US Cyber Command ordered to act on operator mental health

US Cyber Command ordered to act on operator mental health

The Pentagon has given U.S. Cyber Command a list of mandatory, time-bound steps to protect the well-being of its personnel. The order follows reports earlier this summer of a cluster of suicide deaths at the command.

The instructions are in an unclassified memo dated August 31, written by Katherine Sutton, the Pentagon's assistant secretary for cyber policy and principal cyber adviser. It is addressed to Army Gen. Joshua Rudd, who leads Cyber Command. Recorded Future News obtained the document exclusively.

"As we look to expand and enhance the long-term resilience and readiness of our cyber forces, we must establish formal, proactive structures to support our operators," Sutton wrote.

It is not known whether daily workloads played a role in the deaths. The memo, however, shows that senior officials are considering that possibility. It says the "continuous, high-tempo nature of ongoing active cyber operations imposes a unique cumulative, cognitive and psychological toll." It also notes that, unlike traditional kinetic forces, cyber teams have no standardized recovery periods between deployments, which affects retention and long-term analytic performance.

Seven steps, tight deadlines

Sutton asked the command to move "from a reactive posture to a systematic, proactive force preservation model" through seven measures.

Within 30 days, Cyber Command must:

  • hand over four years of historical organizational climate survey data and standardized exit interview summaries, so officials can set a health baseline for the force
  • finalize an agreement with the National Security Agency to share mental and behavioral health professionals inside the operational spaces of the Cyber Mission Force (CMF), the command's main operational arm

The NSA shares the Fort Meade, Maryland, site with Cyber Command, and Rudd leads both. The memo describes the shared staffing as an interim capability until permanent support is in place.

By mid-October, the command must set up a Cyber Occupational Resiliency and Engagement Framework to support operator wellness and performance over the long term. It must also introduce force employment and "dwell phasing" measures meant to make recovery more predictable and reduce cumulative strain within the CMF.

Other steps include:

  • a 60-day review of consecutive tour policy, with a proposal that adds career pathing, technical instructor duties and educational assignments to break up continuous operational stress
  • appointing a co-lead for the Governance and Cyber Wellness Working Group, who will also act as the main liaison between Fort Meade and Sutton's office
  • working with the Defense Department and the Joint Staff to prioritize digital warfighting campaigns in a way that weighs operational demands against long-term force health. That planning process usually starts in the spring and takes most of the year.

Several of these items trace back to commitments the department made after the fiscal 2024 defense policy bill required a study of the CMF's "occupational resiliency." A source familiar with the memo said many of the benchmarks were already part of the "Cyber Command 2.0" implementation plan, the department's overhaul of the command. Following the deaths, some were moved forward by years. The source suggested that the new Cyber Talent Management Organization, created under that overhaul, would likely lead many of the efforts, but raised concerns that it is still in development.

The Pentagon and Cyber Command did not respond to requests for comment before publication.

"Our surge just became the pace"

At HammerCon, the annual event of the Military Cyber Professionals Association, officials described the pressure on operators in plain terms.

Air Force Col. Dan Kim, senior military adviser in Sutton's office, said the department is working on "optimized unit phasing." This would allow operators who are "most of the time 100% in contact" with adversaries to step away from their keyboards regardless of operational demands. He added that the command is developing "elite performance modeling" based on U.S. Special Operations Command's Preservation of the Force and Family program.

Col. Bryon Owen, chief of staff at Marine Forces Cyberspace Command, said: "At some point, our surge just became the pace." His branch requested badges so chaplains and religious program specialists can enter operational spaces. According to Owen, troops began asking for time to talk for the first time, and he called the change "life changing."

Lt. Gen. Christopher Eubank of Army Cyber Command recalled that two weeks into Operation Epic Fury, the military's eight-month-old conflict with Iran, he "had to tell people to go look at clouds. Touch grass." His team found that operators' hobbies resembled their work, such as late-night gaming before returning to do the same thing again the next day. "We had to actually institute ... rest plans," he said, adding that it "should have been a blinding flash of the obvious, probably."

Why It Matters

Discussions about cyber workforce capacity usually focus on hiring and skills. This memo looks at a different problem: how long people can keep up offensive and defensive operations without built-in recovery time. Many civilian security teams will recognize the pattern officials described, where a "surge" quietly becomes the normal pace, as in round-the-clock incident response or SOC rotations.

Commitments made under the fiscal 2024 bill were only accelerated after a crisis. This suggests that formal resiliency programs had not been treated as urgent until then. Two things are worth watching: whether Cyber Command meets the October deadlines, and whether the still-developing Cyber Talent Management Organization can take on this work. It is also unclear whether "dwell phasing" can hold up while the conflict with Iran continues to drive operational tempo.

If you or someone you know is struggling, please reach out to a local crisis line or emergency services.