Problem-Solving in Chaos: the Evolution of the "Attack the Network" (AtN) Methodology - A Unique Perspective
INTRODUCTION
The Global War on Terror (GWOT) forced the most significant doctrinal pivot in modern military history. Confronted by decentralized, non-state terrorist networks in Iraq and Afghanistan, the United States military and its interagency partners discovered that conventional, linear models of warfare were inadequate for achieving decisive effects. We excelled at short-term, tactical victories while longer-term strategic success often eluded us.
This paper provides an historical analysis of how the Attack the Network (AtN) methodology evolved from an isolated tactical theory into a formalized joint doctrine. It documents the critical intellectual and operational milestones of this transition, highlighting the specific role I played as a principal advisor and author. It is not intended to show that I am the sole creator of AtN, but rather that I was extremely fortunate to work alongside key leaders within Special Operations Forces and the Asymmetric Warfare Group (AWG) at pivotal times that led to significant advancements in targeting. I will always be grateful to those who supported me, gave me second chances, and allowed me to be a part of critical operations at a decisive moment in our history. The saying, “I walked among giants…” certainly applies here!
I also want this paper to be of value to those whom our team at Crisis Response Leader Training (CRLT), Inc. work hard to support now: those on the frontlines providing safety and security for our communities and our society. Where possible, I have inserted lessons-learned summaries intended to add hindsight for those dedicated to making our lives safer.
PART I: THE MODIFIED ISM (2001–2003)
To understand the evolution of AtN, it is necessary to examine the pre-9/11 conventional architecture, when we were already beginning to recognize its impending failure. For decades, the U.S. military relied on the D3A methodology (Decide, Detect, Deliver, Assess), an attrition-based model optimized for linear battlefields and static, conventional threat formations.
The first significant departure from this model occurred during the 2000–2002 timeframe at the National Training Center (NTC). As a senior Observer Controller (OC) for Brigade Combat Team (BCT) staffs, I watched dozens of training rotations that forced commanders and their staffs to conduct deliberate and hasty Military Decision Making Processes (MDMP), as well as joint targeting. It was while I was at NTC that 9/11 happened; I was there while we conducted rehearsals of BCTs for the invasion of Iraq. I remember two frustrating things that I repeatedly witnessed while serving there.
First, there was a solid foundation for a targeting process based on the doctrinal application of Center of Gravity (COG) analysis, determining High-Value Targets (HVT), and focusing on High-Priority Targets (HPT). However, this was a laborious analytical process that was difficult to adapt to rapid, incoming significant activities; the process was not adaptive enough for the modern battlefield. Second, nearly half of our friendly casualties during the “force-on-force” training were due to insurgent actions behind the Forward Line of Troops. We were too accustomed to fighting a recognizable enemy that would go “head-to-head” against us. We were not ready to identify and aggressively neutralize threats that focused specifically on our rear-area weaknesses.
From these interactions, I authored an article detailing a restructuring of the traditional Intelligence Synchronization Matrix (ISM). Historically, the ISM was a rigid planning tool used to track physical threat formations across distinct geographic sectors. The original ISM was often criticized for being overly rigid, text-heavy, and detached from the fluid realities of the battlefield, frequently functioning as a static collection plan rather than a dynamic operational tool. In contrast, the proposed Modified Intelligence Synchronization Matrix (MISM) shifted the focus from a purely asset-driven schedule to a time-phased, event-driven visualization that directly linked intelligence collection to the commander’s maneuver timeline, Decision Points (DPs), and Target Areas of Interest (TAIs). The primary intended benefit of adopting the MISM was enhanced cognitive speed and operational synchronization. By transforming a complex process and document into a highly visual, readable tool, it allowed tactical operations centers to rapidly re-task sensors in real time as the battlefield changed, ensuring intelligence drove operations rather than merely reacting to them.
My intent was to re-engineer the matrix to map non-linear actions and activities: dynamically changing human intent, localized cell interactions, shifting priorities, and limited resources—all while maintaining focus on what the commander wanted and needed from intelligence to make rapid decisions on the battlefield. This early paper helped shape the initial concept that conventional planning tools could be adapted to model human networks.
As the commitment of both special and conventional forces to the GWOT expanded, there was a growing awareness of our targeting limitations: limited collection assets, too many unprioritized targets, and confusion on how to modify doctrinal processes. Years later, while operating in Iraq as we collectively became accustomed to a reactive “Whack-a-Mole” targeting approach, I remember a think tank paper arguing that we could not model insurgent behavior because it was too asymmetric. I adamantly disagreed.
