https://www.millabs.net/blog/stovepiped-weapon-system-network-cost/

Your weapon system has dedicated circuits connecting its processing sites. Dedicated encryptors at each end. Dedicated routers, dedicated firewalls, dedicated network monitoring. The circuits were provisioned when the system was fielded — sometimes as TDM links, sometimes as dedicated IP circuits — and they've been maintained, refreshed, and sustained ever since.

The servers got the attention in the infrastructure consolidation conversation. The network didn't. But the network cost follows the same pattern: dedicated infrastructure maintained per-system, at per-system cost, doing work that a shared transport could provide.

The parallel cost structure

Everything that makes dedicated compute expensive also makes dedicated networking expensive:

Dedicated circuits. Each weapon system maintains point-to-point connections between its processing sites. These circuits are provisioned through DISN or commercial transport, with costs that scale per-circuit, per-bandwidth, per-site. A weapon system with processing at 5 sites doesn't share circuits with other systems at those sites — it maintains its own.

Dedicated encryption. Each circuit terminates in encryption devices — historically HAIPE encryptors — at each end. These devices require procurement, maintenance, key management, and replacement on a refresh cycle. Each weapon system manages its own encryption infrastructure independently of every other system at the same site.

Dedicated network hardware. Routers, switches, and firewalls at each site, configured for the weapon system's specific data flows. Maintained and patched on the weapon system's schedule, by staff who understand the weapon system's network architecture.

Dedicated network authorization. The network infrastructure is part of the weapon system's ATO boundary. Changes to routing, firewall rules, or encryption configuration require authorization review — consuming SCA capacity from the AO's office for each system independently.

Legacy transport technologies. Some weapon systems still run on TDM circuits that the Department's CIO has directed be eliminated in favor of IP-based transport. These legacy circuits carry higher maintenance costs, offer limited scalability, and increase cybersecurity risk — but they persist because the weapon system's architecture was built around them and migration wasn't scoped. And TDM emulation over IP — wrapping the same legacy protocols in IP transport — doesn't solve the underlying problem. It preserves the dedicated, per-system architecture on a different wire. The cost structure stays stovepiped even if the physical transport changes.

The Department's IT Enterprise Strategy identified the same redundancy in networking that it identified in compute: each program "delivered unique, largely redundant and tremendously costly network and computing infrastructures." The network half of that redundancy has been slower to address because network changes feel riskier than server changes — and for high-availability weapon systems, that caution is understandable.

What the network costs

Estimating weapon system network costs is harder than estimating compute costs because the circuits are often funded through different budget lines than the servers. The encryptors may be managed by a different organization than the weapon system program office. The network staff may be shared across multiple systems at a site, making per-system attribution difficult.

But the cost components are real:

Component Per-site cost Notes
Dedicated circuit (IP or TDM) $50K-$300K/year Varies by bandwidth and distance
HAIPE encryptors (pair) $30K-$80K procurement, $10K-$20K/year maintenance Refresh every 5-7 years
Network hardware (router, switch, firewall) $20K-$50K procurement, $5K-$15K/year maintenance Per-site, per-system
Key management $10K-$30K/year Per encryption device pair
Network staff (proportional) $50K-$100K/year per system Shared staff, per-system allocation

For a weapon system with 5 distributed sites, the network infrastructure cost is $500K-$2M annually — on top of the $10-15M in compute infrastructure estimated in the first post of the IT modernization series.

These are modeled estimates. Like the compute costs, the actual numbers are rarely visible to the program office because they're distributed across circuit contracts, encryption device inventories, and shared network staff budgets.

The enterprise network already exists

DISN provides enterprise transport across the Department at multiple classification levels. SIPRNet, NIPRNet, and JWICS are operational, authorized, and available at the sites where weapon systems operate. The Thunderdome initiative is bringing SD-WAN and zero-trust network access to the DoW enterprise. DISA's Software Defined Enterprise program is automating network provisioning to transform DoW networking from a physical paradigm to a software-defined capability.

The enterprise transport exists. It's authorized. It's maintained by an organization whose primary mission is network operations. And it provides the same connectivity that each weapon system is maintaining independently at each of its sites.

The weapon system's dedicated circuits exist because they predate the enterprise alternative — not because the enterprise can't meet the requirement. Like dedicated servers, dedicated circuits persist because the architecture was built around them and nobody has scoped the migration.

The question is the same

The first post in the IT modernization series asked: what does your weapon system's compute infrastructure actually cost? This post asks the same question about the network.

If your program office can itemize the cost of dedicated circuits, encryption devices, network hardware, and network staff across all sites — and compare that cost to what enterprise transport would cost for the same connectivity — the spending decision becomes visible.

If the program office can't produce that comparison — because the network costs are distributed across budget lines that don't roll up to the weapon system — then the first step is the same: visibility before decisions.

Next in this series: how encrypted transport and software-defined networking make the enterprise network viable for classified weapon system data.


Robert Burckner is the founder of Millabs Corporation, a Service-Disabled Veteran-Owned Small Business. He has served as ISSM and ISSE for legacy weapon systems at the Air Force Lifecycle Management Center, where network architectures included dedicated TDM circuits, HAIPE encryptors, and site-specific network infrastructure, and as Division Chief at the Space Warfighting Analysis Center (USSF/NRO).

If your program maintains dedicated network infrastructure for a weapon system and nobody has compared that cost to enterprise alternatives, contact Millabs. This assessment can be performed independently on behalf of the program office through existing government contract vehicles.

Share this post
Email LinkedIn
GET IN TOUCH WITH US

Find out what the gap between your product and an authorized environment actually looks like.