Boyd’s OODA Loop and the Pace of Naval Cyber Defense
Boyd’s OODA loop (Observe, Orient, Decide, Act) came from aerial combat. Boyd, an Air Force colonel and fighter pilot, designed it to beat opponents in dogfights by cycling through decisions faster. Frank applies the same logic to naval cyber. Ships face adversaries in complex adaptive systems where every action triggers a reaction. Getting inside an adversary’s decision loop, in cyber terms, means detecting and responding before they can complete their next move. Speed of action determines who controls the engagement.
Aegis and CANES: The Attack Surface on 250 Ships
The US Navy’s 250 active ships, mostly destroyers, carry enormous IT and OT complexity. Two systems stand out. Aegis, operational since the 1980s, links ground-based, space-based, and ship-based sensors to intercept ballistic threats. Its ICS/SCADA components respond at machine speed because no human can react fast enough. CANES (Consolidated Afloat Networks and Enterprise Services) is the IT backbone running Aegis and nearly everything else on ship. Growing CANES integration with OT systems expands the attack surface, and the infrastructure is aging.
MOSAICS: Standardizing ICS Defense Across the Fleet
MOSAICS (More Situational Awareness for Industrial Control Systems) is a DoD framework led by the Department of the Navy and built at NIWC Atlantic. Originally designed for shore bases and ports, it now extends to shipboard systems. Block 1 shipped this spring; Block 2 follows next year. The phased approach moves from passive monitoring through active monitoring and response to automated response actions. By aggregating data across ships, operators can share threat intel fleet-wide rather than each vessel defending in isolation.
The Adoption Gap: Getting New Tools onto Ships
Frank draws a distinction between having good ideas and fielding them. The US has no shortage of defense-tech innovators, but the acquisition system creates friction when startups try to enter DoD programs of record alongside primes like Lockheed and Northrop. Frank’s civilian work focuses on closing that gap, getting founders and private capital integrated into the department’s supply chain. For MOSAICS specifically, capable monitoring tools still need to reach ships before any conflict starts.
Notable Quotes
cycling at a faster rate than they are. Michael Frank · ▶ 4:09
machine speed. They need to be moving Michael Frank · ▶ 7:51
start with passive monitoring, then we Michael Frank · ▶ 11:15
Key Takeaways
- MOSAICS standardizes ICS monitoring across the fleet, replacing ad-hoc individual ship defenses with shared threat intel.
- Aegis and CANES both require machine-speed defensive responses faster than any human can provide.
- Acquisition reform matters as much as security tooling for getting MOSAICS onto ships fleet-wide.
About the Speaker(s)
Michael Frank serves as Deputy Chief Technology Officer for the Department of the Navy, tracking emerging technology across the Navy and Marine Corps. Before joining the Pentagon, he spent about eight years as a cybersecurity and digital transformation consultant with Boston Consulting Group, serving financial institutions, healthcare companies, insurance firms, and DoD clients. As a Marine reservist, he leads the cyber portfolio for the Marine Innovation Unit and has run the Red Cell for Exercise Cyber Yankee for five years. He holds an MS in Information Security from Carnegie Mellon University, an MBA from the Darden School of Business, and a BA in Accounting from Washington and Jefferson College.