Hull Integrity: Applying MOSAICS to Naval Mission Systems
Michael Frank (Deputy CTO · Department of the Navy)
DEF CON 33 · Day 1 · Main Stage
Overview
In a revealing talk at DEF CON, Michael Frank, the Deputy CTO for the Department of the Navy, presented a critical initiative aimed at fortifying the cybersecurity posture of the U.S. Navy and Marine Corps' vast and complex operational technology (OT) and industrial control systems (ICS). Titled "Hull Integrity: Applying MOSAICS to Naval Mission Systems," the presentation delved into the strategic imperative of securing naval assets against sophisticated cyber threats, emphasizing the unique challenges posed by shipboard environments and the increasing convergence of information technology (IT) and OT.

Key moments
- 0:00 Speaker's role and background (Dept. of Navy)
- 2:00 John Boyd and the OODA Loop decision framework
- 4:00 Analyzing naval ships as complex adaptive systems
- 5:00 IT/OT challenges and critical weapon systems on ships
- 6:00 Deep dive into the Aegis weapon system
Hull Integrity: Applying MOSAICS to Naval Mission Systems
Speakers: Michael Frank, Deputy CTO, Department of the Navy
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=A6AkQrXDgQ4
Overview
In a revealing talk at DEF CON, Michael Frank, the Deputy CTO for the Department of the Navy, presented a critical initiative aimed at fortifying the cybersecurity posture of the U.S. Navy and Marine Corps' vast and complex operational technology (OT) and industrial control systems (ICS). Titled "Hull Integrity: Applying MOSAICS to Naval Mission Systems," the presentation delved into the strategic imperative of securing naval assets against sophisticated cyber threats, emphasizing the unique challenges posed by shipboard environments and the increasing convergence of information technology (IT) and OT.
The core of Frank's discussion centered on MOSAICS (More Situational Awareness for Industrial Control Systems), a Department of Defense (DoD) framework spearheaded by the Department of the Navy. This framework is designed to provide operators with a standardized set of tools, procedures, and policies to enhance the defense of critical ICS, initially developed for traditional infrastructure like bases and ports, but now being strategically applied to the intricate systems aboard naval vessels. The talk underscored the urgency of this endeavor, given the aging infrastructure of current naval fleets and the ever-present threat of great power competition, where cyber warfare could play a decisive role.
This initiative is not merely a technical upgrade but a strategic shift, recognizing that modern warfare demands an accelerated decision-making cycle—a concept rooted in Colonel John Boyd's OODA Loop (Observe, Orient, Decide, Act). By enhancing situational awareness and standardizing defensive actions through MOSAICS, the Department of the Navy aims to enable its warfighters to operate "inside the OODA loop" of potential adversaries, ensuring resilience and operational superiority in an increasingly contested cyber domain.
Background
▶ Watch: Speaker's role and background (Dept. of Navy) (0:00)
The foundation of modern military strategy, particularly in maneuver warfare, often traces back to the concepts espoused by retired Air Force Colonel John Boyd. Frank introduced Boyd's OODA Loop (Observe, Orient, Decide, Act) as a critical decision-making framework, initially conceived for fighter pilot dogfights but profoundly applicable to the cyber domain. The essence of the OODA Loop is to cycle through these four stages faster than an adversary, thereby dictating the pace of engagement and maintaining initiative. This rapid, adaptive decision-making is paramount in the context of complex adaptive systems, a concept Boyd also championed, which aptly describes the intricate, interconnected, and dynamic environments of naval operations.
Naval vessels are quintessential examples of complex adaptive systems. The U.S. Navy operates approximately 250 active ships, predominantly destroyers, but encompassing a diverse fleet of various shapes and sizes. These ships are, in essence, floating cities, equipped with an extensive array of IT and OT systems managing everything from HVAC and power generation to highly sophisticated weapon systems. The sheer volume and interconnectedness of these systems, coupled with their dual IT and OT nature, present a formidable cybersecurity challenge. The reliance on these systems for mission-critical functions, from firing weapons to intercepting incoming threats, means their integrity is directly tied to national security.
