Then in LinkedIn: Write article → click into the body → paste (Ctrl+V). Headings, links and images come with it. The title usually pastes as the first line — cut it into LinkedIn's title field. back to the article

How War, Security, and Technological Power Actually Work

Nuclear deterrence, military logistics, and cyber conflict follow documented mechanics, not the drama of headlines — this is what the doctrine, the treaties, and the incident record actually say.

A long archive table holding an open treaty document box, a laminated logistics route map, a model container cluster, and a disassembled drone frame, with a filing drawer of event-coding cards still half open

Security policy is studied here the way it is actually made: as paper doctrine, physical supply chains, inert hardware, and counted incidents — not as a single dramatic weapon. — Image prompt and art direction by Brecht Corbeel; generation pending.

Abstract

Public argument about military power runs on two exaggerations at once: that nuclear war is prevented by little more than mutual fear, and that "cyber war" is a coming apocalypse indistinguishable from science fiction. Both compress documented mechanics into slogans. This article opens a series on war, security, and technological power by establishing, from primary doctrine, treaty text, and the incident record, how second-strike deterrence is actually built and verified, how logistics rather than firepower sets the outer limit of what an armed force can do, what a real cyber operation against physical infrastructure actually required, and how proliferation, autonomy, and escalation are governed today. Throughout, documented fact is separated from vendor and government claims, analytical inference, and explicit scenario reasoning.

What this series is not

Public argument about military technology runs on two exaggerated pictures at once. The first treats nuclear peace as a fragile accident held together by little more than mutual terror, one miscalculation from collapse. The second treats “cyber war” as an undifferentiated menace, one keystroke from blacking out a country. Both compress a body of documented doctrine, verified incident reporting, and quantitative conflict research into a mood. This article, opening a series on war, security, and technological power, tries to do the opposite: state what nuclear deterrence doctrine actually claims and how it is built to be credible; what determines how far and how long an armed force can actually operate; what a real, confirmed cyber-physical attack required in practice, against the much larger volume of cyber activity that is intelligence collection or crime; and how proliferation, autonomy, and escalation are actually governed by existing instruments, imperfect as they are.

The discipline that follows this introduction separates four kinds of claim explicitly. Fact: what a treaty text says, what a declassified review states, what an incident investigation documented, what a dataset counts. Vendor or government claim: an assertion made by an interested party — a defense ministry, a security company, a coalition of states — presented as their position, not as independently verified truth. Analysis: an inference this article draws from the facts, clearly marked as interpretation. Scenario or prediction: an explicit conditional statement about the future, with a stated horizon, assumptions, and a condition that would prove it wrong.

Deterrence is an engineering claim before it is a psychological one

Nuclear deterrence is often described as though it depended primarily on leaders being sufficiently frightened. That framing is not wrong so much as incomplete. Thomas Schelling’s foundational work on the strategy of conflict reframed military strategy as, in large part, the deliberate manipulation of risk and the communication of resolve rather than the pursuit of battlefield victory — deterrence and compellence work through the threat of what one side could still do, not only through what either side has already done [1]. But the credibility of that threat rests on a concrete engineering fact: whether a state’s ability to retaliate would actually survive the attack it is trying to deter.

This is the second-strike condition, and it is the single most load-bearing idea in deterrence doctrine. A force is first-strike vulnerable if an adversary could plausibly destroy enough of it in a surprise attack to leave no credible retaliation. A force has second-strike capability if enough of it — hardened, mobile, or hidden — would survive a first strike and remain able to retaliate. The doctrinal claim is that mutual second-strike capability is what makes a strategic balance stable: neither side gains anything by striking first, because striking first does not remove the other side’s ability to respond. A situation where one or both sides believe a disarming first strike is achievable is the doctrinally dangerous one, because it creates pressure to strike first rather than wait to be struck.

