R-2A Activity · President's Budget PB2027

Threat Information Warfare

Activity a0·Project 976 — Army Threat Sim (ATS)·PE 0604256A·U.S. Army
FY2027 Request
$11.4M
▼ 60% vs FY2026
HitchAI read

This activity requests $11.4M in FY2027, 19% of project 976, down 60% on FY2026. The R-2A exhibit describes it across FY2025–FY2027, including what the FY2027 money is planned to buy.

FY2027 Request
$11.4M
▼ 60% vs FY2026
FY2026 Enacted
$28.8M
▲ 34% vs FY2025
FY2025 Actual
$21.4M
Prior year
Planned work

What the FY2027 request buys

Verbatim from the R-2A exhibit for project 976 of PE 0604256A. This is the budget justification's own description of work that has not happened yet — the one thing no other level of the budget carries.

FY2027 planned work

Sustainment of existing threat-based Red Team capabilities, including previously developed toolsets and distributed operations infrastructure. Maintain Red Team Certification and Accreditation (C&A) required for on-network operations. Continued development of state and non-state threat targeting packages that are current, accurately profiling attack trends and timelines, intent, levels of sophistication, and threat training. These threat packages represent state and non-state level forces using both active and passive network attack to selectively degrade or disrupt Command, Control, Communications, Computers (C4) Intelligence, Surveillance and Reconnaissance (C4ISR) and Enterprise Business Systems. Development of threat targets and networks as new real-world targets sets and capabilities evolve.

FY2026 to FY2027 change

Funding decrease reduces planned threat assessments to focus on the highest priorities.

Before the request year

FY2025–FY2026: what came before

Prior-year accomplishments and current-year plans from the same exhibit. Context for the FY2027 plan, not a series — an activity partitions its project exactly in the request year, but can under-cover it in earlier years.

FY2026 plans — current year

Execute information and decision advantage threat simulation to support Army critical program information protection. Provide Army Programs with quantifiable information regarding risks to critical information within the public domain. Assess effectiveness of measures and countermeasures employed within OPSEC and program protection plans. Plan, execute and provide threat assessments to prioritized systems and activities spanning key areas of concern across Army. Advancement of existing threat-based Red Team capabilities, including previously developed toolsets and distributed operations infrastructure. Maintain Red Team Certification and Accreditation required for on-network operations. Continued development of state and non-state threat targeting packages that are current, accurately profiling attack trends and timelines, intent, levels of sophistication, and threat training. These threat packages represent state and non-state level forces using both active and passive network attack to selectively degrade or disrupt Command, Control, Communications, Computers Intelligence, Surveillance and Reconnaissance and Enterprise Business Systems. Development of threat targets and networks as new real-world targets sets and capabilities evolve. Continued development and employment of intelligence validated LVC dynamic Commercial, Multi-National & Military (Red and Gray) Environments required for Army and Joint Offensive Cyber Operations and Defensive Cyber Operations-Response Actions program development; Test and Evaluation (e.g., Joint Common Access Platform OT); and mission rehearsal/capabilities assessments in support of Army and Joint Multi-Domain Operations ranges. Conduct Foreign Commercial Aquisition and Foreign Commercial Purchase actions.

FY2025 accomplishments

Development of existing threat-based Red Team capabilities, including previously developed toolsets and the Red Team Shared Infrastructure (RTSI) - a distributed operations infrastructure. Infrastructure hardware refresh. Maintain Red Team Certification and Accreditation required for on-network operations. Continued development of state and non-state threat targeting packages that are current, accurately profiling attack trends and timelines, intent, levels of sophistication, and threat test and evaluation. These threat packages represent state and non-state level forces using both active and passive network attack to selectively degrade or disrupt Command, Control, Communications, Computers (C4), Intelligence, Surveillance and Reconnaissance (C4ISR), and Enterprise Business Systems. Persistently replicates Advance Persistent Threats from near-peer actors across the materiel enterprise (into operations) which threaten Army modernization and readiness. Development of threat targets and networks as new real-world targets sets and capabilities evolve.

Money

Three years, and no five-year plan

An R-2A activity publishes the prior year, the current year and the budget year. The FYDP outyears exist at project and program-element level and are deliberately absent here rather than inferred. Estimate types are colored and never summed into one figure.

25021.4FY25ACTUAL28.8FY26ENACTED11.4FY27REQUEST
Actual Enacted Request
Fiscal YearEstimate TypeAmount ($M)
FY2025Actual21.4
FY2026Enacted28.8
FY2027Request11.4

This activity is 19% of project 976's FY2027 request and 19% of PE 0604256A's. In the request year the activities under a project sum to it exactly; in the current year they under-cover it in about 9% of cases, so an activity's delta can legitimately exceed its parent's and the two must not be compared row to row.

Where this sits

3 activities in project 976

Every R-2A line of this project, largest FY2027 request first. Linked where the activity has enough of its own narrative to carry a page; the rest are shown in full on the program-element page.

Threat Electronic Warfare$36.9M ▲ 2%Threat Network and Mission Command$12.0M ▲ 20%
Threat Information Warfare — this activity$11.4M ▼ 60%
Source
FY2027 Department of the Army RDT&E Budget Justification · Exhibit R-2A · PE 0604256A, project 976 (President's Budget PB2027). Congressional marks are recorded on the program element, never on an activity.
Machine access
Markdown twin /programs/0604256A/976/a0.md · MCP mcp.hitchintel.combudget_get_activity