Cyber Key Terrain for the Non-Technician
Theory Talk
By Lt. Col Jerome M. Althoff
| Army Communicator, Summer 2026 Edition
Read Time: < 12 mins
In this article, I combine my love of history and teaching. I attempt to take some technically challenging theory and provide concepts that make the theory more approachable to individuals in disciplines not involving signal or cyber. The goal is to reduce the perceived complexity of pure cybersecurity and offer alternative ways to understand some of its fundamental terms and mindsets.
This article aims to make the concept of key terrain in cyber operations more approachable to non-technical readers. Granted, defining cyber could easily spin off into its own series. Here, it will be used as a colloquial term encompassing technologies and methods used in modern digital communication, commerce, and war-fare. This is important to both those who work within the Cyber branch and everyone else, as it has become a domain of the modern world and its battlefield. Like many complex things, I will attempt to build abstractions to make discussion manageable. By building abstractions and using historical and non-technical examples, I aim to provide a clearer perspective.
The Joint Force explicitly defines three layers of cyberspace: physical network (things we can touch: wires, power, etc.), logical network (e.g. software, protocols), and cyber-persona (the “acting” element) (JP 3-12). A helpful analogy might be American railroad terminology. Most people do not have specifics of railroads in their daily lives, yet they can likely dredge up some terms like “all aboard, dining or sleeper car.” In the same vein, people generally pay little attention to the specifics of cyber, though they can appreciate that a firewall is somehow always the problem.
Moving forward, I will provide several mental constructs that should be useful as well as identify what I believe to be the most essential cyberspace key terrain features.
Layers: Physical Network, Logical Network, and Cyber-Persona
All aspects of warfighting have key terrain – many with significant overlap. While a logistician or a maneuver expert might recognize a town, bridge, or hill as key terrain for different reasons, the “thing” physically exists and can be fought over.
Some physical terrain provides greater advantages to either friendly forces or the adversary and enjoys the moniker “key.” A hill overlooking a flat expanse of ground is a prime piece of key terrain – one we can all visualize and internalize. The topography, hydrology, and flora of that hill constitute overlays that aid in understanding what “the hill” is easier and more discrete, which influences how and where we fight. Just as the hills overlooking a small Pennsylvanian town were key terrain for the battle of Gettysburg – hills which gave Union forces a literal upper hand – that hill is a chunk of our physical world. It is physical key terrain.
But what about key terrain in cyberspace? Just as physical terrain has overlays of topography, hydrology, and fauna, cyber has its own overlays: the physical network, the logical network, and the cyber-persona. Physical Network Layer
Cyberspace’s physical overlay is loosely contained by two terms: transport and devices. Transport refers to all the methods in which memes move, including wireless (Wi-Fi, Bluetooth, near-field, infrared, etc.) and wired (fiber, copper, etc.). Devices cover all the various media that people use to see, edit, or create memes as well as the intermediary equipment required to spread memes. This is somewhat akin to railroad infrastructure with the train as the meme, rails the transport, and the various stations the devices. Generally, physical aspects of cyber infrastructure can be targeted in the same way as hills or bridges and can be planned for accordingly. It is eminently possible to target the physical fiber and copper lines, as well as the antenna and transceivers used for wireless.
Early morning Aug. 5, 1914, began with the British navy dispatching a ship to dredge up and cut the trans-Atlantic telegraph cables of the German Empire. This is the first example of severing global electronic communications.
With the transport split, Imperial Germany had no alternative electronic option but to send their messages via the infrastructure owned and operated by their British adversaries. This was possible largely due to geography. There were few ideal locations in Europe for the trans-Atlantic cables which made it easy for the key terrain to be decisively seized (Corera, 2017). The same routes that once carried telegraph lines across the Atlantic now host the intricate web of our modern global fiber optic cables. The routes that painstakingly began in a pre-American Civil War era are now widely known and even more vulnerable to sabotage.
Now for the invisible elephant in the room: the electromagnetic spectrum (EMS). It is our term for the incredible span of energy that surrounds us. Humans have managed to tap into EMS, thus enabling wireless communications, since the late 1880s.
Over the subsequent 140 years, our ability to utilize the EMS has increased exponentially. This has led to streaming music from the cloud to your phone, then to your wireless headphones, all while you navigate a city using real-time location information updated by satellites. EMS is a massive enabler with myriad applications. It is also easily susceptible to interference from both natural and manmade, innocent and intentional actions.