Frank highlighted two specific, highly critical systems to illustrate the complexity and vulnerability of naval mission systems:
- Aegis Weapon System: An advanced, complex weapon system that has been in service since the 1980s, undergoing continuous modernization and evolution. Aegis is designed for ship defense, integrating radars, sensors, and weapon systems to detect and intercept enemy threats, particularly ballistic missiles. Its operational effectiveness relies heavily on Industrial Control Systems (ICS) and SCADA (Supervisory Control and Data Acquisition) components, which must react at machine speed—faster than human intervention—to counter threats. The system integrates ground-based, space-based, and ship-based sensors to provide a comprehensive threat picture, making its OT components absolutely vital for kinetic response. The emergence of hypersonic weapons, as Frank noted, presents a new frontier of challenges that require even more advanced countermeasures.
- CANES (Consolidated Afloat Network and Enterprise Services): This system serves as the primary IT backbone for naval ships, supporting not only Aegis but virtually all other network-dependent operations onboard. Frank emphasized CANES's significant "hooks" into the ship's ICS/SCADA systems. Historically, IT and OT systems on ships maintained a greater degree of separation, often operating in an "air-gapped" or "diesel environment" with degraded or limited communications. However, increasing integration between IT and OT, driven by modernization and operational efficiency goals, introduces both benefits and significant risks. This convergence creates new attack surfaces and pathways for adversaries to potentially bridge the gap between enterprise IT and mission-critical OT, underscoring the need for a robust and unified defensive strategy.
The underlying problem, as articulated by Frank, is the aging infrastructure and technology present across the fleet. While dedicated personnel are constantly working to modernize, update, and defend these systems, their inherent vulnerabilities persist. This necessitates a systemic, standardized approach to cybersecurity, which is precisely where the MOSAICS framework comes into play.
Key Findings
▶ Watch: John Boyd and the OODA Loop decision framework (2:00)
The central finding and contribution presented in the talk is the development and ongoing implementation of the MOSAICS (More Situational Awareness for Industrial Control Systems) framework. This initiative represents a significant strategic shift within the Department of Defense, particularly led by the Department of the Navy, to standardize and enhance the cybersecurity of critical industrial control systems across its operational landscape.
Key findings related to MOSAICS include:
- A Comprehensive Framework: MOSAICS is not merely a piece of technology but a holistic framework encompassing a set of tools, procedures, and policies. It addresses the "people, process, and technology" aspects necessary for effective ICS defense, providing operators with a standardized approach to protecting their systems.
- DoD-Wide Impact, Navy-Led Development: While a DoD-wide effort, MOSAICS was developed specifically by the Department of the Navy at Nywick Atlantic. This highlights the Navy's proactive role in addressing critical infrastructure security challenges.
- Expanded Application to Shipboard Systems: Initially designed for more traditional critical infrastructure, such as land-based military bases and ports, MOSAICS is now being strategically applied to the unique and complex environment of naval shipboard systems. This expansion acknowledges the increasing IT/OT integration on ships and the need for standardized defense in these distributed, often communication-limited environments.
- Phased Rollout for Strategic Implementation: The framework is being rolled out in a phased approach to ensure manageable and effective implementation across a vast organization. Block 1, focusing on passive monitoring, was released in the spring, with subsequent phases (e.g., Block 2 for active monitoring, followed by response actions) planned for future deployment. This incremental approach allows for continuous improvement and adaptation.
- Standardization and Aggregation of Threat Intelligence: A critical goal of MOSAICS is to standardize ICS defense processes across the Navy. Historically, various units and commands have developed their own innovative but disparate approaches. MOSAICS aims to aggregate data from these standardized defenses, enabling the sharing of valuable threat intelligence across the entire department. This aggregation enhances collective resilience and provides a more holistic understanding of the threat landscape.
