Reference
The NADAC framework
A Layered National Defense Framework for AI-Enabled Cyber Warfare: Actionable Controls, Metrics, and Implementation — Shahmeer Amir, Independent Cybersecurity Researcher. Four defensive tiers, 21 controls each with an explicit threat mapping and numeric target, a three-phase 36-month roadmap, and seven indicators that make progress auditable.
Foundational Cyber Hygiene
Controls that mitigate the largest fraction of documented intrusions regardless of AI involvement. Emphasis on living-off-the-land detection and identity-layer hardening, per the Volt Typhoon and Salt Typhoon disclosures.
PrerequisiteWithin reach of any state with a functional cybersecurity institution.
AI-Specific Technical Controls
Attack surface that did not meaningfully exist before 2022: prompt injection, indirect prompt injection, data poisoning, model extraction, foundation-model supply chain compromise, and shadow AI.
PrerequisiteRequires regulatory sophistication and enforcement capacity.
Institutional Capability
The human and institutional capacity required to sustain Tiers 1 and 2 — a national AI-CSIRT, mandatory reporting, bug bounty with AI scope, defensive AI tooling, and ISAC intelligence channels.
PrerequisiteRequires significant human capital.
International Coordination
The threat is transnational and the highest-fidelity intelligence on AI misuse sits with a small number of frontier model providers. Provider MoUs, allied sharing channels, UN OEWG norm-building, and cross-border evidence protocols.
PrerequisiteSmaller states can substitute regional coalitions (ASEAN CERT-SEA, AU-CERT, OAS CSIRTAmericas).
Catalogue
21 controls
Each control pairs a specific threat with a measurable target and a delivery phase.
| ID | Control | Target | Phase |
|---|---|---|---|
| T1T1.1 | Phishing-resistant MFA (FIDO2/WebAuthn) | 100% critical infrastructure by M12 | P1 |
| T1T1.2 | ASM/EASM continuous inventory | ≤ 24h external asset discovery | P1 |
| T1T1.3 | KEV-aligned patch SLA | ≤ 7d critical infra; ≤ 14d elsewhere | P1 |
| T1T1.4 | Zero-trust OT/IT segmentation | ≥ 90% of OT/IT boundary by M24 | P1 |
| T1T1.5 | 24/7 security operations with SLA | MTTD ≤ 4h; MTTR ≤ 24h | P1 |
| T2T2.1 | Prompt-injection testing in CI | ≥ 95% pass on OWASP LLM01 corpus | P2 |
| T2T2.2 | Agent tool-permission scoping | Automatic review above pre-approved baseline | P2 |
| T2T2.3 | Model SBOM (M-SBOM) | 100% of production models | P2 |
| T2T2.4 | Deepfake detection at chokepoints | Real-time confidence scoring | P2 |
| T2T2.5 | Out-of-band transaction verification | Mandatory above ≈ US$100k | P2 |
| T2T2.6 | Dual-LLM quarantine pattern | All agents processing untrusted content | P2 |
| T2T2.7 | Shadow-AI discovery | 100% discoverable ≤ 30d by M18 | P1 |
| T3T3.1 | National AI-CSIRT unit | 15–25 FTE per 50M population | P1 |
| T3T3.2 | Mandatory AI-linked breach reporting | ≤ 72h from confirmation | P1 |
| T3T3.3 | National bug bounty with AI scope | Legal safe harbor + AI-class minima | P2 |
| T3T3.4 | Defensive AI (AIxCC open-source) | ≥ 60% of federal software by M36 | P3 |
| T3T3.5 | ISAC AI-misuse intelligence channel | Quarterly sharing mandate | P3 |
| T4T4.1 | Frontier model provider MoUs | Quarterly threat-intel reporting | P2 |
| T4T4.2 | Allied AI-misuse sharing channel | Operational by M18 | P2 |
| T4T4.3 | UN OEWG AI-in-cyber track | Baseline within 36 months | P3 |
| T4T4.4 | Cross-border MLAT evidence protocols | AI logs admissible in ≥ 20 states | P3 |
Roadmap
36-month sequencing
Annual budget bands are the paper's figures for the ~50M-population reference country.
P1 Foundations
Months 0–12
US$40–80M / yr
T1.1–T1.5 rollout audit; T3.1 AI-CSIRT stand-up; T3.2 reporting regulation enacted; T2.7 shadow-AI baseline established.
P2 AI controls
Months 12–24
US$60–120M / yr
T2.1–T2.6 deployed in regulated sectors; T4.1 MoUs signed with top 5 model providers; T3.3 bug bounty operational.
P3 Diffusion
Months 24–36
US$50–100M / yr
T3.4 AIxCC OSS deployed to ≥ 60% federal software; T4.2 Five Eyes+ channel operational; T4.3 OEWG outputs; T4.4 MLAT protocols.
Measurement
Seven KPIs
| ID | Indicator | Baseline 2025 | M12 | M36 |
|---|---|---|---|---|
| K1 | MTTD for AI-linked intrusions | ~194 days | ≤ 90 days | ≤ 30 days |
| K2 | % KEV CVEs patched within SLA (critical infra) | ~55% | ≥ 85% | ≥ 95% |
| K3 | % critical infra with living-off-the-land detection | < 30% | ≥ 70% | ≥ 95% |
| K4 | % frontier providers reporting quarterly | 0% | 100% | 100% |
| K5 | Deepfake fraud loss as share of GDP (quarterly) | Untracked | Baselined | ≥ 50% reduction |
| K6 | % federal software with defensive-AI coverage | 0% | ≥ 20% | ≥ 60% |
| K7 | Prompt-injection CI pass rate | Untracked | ≥ 90% | ≥ 95% |
Caveats
Stated limitations
- The empirical baseline reflects only publicly disclosed incidents; true incidence is likely one to two orders of magnitude larger.
- NADAC presupposes state capacity not all states possess. Tier 2 requires regulatory sophistication; Tier 3 requires significant human capital.
- Tier 4 telemetry sharing is dual-use and must be narrowly scoped, with judicial oversight and limits on downstream data use.
For a country of ~50 million population with moderate critical-infrastructure exposure, cumulative three-year expenditure of US$150–300M is consistent with the NADAC specification.