Digital Force Protection (DFP) is force protection extended into the digital, electronic, and signature domain. It protects personnel and operations from the exposure created by their electromagnetic, cyber, and commercial-data footprint by measuring and managing the aggregate signature an adversary could fuse from device emissions, location data, social media, and other observables.
The one-line version: DFP is seeing your own signature the way a fused adversary would see it, then controlling what that signature reveals.
Why Digital Force Protection exists
Traditional force protection assumed physical threats: perimeter defense, access control, protective details, hardened facilities. Traditional OPSEC assumed an adversary who had to task dedicated collection against you. Both assumptions broke when the surveillance environment became ubiquitous, persistent, commercial, and retroactive.
Ubiquitous Technical Surveillance (UTS) is the condition in which the digital and physical traces left by ordinary activity are so pervasive, persistent, and cheaply fused that an adversary can reconstruct identity, location, associations, and pattern of life without tasking dedicated collection. UTS operates across five threat vectors:
- Online: browsing history, search, social media, LLM interactions
- Electronic: device emissions (cellular, Wi-Fi, Bluetooth, TPMS, wearables)
- Visual-physical: cameras, license plate readers, biometrics, facial recognition
- Financial: transaction records, loyalty programs, payment identifiers
- Travel: bookings, reservations, border crossings, transportation records
Any one vector is a nuisance. Overlaid, they are a targeting product. The adversary does not work on one vector at a time. The power of UTS is in data fusion products that collapse individually weak signals into identity with a schedule.
In April 2026, U.S. Central Command confirmed to Congress that commercial location data had been used to target or surveil U.S. personnel in an active theater. The data was not obtained through a device compromise. It was part of the commercial surveillance ecosystem. That confirmation is what made the problem undeniable at the institutional level.
Digital Force Protection is the operational response: measuring and managing the signature that UTS collects, before an adversary can exploit it.
The DFP problem: you cannot manage what you cannot see
The fundamental challenge is that most organizations do not know what they emit. They have never measured their aggregate signature across all five UTS vectors. They audit one domain at a time (cybersecurity for the network, OPSEC training for social media, physical security for the perimeter) and assume the sum is covered.
It is not. The adversary runs the join across all vectors simultaneously. A defender who audits one vector at a time is playing a game the adversary is not playing.
The correct unit of measurement is the fused picture an adversary could build. That means:
- What devices are emitting inside your fence line, and can you account for all of them?
- Which of those devices correlate with each other in ways that reveal team membership?
- What does the commercial advertising ecosystem know about your personnel's movements?
- What does your open-source footprint reveal when aggregated across all members, families, vendors, and public affairs?
- Which approaches to your facility show recurring unknown devices at operationally significant times?
- If you turned off every device, would the absence itself become an observable?
Until you can answer these questions with data rather than assumptions, "low signature" is a story the organization tells itself.
Core DFP capabilities
A Digital Force Protection system operates on the same Sense - Make Sense - Act continuum as any fusion architecture:
Sense: device census and environmental baseline
The first step is building a fused inventory of all electromagnetic emitters within a defined volume of space, correlated across radio types (cellular, Wi-Fi, Bluetooth, satellite, vehicle telemetry, industrial IoT) and over time.
No single sensor produces a complete census. Carrier visibility, network telemetry, passive RF observation, MDM inventory, access-control records, asset registries, and physical surveys each reveal different portions of the environment. Reconciling them produces the device census.
The census answers: what is authorized, what is expected but unmanaged, what is environmental background, what is a known unknown, what appears only during specific activities, and what disappears during those same activities.
The number of detected emitters is always higher than the badge count. It always includes devices nobody can account for. That gap is where the vulnerability lives.
Make Sense: fusion, co-travel, and anomaly detection
Raw emitter data becomes intelligence through fusion:
Co-traveler analysis identifies entities whose movements repeatedly correlate with a target of interest. Defensively, it answers: which unknown devices are shadowing a protected person or asset, and which of our own devices are correlating in ways they should not? A protective detail that repeatedly converges with the principal is the vulnerability that got Khamenei killed, his bodyguards' pattern of life resolved him.
Anomaly detection over approaches identifies devices or vehicles that recur along ingress routes at a periodicity that does not match any explicable population. The adversary rehearses before you ever see him, and commercial location data resolves the approaches without physical presence.
Pattern-of-life reconstruction builds behavioral models of the defended element's own routines, identifying which patterns are predictable enough to exploit and which countermeasures have actually changed the observable pattern versus merely adding a compliance checkbox.
Identity resolution connects observations across time, linking replacement devices to previous identities through behavioral continuity rather than static identifiers. A burner phone that reproduces the old phone's pattern of life is not a new identity; it is another selector attached to the same person.
