Education
Whitepaper | The Economics of Ubiquitous Technical Surveillance: Why Watching Us Got Cheap, & How We Make It Expensive Again
By: Michael Stokes, SVP of Emerging Technologies
A Veilant white paper. Fourth in the series following Operating Beyond Obscurity, From Awareness to Readiness, and Legibility Is Now the Default.
Executive Summary
Ubiquitous technical surveillance (UTS) is usually briefed as a security problem. It is also an economic one, and that framing gives senior leaders something to act on. Our adversaries can now target the force cheaply while we spend heavily to build the capabilities that surveillance exposes. The Department of War invests billions to field a sensitive capability. An adversary can begin to unravel it for the price of a commercial data subscription. Disciplined signature management is how we change that ratio and make watching us expensive again.
Two shifts drove the cost of targeting U.S. persons toward zero. Analysis got cheap: Stanford’s 2025 AI Index reports that the cost of querying a model at GPT-3.5 level fell from twenty dollars per million tokens in late 2022 to seven cents by October 2024, a drop of more than 280 million times. And collection became ambient. Phones, vehicles, connected homes, and commercial data brokers turn ordinary life into a sensor layer, a condition the Office of the Director of National Intelligence has formally recognized in its framework on commercially available information.
Together those shifts produce one asymmetry. Building a capability is expensive. Exposing it is cheap. Records on individual U.S. service members have sold for about twelve cents each. The Department’s most recent agency-wide audit covered 4.65 trillion dollars in reported assets, and the force that operates and guards those assets carries no dedicated program of record for managing its own digital signatures. That gap between what we protect physically and what we leave readable digitally is where a modest investment buys disproportionate protection.
The United States is paying for both sides of this exchange. Our data economy sells detailed records on Americans, service members included, while China locked down the sale of its citizens’ data years ago. The same cheap data, read in the other direction, is an intelligence advantage the force has already paid for. And the consequences are on the record: cheap pattern analysis has already defeated expensive tradecraft, from a burner phone on the southern border to a covert communications network. Signature management is the corrective. It lowers the probability of exposure, raises the adversary’s cost to collect and exploit, and extends the useful life of everything the force has already bought. The choice is not whether to spend, because a funded mandate is already in law. The choice is whether to spend early and by design, or late and under pressure, after a compromise sets the price.
The Cost Curve Moved
For most of the history of surveillance, the expensive part was not collection. It was understanding. Someone had to read the take, connect the fragments, and decide what mattered, and that human bottleneck forced the adversary to triage. Triage is what protected most of the force. The operator at the tip of the spear got studied. The clerk, the spouse, the logistician, and the contracting officer did not, because nobody had the attention to spare.
Both halves of that protection are gone. Analysis got cheap first. Token price is not the whole cost of reconstructing a person’s pattern of life; data, engineering, and judgment still cost money. But the step that once required a trained analyst now runs at scale for a rounding error, and that was the step forcing triage in the first place. Collection changed too. An adversary once had to task a sensor, fly a platform, or run an officer. Now ordinary life builds the collection layer on its own and sells it, and the ODNI framework on commercially available information describes how purchasable, sensitive data can be acquired and fused at scale. When the world collects on itself and analysis costs pennies, the adversary no longer has to choose whom to study before studying them. It reads broadly and sorts later. Veilant traced this shift, and the collapse of what we called the boutique illusion, in From Awareness to Readiness and Legibility Is Now the Default. This paper takes that conclusion as its starting point.
One consequence deserves its own paragraph because it changes the economics of time. Data collected today can be stored for almost nothing and read years later by an actor whose intent has changed after an election, a crisis, or a policy shift. The risk is not just who wants to read the force now. It is who could read it later, using records that already exist.
The Trend Runs Against Us

Figure 1: Number of connected devices
The chart above is fifteen years of one trend. Collection got broader, analysis got cheaper, and neither curve shows any sign of turning. For the Department of War that means the risk does not hold steady from one budget cycle to the next. It compounds. Every year of waiting raises our cost to protect and lowers the adversary’s cost to attack.
The defining feature of this environment is asymmetry of cost. The money required to build a capability and the money required to expose it are not even in the same order of magnitude. This is the most important idea for a resourcing conversation because asymmetry is where investment earns its highest return.
The Red Sea air defense fight made the imbalance concrete in the kinetic domain. Adversaries launched one-way attack drones that cost a few thousand to a few tens of thousands of dollars each, and U.S. warships answered with interceptors that cost between roughly two and four million dollars apiece. By late 2024, the running munitions bill had reached the order of 1.8 billion dollars. Winning every engagement while losing the cost exchange is not a sustainable position.
