Paul Cabral and the 1998 Map of Digital Vulnerability

By Miriam Adler ·

The Army's 1998 strategy for 'protecting' the web masked a deeper interest in how to dismantle it, leaving the public's data exposed to the very agencies claiming to shield it.

The people whose private data migrated to the early web in the late nineties did so under the assumption that the state was a clumsy bystander. They were wrong; the state was not a bystander, but a student, meticulously mapping the vulnerabilities of the digital world to ensure that when the time came to break things, it knew exactly where to strike.

I am working from the archive's curated description of the paper rather than its original pages. The record is a March 6, 1998, study produced by Paul A. Cabral through the U.S. Army War College, a staff college in Carlisle Barracks, Pennsylvania, that prepares senior military and government leaders for strategic leadership roles. The paper, titled "Information Warfare and Information Operations: Protecting the Global Information Environment," serves as a primer on the fragility of the wires.

According to the record, the study "examines vulnerabilities in global, national and defense information infrastructure; reviews directives, regulations, and policies; and discusses the role of government in protecting information infrastructure." On its face, it is a manual for defense. In the context of the era's broader signals intelligence goals, it is a blueprint for exploitation.

The Carlisle Blueprint

In 1998, the Army War College was not merely teaching colonels how to move tanks; it was teaching them how to move data. The focus on the "Global Information Environment" in Cabral's paper suggests a shift in the military's gaze. By framing the entire world's interconnected networks as a single environment, the Army moved beyond traditional borders.

Paul A. Cabral, the author, provides the most striking trajectory in this file. The public record identifies him as Cabral Libii Li Ngué, a journalist and law instructor who would eventually be elected as a Member of Parliament in the National Assembly of Cameroon in 2020. The line from a U.S. military strategic college to the legislature of a Central African nation is not a coincidence; it is a study in the globalization of information power. Cabral was in the room at Carlisle to synthesize how a superpower views the digital plumbing of the world, and he carried that understanding of systemic vulnerability into a career in law and politics.

Document imagery from nsarchive.gwu.edu From the files: nsarchive.gwu.edu

The GAO Gap

There is a caustic irony in the timing of the record. While Cabral was outlining the "role of government" in protecting infrastructure in March, the actual government was failing its most basic security tests.

Two months later, on May 19, 1998, the Government Accountability Office—the congressional watchdog responsible for auditing federal spending and efficiency—issued a report titled "INFORMATION SECURITY, Serious Weaknesses put State Department and FAA Operations at Risk." The public record shows that while the strategic thinkers at the War College were theorizing about the "Global Information Environment," the Federal Aviation Administration, which manages all U.S. airspace, and the State Department were riddled with "serious weaknesses."

This gap between strategic optimism and technical incompetence is where the danger lived. The Army War College was drafting the philosophy of digital protection while the agencies responsible for the nation's flight paths and diplomatic cables could not secure their own doors. The record shows a government that was obsessed with the concept of information warfare but remained functionally illiterate in the practice of basic cybersecurity.

A Mask for Offensive Operations

When a military institution spends its time "examining vulnerabilities" under the guise of "protecting" them, the desk's reading is that the paper serves as a sanitized conceptual framework for a classified offensive counterpart. In the physics of information warfare, there is a perfect symmetry: you cannot protect a network unless you have already mastered the art of dismantling it. To identify a vulnerability for the purpose of patching it is the same technical act as identifying a vulnerability for the purpose of exploiting it.

If this file is shaped the way it looks, the "protection" discussed by Cabral was the prerequisite for aggression. The record mentions "directives, regulations, and policies," but it does not mention the lack of legal authority the government had to compel private-sector cooperation. By 1998, the global information environment was rapidly shifting into private ownership. The government did not own the wires; companies did. The desk's reading is that the paper ignores this dependency because the military's actual strategy was not based on corporate cooperation, but on the exploitation of those very private-sector gaps.

The Global Abstraction

Throughout the record, the term "Global Information Environment" is used as a convenient abstraction. It is a phrase that allows the author to discuss targets without naming them. The surrounding archive from 1998 is preoccupied with the collapse of Boris Yeltsin's Russia and the volatility of North Korea. Yet, the Cabral paper avoids naming specific adversaries.

The pattern suggests that the "Global Information Environment" was used to avoid pinning the Army's interests to a specific geopolitical target, thereby keeping the strategy flexible and the intentions opaque. By treating the entire world's data as a single environment, the Army effectively claimed the right to operate anywhere the signal traveled.

The Reading of the Record

The desk's reading is that this paper was never about protection. It was an exercise in mapping the terrain. By documenting the "vulnerabilities in global, national and defense information infrastructure," the Army War College was creating a taxonomy of weakness. The subsequent GAO report confirming the incompetence of the State Department and the FAA proves that the government was not interested in fixing these holes for the sake of public safety. They were interested in the holes because holes are where the intelligence goes in.

If a full release of the War College's 1998 curriculum were available, it would likely show that Cabral's paper was the public-facing mirror of a much darker set of instructions. The withheld pages would not be about "protecting" the environment; they would be about how to weaponize the "serious weaknesses" that the GAO had already identified. The cost of this strategy was borne by the public, who were told the state was their shield while the state was actually studying the exact points where the shield was thinnest, ensuring that the government remained the only entity in the room that knew how to break the world.

Sources

  1. Paul A. Cabral, U.S. Army War College,Information Warfare and Information Operations: Protecting the Global Information Environment, March 6, 1998. Unclassified. — National Security Archive (GWU)
  2. Document PDF (Paul A. Cabral, U.S. Army War College,Information Warfare and Information Operations: Protecting the Global Information Environment, March 6, 1998. Unclassified.)
  3. Background: Cabral Libii — Wikipedia