- Addressing the Innovation Adoption Gap: Beyond the technical framework, Frank identified a significant challenge in the defense sector: an "innovation adoption problem." While the U.S. has no shortage of innovative founders and private capital developing cutting-edge technologies (often outside of traditional defense primes like Lockheed or Northrop), there isn't an efficient mechanism to integrate these emerging capabilities into existing programs of record and get them into the hands of warfighters. The Department of the Navy is actively working to change this culture and streamline the acquisition process for commercial innovations.
In essence, MOSAICS is a foundational step toward a more unified, resilient, and adaptive cybersecurity posture for naval mission systems, directly addressing the vulnerabilities of aging infrastructure and the complexities of IT/OT convergence, all while striving to accelerate defensive capabilities within the OODA Loop framework.
Technical Deep Dive
▶ Watch: Analyzing naval ships as complex adaptive systems (4:00)
The technical core of Michael Frank's presentation revolves around the MOSAICS framework itself, its application context within naval systems, and the inherent technical complexities of the platforms it seeks to protect. MOSAICS is not a single tool but a comprehensive strategy, designed to bring coherence and enhanced capability to the defense of Industrial Control Systems (ICS) within the Department of the Navy.
The acronym MOSAICS stands for More Situational Awareness for Industrial Control Systems. Its primary objective is to empower operators with better means to defend the critical OT environments they manage. The framework is structured as a combination of:
- Framework: A guiding structure for implementing ICS security.
- Set of Tools: Specific technologies and software to aid in monitoring and defense.
- Procedures: Step-by-step instructions for operational security tasks.
- Policies: Departmental mandates and guidelines for ICS cybersecurity.
This "people, process, technology" approach is crucial for large, distributed organizations like the Navy. The development of MOSAICS was spearheaded by the Department of the Navy at Nywick Atlantic, demonstrating an internal commitment to solving these complex challenges.
A key technical aspect of MOSAICS is its phased implementation. The strategy acknowledges that a massive, global organization cannot overhaul its entire ICS defense posture overnight.
- Block 1, which was released recently, focuses on passive monitoring. This initial phase emphasizes collecting data from ICS environments without actively interacting with or potentially disrupting them. This is critical for establishing a baseline, understanding normal operational behavior, and identifying anomalies through non-intrusive methods. Passive monitoring might involve network tap points, specialized sensors for industrial protocols, and log aggregation from OT devices.
- Subsequent phases, such as Block 2, will introduce active monitoring and eventually move into response actions. Active monitoring could involve controlled scanning, querying devices for status, or deploying agents where appropriate—steps that require a more mature understanding of the OT environment and potential impacts. The final stages will focus on automated or semi-automated response mechanisms to detected threats, aiming to achieve the "Act" phase of the OODA Loop with increased speed and efficacy.
The application of MOSAICS to shipboard systems is particularly technically challenging. Naval vessels historically maintained a relative separation between their IT and OT networks, often operating in a "diesel environment"—characterized by distributed operations, degraded communications, and limited connectivity (sometimes referred to as air-gapped). However, Frank explicitly stated that "there has been more integration of late," meaning the traditional air gap is diminishing. This convergence of IT and OT on ships introduces new attack vectors and necessitates a unified security approach. MOSAICS aims to provide tools and standards specifically for this IT/OT connection, allowing operators to defend both sides of the network more effectively.
To illustrate the highly integrated and vulnerable nature of these systems, Frank referenced two critical naval platforms:
- Aegis Weapon System: This system is a prime example of an OT-heavy, mission-critical application. It comprises a sophisticated array of radars, sensors, and weapon systems designed for defensive operations, specifically detecting and intercepting incoming threats like ballistic missiles. The technical challenge lies in the requirement for machine-speed response. The ICS/SCADA components within Aegis are not just reporting data; they are actively controlling the physical response mechanisms—the firing of interceptor missiles, the positioning of radars, and the overall coordination of defensive actions. A cyber compromise of these ICS components could directly impair the ship's ability to defend itself, highlighting the extreme criticality of their security. The system's evolution since the 1980s implies a complex legacy architecture intermingled with modern components, creating a challenging environment for integrated security.
