IN Brief:
- Leidos has secured a five-year, $301 million defensive-cyber contract with the US Army.
- The programme covers round-the-clock monitoring of the Department of War Information Network used across US military organisations.
- Leidos will combine continuing cyber operations with engineering, technology development, and AI-enabled defensive capabilities.
Leidos has secured a five-year, $301 million US Army contract to continue round-the-clock defensive cyber operations across the Department of War Information Network. The follow-on programme combines 24/7 monitoring of the global military network with engineering and development work intended to introduce additional defensive capabilities over the life of the contract.
The network is used across US military organisations, giving the programme an operating environment that extends well beyond a conventional corporate estate. Users, endpoints, applications, fixed infrastructure, cloud services, and deployed systems can be distributed across numerous locations and security domains while supporting missions that cannot wait for a convenient maintenance window.
Leidos says its existing work on the programme has integrated cyber operations, engineering, and technology development, including AI-enabled tools intended to improve situational awareness and reduce the interval between detection and response. The company has not disclosed staffing numbers, specific platforms, locations, or the individual AI systems covered by the new award.
The five-year structure makes continuous technical change unavoidable. Operating systems, cloud platforms, network equipment, defensive tools, applications, identities, and attacker techniques will all develop during the contract period. A defensive architecture fixed around the environment present in August 2026 would become progressively less useful long before the programme ended.
That gives engineering work equal weight with monitoring. Sensors have to collect meaningful telemetry from a large and varied estate, data pipelines must preserve enough context for analysis, and defensive tools need to exchange information without creating another collection of incompatible interfaces. New capabilities also have to be introduced without destabilising services that remain operational while the work is taking place.
Alert volume is one of the practical constraints. A large military network produces extensive legitimate changes in user behaviour, device state, software, connectivity, and configuration, all of which can resemble suspicious activity when viewed without context. Defensive teams therefore need ways to distinguish meaningful anomalies from routine noise quickly enough that genuinely hostile activity is not buried underneath low-value alerts.
AI-enabled tools can assist with that filtering by correlating events, highlighting patterns, ranking alerts, or supporting analyst investigation. The contract announcement does not describe autonomous defensive actions, nor does it provide details of the models or training data being used. Human judgement remains particularly important where an automated response could isolate legitimate systems and disrupt operations at the same time as it contains a threat.
Resilience also reaches beyond intrusion prevention. A military network has to keep priority services functioning when parts of the architecture are damaged, disconnected, compromised, or forced onto alternative communications paths. Segmentation, recovery procedures, identity controls, configuration management, service redundancy, and the ability to restore trusted systems all become part of defensive engineering.
The follow-on award arrives during wider investment in US military enterprise networks. General Dynamics Information Technology recently secured a separate $1.3 billion Army National Guard network and cyber contract combining operations, modernisation, and defensive services. The two programmes serve different environments, but both place cyber defence inside continuing network operation rather than treating security as an isolated software layer.
That model also changes workforce requirements. A round-the-clock programme needs incident responders and cyber analysts, but it also depends on network engineers, developers, data specialists, system architects, cloud personnel, and staff able to work across classified and unclassified environments. Maintaining enough depth to cover continuous operations becomes part of service resilience in its own right.
Knowledge retention matters over five years. Systems can become difficult to operate securely when critical understanding of network topology, legacy applications, exceptions, and configuration choices sits with a handful of experienced personnel. Documentation, automation, configuration databases, and repeatable engineering processes reduce that dependency while making it easier to introduce new staff without repeatedly rediscovering the same architecture.
Legacy systems add another constraint because large defence networks rarely move onto a single technology generation at once. New cloud and identity platforms can coexist with specialised applications and devices built around older assumptions, forcing defensive teams to protect systems that cannot always accept the newest controls or patching schedules.
That mixed estate is one reason a follow-on services contract can be more useful than a sequence of isolated technology purchases. The Army is buying continuing defensive operation while retaining a mechanism for engineering and technology development as the network changes. The challenge is to prevent continuous innovation from becoming continuous tool proliferation.
Leidos has not published operational metrics for the programme, and many of the most useful measures are unlikely to appear publicly. Detection time, response speed, recovery performance, service availability, false-positive rates, and the time required to deploy new defensive capabilities would provide a more complete picture than contract value alone.
The $301 million award gives the company another five years to maintain that balance between stability and change. Military networks cannot stop evolving while cyber teams modernise the systems protecting them, and attackers are unlikely to wait politely for the next technology refresh either. The engineering job is therefore to improve the defence without turning the improvement programme itself into another source of operational fragility.