A cutaway model submarine hull and a mobile launcher model set apart on a laminated basing map, a third model crane caught lowering a warhead mock-up toward an empty dispersed pad

Figure 1. Second-strike doctrine is a claim about survivability, not explosive yield: a force that can absorb a first strike and still retaliate is what makes retaliation credible enough to deter. — Image prompt and art direction by Brecht Corbeel; generation pending.

This is why the physical architecture of a nuclear force — the specific fact of dispersal, mobility, and concealment — is not incidental detail but the substance of the doctrine. Submarine-based missiles are difficult to locate and destroy while submerged; road-mobile launchers complicate targeting by moving; hardened silos raise the number of weapons an attacker must expend per target. The United States’ 2022 Nuclear Posture Review states that the country will maintain a survivable second-strike capability across a triad of delivery systems specifically to preserve deterrence stability, and frames arms control and risk reduction as complementary to, not substitutes for, that survivability [3]. This is a fact about stated doctrine, not a claim that deterrence has never failed or could never fail — the historical record includes numerous acknowledged close calls that doctrine documents do not resolve away.

It is worth separating what is fact here from what is analysis. It is fact that survivability, not warhead count alone, is the doctrinal basis for stability, and that this is documented in declassified official reviews. It is analysis — widely shared among security-studies scholars but not something a treaty proves — that arms racing toward disarming first-strike capability (for example, through missile defense or highly accurate low-yield weapons married to good targeting intelligence) can be doctrinally destabilizing even if each individual system is presented as defensive. Readers should treat any specific claim that a named system is “destabilizing” as analysis, not settled fact, because it depends on contested assumptions about adversary perception.

A second, related doctrinal distinction worth stating plainly is the difference between deterrence and compellence. Deterrence tries to prevent an adversary from starting an action by threatening unacceptable costs if they do; compellence tries to force an adversary to stop an action already under way, or to undertake some new action, through the same threat of cost. Schelling’s framing treats these as two faces of the same coercive logic, but they are not symmetric in practice: deterrence asks an adversary to maintain the status quo, which requires no proof of resolve beyond restraint, while compellence asks an adversary to visibly back down, which is politically harder and historically less reliable [1]. Much of the confusion in public commentary about whether a given threat “worked” stems from not noticing which of the two is actually being attempted. A blockade intended to force a withdrawal is compellence; a standing force posture intended to prevent an invasion that has not yet happened is deterrence. Conflating the two leads observers to judge a deterrent posture as having “failed” the moment it is tested by a compellent crisis it was never designed to resolve.

Logistics sets the boundary that firepower cannot cross

If deterrence is about what a force could still do after being struck, operational reach is about what a force can actually do while it is moving forward. Military history and contemporary planning documents converge on an unglamorous conclusion: the limiting factor in sustained military operations is usually not the number of weapons available but the ability to move fuel, ammunition, spare parts, and food to the point of contact, repeatedly, under contested conditions.

A lateral row of scale-model shipping containers and fuel pallets along a laminated route map, the furthest container caught tipping off the edge of the mapped supply line

Figure 2. Operational reach is set by the supply line, not the front line: a force runs out of the ability to sustain contact with the enemy well before it runs out of things to shoot at. — Image prompt and art direction by Brecht Corbeel; generation pending.

Recent RAND analysis of naval logistics in contested environments documents this concretely: current supply chains and afloat stockpiles were built around steady-state peacetime demand and near-term readiness rather than the sustained consumption rates of major combat operations, and the study finds that industrial base capacity — the rate at which weapons and components can actually be manufactured and replenished — would constrain resupply well before available platforms would [6]. This is a fact about a specific documented analysis, not a general law of war; the numbers are service- and scenario-specific. But the underlying mechanism it illustrates is general and well established in logistics and operations research: sustaining forces at distance requires a “tail” of transport, storage, and resupply that grows faster than the “tooth” of combat power it supports, and that tail is vulnerable to interdiction, industrial bottlenecks, and simple distance in ways that combat units themselves often are not.

