The systems that run military networks, critical infrastructure, businesses, and everyday devices are becoming more powerful, interconnected, and complex — but the ability to fully understand how they function has not kept pace. A report produced by The Soufan Center, titled “Software Understanding and U.S. National Security,” identifies this widening divide as a central national security challenge, arguing that weaknesses in software-defined systems have created new opportunities for espionage, disruption, and cybercrime.
The report describes this challenge as the “software understanding gap”: the difference between the increasing complexity and importance of software systems and the ability to verify their security, reliability, and behavior before deployment. According to the report, this gap has expanded as governments, militaries, industries, and societies have become increasingly dependent on software-driven and cyber-physical systems.
The consequences are already visible in the way state and non-state actors use cyber capabilities to pursue strategic goals. The report states that software vulnerabilities have lowered the barriers to actions that might otherwise be too costly, risky, or difficult to conduct in the physical world. Cyber operations have allowed adversaries to conduct espionage, steal intellectual property, disrupt infrastructure, and generate financial resources from a distance.
The report highlights the role of state actors, including Russia, Iran, the People’s Republic of China, and North Korea, in exploiting weaknesses in software systems for different strategic purposes. Russia has used cyber operations as part of broader efforts to weaken European security structures and maintain influence along its western borders, with intrusions providing opportunities for intelligence collection, network positioning, and support for military operations.
Iran has used cyber capabilities as a form of asymmetric competition, allowing it to impose costs on more powerful adversaries despite having fewer conventional military resources. The report notes that weaknesses in industrial control systems and other software-dependent infrastructure have provided opportunities for harassment, signaling, and retaliation below the threshold of traditional military conflict.
The People’s Republic of China, according to the report, has pursued a more strategic and long-term approach, using software vulnerabilities primarily for sustained espionage, intellectual property theft, and the collection of sensitive information. The report states that Chinese cyber espionage has contributed to a narrowing of technological and military capability gaps by enabling access to commercial innovations and technical knowledge.
The economic impact described in the report is substantial. It cites estimates that Chinese espionage operations have cost the U.S. economy between $200 billion and $600 billion annually through intellectual property losses. While the exact effect of these operations on China’s military development remains unclear, the report states that stolen commercial innovations are likely incorporated into research and development efforts, accelerating economic and technological growth.
North Korea has developed cyber programs that combine espionage with financial operations. The report identifies groups linked to Pyongyang, including Andariel, Onyx Sleet, DarkSeoul, Silent Chollima, and Stonefly/Clasiopa, as organizations targeting defense, aerospace, nuclear, and engineering entities to obtain sensitive information supporting military and nuclear ambitions. It also describes North Korean efforts to place information technology workers inside foreign companies for espionage and revenue generation.
Beyond state actors, the report describes cybercrime as an expanding global industry. Criminal organizations use ransomware, fraud schemes, and other cyber-enabled methods to generate revenue. Some estimates cited in the report suggest that cybercrime, including losses from destroyed data, reduced productivity, and related effects, could cost the world economy $12.2 trillion annually by 2031.
The Soufan Center report argues that closing the software understanding gap would not eliminate cyber threats but would significantly change the environment in which attackers operate. If software-defined systems were verified for function, safety, and security before deployment, entire categories of vulnerabilities could be reduced, critical systems could become more resilient, and attackers would face higher costs and fewer opportunities.
A central recommendation is the broader use of artificial intelligence-enabled formal methods, which the report says could transform the economics of software verification. Historically, formal methods were limited by high costs, long development timelines, and a shortage of specialists. The report argues that advances in artificial intelligence may reduce these barriers, allowing rigorous verification techniques to be applied more widely.
The report calls for a coordinated national approach through the creation of a permanent Software Understanding National Security Committee, building on the 2023 Software Understanding for National Security initiative. The proposed body would coordinate efforts across federal agencies, develop research priorities, and support collaboration between government, industry, and other organizations.
It also recommends changing the incentives that have shaped software development for decades. The report argues that software markets have traditionally rewarded speed, functionality, and lower upfront costs rather than security and resilience. It recommends using government procurement requirements, security benchmarks, and industry standards to encourage companies to develop more secure software.
The report further recommends that software assurance become part of mission planning, acquisition decisions, and operational requirements rather than being treated only as a technical compliance issue. It argues that organizations should measure software risks based on potential mission failures, including the consequences of disruptions to critical defense, intelligence, and infrastructure systems.
However, the report emphasizes that improving software security will not end cyber conflict. As stronger protections are implemented, adversaries are expected to adjust their methods and shift attention toward less-secured targets, including smaller organizations and civilian systems. The report recommends continued investment in traditional cybersecurity practices, including vulnerability management, monitoring, patching, and incident response.
The final recommendations focus on accountability and adaptation. The report calls for stronger mechanisms to attribute malicious cyber activity, improve deterrence, and monitor how adversaries respond as software security improves. It also recommends establishing a lessons-learned capability to track changes in cyber operations, conduct assessments, and share knowledge across sectors.
As software continues to control an expanding share of military, economic, and civilian systems, the report concludes that understanding and verifying the technology behind those systems has become a critical security requirement. The challenge identified by The Soufan Center is not limited to preventing individual cyberattacks, but ensuring that the software infrastructure supporting modern society can be trusted before it becomes a target.