Lessons Learned for Modern Public Safety:
Move from Asset-Driven to Event-Driven Planning: In multi-jurisdictional emergencies or complex active-threat scenarios, crisis leaders often plan based strictly on what assets are currently available (e.g., "Where are my trucks?"). True resilience requires switching to an event-driven visualization. Public safety plans must directly tie resource deployment to specific, anticipated cascading failures or leader decision points in real time.
Overcome Information Overload via Visual Tools: Complex, text-heavy emergency management plans can drop in uncertainty when chaos hits. To increase cognitive speed during an unfolding disaster, emergency managers and corporate infrastructure chiefs must replace dense, bureaucratic status sheets with highly visual, dynamic matrices that map shifting priorities, localized risks, and resource gaps on a single, shared operational picture.
Integrate and Synchronize Assets: It is one thing to ensure all assets are integrated into a plan. It is another thing all together, ensuring that each asset is doing the right thing at the right time for the intended purpose and outcome. An execution checklist should not be about organizational hierarchy and setup; it is about the detailed actions each subordinate element must accomplish on a dynamic timeline, or in support of a leader’s decision points.
PART II: THE EXPERIMENTAL ECOSYSTEMS: MOSUL, THE FINER POINTS OF F3EAD, AND INTERAGENCY FUSION
Following the 2003 invasion of Iraq, the proliferation of decentralized insurgent infrastructure made it clear that the conventional targeting loop was failing. While elite special operations forces popularized the F3EAD cycle (Find, Fix, Finish, Exploit, Analyze, Disseminate), the pipeline remained intensely focused on a narrow, rapid "Kill/Capture" high-value target (HVT) cycle that often treated the symptoms rather than the systemic infrastructure of the threat. At this time, I became more uniquely involved in the GWOT. I was assessed, selected, and trained to conduct sensitive activities on behalf of our government, with my primary purpose being to identify and neutralize terrorist network leaders. It was a challenging time in many regards; even the way we conducted traditional collection operations needed to adapt—just as our enemies were adapting to survive and attack our vulnerabilities. Mistakes were made; I made mistakes. I am grateful that we survived, for the second and third chances that I was given, and that I was able to take my lessons learned and help advise others so that they might advance our processes. To the point, we needed to mature and evolve. I did and the system needed to, also.
The Genesis of the Iraqi Counter Terrorism Force (ICTF)
Following the 2003 invasion of Iraq and the subsequent dissolution of the legacy military apparatus, a critical capability gap emerged for a non-sectarian, precision counterterrorism asset. To meet this requirement, the Iraqi Counter Terrorism Force (ICTF) was conceived as an elite, cross-sectarian capability. The foundational selection and training of the initial cohort took place via an out-of-country pipeline in Jordan, driven by a combined footprint of U.S. Army Special Forces and Jordanian Special Operations elements. While the Jordanian partners provided vital cultural cohesion and mentorship to steady the raw recruits under immense pressure, U.S. SOF rigorously vetted and trained the force in precision close-quarters battle (CQB) and marksmanship. Out of roughly 100 original candidates, strict attrition left only a small, highly vetted core of approximately 35 operators. This elite nucleus was explicitly designed to operate as an integrated precision strike force alongside U.S. Special Operations Forces.
Author note: My direct involvement in this mission remains sensitive. I have focused on the historically verifiable information of the ICTF while establishing how it influenced me and the broader AtN methodology work that was emerging, without compromising my role in early counter-terrorism operations.
The Transition to Network-Centric Strategic Targeting
This model of specialized, high-standard host-nation training provides a vital framework for understanding the broader evolution of modern targeting. In the earliest phases of the post-invasion conflict, assets like the ICTF were primarily viewed through a tactical lens: precision instruments designed for localized hostage rescue and high-risk kinetic raids. However, as the insurgency rapidly decentralized into complex, asymmetric networks, the limits of isolated, node-based kinetic operations became apparent. This operational friction drove a necessary evolution toward integrated fusion cells, such as those established during the formative targeting campaigns in Mosul. The role of elite host-nation forces shifted fundamentally during this period; they transitioned from standalone raid elements into a vital operational arm of a broader, intelligence-driven strategic targeting mechanism.
