was never that somebody possessed one enormous red button marked TURN OFF AMERICA. The lesson was that the system itself can become the mechanism through which failure travels.
That lesson is even more significant today because physical infrastructure now sits beneath additional layers of digital dependency: cloud computing, telecommunications, GPS, software supply chains, digital payments, automated logistics, identity services, multi-factor authentication and internet-connected industrial controls.
The system is more capable than ever.
It is also more interconnected than ever.
That brings us back to Suisun City.
The most important detail may not be that a California municipality was hacked. It may be that when its digital environment became unsafe, an alternate county system could assume emergency communications functions.
The first system failed.
Another system caught it.
The cascade stopped.
That is resilience.
Now imagine the alternate system depended upon the same compromised network.
Imagine the county and city shared the same cloud identity provider. Imagine a national telecommunications outage was occurring simultaneously. Imagine nearby water-system PLCs began behaving abnormally. Imagine intelligence analysts could not authenticate into the systems needed to determine whether the events were connected. Imagine social-media accounts immediately began telling residents their water was poisoned and government officials were hiding the truth.
Imagine frightened citizens arriving at stores, hospitals, gas stations and police departments simultaneously.
That is the scenario national resilience planning should contemplate, not because there is evidence that all of these recent incidents form one coordinated operation, but because we already know every individual failure mode is possible. Responsible intelligence analysis requires restraint.
Every AWS outage is not sabotage. Every Verizon outage is not a state actor. Every municipal cyberattack is not Volt Typhoon. Every malfunctioning water system is not an act of war. Every hateful account online is not a Russian troll.
Correlation is not attribution.
But analytical discipline works in both directions. We should not invent connections where evidence does not exist. We also should not become so committed to studying each event in isolation that we fail to recognize the architecture connecting them.
The intelligence question therefore cannot remain simply:
Who hacked this system?
We also have to ask what depends upon it, what happens when it becomes unavailable, what fails next, whether the backup relies upon the same cloud or telecom provider, whether legitimate operators can still authenticate, whether dispatch can continue, whether utilities can function manually, whether fuel can still move, whether government can communicate with the public, whether analysts can distinguish actual threats from coordinated misinformation, and which hostile actors may already possess persistent access to systems upon which those functions depend.
Sun Tzu also wrote that “supreme excellence consists in breaking the enemy’s resistance without fighting.”
A twenty-first-century adversary capable of penetrating critical infrastructure, exploiting technological concentration, disrupting communications and authentication, manipulating connected physical systems from thousands of miles away and amplifying existing social division may not need to defeat American military power on a conventional battlefield. It may seek something considerably more elegant. Create the conditions in which the system defeats itself.
The defense against that strategy is not simply another firewall, another cloud service or another piece of software. Nor is it abandoning technology and retreating from the connected world.
It is genuine resilience: strong cybersecurity combined with independent redundancy, segmented systems, offline recovery, alternate authentication, geographically separated infrastructure, resilient communications and the preservation of basic continuity capabilities that continue working when the digital environment does not.
Sometimes that means the most sophisticated technology available. Sometimes it means a radio, a sheet of paper, a mechanical control and a person who remembers what to do when every screen in the room goes black. Because the most technologically advanced backup system in the world is useless if it depends upon the same network that just disappeared.
That is resilience.