This is also why military expenditure and arms holdings, tracked over decades, are informative but insufficient predictors of what a force can do. SIPRI’s Military Expenditure Database provides consistent time series of national military spending back to 1949, and its Arms Transfers Database tracks the flow of major conventional weapons systems between states since 1950 [7, 8]. These are facts about recorded totals — how much was spent, what was transferred, when. They do not, by themselves, indicate whether the resulting force could sustain operations at range; that additionally requires data on stockpile depth, industrial surge capacity, and transport capability, which is precisely the gap the RAND logistics analysis is documenting. An analyst who infers “capability” directly from spending or inventory totals without accounting for sustainment is making an unsupported analytical leap, however common that leap is in public commentary.

The same caution applies to arms-transfer data specifically. A recorded transfer of a major weapons system tells an analyst that a platform changed hands; it does not by itself establish that the receiving force has the trained personnel, the maintenance pipeline, the compatible fuel and ammunition standards, or the doctrine to employ it effectively, and it says nothing about whether that force could sustain the platform through a extended campaign rather than a short engagement. Comparative rankings built by summing transferred hardware across very different states — different training pipelines, different logistics doctrines, different industrial bases — routinely overstate how comparable the resulting capabilities actually are. This is precisely the kind of cross-context ranking this article treats with suspicion throughout: two states holding a nominally identical inventory of a weapons system can have dramatically different actual operational reach, for reasons that show up in sustainment data rather than in inventory counts.

What “cyber conflict” concretely means, against the hype

No case has done more to shape — and distort — public understanding of “cyber war” than Stuxnet, the malware discovered in 2010 that sabotaged centrifuges at Iran’s Natanz nuclear enrichment facility. It is worth being precise about what the documented technical record actually shows, because the popular version of the story (a single piece of code that “hacked” a nuclear program) both overstates how easy the operation was and understates how narrowly targeted it was.

A glass-fronted industrial control cabinet with a programmable-logic controller module on an isolated test bench, a single diagnostic cable caught mid-unplug from its port

Figure 3. The one confirmed case of malware causing physical sabotage required years of engineering against one specific control system, not a generic "hack" — and it needed a hand-carried bridge across an air gap. — Image prompt and art direction by Brecht Corbeel; generation pending.

Symantec’s detailed technical dossier on the malware documents that Stuxnet was engineered specifically to reprogram particular models of programmable logic controllers (PLCs) used to run centrifuge cascades, altering their behavior to damage the centrifuges while feeding false “normal operation” readings back to plant operators and concealing the changes from monitoring systems [4]. This is a fact drawn from a detailed reverse-engineering report, not a leaked government claim; no government has ever officially confirmed authorship. Several elements of the case are frequently omitted from popular retellings but are load-bearing for understanding what such an operation actually requires: the malware had to be introduced to an air-gapped facility — a network deliberately not connected to the internet — meaning the initial infection vector had to cross that gap physically, most plausibly via removable media; it required detailed engineering knowledge of the specific industrial hardware and the specific physical process (centrifuge rotational behavior) being sabotaged, not generic hacking skill; and it took the effort of a sophisticated, well-resourced effort over an extended period, not an improvised attack.

It is also worth being explicit about what the Stuxnet case does not establish, since it is frequently over-generalized. It does not establish that any comparably resourced actor could replicate a similar effect against an arbitrary piece of industrial infrastructure; the operation depended on detailed, plant-specific engineering intelligence that took years to assemble and would need to be substantially redone against a different facility with different hardware. It does not establish that air gaps are worthless, since the air gap is exactly why the operation required a physical bridging step rather than a purely remote intrusion; if anything, the case is a documented argument for the continued value of physical isolation, not against it. And it does not establish a general precedent for cyber-only military campaigns, since no confirmed cyber-only operation since has produced a comparable, verified physical sabotage effect at this level of documented technical detail — most publicly reported “cyberattacks” on infrastructure in the years since have caused disruption (outages, data loss, delayed operations) rather than the kind of engineered physical damage the Stuxnet dossier documents.

