# What Afferton said Tom Afferton, president of Peraton's cyber and intelligence sector, discussed how his organization approaches automation in defensive cyber operations, practical barriers to adoption across government customers, and why influence campaigns merit equal attention to conventional cyberattacks. He also framed the addition of "intelligence" to his title as a formal alignment of missions Peraton already supports.
# How Peraton draws guardrails for automation Peraton's approach is explicitly risk-based. The company evaluates an action by three basic criteria: how well-defined the action is, whether it's reversible, and the potential consequence of a mistake. That leads to practical rules of thumb:
- Automate routine, well-scoped, reversible tasks (example: blocking known-bad IP addresses).
- Require human validation for high-stakes, complex remediation actions (example: auto-generated code to fix chip-level zero-day exploits).
Afferton frames the goal as improving human decision-making rather than replacing operators: automation should accelerate processing and remediation while letting people retain control over high-risk choices.
# Adoption challenges in government operations Afferton identifies three concrete constraints he sees in customer environments:
- Data gaps. Poor data quality and inconsistent data management limit automation effectiveness.
- Tooling and classification barriers. Access to advanced tools at different security classifications can be restricted, slowing operational use.
- Human factors. Operator proficiency varies widely, affecting both output quality and operational cost (for example, token consumption when using commercial platforms).
Peraton has taken its own internal lessons to customers—training, data hygiene, and policy-aligned governance are part of getting automation to work in practice.
# Operational context: Army cyber programs The recent contract to support the U.S. Army's Regional Cyber Center-Europe continues a nearly 20-year partnership between Peraton and the Army. That work sits alongside support to Army Cyber Command at Fort Gordon and the Network Enterprise Technology Command's Global Cyber Center at Fort Huachuca. Peraton describes its role as enabling full-spectrum defensive cyber operations and delivering information advantage to commanders at multiple echelons.
# The intelligence addition to Afferton's role Afferton now oversees both cyber and intelligence missions. He positions that change as formal recognition of overlapping mission needs rather than a wholesale shift in focus: cyber defense, intelligence collection and analysis, and operational decision support are increasingly intertwined in the programs Peraton supports.
# Threat focus: influence campaigns and new attack surfaces Afferton warned that adversarial influence campaigns are as dangerous as conventional cyber intrusions because they target decision processes and trust. He also highlighted a new attack surface introduced by automation platforms themselves, which requires governance and policy controls to mitigate.
# Practical next steps implied by the interview
- Prioritize automation for reversible, low-consequence actions while building approval flows for high-consequence responses.
- Invest in data quality and cross-classification access to tooling as prerequisites for scaling automation.
- Standardize operator training and measure proficiency to reduce variability in outcomes and costs.
# Bottom line Peraton's stance is operationally pragmatic: use automation where it clearly reduces risk and workload, keep humans in the loop where stakes are high, and treat governance, data, and people as the primary barriers to wider adoption.