Analysis · Industry · Company Updates

News & Insights

Analysis from the Forge & Flight team on UAS technology, defense acquisition, domestic manufacturing, and the regulatory landscape.

September 21, 2026

Drone as a Service for Military Exercises: What Red Air Operations Actually Provides

Most units training against the UAS threat do so against a notional threat, a demonstration system, or a contractor-operated platform that bears little resemblance to what they will face in a contested environment.

The result is predictable: units qualify against a system that does not replicate adversary behavior, do not develop the detection and defeat muscle memory that real operational tempo builds, and arrive at an actual adversary UAS encounter with training that did not prepare them for it.

Read More →

September 18, 2026

What Organic Personal Security Capability Actually Looks Like at the Unit Level

There is a pattern in how DoD units approach skills that matter but are not directly tied to the primary mission: they contract it. Someone comes in, delivers a training event, and leaves. The unit has certificates. The unit does not have capability.

Personal digital security is in that pattern right now. Most units that care about it bring in a contractor for an annual security awareness event. Operators get a briefing. They might get a checklist. The contractor leaves. Six months later, the threat environment has changed, new personnel have rotated in, and the unit’s actual security posture is roughly what it was before the contractor arrived, because the knowledge left with the contractor.

Read More →

September 10, 2026

The Digital Signature Problem Every Deployed Unit Has and Nobody Is Training For

Annual OPSEC training teaches operators that threats exist. It does not teach them to do anything about those threats that they weren’t already doing. The gap between awareness and capability is where real exposure lives.

Every operator who deploys or travels to a threat environment carries a personal device that has spent years accumulating data about their habits, location history, contacts, and identity. That device is not neutral. It broadcasts, syncs, and logs in ways that are invisible to the person carrying it and valuable to an adversary with basic collection capability. A one-hour annual briefing does not change any of those behaviors.

Read More →

September 5, 2026

Three Categories of Personal Threat That Live Outside the SCIF

Inside a classified facility, information security is structured, enforced, and regularly audited. Cleared personnel know what the rules are, why they exist, and what the consequences of violating them look like.

Outside that facility, most of the same personnel operate with no structured framework at all. They carry personal devices that have spent years accumulating sensitive data. They use consumer applications built for ad revenue, not security. Their personal networks, location patterns, and identity information are indexed in commercial databases accessible to anyone willing to pay for them.

Read More →