This is the final post in the black core networking series. The first examined the cost of dedicated network infrastructure. The second explained how encrypted transport and SDN make shared networking viable. This one connects both infrastructure migrations — compute and network — into a complete architecture.
The weapon system IT modernization series proposed moving weapon system processing from dedicated servers onto enterprise platforms — in waves, with dedicated hardware remaining where technically required. That migration delivers $6-11 million per system annually in compute infrastructure savings.
But if the weapon system's processing moves to an enterprise platform while its network stays on dedicated circuits, the migration is incomplete. The sensor data still travels over dedicated circuits to reach the enterprise platform. The enterprise platform's data products still travel over dedicated circuits to reach the operators. The weapon system is running on shared compute but communicating over private transport — and the private transport carries its own cost.
The complete architecture migrates both.
The target architecture
A weapon system fully migrated to enterprise infrastructure has three zones:
The sensor edge. The hardware that collects data — radar arrays, satellite ground terminals, signal processors, environmental sensors. This hardware stays dedicated because it has genuine technical requirements for direct hardware access, specialized I/O, or real-time processing. The sensor edge is the part of the system that can't run as software on a shared platform.
The enterprise platform. The processing, storage, analytics, and operator interfaces that were previously running on dedicated servers at dedicated sites. These workloads now run on Platform One, a Big Bang-derived environment, or an authorized cloud service — benefiting from shared compute, shared authorization, shared patching, and DevSecOps pipelines. This is the migration described in the IT modernization series.
The encrypted transport fabric. The network connecting the sensor edge to the enterprise platform and the enterprise platform to operators. This transport uses whatever paths are available — DISN backbone, commercial terrestrial, MILSATCOM, commercial LEO SATCOM — with layered encryption protecting the data and SDN policy controlling the routing. The transport is shared; the security is in the encryption.
The weapon system's authorization boundary narrows to the sensor edge hardware, the encryption endpoints, and the application running on the enterprise platform. The compute infrastructure is authorized by the platform operator. The transport infrastructure is authorized by whoever operates the transport. The weapon system authorizes what it uniquely owns — which is a fraction of what it previously maintained.
What the complete migration saves
The IT modernization series estimated $6-11 million per year in compute savings for a single weapon system with 3-5 distributed sites. The network cost post estimated $500K-$2M per year in dedicated network infrastructure.
Combined:
| Infrastructure | Current annual cost | Post-migration annual cost | Savings |
|---|---|---|---|
| Compute (servers, storage, security, ATO) | $10-15M | $2-4M (platform fees + app sustainment) | $6-11M |
| Network (circuits, encryptors, network HW) | $500K-$2M | $100K-$400K (transport fees + encryption) | $400K-$1.6M |
| Total | $10.5-17M | $2.1-4.4M | $6.4-12.6M/year |
Over a 10-year remaining lifecycle, a single weapon system saves $64-126 million. Over a portfolio of 10 similar systems, the savings potentially exceed a billion dollars.
These are modeled estimates. The actual numbers depend on the specific weapon system — its site count, its circuit costs, its hardware age, and its staffing model. Each system needs its own assessment.
What changes for the program office
Budget composition shifts. The program office's infrastructure spending drops by 60-80%. The budget that was consumed by hardware refresh, circuit maintenance, encryption device management, dedicated security staff, and standalone ATO maintenance becomes available for capability investment. IT becomes a variable cost — platform fees that scale with usage — rather than a fixed cost that persists regardless of mission evolution.
Delivery speed increases. On dedicated infrastructure, every software update requires testing against the weapon system's specific hardware configuration, patching the standalone environment, and navigating a system-level ATO review. On an enterprise platform with DevSecOps pipelines, software updates deploy through automated build, scan, and release processes. The cycle time from requirement to fielded capability shortens from months to weeks. And when the network is software-defined, network changes follow the same model — routing and policy updates managed through version-controlled configuration rather than manual change requests. The same GitOps practices that accelerate application delivery accelerate network operations.
Sensor integration simplifies. When the transport is encrypted and policy-driven, connecting a new sensor to the weapon system is a policy configuration — not a circuit provisioning effort. A new radar, a new satellite ground terminal, or a new data feed connects to the encrypted transport fabric and reaches the enterprise processing through SDN policy. The program office adds capability by configuring policy, not by building infrastructure. The Istio service mesh parallel applies: at the application layer, adding a new service is a configuration change, not a network rebuild. At the transport layer, SDN provides the same agility.
Resilience improves. A weapon system on dedicated circuits and dedicated servers has single points of failure at every layer. A weapon system on enterprise compute with SDN-managed encrypted transport has redundancy at every layer — multiple compute zones, multiple transport paths, automated failover. The system's availability is designed to be higher than the dedicated model, not lower.
The assessment path
This is not one assessment. The compute migration and the network migration are related but independent evaluations, and each weapon system in the portfolio needs its own:
Portfolio architecture study. What does the target state look like across the portfolio? Which enterprise compute platform and which transport options serve as the consolidation target? What's the migration sequence — which systems move first, and what dependencies exist between them? This is an architecture assessment that scopes the entire effort before any individual system moves.
Per-system compute assessment. For each weapon system: which workloads move to the enterprise platform, which stay on dedicated hardware, what's the authorization pathway, and what does the interconnect between dedicated and enterprise look like? This is a systems authorization study specific to the compute migration.
Per-system network assessment. For each weapon system: which circuits can be replaced by encrypted enterprise transport, which encryption model applies (CSfC, Type 1, hybrid), what are the bandwidth and latency requirements for each data flow, and what does the SDN policy architecture look like? This is a network architecture study specific to the transport migration.
Combined authorization assessment. The compute and network migrations together change the weapon system's authorization boundary. The combined assessment maps the new boundary — what the weapon system owns, what the enterprise platform owns, what the transport provider owns — and produces the authorization strategy for the migrated system.
Each of these assessments is bounded, specific, and cheaper than one year of maintaining the infrastructure it evaluates.
The trajectory
The Department is already moving in this direction. The Space Force's Enterprise Ground Services architecture is consolidating space ground system compute. DISA's Software Defined Enterprise is automating network provisioning across the DoW. Thunderdome is bringing zero trust and SD-WAN to the enterprise. CSfC is replacing expensive Type 1 encryptors with layered commercial encryption. The CCS-C contract is consolidating four satellite communication ground systems under shared sustainment.
The program offices that scope this transition now — before it becomes a directive — are the ones that capture the savings early and apply them to capability. The assessment cost is a fraction of one year's infrastructure spending. The return is measured in decades of reduced sustainment and increased mission investment.
The complete migration — compute and network — converts infrastructure spending into capability budget. The sensor edge stays dedicated. Everything else moves to shared, authorized, resilient enterprise infrastructure. The weapon system gets more reliable, more adaptable, and less expensive to sustain. The money that was maintaining servers and circuits goes to making the system better at its mission.
Robert Burckner is the founder of Millabs Corporation, a Service-Disabled Veteran-Owned Small Business. He has served as ISSM and ISSE for legacy weapon systems at the Air Force Lifecycle Management Center, participated in the DoW TDM circuit elimination initiative, and served as Division Chief at the Space Warfighting Analysis Center (USSF/NRO).
If your program manages a weapon system on dedicated compute and network infrastructure and wants to understand the complete migration path, contact Millabs. The portfolio architecture assessment, per-system compute and network evaluations, and combined authorization studies can be performed independently on behalf of the program office through existing government contract vehicles.