The doctrinal picture of state cyber activity below the level of a Stuxnet-class operation looks considerably less dramatic and considerably more continuous. U.S. Cyber Command’s doctrine of “persistent engagement” and “defend forward,” analyzed in detail by cybersecurity scholar Jason Healey, holds that most state-on-state cyber competition occurs below the threshold of armed conflict and is better understood as constant, low-intensity contact and disruption rather than discrete strikes — the doctrine explicitly rejects a model built around rare, decisive cyber “attacks” in favor of continuous operations intended to impose cumulative friction on an adversary [5]. This is a fact about the stated doctrine of one country’s military cyber command, and Healey’s peer-reviewed analysis is explicit that this is a contested strategic theory, not a settled result: he documents open academic and allied concern that persistent, forward operations inside foreign networks could itself be escalatory, could blur the line between espionage and attack preparation in ways adversaries read differently than intended, and currently lacks agreed metrics for success or failure. Readers encountering claims that a specific cyber incident constitutes “cyberwar” should ask whether it caused a documented physical effect comparable to Stuxnet, or whether it is espionage, disruption, or criminal activity being relabeled for effect — the great majority of reported “cyberattacks” are the latter.

Proliferation control runs on inspection, not just signatures

The Treaty on the Non-Proliferation of Nuclear Weapons, in force since 1970 and joined by 191 states, is often treated in public discussion as though the text itself prevents proliferation. The treaty’s actual mechanism is narrower and more procedural: non-nuclear-weapon states parties commit not to acquire nuclear weapons, and in exchange accept a verification regime under which the International Atomic Energy Agency administers inspections — physical, on-the-ground safeguards — intended to confirm that declared nuclear material has not been diverted to weapons purposes [2].

A row of archival treaty binders each bearing an intact wax seal, an inspection tag being lowered onto the one binder whose seal is broken

Figure 4. Non-proliferation runs on verification, not promises: safeguards inspections exist because a treaty text cannot, by itself, prove that a declared stockpile is the whole stockpile. — Image prompt and art direction by Brecht Corbeel; generation pending.

This is a fact about treaty structure: the NPT’s non-proliferation function depends on the IAEA’s inspection and safeguards apparatus being able to detect diversion, not on the prohibitive language of the treaty alone. It follows analytically — and this is widely discussed in the nonproliferation literature rather than stated directly in the treaty text — that the treaty’s practical strength in any given country depends heavily on the scope of safeguards agreements that country has actually accepted, the IAEA’s actual access, and the political willingness of other states to respond when inspections raise concerns. A state’s signature is a documented fact; a state’s compliance is a separately verified fact; the two are not the same thing, and conflating them is one of the most common errors in popular reporting on proliferation.

The same distinction between formal instrument and functioning verification applies to newer domains of arms control, including autonomous weapons. The Group of Governmental Experts on Lethal Autonomous Weapons Systems, convened under the UN Convention on Certain Conventional Weapons, has been meeting for multiple years to consider possible international measures on weapons systems that select and engage targets without direct human control [9]. It is a fact that this body exists, has met repeatedly, and has not produced a binding treaty; it would be a vendor/government-style claim, not a fact, to assert that any specific national policy on autonomous targeting fully satisfies whatever eventual international standard emerges, since no such binding standard yet exists.

Autonomy and escalation are the same governance question

A disassembled small quadcopter airframe on a foam tray beside a card-catalogue drawer of conflict-event tally cards, one card caught being filed under a hand-lettered heading

Figure 5. Autonomy and escalation are governed by the same question in different clothes: which decisions are delegated away from a person who can be held accountable, and how is that delegation checked afterward. — Image prompt and art direction by Brecht Corbeel; generation pending.