In 2013, a team of student researchers from the University of Texas at Austin managed to GPS spoof an $80 million yacht. While the crew and passengers could see the ship changing course, the yacht's command and navigation system still displayed as though the ship was on its initial course (Austin, 2013). Just over a decade later, use of EMS is more prevalent, as are its associated risks. A review of current events in Eastern Europe should provide plenty to think about regarding EMS operations.
During World War II, another EMS-based command and control issue led to an instant strategic upset.
Maneuvering forces across time and space to strike decisive blows required humans in the loop during the 1940s. There were no autonomous drones or artificial intelligence (AI) driven weapon systems. But just as drones or AI need some initial guidance, the humans controlling aircraft and ships in the Pacific did, too. This was generally done via wireless telegraphy, restricted from the adversary by using cryptography.
U.S. Naval cryptanalysis was able to break the Japanese Imperial Navy’s code and provide details on when and from where the attack on Midway would occur. Admiral Chester W. Nimitz was quoted as saying, “Well, you were off only five minutes, five degrees and five miles out” (Carlson, 2011), which in the Pacific gave Allied forces what they needed to stop the driving wind behind the Imperial Japanese forces. Once they lost their secure command and control, their forces’ effectiveness was reduced, followed swiftly by the sailors, pilots, and ships.
Logical Network Layer
The logical overlay of cyber is much more abstract. How devices talk to each other, how memes are packaged and sent, how to ensure only the intended audience can enjoy the meme, and how content is transportedfrom an initiator device to an intended device are all examples of how cyber operates in the logical realm. Consider a box filled with train parts in a child’s play-room. Regardless of well-intentioned adult intervention and organization, the various sets commingle. Tracks, scenery, cargo, gauges, even forms of locomotive technology will be mashed together in multiple configurations – each existing for a period, each working to some degree – before being reimagined. This ever-changing reality resembles the hodgepodge nature of the logical overlay. New pieces of logic are continuously created, either out of nothing or by bringing existing pieces together. This requires constant vigilance over the logical overlay. Logically, the world truly is flat and can fit in your pocket.
Cyber Key Terrain
Today, there are five states on the Iberian Peninsula: Spain, Portugal, France, Andorra, and the United Kingdom. In the 1150s, there were many more Christian kingdoms and Muslim emirates with shifting borders and allegiances. One particularly powerful king was Ibn Mardanīsh, known as “Wolf King.” He carved out his kingdom as the Almoravid Emirate fell to the Almohad Caliphate. Over time, Wolf King aligned with other regional powers to continue to secure his realm. With extensive and organized kingdoms boxing him in on his north and west, Wolf King’s primary source of growth was to the south and east. These regions were suffering disorder and fragmentation during the transition from Almoravid to Almohad authorities. Wolf King chose to besiege Cordoba in 1159. City leaders did not think they would outlast Wolf King, so they asked for help from the city of Seville. Leadership in Seville came up with a plan: an agent posing as an oil merchant sent by a fake noble of Seville.
Seville was both a significantly more attractive city-state to capture and much better prepared to withstand a siege – unless, of course, the city could be delivered to Wolf King. The agent went to Wolf King’s court and convinced him to break the siege and move to Seville. Because he believed this messenger, he failed to take either city (Kennedy, 2014) (Eastaugh, 2023).
What relevance does cyber have to a military campaign conducted 865 years ago? Decisions ultimately stem from trust, trust comes from being able to identify the players on the battlefield, and in JP 3-12, that is wrapped up in cyber-persona. This aspect of cyber key terrain is the single most important, being essential to all permutations and combinations of any consideration of cyber key terrain. Without a solid understanding and control of cyber-persona within your mission planning, all other key terrain and the ability to command troops outside of shouting range is mute.
Validating who you are, who the other person is, and maintaining that validation is paramount. By this point, most people are likely being irritated by the increased use of multi-factor authentication, even if they know deep down it is essential. Authentication apps, physical keys, push notices, one-time pins, and phone calls are all examples of increased focus on validating identity. Just as Wolf King learned, if you trust the identity of someone or something without verification, you can lose out on acquiring your next city-state, access to your banking, or control over your maneuver elements. Clicking on a link, opening an email, or accepting position location information – someone’s location on the planet - are all actions that need to happen so we can do our jobs. All of that relies on you being you, them being them, and both knowing it.
