July 29, 2026

Podcast: Drone War Series – Protecting Data at Risk on Edge of Combat

How can sensitive mission data remain secure when a device is lost, captured, or operating beyond the protection of the network?

Modern military operations depend on laptops, tactical servers, unmanned systems, ISR platforms, and other edge devices that collect, process, and store classified information. These systems frequently operate in disconnected, contested, or physically exposed environments where traditional network security is no longer enough.

In this episode of the Drone War Series, Cigent CEO Brett Hansen discusses the critical challenge of protecting Data at Rest on devices deployed at the edge of combat. The conversation examines how organizations can safeguard classified information even when a device falls outside friendly control.

Securing the Data, Not Just the Network

A device may begin its mission connected to a controlled network, but that protection can disappear when communications are interrupted, the system is powered down, or the hardware is physically captured.

The sensitive information stored on that device remains at risk, including:

  • Mission plans and operational intelligence
  • Authentication credentials and communication records
  • Sensor and ISR data
  • AI models and algorithms
  • Platform software and firmware
  • Other classified or mission-sensitive information

Effective Data-at-Rest protection must be built directly into the device and remain active regardless of its connection status.

A Layered Approach to Classified Data Protection

During the discussion, Brett explains how the NSA Commercial Solutions for Classified Data-at-Rest Capability Package provides an approved framework for protecting classified information using commercial technologies.

The architecture combines independent security layers, including:

  • Hardware full-drive encryption
  • Pre-Boot Authentication
  • Software Full Drive Encryption
  • Multi-Factor Authentication

Pre-Boot Authentication is especially important because it verifies the user before the operating system loads. Without proper authentication, the encrypted drive remains locked and its data inaccessible.

A self-encrypting drive alone does not provide complete protection. The encryption must be paired with an authentication platform that prevents an unauthorized individual from simply powering on the device and accessing its contents.

Protecting Data When Recovery Is Impossible

The discussion also addresses rapid data sanitization for situations in which a device is at immediate risk of loss or capture.

Cryptographic erasure destroys the encryption keys protecting the data, rendering the information permanently inaccessible in milliseconds. When more time is available, block erasure can provide an additional method of removing stored information.

These capabilities give defense teams greater control over sensitive data throughout the device lifecycle, including circumstances where the hardware itself cannot be recovered.

Learn how layered encryption, Pre-Boot Authentication, and rapid data sanitization can help protect classified Data at Rest across tactical edge environments.

Watch the video to explore:

  • Why network security alone cannot protect disconnected devices
  • How NSA CSfC requirements apply to Data-at-Rest protection
  • The role of Pre-Boot Authentication in securing encrypted drives
  • How data can be protected when devices are lost or captured
  • Why sanitization provides an additional layer of mission assurance