Navy's "Clean Install" Strategy Overcomes Hostile Networks
The Navy's Quiet Revolution: How a "Clean Install" on Hostile Networks Creates a National Security Advantage
This conversation reveals a critical, yet often overlooked, vulnerability in the fabric of modern life: the compromised nature of global cellular infrastructure. The immediate implication of the Salt Typhoon breach--China's deep infiltration of major US carriers--is chilling, exposing lawful intercept capabilities and the potential for mass surveillance. However, the deeper consequence, illuminated by Justin Finelli (CTO of the Navy) and John Doyle (CEO of Kape), is the realization that assuming existing networks are hostile is not paranoia, but prudent strategy. This discussion is essential for defense technologists, government contractors, and cybersecurity professionals who need to understand how to build and deploy secure solutions in an increasingly compromised digital landscape. It offers a blueprint for leveraging commercial innovation to achieve national security objectives, providing a distinct advantage to those who grasp the necessity of operating from a baseline of assumed hostility.
The Hostile Network Assumption: A Foundation for Resilience
The revelation of "Salt Typhoon"--China's sophisticated infiltration of major US cellular carriers--shattered the illusion of secure telecommunications for many. John Doyle, CEO of Kape, vividly recounts a Davos cyber forum where, among 60 cybersecurity professionals, only five had heard of the breach, underscoring a widespread lack of awareness regarding the depth of this compromise. This infiltration grants adversaries the ability to listen to phone calls, access lawful intercept points, and control communications, effectively rendering vast swathes of the US cellular infrastructure untrustworthy. The immediate consequence is a profound erosion of privacy and national security.
However, the conversation pivots from alarm to strategy. Doyle explains Kape's foundational principle: a "clean install of a telco on top of the existing physical infrastructure." This isn't about patching a leaky ship; it's about building a new, secure vessel designed to sail on potentially hostile waters. The core insight here is that attempting to "ferret through the existing carriers... and find all the China and try to get rid of it" is a Sisyphean task. Instead, the more effective approach, tested by the Navy on Guam, is to assume the underlying physical network is compromised and build security into the software layer. This proactive stance, anticipating threats rather than reacting to them, is where lasting competitive advantage is forged.
"Rather than trying to ferret through the existing carriers on Guam and find all the China and try to get rid of it, let's just do a clean install of a telco on top of the existing physical infrastructure. Just assume it's hostile."
-- John Doyle
This philosophy directly challenges conventional wisdom, which often prioritizes speed and cost-effectiveness by leveraging existing, unverified infrastructure. The downstream effect of this conventional approach, as exemplified by the Salt Typhoon breach, is a compounding vulnerability. Kape’s model, conversely, creates a resilient network of networks, renting capacity from multiple providers to avoid single points of failure. This resilience is not merely about uptime; it's about maintaining operational capability even when the physical underpinnings are compromised. The Navy's adoption of this strategy, particularly in sensitive locations like Guam, highlights the urgency and the strategic value of this "hostile network" assumption.
From Bureaucratic Inertia to Agile Adoption: The Navy's Internal Transformation
Justin Finelli, CTO of the Navy, offers a crucial perspective on the internal shifts necessary to embrace such innovative solutions. He describes a Navy that, for decades, was structured around acquiring complex hardware with long lead times, a process ill-suited for the rapid pace of software development and commercial innovation. The "barbell strategy" Finelli mentions -- excelling at the high-end, complex systems while struggling with the lower, commercial end -- points to a systemic issue of procurement and acquisition processes optimized for a different era.
The bottleneck, Finelli argues, was not a lack of talent or technology in the private sector, but an "inside out" problem within the government: a lack of internal education, training, and a willingness to adapt. The traditional approach of "make everything yourself, innovate" was replaced by a new imperative: "let's be adopters of innovation." This shift required a fundamental re-education of program managers and contracting officers through initiatives like bootcamps, designed to accelerate processes from 18 months to three months. This internal transformation is a critical, non-obvious insight: for external innovation to succeed, the internal mechanisms of adoption must evolve in parallel.
