Through Operation StormBreaker, mission owners can inherit about 80% of all security controls and move software into production in as little as 15 minutes.
One of the biggest obstacles to delivering capabilities to warfighters is the process that governs the authority to operate.
For many systems, it can take up to 18 months to get the security approval to put the application on the Defense Department’s network. That timeline fails to support immediate mission needs of warfighters.
But what if a commander could obtain an ATO for an urgent requirement in 15 minutes? That is what Operation StormBreaker is offering to military services and Defense agencies.
“We built a greenfield capability. It’s a cloud-native enclave to support this modernization effort for our own organization, following all the DoD CIO guidance for a continuous ATO, DevSecOps and often other modern things, and mirroring ourselves to the highest degree we can, with both commercial technology and commercial support,” said David Raley, chief digital business officer of the Marine Corps Community Services on Federal News Network’s DoD Modernization Exchange 2026.
“We are using commercial best practices to actually deliver software. We now have a technically mature, secure and compliant platform that allows us to deliver workloads into production within 15 minutes with an authorization.”
Operation StormBreaker relies on agile development practices using a continuous integration/continuous delivery pipeline. This lets users build and release new software code multiple times a day and obtain a new authorization each time through an automated process.
Raley said commanders using Operation StormBreaker can increase cycle times to meet warfighter requirements without the constraints of having to obtain an ATO on their own.
“It’s almost like a white-glove, all-inclusive type of service. So if you’re a mission owner with no interest or capacity in cybersecurity or creating the underlying infrastructure and doing things like that to support an application, but you have the need to quickly acquire some commercial technology for example, an application to run and you need a place to hosting an ATO, that’s what StormBreaker specifically is designed for,” he said.
“It’s a tiered control inheritance enclave that supports about 85% of the controls. It is a shared responsibility model. There are certain responsibilities that the platform team has when it comes to security controls and the authorization piece. We drive it, and we manage it. We have all the requisite security compliance staff that you might expect, like security control assessors and validation teams.”
The mission owner is responsible for the other 15% of the process. Raley said that includes getting the sign off from their security compliance experts.
Growing interest among mission ownersBut through the platform, the mission owners inherit all the processes that support and automate the security reviews of the code, the creation of a software bill of materials and mitigate any vulnerabilities found during the scan. The code is built and scanned in containers, so any changes are automatically rescanned for vulnerabilities.
Any problems are fixed and tested again. Raley said typically that all takes a small amount of time, sometimes as little as 15 minutes, and the code is pushed into production.
Currently, Operation StormBreaker is supporting applications from the Marine Corps and the Defense Innovation Unit. Raley said there is a growing interest in using the platform, especially from vendors who are struggling to get an authorization under FedRAMP or through the DoD Impact Level process.
“I’m seeing a massive gap where vendors, who have this very compelling technology like quantum and artificial intelligence, and it solves this really big problem. They meet with a mission owner, and the mission owner asks, ‘Do you have a FedRAMP [authorization]?’ Very often, they don’t yet. They don’t have an ATO either and the mission owners don’t know what to do with that,” Raley said. “So the mission owner turns this vendor away, and says, ‘We really don’t have any way to leverage your technology.’ I’ve started educating some of these vendors about providing a pathway to production for them and their customer mission owners. There’s a lot of appeal from that perspective.”
Raley said he has several agreements in the works to host or build a product for DoD offices.
“About 80% of my customers that I’m supporting are other components across the Department of War that have come to me because I had an initial interaction with a vendor who found out about how Operation StormBreaker works,” he said.
“The sad part about this is that there are vendors out there who have entered into engagements with a DoD component and their software is sitting idle, and sometimes for multiple years, because they can’t solve these same [security] problems. Those vendors, while they’re making money, that’s not what their mission is. Their mission is to support these warfighter capabilities. When they find out there’s a way that we can solve pain for them and their mission owner that might be really efficient, it gets them really fired up about that.”
Cheaper than going at it aloneThere is a cost for Operation StormBreaker and the white-glove services it provides.
Raley said that many times he has to explain why the costs are actually cheaper for the mission owner than they initially thought because so many mission owners don’t directly pay for their cybersecurity services or application platforms.
“I did my own analysis internally. It’s about a $1 million just to get an ATO for a system in the traditional way, and it takes 12 to 18 months. So, if you multiply that across the department and the 5,500 authorization packages that currently exist, you start to see a cost of about $8.9 billion every three years that is spent or wasted on the ATO process,” he said.
“The way I would describe that too is an ATO process takes 8,200 FTE years across those 5,500 authorization packages, every three years. So those are the types of things you look at that. The cost associated with the actual authorization process and all the costs that are baked into that, including the hosting environment, the cloud native access points, the identity management and all the underlying security tools and services, are much less than doing the ATO process on your own.”
Raley noted that Operation StormBreaker is in the production phase and ready to scale up by adding dozens more customers.
“One of the reasons why I’m so interested in generating additional revenue through this and supporting other workloads is it’s going to allow me to scale the platform up and increase its capability. Everything else I’m hearing in terms of what the customers are demanding, I want to be able to react to that based on the way we approach business,” he said.
“One of the other things that I want to be really careful about when highlighting the platform is, because we are a government organization inside the Marine Corps and my parent organization runs all the quality of life programming for Marines and their families on bases, any revenue that’s generated here just goes back into supporting those programs for Marines. So this is actually a really great fit from that perspective, where anything that’s being supported through this platform is actually going back to benefit Marines and their families.”
Discover more articles and videos now on the DoD Modernization Exchange event page.
Copyright © 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | DoD Modernization Exchange 2026: Navy’s Scott St. Pierre on modernizing the service’s enterprise information ecosystem | 0 | 12.71 | 06-04-2026 |
| 2 | Federal Executive Forum IT Modernization and Transformation in Government 2026 Progress & Best Practices | 0 | 14.05 | 13-04-2026 |
| 3 | Federal Executive Forum Secure Data Sharing Strategies in Government 2026 Progress & Best Practices | 0 | 14.69 | 27-03-2026 |
| 4 | STRATCOM: Modernization Effort ‘Once-In-Every-Other-Generation’ | 0 | 24.6 | 05-08-2026 |
| 5 | 5 Best Kubernetes Security Tools in 2026: Full Breakdown | 0 | 5 | 06-05-2026 |
| 6 | Under new management: the Pentagon’s autonomous systems get new oversight | 0 | 5 | 02-07-2026 |
| 7 | Army overhauls software acquisition to speed delivery | 0 | 11.94 | 27-08-2026 |
| 8 | Hacked, leaked, and held for ransom: The worst breaches of 2026 so far | -2 | 7 | 07-06-2026 |
| 9 | Navy tracking efficiency gains as part of AI training efforts | 0 | 8.75 | 01-05-2026 |
| 10 | Why Role-Based Access Control Isn't Enough for OT Security | 0 | 5 | 28-06-2026 |