The same imbalance governs the data fight, and it is even more lopsided. The force spends years and large sums to train and field its people and programs. RAND has estimated the cost to train a single fighter pilot in the millions of dollars, and a sensitive program can run into the billions. Yet the data that begins to expose those investments sells for about twelve cents per record. Billions to build a capability. Hundreds of dollars to start exposing it. That is the message a comptroller needs to hear because it reframes signature management from a cost center into loss prevention on the most expensive assets the force owns.
The metric that reconciles those two numbers is cost per effect. A comptroller does not compare the price of a drone to the price of a Standard Missile 6 (SM-6). The comptroller compares what each side must spend to achieve one unit of operational result. By that measure, a cheap signal from the force becomes a cheap targeting cue for the adversary, and the middle of the force, the people the old economics never bothered to read, becomes readable for pennies. Signature management is how the force flips that curve, by raising what the adversary must spend to find, fix, and finish.
Scale makes the asymmetry concrete. The Department’s most recent agency-wide financial audit covered 4.65 trillion dollars in reported assets, held across all fifty states and more than forty countries. The people who operate, maintain, and guard those assets are funded through a military personnel account that runs to roughly 190 billion dollars a year. There is no comparable line for managing the digital signatures of those same people. Ten basis points of that asset base would be about 4.65 billion dollars annually. Force-wide signature management would cost a small fraction of that figure. Today, it is not carried as a dedicated program of record at all.
This paper does not put a price on the program, and that is deliberate. A defensible number comes out of a baseline of the Department’s actual exposure, which is the first step on the path laid out at the end of this paper. The ten-basis point figure is a ceiling for scale, not an estimate.
The Department already knows how to protect an asset once it decides the asset is worth protecting. The B-2 is the clearest illustration. The program cost roughly 2.1 billion dollars per aircraft, and the surviving fleet of nineteen operates from a single hardened home at Whiteman Air Force Base. Security forces patrol restricted flight lines. Maintenance happens in climate-controlled hangars behind access control. Uncleared maintainers require escorts. Clearances are compartmented. That protection is layered, funded, and taken seriously because the asset is visible and the price tag is known.
Two pilots fly the aircraft. A large cadre keeps it flying: maintainers, fuel handlers, logisticians, clerks, and contractors, all inside the same program. The Department invests heavily in the two people in the cockpit and rarely accounts for the exposure of everyone else around the aircraft. Physical security ends at the fence line. Digital signatures walk out the gate every evening. An adversary does not need to target the pilot. A maintainer’s phone on the flight line, a fuel handler’s fitness application, and a contractor’s vehicle telematics each map the same aircraft that the fences and the hangars protect.
Timing compounds the problem. A signature begins accumulating on the day a person joins the force. Signature Management, when it arrives at all, usually begins when that person is involved in a sensitive program. Sensitive units and programs recruit from inside the force, which means candidates spend years building a readable pattern of life before anyone decides they are worth protecting. A record cannot be unwritten after the fact. Signature management that starts late in the service member’s career protects the last chapter of a story the adversary has already read. That is the economic case for making the discipline force wide and early rather than narrow and late.
Part of what makes exposure cheap is that the United States supplies the raw material. The domestic data economy collects, packages, and sells detailed information on Americans, service members included, with few limits. When Duke University researchers went shopping for records on U.S. military personnel, brokers sold them sensitive data with little diligence about the buyer, including buyers reachable through overseas addresses. The purchased datasets held exact ages and birthdays, gambling habits, credit ratings, net worth, political donations, and foreign investments. The FTC found years earlier that brokers hold thousands of data elements on nearly every American consumer, most of it gathered without the person’s knowledge. An open commercial market is underwriting a large share of the adversary’s collection budget. The force pays to create the people and the programs. The market then sells the means to find them.
And the rules run one way. The United States has no comprehensive federal privacy law, and for years the bulk sale of personal data, military personnel included, faced almost no restriction. The first meaningful limits arrived only recently, through Executive Order 14117 in 2024 and the Department of Justice rule that took effect in April 2025, which restrict bulk transfers of sensitive data to countries of concern. China went the other direction years earlier. Its Personal Information Protection Law and Data Security Law, both passed in 2021, put strict controls on personal data and tightly license its movement across borders. Buying bulk data on Chinese citizens is hard. Buying the equivalent data on Americans has been retail. For a decade the adversary could read us for pennies while shielding its own people, and signature management is how the force closes that gap on the side it controls.
The same market cuts both ways. The open data that maps our force also maps a competitor’s strategy: financial flows, shipping data, construction contracts, and corporate filings reveal the pattern of life of China’s global positioning, from its stakes in dozens of overseas ports to its grip on critical mineral refining. The discipline that protects our own signatures is the same discipline that sharpens our read on theirs.
Cheap surveillance has already produced consequences, and the most useful examples are the ones where cheap pattern analysis defeated careful, expensive tradecraft.