Act: policy, alerting, and measurement
The fusion layer feeds a policy engine that automates response:
- Alert when an unaccounted-for emitter appears inside a restricted zone
- Alert when co-travel scores exceed threshold for a protected person
- Alert when the aggregate signature of a formation deviates from the expected envelope
- Alert when cell-site simulator or GNSS interference is detected
- Produce measures of effectiveness: can a red team still resolve the unit after the countermeasure was applied?
The distinction between measures of performance (was the control executed?) and measures of effectiveness (did the control work?) is load-bearing. A dashboard showing 100% device compliance is useful. A system demonstrating the adversary can no longer resolve the unit is force protection.
The advertising ecosystem as a targeting architecture
The commercial advertising infrastructure is the single largest contributor to the UTS problem:
Real-time bidding (RTB): When an application has ad space to fill, it broadcasts a bid request containing the device's advertising identifier, GPS coordinates, timestamp, device model, OS, and application context to hundreds of potential buyers. Only one wins the auction, but every participant keeps the data. Anyone who can present themselves as a plausible ad buyer receives a global location firehose.
Software development kits (SDKs): Data brokers pay developers to embed SDKs that report location continuously and directly. Weather apps, navigation apps, dating apps, fitness apps, and family-safety apps all have defensible reasons to request location permission. The user consented in a modal dialog they dismissed to see the weather.
Mobile advertising identifiers (MAIDs): The IDFA (iOS) and GAID (Android) are persistent selectors that let a collector pull every record associated with one device. They are user-resettable but rarely reset, and an entire industry exists to resolve MAIDs to real identities for a fee.
Identity resolution services: Companies that accept a MAID and return names, email addresses, and physical addresses, marketed as a routine marketing service. The de-anonymization step is merely another product.
None of this is illegal in most of the world. None of it is a data breach. The entire architecture is functioning exactly as designed. Its design output is a real-time global movement database of unprecedented resolution, offered for sale by companies whose names you have never heard. Our adversaries are customers on it.
DFP for distributed forces: EABO and Stand-In Forces
The Indo-Pacific theater presents the most demanding DFP challenge. Expeditionary Advanced Base Operations (EABO) and Stand-In Forces (SIF) place small teams at austere sites inside contested areas, embedded in host-nation cellular networks, host-nation power, and civilian populations carrying thousands of emitting devices.
On small islands with limited roads, ports, and settlements, a device census is a tractable computational problem for anyone with the data. The People's Republic of China has invested more heavily than any other state in exactly this technology stack, and Salt Typhoon demonstrated persistent access to telecommunications infrastructure across the theater.
The phase of the conflict where UTS does the most damage is the phase before the conflict. The adversary spends the decade before the fight quietly assembling pattern of life for every logistics node, every fuel contract, every dependent school, every port call, in a database queried on day one.
A force that has never measured what it emits believes it is concealed. That gap between believed and actual signature is where the first day of a war gets decided.
DFP is not a privacy checklist
Marine Corps doctrine describes signature management as a deliberate, mission-focused component of operations security: understand friendly signatures and indicators, understand how the adversary can collect and analyze them, apply countermeasures to mask them, and project signatures that complicate the adversary's understanding when necessary.
The objective is not zero emission. It is controlled ambiguity: a signature consistent with the mission, stable across time, compatible with the surrounding environment, and difficult for the adversary to interpret correctly.
This means:
- Signature management is measured and shaped, not suppressed
- Going dark is one maneuver inside a larger problem, not a solution
- Perfect hygiene practiced by a tiny minority looks deliberate, not invisible
- The relevant boundary is the operational graph (the team, its support, its families), not the individual
- A countermeasure that has never been tested against realistic adversary analytics is an assumption, not a defense
Where Empyrean fits
Empyrean's Digital Force Protection capability is built on seeing your own signature the way a fused adversary would see it:
- Device census across radio types, correlated over time into tracks with identity resolution
- Co-travel detection answering whether unknown devices are shadowing a protected person or asset
- Anomaly detection over approaches surfacing recurring vehicles or handsets at operationally significant periodicity
- Cell-site simulator and GNSS interference detection identifying active threats in the electronic vector
- Edge-deployable and air-gap capable because a force protection tool that phones home is an instrument of the problem it claims to solve
The platform fuses the same external feeds an adversary would use (commercial ALPR, wardriving and positioning databases, imagery, open-source footprint) so the picture you audit is the picture they can assemble.
The doctrine is simple: Sense, Make Sense, Act. Sense is the census. Make Sense is the fusion layer. Act is the policy engine. The adversary has all three. Most defenders have none of them, and awareness without measurement is superstition.
See Digital Force Protection capability and Digital Force Protection FAQ.