- CANES (Consolidated Afloat Network and Enterprise Services): As the "IT backbone for a ship," CANES provides the networking infrastructure that supports Aegis and virtually all other digital systems. Frank's emphasis on CANES having "a lot of hooks into the ICS SCADA systems on ship" underscores the technical reality of IT/OT convergence. This means that vulnerabilities in the general-purpose IT network (CANES) could potentially be leveraged to pivot into the sensitive OT systems controlling weapons and propulsion. Securing this interface—the "hooks"—is paramount. MOSAICS, by providing standards and tools, is intended to help operators manage the risks associated with this integration while still reaping its operational benefits.
The standardization aspect of MOSAICS is a technical necessity for aggregation. By mandating common tools and procedures, the Navy can collect and analyze data from individual ships in a uniform manner. This allows for the creation of a centralized repository of threat intelligence, which can then be shared back to individual ships, enhancing their local defensive posture and accelerating their OODA Loop. Without standardization, aggregating disparate data from various ad-hoc security implementations would be a near-impossible task, hindering the department's ability to achieve a holistic and proactive defense.
Demo / Proof of Concept
▶ Watch: IT/OT challenges and critical weapon systems on ships (5:00)
Due to technical difficulties experienced at the conference venue, the speaker explicitly stated that his slides were not available, and he did not have "the whole run of show." Consequently, no live demonstration or detailed proof of concept of the MOSAICS framework or its application to naval systems was presented during the talk.
Defensive Implications
▶ Watch: Deep dive into the Aegis weapon system (6:00)
The insights shared regarding MOSAICS and the cybersecurity challenges facing naval mission systems carry significant defensive implications for military and critical infrastructure operators alike. The talk underscores a shift towards a more proactive, standardized, and integrated approach to securing complex IT/OT environments.
- Prioritize and Implement ICS/OT-Specific Frameworks: The most immediate implication is the necessity for organizations operating critical infrastructure, particularly those with integrated IT and OT, to adopt and implement specialized frameworks like MOSAICS. This means moving beyond generic IT cybersecurity practices to embrace methodologies tailored to the unique characteristics, protocols, and operational constraints of industrial control systems. The phased approach of MOSAICS (starting with passive monitoring) serves as a valuable blueprint for gradual, risk-managed implementation.
- Standardize Security Processes Across Distributed Environments: The Navy's move to standardize ICS defense processes through MOSAICS directly addresses the challenges of varied, ad-hoc security implementations in large, distributed organizations. Defenders should strive to standardize their tools, procedures, and policies to ensure consistent protection levels, streamline training, and facilitate the aggregation of security data. This standardization is crucial for achieving a holistic view of the threat landscape and enabling effective threat intelligence sharing.
- Actively Manage IT/OT Convergence Risks: The increasing integration of IT and OT systems, exemplified by CANES's "hooks" into shipboard ICS/SCADA, demands a heightened awareness of convergence risks. Defenders must identify and secure the interfaces between these domains, implementing robust monitoring, segmentation, and access controls. Understanding the attack paths that could bridge IT and OT is paramount, requiring specialized expertise that spans both traditional IT security and industrial control system knowledge.
- Accelerate the OODA Loop for Cyber Defense: Michael Frank's emphasis on Colonel John Boyd's OODA Loop is a call to action for cyber defenders. The goal is to observe and orient to threats faster than adversaries can execute their attacks, enabling quicker decisions and defensive actions. MOSAICS, by enhancing situational awareness, directly contributes to accelerating this loop. Defenders should invest in capabilities that improve threat detection, analysis, and automated response to compress their decision-making cycle.