Consider a documented case from the southern border. A drug cartel identified a FBI informant not by breaking a code, but by reading a pattern. The informant carried a burner phone that powered on only near a U.S. government facility and contacted only one or two numbers. A cartel-affiliated telecom insider flagged that pattern, cross-referenced the call logs, identified the contact as a known U.S. handler, and the informant was located and killed. Careful tradecraft, a burner phone in the hands of a disciplined handler, was beaten by ordinary metadata read cheaply. The cost asymmetry in that case was fatal.
The same logic scales to programs. A reported covert communications network was unraveled after its supporting websites shared structural tells, exposing roughly 885 sites and the people who relied on them, with deadly consequences. The capability was expensive. The thing that exposed it was cheap and avoidable. Consumer digital exhaust alone can be enough. A fitness application’s public heat map once illuminated the layout of overseas bases and patrol routes, prompting a military review. In each case, the expensive asset was a person, a program, or a base, and the thing that exposed it cost almost nothing.
Signature management protects the investment and extends its useful life, and it does so through a defined discipline rather than a one-time fix. Veilant frames that discipline as Digital Signature Warfare, which aligns behavior and emissions across the full mission timeline through four actions: see your own discoverability; shape a plausible pattern; control emissions and behavior to fit it; and deceive the adversary’s model where it helps. Those actions map onto the three-ring view of an operation shown below: the outer ring works before the act to avoid investigative triggers, the inner ring protects the operational moment, and the middle ring denies a clean reconstruction afterward, so that replay yields ambiguity rather than attribution.

Figure 1: Three Ring View
Stated as a return, signature management does three things. It lowers the probability that a sensitive activity is detected at all. It raises the adversary’s cost in time and money to collect and exploit what it does see. And it creates uncertainty, so the adversary cannot trust what its own data appears to show. If an adversary spends a certain amount to find protected information today, a force that invests in protection forces the adversary to spend more, wait longer, and accept a higher chance of being wrong. That is cost imposition, and it is the most durable form of return in this competition.
Framed as a portfolio decision, the argument is arithmetic. A program is a sunk cost amortized over the years it remains effective. A five billion dollar capability that stays useful for five years costs one billion dollars per year of capability. The same capability, protected so that it stays useful for ten, costs half that. Same investment. Twice the life. Half the cost per year. The numbers are illustrative; the mechanism is not. Exposure works in the other direction, because it shortens the period during which a capability still surprises anyone. It is not the only way a capability loses value, since obsolescence and adversary adaptation take their share, but it is the one the force can contest. The covert communications network described earlier is the cautionary version of that math. An expensive capability lost its useful life early because a cheap and avoidable pattern gave it away. A modest, recurring investment in signature management extends the life of assets the force has already bought, and it is the rare defensive expenditure whose return can be stated as a lower cost per year of capability.
The alternative has a price too, and not one denominated only in dollars. A compromise buys investigations and damage assessments, relocation and protective measures, reissued identities and devices, rebuilt infrastructure, and missions repeated because the first attempt was anticipated. Prevention is a fraction of that bill, and prevention gets to pick its own timing. Remediation does not; the adversary sets the schedule.
The return also compounds in ways a single line item does not capture. Commercial collection scales beautifully, and fragmenting the underlying signals is what breaks that scale. Units that can train, move, and prepare without revealing intent keep their tempo instead of paying for workarounds. Well-designed protection also shrinks the blast radius of any breach that does happen, because leaked data that cannot be linked to real people, units, and missions is worth far less to the buyer. Hold vendors and contractors to the same standards and the periphery stops being the soft way into a hard program. There is a deterrence effect at the end of all this: when exploitation becomes expensive and unreliable, adversaries take their effort somewhere else.
This return grows as the threat improves. As machines get better at combining weak signals and data across time, the ambiguity that once protected ordinary activity erodes on its own. Sparse data that used to resolve to nothing now resolves to a pattern. That is the loss of ambiguity described in the companion paper, and it carries a direct economic consequence. Ambiguity can no longer be left to chance. It has to be produced deliberately, which is what the middle ring does. Signature management is the manufacture of ambiguity in an environment where ambiguity is otherwise disappearing at no cost to the adversary.
A credible case states the limits. Detection is not deduction. As MITRE’s Shawn Benson argued in 2024, raw surveillance data does not automatically become actionable intelligence. It still requires analytics, access, talent, and decision processes. Two frictions still buy time. Analytic systems remain fragmented, and a human usually still sits at the decision point. Those frictions are the remaining window, not a permanent defense, and the cost of the analytic step has already moved sharply in the adversary’s favor.
That gap is also narrowing from the other side. As Veilant argues in Legibility Is Now the Default, machines increasingly return interpretation rather than raw detections, which compresses the very distance between detection and deduction that the honest objection rests on. The analytic step is getting cheaper, faster, and more automated at once.
