Lt. Col. Michael J. Thompson and the 1997 Fight Over Who Owned the Internet's Failures

By Miriam Adler ·

Kept unclassified but vague, a 1997 report on the National Information Infrastructure masked a widening gap between federal warnings and a military pivot toward offensive cyber-war.

The people moving their lives and legacies onto the early American internet in the late 1990s were doing so without a map and without a shield. They were trusting a fragile web of wires and protocols that the government knew were failing, but the government could not decide who was supposed to fix it.

What survives of this era in the archive is not the full internal debate, but a curated description of a specific report. This description establishes the contours of a crisis that was managed through strategic ambiguity. On March 3, 1997, Lt. Col. Michael J. Thompson, a senior officer tasked with examining the intersection of technology and strategy, filed a report titled "Information Warfare - Who Is Responsible?: Coordinating the Protection of Our National Information Infrastructure."

Thompson wrote the piece while affiliated with the U.S. Army War College, the graduate-level institution at Carlisle Barracks in Pennsylvania that prepares senior military officers and government civilians for the highest levels of leadership. The report's central aim was to "explore the role of the federal government in protecting the national information infrastructure," a term known as the NII. The NII was the public-facing policy buzzword of the Clinton administration, born from the High Performance Computing Act of 1991 and championed by Vice-President Al Gore to describe the transition to a high-speed, interconnected digital society.

The Fragility of the NII

According to the record, Thompson did not sugarcoat the technical state of the union. He focused on the "vulnerabilities and fragility of the infrastructure" and noted a sharp "increase in hacking." The document was not a technical manual but a query into authority. It sought to determine how the federal government should coordinate "actions to protect the infrastructure" when the infrastructure itself was a sprawling, chaotic mix of public and private interests.

This is where the record meets the public record with a jarring friction. While Thompson was asking who was responsible for the NII in March 1997, the Government Accountability Office had already issued a blistering assessment in May 1996. The GAO had reported that computer attacks at the Department of Defense posed "increasing risks," meaning the very organization Thompson served was already bleeding data while the leadership was still debating the organizational chart.

Document imagery from nsarchive.gwu.edu From the files: nsarchive.gwu.edu

A Strategy of Distraction

The connection between the GAO's warning and Thompson's inquiry reveals a deliberate disconnect. The GAO identifies a fire; Thompson asks who owns the fire extinguisher. The record shows that Thompson's report was unclassified, a choice that allowed the Army War College to engage in a high-level doctrinal exercise without triggering the security protocols that would have required actual solutions.

If the shape of this file is what it appears to be, the desk's reading is that the question of "Who Is Responsible?" was a euphemism for an active inter-agency turf war. In 1997, the DoD, the FBI, and the NSA were locked in a struggle to define the boundaries of cyber-authority. By framing the problem as a question of "coordinating protection," the report avoided naming the specific failures of the DoD's own security posture that the GAO had already flagged. It turned a systemic operational failure into a theoretical leadership problem.

Furthermore, the pattern suggests that this report was a doctrinal exercise in liability shifting. Because Thompson was writing from the U.S. Army War College—a school for strategists, not a command for operators—the report functioned as a theoretical framework designed to deflect blame. If the government could not agree on who was responsible for the NII, then no single official could be held accountable when the inevitable breaches occurred.

The Offensive Pivot

There is a darker irony hidden in the timing of this document. While Thompson was exploring the "protection" of the NII in March 1997, the military's actual trajectory was moving in the opposite direction. Just months earlier, in November 1996, the Joint Chiefs of Staff had issued a strategy titled "Information Warfare: A Decisive Edge in War."

The contrast is absolute. Thompson’s record focuses on "protection," "fragility," and the "role of the federal government" as a guardian. The Joint Chiefs' strategy focused on the "decisive edge," treating the digital realm not as a fragile infrastructure to be shielded, but as a battlefield to be dominated. The desk's reading is that the "protection" narrative in the Thompson report served as an unclassified mirror to a classified pivot toward offensive cyber-weaponization. The government was publicly wondering who would guard the gates while privately building the tools to kick in everyone else's.

This suggests that the "increase in hacking" mentioned by Thompson was not viewed by the Pentagon as a warning sign for domestic defense, but as a proof of concept for offensive operations. The vulnerabilities Thompson lamented were the same apertures the military was learning to exploit in adversaries. The NII was not being protected; it was being mapped.

The Gap in the Record

The record omits the most critical variable of the NII: the private sector. The National Information Infrastructure was predominantly privately owned, yet Thompson’s report focused on the "role of the federal government." The pattern suggests a systemic friction—a jurisdictional refusal by the companies that actually owned the wires to grant the federal government oversight. The government could not "coordinate protection" because it did not own the assets, and it could not force private companies to secure them without admitting how vulnerable the entire system actually was.

This gap is shaped like a confession. By focusing on the internal coordination of the federal government, the record ignores the reality that state actors were already leveraging the "increase in hacking" for reconnaissance of the very infrastructure Thompson sought to protect. The report treats hacking as a series of isolated incidents to be managed; the reality was a strategic infiltration already in progress.

The desk's reading is that the Thompson report was never intended to solve the problem of NII fragility. It was a placeholder, a way to signal that the government was "exploring" the issue while the actual work of the 1990s shifted from defense to dominance. The focus on "Who Is Responsible?" was the perfect smoke screen. It allowed the administration to maintain a posture of concerned inquiry while the Joint Chiefs pursued the "Decisive Edge."

If the remaining withheld pages of the era's information warfare files were released, they would likely show that the vulnerabilities Thompson highlighted were not bugs to be fixed, but features to be exploited. The cost of this strategic ambiguity was paid by the American public, who were told their digital future was being coordinated for their protection, while the state was actually preparing the NII to be a weapon of war. The tragedy of the 1997 report is that it asked the right question to ensure the wrong answer remained the official policy.

Sources

  1. Lt. Col. Michael J. Thompson, U.S. Army War College,Information Warfare - Who Is Responsible?: Coordinating the Protection of Our National Information Infrastructure, March 3, 1997. Unclassified. — National Security Archive (GWU)
  2. Document PDF (Lt. Col. Michael J. Thompson, U.S. Army War College,Information Warfare - Who Is Responsible?: Coordinating the Protection of Our National Information Infrastructure, March 3, 1997. Unclassified.)
  3. Background: National Information Infrastructure — Wikipedia