Strip away the specific technologies and a common question runs through deterrence, logistics dependency, cyber doctrine, and autonomous weapons alike: which decisions have been delegated away from a person who can be held accountable for them, and what mechanism checks that delegation after the fact? A second-strike force is trusted with retaliatory authority precisely because launch decisions remain under tightly documented human political control even under extreme time pressure — the credibility of deterrence depends on this control being real, not merely asserted. A persistent-engagement cyber doctrine raises the same question at machine speed and lower visibility: continuous forward operations inside adversary networks compress the time available for the kind of political review that nuclear command-and-control was explicitly built to preserve, which is exactly the escalation risk Healey’s analysis flags [5]. Autonomous weapons raise the sharpest version of the same question, which is why the CCW process has focused specifically on the retention of human control over target selection and engagement, rather than on the underlying sensor or navigation technology, which is not itself the object of concern [9].

Measuring whether escalation risk is actually rising, rather than merely feeling like it is rising, is where systematic conflict data matters more than any single incident. The Uppsala Conflict Data Program has maintained a continuously updated, publicly available dataset of state-based armed conflict, non-state conflict, and one-sided violence since the 1980s, with records extending back to 1946, specifically so that claims about trends in organized violence can be checked against a consistent count rather than against the salience of recent headlines [10]. This is a fact about an existing, verifiable dataset, and it is the appropriate corrective to both of the exaggerated pictures this article opened with: neither “nuclear peace is one accident from ending” nor “cyber war is already here in the way movies depict it” is a claim that a systematic dataset, a declassified doctrine review, or a detailed incident dossier will straightforwardly confirm. Each of those documents instead shows a narrower, more specific, and more governable set of mechanisms — survivability requirements, sustainment constraints, engineering effort against a specific target, and inspection regimes — that determine how military and technological power actually operates, and that remain, however imperfectly, subject to documented rules, treaties, and counted evidence rather than to fear alone.

What would revise this account

A conditional forecast, not a fact: if verification technology for autonomous weapons and cyber operations (attribution, forensic logging, tamper-evident audit trails) improves faster than the diplomatic instruments meant to use it, expect governance debates over the next decade to shift from treaty text toward technical verification standards, mirroring the IAEA’s role in nuclear affairs. The horizon is roughly ten years; the assumption is that no single catastrophic incident forces an emergency binding agreement in the interim; and the observable indicator to watch is whether the CCW process or a successor body adopts any technical verification annex rather than a purely declaratory instrument. If, instead, a major state deliberately withdraws from IAEA safeguards or conducts an overt nuclear test outside the current framework, that would disconfirm the assumption of gradual, verification-led governance and should be read as a much sharper discontinuity than incremental doctrine changes of the kind discussed above.

Sources

  1. Nobel Prize Outreach. The Sveriges Riksbank Prize in Economic Sciences 2005: Thomas C. Schelling. The Nobel Prize (2005).
  2. United Nations Office for Disarmament Affairs. Treaty on the Non-Proliferation of Nuclear Weapons (NPT). UNODA (1970).
  3. U.S. Department of Defense. 2022 National Defense Strategy, Nuclear Posture Review, and Missile Defense Review. U.S. Department of Defense (2022).
  4. Nicolas Falliere, Liam O. Murchu, and Eric Chien. W32.Stuxnet Dossier. Symantec (Security.com) (2011).
  5. Jason Healey. The implications of persistent (and permanent) engagement in cyberspace. Journal of Cybersecurity (2019). DOI: 10.1093/cybsec/tyz008.
  6. RAND Corporation. Naval Logistics in Contested Environments: Examination of Stockpiles and Industrial Base Issues. RAND Corporation (2024).
  7. Stockholm International Peace Research Institute. SIPRI Military Expenditure Database. SIPRI (2026).
  8. Stockholm International Peace Research Institute. SIPRI Arms Transfers Database. SIPRI (2026).
  9. United Nations Office for Disarmament Affairs. Convention on Certain Conventional Weapons — Group of Governmental Experts on Lethal Autonomous Weapons Systems. UNODA (2024).
  10. Department of Peace and Conflict Research, Uppsala University. Uppsala Conflict Data Program. Uppsala University (2026).

Originally published at https://absolutedigitalpublishers.com/articles/how-war-security-and-technological-power-actually-works.