Protection is not free either, and a credible case says so. Signature management adds training time, technology, tradecraft, and friction to daily routines. Those costs are real, and a program should plan for them instead of discovering them. In Veilant’s assessment they are small next to the losses they prevent, and the measures below are how a program proves that claim rather than asserts it.
There are four further objections which deserve a direct answer rather than a rebuttal. New requirements can squeeze small and nontraditional vendors unless the standards are clear, scalable, and written once rather than reinvented for every program. Signature protective tooling does not always integrate cleanly with legacy networks, coalition systems, or mission partner environments. Some defensive approaches touch the devices, applications, travel, and data of service members, which raises privacy and civil liberties questions that should be settled in policy beforehand rather than after an incident; a discipline built to reduce collection on our own people must be scoped and governed so that it never becomes a warrant to expand it. And adversaries adapt. Close one signal stream and they shift to another, which makes signature management a recurring operating cost rather than a one-time purchase. None of these objections argues against the investment. Each argues for designing it well.
The way to manage an investment is to measure it. Three measures of effectiveness make the return visible and tie it to readiness: Trigger rate captures how often a force generates anomalies that draw adversary attention; correlation depth captures how many independent data vectors align on the same person or unit; and reconstruction error captures how much ambiguity remains after an adversary attempts to replay events. Track those numbers, report them alongside readiness, and resourcing decisions stop being guesses. They become a portfolio managed for measurable effect.
A funded mandate is already in law. Section 1511 of the Fiscal Year 2026 National Defense Authorization Act, enacted in December 2025, requires the Department to acquire wireless mobile phones and related telecommunications for senior officials and personnel performing sensitive national security functions under contracts that mandate enhanced cybersecurity protections, defined to include encryption, obfuscation and periodic rotation of persistent device identifiers, and continuous monitoring, all within ninety days of enactment.
That provision is narrow by design. It reaches a defined population of devices rather than the whole force. But it establishes the principle in statute that persistent identifiers and device discoverability are the Department’s problem to manage. In October 2025 the Government Accountability Office reinforced that statute, finding that the Department needs to address the security risks of publicly accessible information and naming UTS directly.
Governance is moving in the same direction. National Security Presidential Memorandum 12, signed on June 12, 2026, rescinded the 1990 and 2022 directives that governed national security systems and re-established the Committee on National Security Systems for the first time in more than thirty-five years, naming the Department’s chief information officer among the authorities the committee relies on to close gaps in those defenses. NSPM-12 is a cybersecurity governance instrument, not a signature management mandate, and it should not be oversold as one. What it creates is the accountability machinery to which a funded signature management discipline can attach: named owners, binding directives, reporting requirements, and performance metrics.
The trend line in law continues. The House-passed Fiscal Year 2027 NDAA (H.R. 8800, as reported) carries Section 1098, UTS and Digital Force Protection, which would take up the broader problem that Section 1511 only touches at the device level. As proposed House language, it is not yet law and its number and scope can change in conference, so it is best read as the direction Congress is moving rather than a settled requirement. Taken together, Section 1511 supplies a narrow operational requirement today, NSPM-12 supplies the governance machinery, and the FY2027 language signals the wider mandate coming. What is still missing across all three is a funded program of record for force-wide signature management.
Funding will flow either way. The decision in front of leaders is whether it flows efficiently and early or inefficiently and late. The disciplined path is short to describe: baseline the Department’s UTS exposure, stand up immediate protective measures for the most exposed personnel, and set standards for personal device use, device use overseas, and digital signature management so that protection is routine rather than exceptional. Fund the program before a compromise sets the price.
Conclusion: Make Watching Us Expensive Again
The economics of UTS now favor the observer. Collection is everywhere, analysis is cheap, and the United States supplies much of the raw material while its competitor shields its own. Left unmanaged, that asymmetry quietly raises the cost of every operation and lowers the value of every capability the force has already bought.
Signature management is the lever that resets the ratio. It is loss prevention on the most expensive assets the Department owns, an intelligence advantage when turned on the adversary, and a measurable investment with a defined return. The objective is to make adversary observation expensive, uncertain, delayed, and unreliable, while the force keeps operating at tempo. The question is no longer whether we are being watched. The question is what we are willing to invest so that watching us stops being cheap.
About Veilant
Veilant supports organizations confronting the operational realities of UTS through assessment, training, digital signature analysis, operational planning support, and fieldable technical solutions. Our work helps leaders move from awareness to measurable action while preserving mission effectiveness in environments where commercial data, connected devices, and AI enabled analytics increasingly shape operational risk.
Disclaimer
All statements of fact, opinion, or analysis are those of the author and do not reflect the official positions or views of the U.S. Government. Nothing in this paper should be construed as asserting or implying U.S. Government authentication of information or endorsement of the author’s views.