Entering the Cyber Battlespace
Digital Systems as Mission Terrain Evidence, Threat Intelligence, and Incident Response Authorization, Ethics, and Safe Practice What Cyberwarfare Is—and Is Not Cyberspace as an Operational Environment
The Road to Persistent Cyber Conflict
Estonia, Georgia, Stuxnet, and the First Shock Ukraine, 2015–2026: Campaigning Under Fire
Actors, Proxies, and Strategic Behavior
The State Cyber Ecosystem Strategic Cultures Without Stereotypes
Law, Authority, and Civilian Protection
Below Armed Conflict: Sovereignty, Intervention, Force, and Responsibility Armed Conflict: IHL and Cyber Effects
Intelligence, Indications, and Attribution
Intelligence Support to Cyber Operations Attribution Under Deception
Campaign Design and Command
From Policy Aim to Cyber Campaign Command, Authorities, and Deconfliction
Target Systems, Access, and Operational Security
Target-System Analysis and Cyber Key Terrain Access Stewardship, Capability Fit, and OPSEC
Effects Engineering and Campaign Assessment
Designing and Bounding Cyber Effects Measuring What the Campaign Changed
Critical Infrastructure and Cross-Domain Operations
Operational Technology, Safety, and Restoration Space, Telecommunications, and Multi-Domain Integration
Influence, Perception, and Public Truth
Cyber-Enabled Influence Operations Defending Truth, Trust, and Decision Space
Daily Defence in Competition and War
Mission Assurance and the Wartime Operations Floor Continuity, Recovery, and Collective Defence
Deterrence, Emerging Change, and the Final Campaign
Deterrence, Norms, and Collective Response The 2026 Horizon: AI, Supply Chains, Edge, and Identity Capstone: Build, Challenge, and Defend a Cyber Campaign
Target Systems, Access, and Operational Security

Target-System Analysis and Cyber Key Terrain

Find the function, dependencies, control points, observability, and recovery paths behind a target label.

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.

In this lesson, you will learn to:

  • Produce and challenge a target-system folder that supports both effects planning and defence.

Target-System Analysis and Cyber Key Terrain

Learners develop target folders centered on mission behavior rather than asset lists. The method integrates technical mapping, human workflow, intelligence confidence, and civilian dependencies.

Model the function before the component

Define the adversary function: communicate orders, move fuel, identify targets, distribute propaganda, restore power, or authenticate operators. Map inputs, transformations, outputs, decision points, people, software, hardware, suppliers, trust, and feedback. Identify which elements are necessary, redundant, replaceable, or merely visible.

A target folder should include the five cyberspace layers, ownership and geography, normal and crisis workflows, alternate paths, maintenance, observability, failure modes, and recovery. Mark facts, inferences, age, and source. Validate architecture against telemetry and subject-matter experts. A stale diagram can turn precision into collateral effect.

Find control points whose availability or integrity materially changes the function during the relevant window. Then red-team them: Can operators switch to voice, paper, another cloud, a spare radio, or manual control? Does the “single point” also serve civilians or partners? Target value is conditional on timing and adversary adaptation.

Build a target folder that can be challenged

The folder must answer: why the function matters; the desired effect and duration; technical and human control points; access confidence; intelligence gaps; civilian and partner co-use; expected adversary response; restoration; and indicators for target change. Include a “do not infer” page listing attractive but unsupported claims.

Run multidisciplinary challenge. Operators test feasibility, defenders expose detection and recovery, intelligence challenges identity and intent, engineers test process assumptions, counsel tests legal character, and regional experts test political context. Record dissent. Approval should expire when a critical assumption changes.

This same product supports defence. The linked cyber key terrain and mission-dependency mapping guide turns decisive terrain into monitoring priorities; alternate paths become continuity requirements; access hypotheses become hunt plans; recovery dependencies become exercise injects. Offensive and defensive analysis meet in the system model.

Resources