- Leverage Aggregated Threat Intelligence: The ability to aggregate security data from numerous operational units, as envisioned by MOSAICS, is a powerful defensive advantage. Organizations should establish mechanisms for collecting, analyzing, and sharing threat intelligence across their enterprise. This collective intelligence can provide early warnings, identify emerging attack patterns, and inform proactive defensive measures that benefit all connected systems.
- Embrace and Integrate Commercial Innovation: Frank highlighted the "innovation adoption problem" within DoD. For defenders, this implies actively seeking out and evaluating emerging technologies from non-traditional defense vendors and commercial startups. Streamlining procurement processes and fostering partnerships with innovative private companies can introduce cutting-edge defensive capabilities more rapidly, helping to maintain a technological edge against evolving threats. This requires a cultural shift towards openness and agility in adopting external solutions.
- Address Legacy System Vulnerabilities: The acknowledgment of aging infrastructure on naval ships points to a pervasive challenge across many critical sectors. Defenders must develop strategies for securing legacy ICS that may not support modern security controls. This could involve compensatory controls, network segmentation, continuous monitoring, and prioritized modernization efforts to replace or upgrade the most vulnerable components.
In summary, the talk provides a clear roadmap for enhancing the resilience of critical infrastructure by combining strategic frameworks, technological standardization, and an adaptive mindset focused on outmaneuvering adversaries in the cyber domain.
Key Takeaways
- MOSAICS (More Situational Awareness for Industrial Control Systems) is a critical DoD framework, led by the Department of the Navy, designed to standardize and enhance the cybersecurity of industrial control systems across naval operations.
- Naval mission systems, exemplified by the Aegis weapon system and CANES (Consolidated Afloat Network and Enterprise Services), are highly complex IT/OT environments with critical interdependencies that demand specialized, robust cybersecurity defenses.
- The increasing integration of IT and OT on naval vessels, while offering operational benefits, introduces new attack surfaces and necessitates a unified security strategy to manage associated risks effectively.
- The OODA Loop (Observe, Orient, Decide, Act) framework is a strategic imperative for cyber defense, emphasizing the need to accelerate decision-making and action faster than adversaries to maintain operational superiority.
- The phased implementation of MOSAICS, starting with passive monitoring (Block 1), aims to standardize processes, aggregate threat intelligence, and improve the overall resilience and security posture of the fleet.
- Addressing the "innovation adoption problem" by streamlining the integration of emerging commercial technologies into defense programs is crucial for maintaining a technological advantage against evolving cyber threats.
About the Speaker(s)
Michael Frank currently serves as the Deputy CTO for the Department of the Navy, a role that encompasses both the Navy and the Marine Corps. In this capacity, he is responsible for surveying the broad landscape of technology areas to identify and facilitate the adoption of advanced capabilities for sailors and marines. Beyond his civilian role, Frank is also a Marine Reservist, where he leads the cyber portfolio for the Marine Innovation Unit (MIU), focusing on getting the most capable and emerging technologies into the hands of warfighters. Prior to his tenure in the Pentagon, Frank spent approximately eight years as a cybersecurity consultant, advising both private and public institutions, including financial, healthcare, insurance companies, and various DoD clients, with a focus on digital transformation and cyber security.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Frank has a real seat — Deputy CTO, DoD Navy, Marine Reservist running MIU's cyber portfolio — and MOSAICS is a legitimate program worth knowing about. But the talk lands closer to a program overview than a substantive insider briefing: Block 1 passive monitoring, Block 2 active monitoring, eventual response actions. There's signal here, but it's thin signal, and the no-slides situation didn't help.
Heather Calloway (CISO) — SOLID
Frank is a credible voice on a real problem — IT/OT convergence in naval mission systems is a genuine national security risk — and MOSAICS is a substantive institutional response worth knowing about. But this talk operates at program-announcement altitude: it describes the framework without demonstrating it, and the defensive implications it offers are generic enough to apply to any OT environment. It's a useful signal for anyone tracking DoD cybersecurity posture, not a session that changes how a defender operates.