The Army wants a realistic digital model of its network
The U.S. Army’s top network commander is making a case for a major shift in how the service trains cyber operators, tests defenses, and applies artificial intelligence to network security. Speaking at AFCEA’s TechNet Augusta conference, Maj. Gen. Jacqueline Denise McPhail said the Army needs a digital twin of its network environment, a detailed and continuously updated simulation that would let operators and algorithms rehearse against realistic conditions before threats hit the live system.
The proposal is ambitious because the network in question is not a narrow lab environment. McPhail was referring to the Department of Defense Information Network-Army, or DoDIN-A, the set of military networks for which the Army is responsible. Building a live digital counterpart of that environment would be a large-scale technical undertaking. McPhail acknowledged as much directly, describing it as a “big ask” and urging contractors to start small and build outward.
Even so, the request is notable because it frames the Army’s network not simply as infrastructure to defend, but as a system that needs a high-fidelity training and experimentation environment of its own. In aviation, weapons, and logistics, digital twins are commonly discussed as ways to simulate physical systems. McPhail’s argument extends that concept to a sprawling operational network, with cyber defense and AI development as the immediate use cases.
Why NETCOM sees urgency
The scale of the threat environment is central to the case. According to McPhail, NETCOM sees about 1.2 million cyber attacks per day. Just as important, she said the attacks are becoming more sophisticated and less dependent on obvious tactics such as brute-force distributed denial-of-service activity. The challenge is increasingly behavioral: detecting subtle changes, distinguishing meaningful anomalies from background noise, and making sense of very large data flows quickly enough to act.
That is exactly the kind of problem the Army believes AI can help address. But applying AI effectively to operational cyber defense requires more than access to data. It requires a safe environment for training, testing, failure analysis, and iterative improvement. A digital twin could provide that environment by mirroring how the real network behaves and how it degrades or adapts under pressure.
In McPhail’s description, the value would extend to both humans and machines. Network operators could train in conditions that reflect real architecture and live performance patterns. Cyber defenders could rehearse incident response against realistic attack scenarios. AI models could be exposed to changing network behavior, helping analysts identify vulnerabilities, resilience gaps, and abnormal activity with more confidence before new tools are trusted in live operations.
More than simulation for simulation’s sake
The Army is not asking for a digital twin as a futuristic visualization project. The argument is tied to operational outcomes. If the model is continuously updated with live data, it could become a place to evaluate how the network responds to stress, what weak points emerge, and how defensive measures perform before they are deployed broadly. That would make it useful not just for classroom-style training, but for testing architecture changes, validating cyber tools, and improving readiness.
This matters because cyber defense in a military setting has a narrow margin for error. Production environments cannot serve as unrestricted test beds. Live experimentation can introduce operational risk, while static test ranges may not reflect the complexity of the real network. A properly maintained digital twin sits between those extremes: safer than live experimentation, but more relevant than a disconnected lab.
The concept also reflects a broader shift in defense technology thinking. As data volumes rise and network behavior becomes more difficult for human teams to interpret unaided, the value of AI increasingly depends on context. Models need environments that reflect the messy, dynamic realities they will face in service. Without that, promising algorithms can look effective in controlled settings and underperform in the field.
The doctrinal challenge
The source notes that McPhail is using a broader definition of digital twin than the one embedded in Pentagon doctrine, which typically describes a computerized representation serving as the real-time counterpart of a physical object or process. In defense discussions, that concept is often applied to aircraft, supply chains, or medical training systems. Applying it to an enterprise network stretches the traditional framing, but not irrationally.
A modern military network is both physical and logical. It includes hardware, software, configurations, traffic patterns, dependencies, and operator workflows. Its behavior changes continuously, and its vulnerabilities are often exposed not by a single broken component but by interactions across the system. From that perspective, modeling the network as a living process rather than a static asset is consistent with the core purpose of a digital twin, even if it extends the term beyond familiar examples.
That broader framing may matter for procurement and implementation. A network twin is unlikely to emerge as one monolithic product. McPhail’s own emphasis on starting small suggests an incremental path, perhaps with narrower mission areas, selected network segments, or specific training and cyber-defense applications. That approach would be more practical than trying to mirror the entire DoDIN-A at full fidelity from the outset.
What the request signals
The larger significance of McPhail’s remarks is that Army network leadership appears to see AI adoption and cyber readiness as inseparable from environment design. The Army does not just need better algorithms, in this view. It needs a realistic substrate in which those algorithms can be trained, challenged, and validated alongside human defenders.
That is a meaningful shift because it treats digital infrastructure as something that must itself be modeled with the seriousness once reserved mainly for platforms and weapons. If the Army moves in this direction, the resulting work could influence how other defense organizations think about cyber ranges, operational testing, and AI assurance.
For now, the concept remains an appeal rather than a program announcement. But the need described by NETCOM is concrete: a growing volume of attacks, a move toward behavior-based threat detection, and a requirement to train both people and AI on a network too complex to understand adequately through live operations alone. In that context, the proposed digital twin is less a speculative technology project than a bid to create the conditions under which cyber defense can scale.
This article is based on reporting by Breaking Defense. Read the original article.
Originally published on breakingdefense.com






