WarBrief Live | October 6, 2026 | Cyber Intelligence
Every modern military depends on the internet. Orders move through it, logistics systems run on it, and civilian infrastructure that troops rely on is connected to it. This means Censys military cybersecurity work, and internet intelligence in general, has become part of how defense organizations think about defending themselves. But what exactly is internet intelligence, and why does it matter for military and government cybersecurity? The short answer is simple: you cannot defend what you cannot see, and the internet is the place where attackers look first.
Internet intelligence means collecting and analyzing information about devices, services, and networks that are visible on the public internet. This includes which servers are online, which ports they expose, which certificates they use, and which software versions they run. Specialized scanning platforms such as Censys Inspect and similar tools explained in our scanner guide gather this data continuously and index it so analysts can search it like a database. For a military or government defender, this is like having a map of every open door and window on every building they are responsible for.
Key Takeaways
- Internet intelligence maps a defense organization’s internet-facing assets so defenders can find exposed systems before attackers do.
- Real U.S. government programs — including CISA’s BOD 23-01 and BOD 20-01 — already require continuous asset discovery and vulnerability reporting for federal civilian systems.
- The July 2026 attacks on U.S. water-system controllers showed that exposure itself, not a software bug, was the vulnerability.
- Internet intelligence is only one component of military cybersecurity; it must sit alongside classified collection, endpoint defense, and network monitoring.
What does internet intelligence mean in a military context?
When people hear “military intelligence,” they usually think of spies and satellites. Internet intelligence is far less secret. It deals only with what is publicly visible. Anyone, attacker or defender, can observe which devices answer when you connect to them over the internet. That includes web servers, email servers, routers, cameras, industrial controllers, and VPN gateways.
For a defense organization, this data answers basic but critical questions. Do we know about every server our agency has put online? Are any of them running old, vulnerable software? Did a contractor accidentally expose a control system that should be internal? Is there a government-owned certificate being used by a server we do not control?
Attackers ask exactly the same questions, but for different reasons. Nation-state groups routinely scan the internet for exposed infrastructure belonging to their targets. This makes internet intelligence a two-way race: defenders must find their own exposed assets at least as fast as adversaries do.
Why are military and government networks exposed?
Governments are large, and large networks are messy. Departments build new web portals without telling the security team. Contractors connect equipment to the internet for convenience and forget about it. Agencies merge, systems get inherited, and nobody keeps a complete list. The result is a sprawling attack surface that includes forgotten servers, misconfigured cloud services, and industrial equipment connected directly to the open internet.
The U.S. government has tried to fix this with formal orders. In October 2022, the Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive 23-01, which requires federal civilian agencies to perform automated asset discovery every seven days and vulnerability checks across all discovered assets every 14 days, reporting results into a central dashboard. That is a government formally declaring: continuous knowledge of your own internet footprint is mandatory, not optional.
An earlier directive, BOD 20-01 from September 2020, required the same agencies to publish vulnerability disclosure policies so outside researchers can report flaws they find in government systems. CISA then built a shared reporting platform with Bugcrowd and EnDyna so researchers and agencies could exchange findings. The underlying logic is the same: the internet shows everything, so governments might as well see it themselves.
Note that these directives apply to federal civilian agencies, not to the Department of Defense, which operates under its own authorities. But they illustrate the broader trend: internet-facing exposure is now treated as a core security responsibility of government IT.

How does Censys military cybersecurity analysis work in practice?
In practice, platforms like Censys continuously scan the IPv4 internet and record what responds. An analyst can then search for, say, every device presenting a government agency’s TLS certificate, or every exposed industrial controller in a country, or every server running a specific vulnerable software version. The platform keeps historical records, so analysts can see when a device appeared, when its certificate changed, or when a service suddenly opened a new port.
This data enriches threat intelligence in concrete ways. When a new critical vulnerability is announced, defenders can query internet intelligence for exposed instances of the affected software inside their own address space within minutes. When incident responders investigate a breach, they can check whether the attacker’s command-and-control servers have been seen touching other assets. When diplomats and analysts want to understand a foreign state’s cyber posture, historical exposure data shows which parts of its infrastructure are hardened and which are not.
It is worth stating a fact plainly: there is no reliably documented public evidence that any specific military organization uses Censys. What is publicly documented is that CISA, the U.S. civilian cybersecurity agency, named Censys as one of several example exposure-discovery tools in its 2026 Internet Exposure Reduction Guidance, alongside Shodan, Thingful, and Shadowserver, while adding that naming a tool does not imply government endorsement. Military use of such platforms is plausible but unverifiable from public sources, and this article will not claim otherwise.
What real cases show why this matters?
The clearest recent case comes from the U.S. water sector. In July 2026, CISA observed malicious cyber activity targeting more than 100 internet-exposed systems in the water and wastewater sector. The attackers reached programmable logic controllers, the small industrial computers that operate pumps and valves, connected directly to the internet, often through cellular modems. They logged in with default or weak passwords, changed the passwords to lock out the operators, and altered device IP addresses to cut the systems off from their networks. Some utilities had to run their plants by hand.
CISA’s description of the problem is worth quoting directly because it makes the point better than any analyst could:
“In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem.”
The campaign, linked in federal advisory AA26-097A to Iranian-affiliated actors targeting controllers made by Rockwell, Siemens, and Schneider Electric, had no sophisticated exploit at its heart. The vulnerability was exposure itself. Researchers using internet-scanning services counted more than 4,100 exposed Rockwell and Allen-Bradley hosts, over 4,100 Siemens hosts, and roughly 2,000 Schneider devices reachable from the public internet during the same period. The scale of exposure was measurable from the outside, by anyone, before the attacks peaked.
