The Surveillance Gap in the NDAA
The Fiscal Year 2027 National Defense Authorization Act includes a provision that would force the Pentagon to confront a shadow threat: adversaries buying commercially available location data to track U.S. forces. Erik Wittreich, a former U.S. Army Green Beret and CEO of the multi-domain tech firm Veilant, warned Military.com that the ubiquitous technical surveillance (UTS) enabled by apps like Waze and Uber amounts to "an operational terrain" that the Defense Department has so far failed to own.
The problem is simple but sweeping. Most smartphone users opt into sharing their location and digital habits with ad-tech and marketing platforms. Wittreich argues that hostile states can purchase that data, then piece together troop movements and facility patterns—just as a BBC report did when a sailor’s routine use of the fitness app Strava inadvertently exposed the location of the French nuclear-powered aircraft carrier Charles de Gaulle. "If publicly available data can expose the location of an allied aircraft carrier, we should assume sophisticated, near-peer adversaries like China are already intentionally using the same methods," Rep. Ronny Jackson (R-Texas) wrote in a recent editorial.
The NDAA language, shaped by Jackson, would require the secretary of defense to designate a single organization and leader responsible for UTS—addressing the current vacuum where no one in the department "has responsibility over UTS," Wittreich said. That official would then develop a strategy for research, development, and procurement of secure communications and obfuscation technologies. With bipartisan backing, the provision is widely expected to survive Senate negotiations and become law.
Why a Former Green Beret Sees UTS as the New Operational Terrain
From a Green Beret's Warning to a Legislative Push
Wittreich spent about 48 months in Iraq and Afghanistan before founding Veilant, which originally focused on defensive communications when the company realized that the military’s own tools for exploiting cellphone signals—such as "Stingray" devices—could one day be turned against U.S. forces. His message to Congress: the government has been "frozen" on UTS because it sounds daunting, but small initial steps can make it a solvable operational problem. Rep. Jackson, a former Navy officer on the House Armed Services Committee, has become the issue’s leading advocate on Capitol Hill, and the alignment with an industry voice gives the provision both legislative momentum and a concrete use case.
The Missing Owner at the Pentagon
Currently, no single entity coordinates UTS policy across the services and geographic combatant commands. Wittreich likens the challenge to any other terrain that commanders must control. The draft language would create a senior-level official—likely reporting directly to the defense secretary or deputy—to "codify a UTS strategy" and eventually stand up a program of record. That structure would enable the services to make operational decisions tailored to their force dispositions, while still ensuring buy-in at the highest level. Wittreich’s insistence that the appointee also liaise with combatant commands points to the practical difficulty: a policy that works for garrison training may not protect troops deployed abroad.
Turning a Defensive Problem into Offensive Opportunity
While UTS is often framed as a defensive worry, Wittreich argues it can be leveraged offensively. "We can exploit our adversaries' digital signatures," he said, implying that effective UTS management isn’t just about closing holes but about turning the same techniques back on rivals. That dual-use potential could broaden the coalition behind the NDAA provision and shape the kind of technologies the designated office pursues—likely a mix of signal obfuscation, data-buying countermeasures, and intelligence-gathering capabilities that mirror what adversaries do today.
What the Military and Its Contractors Should Do Next
For the Pentagon: Appoint and Empower a UTS Lead
- A named official must have the authority to coordinate across all services and combatant commands, not just draft a paper strategy. Wittreich specifically suggests the appointee report to Secretary Hegseth or Deputy Secretary Feinberg.
- Operational units need clear rules on personal device usage—the French carrier incident shows a single Strava user can compromise a major asset.
- Budget and procurement timelines should be aligned with the threat; the provision’s bipartisan support suggests funding will follow, but the lag between strategy and fielded tools can be years.
For Defense Contractors: Prepare for New Solicitations
- The NDAA language envisions a program of record for secure communications and obfuscation technologies. Companies like Veilant that already offer defensive solutions will be early contenders, but larger primes should expect to integrate UTS countermeasures into existing platforms.
- The dual-use nature of the capability—defensive and offensive—could open contracts across intelligence, cyber, and electronic warfare portfolios. Wittreich’s framing of UTS as an "opportunity" to be exploited suggests future requirements will extend beyond passive protection.
- Firms with expertise in commercial data aggregation and ad-tech could find themselves pulled into the defense ecosystem, either as subcontractors or as sources of insight into how adversaries buy and interpret location data.
Risk & Opportunity Assessment
| Commercial Risk | Medium | If UTS countermeasures aren't adopted broadly, military operations remain vulnerable to low-cost adversary tracking, but the threat is not yet causing direct battlefield losses. |
| Competitive Risk | Medium | Traditional defense contractors may need to pivot into commercial-data obfuscation markets, potentially losing ground to agile startups like Veilant that already focus on this problem. |
| Regulatory Risk | Medium | The final NDAA language and subsequent implementation could be watered down or delayed, leaving the 'no single owner' problem unsolved. |
| Reputation Risk | Low | No major reputation risk for the DoD beyond general concern that the department appears slow to address a well-documented vulnerability. |
| Technology Disruption | Medium | The ability to buy commercial data for military tracking is a genuine disruptive capability that compels a shift in operational security, but the response will likely involve evolutionary communication upgrades rather than a revolutionary leap. |
| Commercial Opportunity | High | A designated UTS program of record would open a new funding stream for secure communications, obfuscation tech, and possibly offensive data exploitation—directly benefiting companies like Veilant. |
Comments 0