"The primes have had 70 years to refine their go-to-market motion of how to sell to the government. They already know how to do it, and it's a new muscle for startups to build."
-- Justin Finelli
This internal agility is what enabled the Navy to partner effectively with Kape. The traditional defense acquisition system, hinging on a slow "requirements axis," was bypassed. Instead, Finelli’s team focused on "little bets that could turn into big bets" through pilots, funded by entities like the Defense Innovation Unit (DIU). This approach, characterized by defining clear "world-class alignment metrics" (WAMs) upfront, ensured that success was measurable and that both the Navy and Kape were aligned on objectives. The successful pilot in Guam, which validated Kape's secure network over potentially compromised infrastructure, occurred precisely when the Salt Typhoon breach became public knowledge, demonstrating the power of proactive, agile adoption. This highlights how embracing difficult, time-consuming internal change can yield significant future advantages.
The Power of Unclassified Validation and Shared Success
A significant hurdle for defense technology startups is the lengthy and often opaque validation process. John Doyle highlights a critical innovation that facilitates broader adoption: unclassified and shareable tech evaluations. The example of an independent third-party penetration test on Kape's technology, paid for by DIU and made unclassified, illustrates a powerful flywheel effect. This report not only validated Kape’s capabilities for the Navy but also became a shareable asset for cross-service adoption, for fundraising, and for other government customers.
This mechanism directly addresses the "inside out" problem Finelli described. By declassifying and sharing these evaluations, the government reduces the redundant effort required for each new agency or service to independently vet the same technology. This dramatically lowers the barrier to entry and accelerates adoption. For founders, this means that a successful pilot, especially one with a shareable validation report, can unlock opportunities across multiple government entities. The implication is that companies focusing on clear, measurable outcomes and robust, shareable validation are best positioned to navigate the defense technology landscape.
"A really powerful thing is unclassified and shareable tech evaluations. ... And that has really positive effects for the company because we don't have to convince people that it works and does what it says that it does."
-- John Doyle
This model transforms the traditional, adversarial relationship between government and industry into a collaborative one. When the government invests in rigorous, shareable validation, it not only de-risks technology adoption but also empowers innovative companies to scale more rapidly. This, in turn, allows these companies to invest more in government-focused work, creating a virtuous cycle. The success metrics (WAMs) discussed earlier are not just for contract fulfillment; they become the data substrate for this flywheel, providing the objective evidence needed to justify further investment and broader deployment. This focus on measurable outcomes and shared validation is a key differentiator for companies seeking to build lasting impact within the national security apparatus.
Key Action Items
- Adopt a "Hostile Network" Mindset: Assume underlying infrastructure is compromised and design security into software and architecture from the ground up. (Immediate)
- Prioritize Measurable Outcomes: Define clear, quantifiable "success metrics" (WAMs) for any proposed solution before engagement, focusing on tangible results like resilience or pain relief. (Immediate)
- Seek Unclassified Validation: Actively pursue independent, unclassified technical evaluations of your solutions, as these can significantly accelerate adoption across government agencies. (Short-term: 3-6 months)
- Invest in Internal Education: For government agencies and large organizations, conduct targeted training (e.g., bootcamps) to re-educate acquisition and program management teams on modern software acquisition and commercial partnership models. (Medium-term: 6-12 months)
- Build a Network of Networks: For critical infrastructure providers, explore architectures that leverage multiple, diverse physical infrastructure providers to enhance resilience against single-point failures. (Long-term: 12-18 months)
- Focus on "Taking Systems Out": When proposing new software solutions, clearly articulate which existing, redundant systems will be retired, demonstrating a commitment to divestment and modernization. (Immediate)
- Be a "Bridge Builder": For individuals and companies, actively seek opportunities to connect innovators with government needs, facilitating communication and understanding between disparate communities. (Ongoing)