Nation-state espionage campaigns make the same point from a different angle. CISA, the FBI, and the NSA have documented Salt Typhoon, a Chinese state-sponsored operation that penetrated U.S. telecommunications networks, and Volt Typhoon, which pre-positioned inside American critical infrastructure including energy and water systems. These campaigns begin with reconnaissance, and reconnaissance begins with what is visible on the internet.
Defense-related background reading on exposed infrastructure in conflict zones can be found in our earlier piece on internet scanning and exposed infrastructure in conflict, and the defensive research toolkit behind such analysis is described in Cyber Warfare Research: Using Internet Scan Data (2026).

Why does it matter who operates these tools?
An often-overlooked detail is that internet intelligence depends on who keeps scanning. In April 2025, Nextgov/FCW reported that CISA instructed its threat-hunting teams to stop using Censys and VirusTotal, the malware-analysis platform, amid budget cuts and restructuring. The agency’s internal email acknowledged the tools’ importance and said it was exploring alternatives.
Then in 2026, CISA’s Internet Exposure Reduction Guidance recommended that critical infrastructure owners “routinely use web-based exposure discovery tools” — naming Censys among them — to find internet-exposed IT and operational-technology assets. That shift, from a federal agency dropping a tool to the same agency recommending its category a year later, shows how unsettled the operational picture is. For military and government defenders, the lesson is that access to internet intelligence is not guaranteed. Redundancy, in-house scanning capability, and contractual continuity matter.
What are the limits of internet intelligence?
Internet intelligence has hard limits, and military planners understand them. First, it only sees what is exposed. An adversary’s internal networks, closed military systems, and air-gapped infrastructure do not appear in scan data. Second, exposure data tells you what exists, not what will happen. A visible server is a potential target, not a confirmed one.
Third, and most important: internet intelligence is one input among many. A serious defense program combines it with endpoint detection, internal network monitoring, identity and access management, classified intelligence collection, threat-hunting teams, and incident response. It also requires the boring fundamentals the July 2026 PLC campaign exposed: change default passwords, remove unnecessary remote access, keep accurate inventories, and never connect industrial controllers directly to the internet.
For defenders thinking about critical infrastructure specifically, Censys and Critical Infrastructure: Finding Exposed Systems covers how scanning data informs protection of power, water, and telecom systems, and How Internet Intelligence Helps Investigate Cyber Attacks walks through how the same data is used when investigating an attack after it happens.
Frequently asked questions
What is internet intelligence?
Internet intelligence is the collection and analysis of information about devices, services, and networks visible on the public internet — such as exposed servers, open ports, TLS certificates, and software versions. It is gathered by internet-wide scanning platforms and used to map attack surfaces and enrich threat intelligence.
Does the military use Censys?
There is no reliably documented public evidence that any specific military organization uses Censys. CISA, the U.S. civilian cybersecurity agency, has named Censys as one example tool in its public Internet Exposure Reduction Guidance, alongside other platforms. Military use is plausible but cannot be confirmed from public sources.
What is CISA BOD 23-01?
Binding Operational Directive 23-01, issued in October 2022 and effective April 3, 2023, requires U.S. federal civilian executive branch agencies to run automated asset discovery every seven days, enumerate vulnerabilities across all discovered assets every 14 days, and feed results into CISA’s Continuous Diagnostics and Mitigation dashboard. It applies to civilian agencies, not the Department of Defense.
How did the July 2026 water-sector attacks work?
According to CISA, threat actors found internet-exposed programmable logic controllers at U.S. water utilities, logged in with default or weak credentials, changed passwords to lock out operators, and altered device settings. No advanced exploit was needed; the controllers were simply reachable from the internet. Federal advisories linked the activity to Iranian-affiliated actors.
Is internet intelligence enough to defend a military network?
No. It is one component of a larger strategy. It maps what is exposed but cannot see internal or classified networks, and it must be combined with endpoint defense, network monitoring, identity security, and incident response to be effective.
Conclusion
Internet intelligence matters for military and government cybersecurity because the internet is where modern conflict begins. Attackers map exposed infrastructure before they strike, and defenders must map it first. U.S. government programs like BOD 23-01, BOD 20-01, and CISA’s exposure-reduction guidance all point in the same direction: continuous, systematic knowledge of your own internet footprint is now a baseline requirement, not a luxury.
The July 2026 water-sector campaign proved the cost of getting this wrong. More than 100 exposed systems were hit by attackers who needed nothing more sophisticated than a reachable login screen. That failure was not a failure of classified intelligence or advanced technology. It was a failure to see what the internet already showed.
But visibility is only the first step. Internet intelligence must feed into real action — patching, disconnecting, segmenting, and hardening — and it must sit inside a defense strategy that includes everything from endpoint sensors to national policy. Scanning the internet is easy. Defending it is hard. The two are not the same thing, and any serious defense program has to treat them accordingly. For readers new to the underlying technology, start with our overview of internet-wide scan data for security research and CensysInspect Explained: Internet Intelligence Guide for a plain-English explainer of the tools involved.
Sources and Further Reading
- CISA — BOD 20-01: Develop and Publish a Vulnerability Disclosure Policy
- Dark Reading — CISA BOD 23-01: What Agencies Need to Know About Compliance
- Industrial Cyber — CISA Issues Internet Exposure Reduction Guidance
- WebProNews — Over 100 U.S. Water Systems Targeted in One Month as CISA Sounds Alarm on Exposed PLCs
- GBHackers — CISA Issues Warning Against Using Censys, VirusTotal in Threat Hunting Ops (reporting Nextgov/FCW)
- SC Media — CISA Urges Critical Infrastructure to Plan for Prolonged Service Delivery (Salt Typhoon / Volt Typhoon)