The National Institute of Standards and Technology recommends separating duties as a security procedure. One way that organizations accomplish separation of duties is to have multiple accounts and account types (Vincent Hu, 2017). Separation of duties reduces the risk of insider threats and error while increasing the chance of discovering fraud.
One effective method that organizations use to implement separation of duties is to provision multiple user accounts and account types for different roles and tasks. This ensures that no single individual controls all critical functions of a process, thereby enhancing security and compliance.
Everyone is likely familiar with the terms user and administrator. Just as a point of interest, any account that is not directly related back to a person falls under the umbrella of non-personal entity – covers things you might have heard of like service or system – are mostly used on the system backside to accomplish a wide range of repetitive or known actions and used to distinguish them from human action. They are generally easier to secure and monitor as they complete their designated tasks. Any action performed outside of their normal activities would ideally raise an alarm. Ensuring that these accounts are secure and performing only their designated functions is an essential aspect of the cyber-persona key terrain.
Focusing on both strengths and weaknesses of the cyber domain, we can concentrate on the common human accounts – user and administrator. Each one of us is a user, and most of us are also administrators on our own devices. What is the difference between the two and how do we know which identity to interact with? A user can only interact with something in a defined way: play the game, enter the data, join the meeting, etc. Administrators can modify the conditions, means, allowable inputs, and destinations of outputs. Typically, hackers are users who are attempting to gain unauthorized administrative privileges or perform unintended actions, which exemplify a user exceeding their assigned identity.
A simple analogy: You are always you, but the clothes you put on changes how you represent your-self and how others perceive you. If you wear a red, orange, or blue shirt at a big box store, you should be prepared to answer questions, as you may be causing identity confusion.
With a basic understanding of the difference between user and administrator being analogous to a change in outfits, and further with the rapid ability to “look” the part based on easy changes to appearance, the driving imperative to know who one is hopefully makes more sense.
Knowing who someone is increases the ability to secure the environment by time, location, role, function, or some combination of things. Being able to positively identify the individual and tie their actions, user or administrator, is fundamental to them. Many failures of cybersecurity are caused by failures surrounding identities.
As AI-related technologies continue to blur lines of human and machine, we have seen machines pass the Turing test, both verbally and written.
Deepfake or deceptive visuals (still or motion) render our eyes suspect. Coupled with the ability for AI to mimic a human’s voice and emotional nuance with only seconds of audio from the individual, we now must question our ears (Edwards, 2023). We could be left wondering which orders do we follow, which is the voice of the commander, do we flank, charge, or withdraw? We will continue to wonder that if we lose control of the cyber-persona – the single most important piece of cyber key terrain.
Take Away
Cyber is a strategic fight that can last a few minutes or span multiple years. While its physical aspects (devices, wires, antenna) are easy to see and target, the electromagnetic and logical portions are impossible to see with the Mark1 eyeball.
It takes education, analogies, and determination from all personnel – uniformed and civilian, entry-level through senior leadership – to understand and fully appreciate the dangers that come hand-in-hand with all the daily benefits.
In addition to our collective military elements, it takes an educated population with their own personal resilience and understanding so they can better handle what will be needed to weather a large-scale, cyber-involved conflict.
Notes
Austin, U. o. (2013, July 29). UT Austin Researchers Successfully Spoof an $80 million Yacht at Sea. Retrieved from The University of Texas at Austin: https://news.utexas.edu/2013/07/29/ut-austin-researchers-successfully-spoof-an-80-million-yacht-at-sea/
Carlson, E. (2011). Joe Rochefort's War: The Odyssey of the Codebreaker Who Outwitted Yamamoto at Midway. Annapolis: Naval Institute Press.
Corera, G. (2017, December 15). How Britain pioneered cable-cutting in World War One. Retrieved from BBC News: https://www.bbc.co.uk/news/world-europe-42367551
Eastaugh, S. (2023, November 10). Reconquista. Retrieved from PodBean: https://reconquista.podbean.com/episode-77-setbacks-all-around/
Edwards, B. (2023, January 9). Microsoft's new AI can simulate anyone's voice with 3 seconds of audio. Retrieved from Ars Technica: https://arstechnica.com/information-technology/2023/01/microsofts-new-ai-can-simulate-anyones-voice-with-3-seconds-of-audio/
Kennedy, H. (2014). Muslim Spain and Portugal. Routledge eBooks.
Vincent Hu, R. K. (2017, June). Verification and test methods for access control policies and models. Retrieved from NIST: https://csrc.nist.gov/pubs/sp/800/192/final