# Detect, Analyze and Mitigate Intrusions

**R-2A activity** of project MC30 — Cyber Operations  
**Program element:** 0603890C — BMD Enabling Programs  
**Component:** Defense-Wide · **Budget Activity:** 4  
**Vintage:** President's Budget PB2027  
**Canonical URL:** https://hitchintel.com/programs/0603890C/MC30/a3  
**Parent:** https://hitchintel.com/programs/0603890C/MC30

## Summary

This activity requests $100.6M in FY2027, 37% of project MC30, up 128% on FY2026. The R-2A exhibit describes it across FY2027, including what the FY2027 money is planned to buy.

## What the FY2027 request buys

**FY2027 planned work.** - Initiates end-to-end support for DCO requirements for new systems, long-haul communications transition, cryptographic, end user support, and legacy cybersecurity tool modernization, and increased SAP network and storage requirements to support Missile Defense System - Next requirements.

**FY2026 to FY2027 change.** Increase from FY 2026 to FY 2027 provides for multiple new requirements supporting the Missile Defense Agency capabilities, including end-to end support for DCO requirements to support new systems, long-haul communications transition, cryptographic, end user support, and legacy cybersecurity tool modernization, and increased SAP network and storage requirements. Increase also provides for realignment of cybersecurity requirements to new OMB Cybersecurity Taxonomy. MDA is required to develop and deliver a comprehensive cybersecurity strategy, methodology, and technical solution set to detect, analyze, and mitigate intrusions, ensure the resilience of its new information systems. This includes ensuring continuity of operations during crises, conducting thorough threat analysis through activities like red-teaming, and performing regular network readiness assessments to identify and reduce vulnerabilities. In the event of a cyber incident, a multi-stage response is required to be triggered, involving federal incident response centers. This required response includes detailed forensic analysis to assess the damage and attribute the attack methodology and responsible parties, followed by remediation and restoral of systems in a timely manner to continue the warfighter effort. This increase also supports the investigation and legal prosecution of those responsible for cyber intrusions related to MDA systems and data.

## Funding

| Fiscal Year | Estimate Type | Amount ($M) |
|---|---|---|
| FY2025 | Actual | 62.0 |
| FY2026 | Enacted | 44.1 |
| FY2027 | Request | 100.6 |

> Prior, current and budget year only — an R-2A activity carries no five-year plan. It sums exactly into its project in the request year and not necessarily in any other.

## Other activities in project MC30

- [Prevent Malicious Cyber Activity](https://hitchintel.com/programs/0603890C/MC30/a6) — FY2027 150.1
- Planning, Policy Development, Workforce Training & Force Management — FY2027 12.5
- Cybersecurity Risk Management — FY2027 9.2
- Facility Related Control Systems (FRCS) — FY2027 1.1
- Preventing Malicious Cybersecurity Activity — FY2027 0.0
- Continuous Monitoring — FY2027 0.0

## Source & machine access

- **Source:** FY2027 Office of the Secretary of Defense RDT&E Budget Justification, Exhibit R-2A, PE 0603890C project MC30 (PB PB2027). Narrative is the government's own text.
- **No marks, no contractors at this grain** — congressional marks land on the program element and R-3 performers on the project.
- **MCP:** `mcp.hitchintel.com` — `budget_get_activity`.

*HitchAI is an independent intelligence service, not affiliated with the U.S. Department of Defense. Budget figures are requests/estimates, not obligations.*