The "So What?" for Attack the Network (AtN)
For AtN frameworks, the evolution of early precision units like the ICTF underscores a critical lesson: a precision kinetic tool is entirely dependent on the fidelity of the network analysis driving it. The true significance lies in the structural position of these units at the intersection of host-nation execution and fusion-cell intelligence. As these forces became battle-hardened, their utility evolved past merely neutralizing isolated targets to serving as vital tools for network identification and analysis. Every precision operation fed the fusion cell with exploitation material, biometric data, and local human intelligence that mapped the adversary's wider infrastructure. By linking elite host-nation capabilities directly into the SOF targeting cycle, these early campaigns pioneered the shift from standard attrition warfare to comprehensive network targeting—proving that defeating an asymmetric threat requires treating the strike force as a vital sensor within a wider, interconnected system.
The Mosul Fusion Cell & Special Operations’ Task Forces (2005–2006)
The practical execution of full-spectrum network-centric targeting was pioneered on the ground during the infancy of the first integrated tactical fusion cell in Mosul (2005–2006). I was involved, as a supporting leader, in an ecosystem that co-located elite operators directly with multi-agency intelligence assets.
This cell bridged the gap between raw field exploitation and immediate operational execution. Rather than chasing the individual bomb-maker, the Mosul cell began mapping the wider economic, tribal, and logistical systems sustaining the network, proving that a threat network's true gravity lay within its underlying infrastructure. The fusion cell also demonstrated the ability to synchronize disparate, and sometimes competing, intelligence agencies for the greater good. It was one of the first times in U.S. history where national-level agencies like the NSA, CIA, and DIA worked side-by-side in direct support of our elite special operations forces; each agency contributed something unique, proving the definitive value of multi-discipline collection and analysis for precision High-Value Individual (HVI) strikes.
Transnational Intersections
This field experimentation did not happen in a vacuum. This was just one effort happening simultaneously with other initiatives across the theater where many of us were coming to the exact same conclusion. Commanders, planners, and operators shared these lessons, drawing upon the structural models of early fusion cells, Joint Operation Centers (JOC), Joint Interagency Task Forces (JIATF), and domestic Joint Terrorism Task Forces (JTTFs). These organizations brought an institutional understanding of link analysis and financial tracing, reinforcing the reality that military forces needed to map the broader socio-economic and logistical systems sustaining an adversary.
Lessons Learned for Modern Public Safety:
Build Multi-Agency Fusion, Not Information Silos: During a major public safety crisis—whether a cyberattack on a power grid or an active shooter event—no single agency owns all the answers. First responder chiefs, state directors, and corporate security leaders must establish real-time "fusion ecosystems" where local responders, emergency management, federal partners, and private stakeholders sit side-by-side. True resilience comes from breaking down institutional rivalries to treat disparate data fields as one unified operating picture. The preferred solution is called the Common Operating Picture (COP), and it is the vital start point to emergency response.
Treat Responders as Sensors to Move Beyond the "Whack-a-Mole"
Response: If a city or corporation only reacts to isolated disruptive incidents (the "Whack-a-Mole" approach), it will eventually be overwhelmed. Field personnel, utility workers, and frontline responders must be viewed as active sensors. The data they collect at the site of an incident—such as local criminal activity, terrorist actions, or repeated infrastructure anomalies—must immediately provide feedback to a centralized analysis center to map out and neutralize the underlying systemic threat before it strikes again.
PART III: THE AWG: COLLABORATIVE INNOVATION AND REVERSE-ENGINEERING THE COG
By the late 2000s, these disparate operational insights were happening simultaneously across various theaters, yet the military lacked a unified, codified framework to teach the broader force. The Asymmetric Warfare Group (AWG) became the central collaborative hub taking on the challenge of capturing, distilling, and institutionalizing these concepts.
The development of the formal AtN doctrine was an intense, collective effort driven by a tight-knit cadre of tactical operators, operational planners, and intelligence officers who were simultaneously hitting the same wall across different combat theaters.
AWG’s D Squadron
A critical intellectual leap occurred within AWG's D Squadron. Legacy military planning heavily prioritized Carl von Clausewitz's concept of the Center of Gravity (COG)—the primary source of power that provides an army its strength. Conventional planning attempted to guess an enemy’s COG abstractly and then deduce its requirements. For me, this was too abstract with little practical application to the GWOT. We were not trying to determine a major bombing campaign against a legacy military-industrial complex; we were fighting against elusive, decentralized networks that were fleeting and required immediate, decisive targeting processes.
D Squadron leadership, working in tandem with the wider AWG advisory staff, turned this model on its head through a sophisticated reverse-engineering process. Rather than guessing a decentralized enemy's COG from the top down, they developed a methodology to derive it from the bottom up based on concrete, observable field intelligence:
Identify Critical Vulnerabilities (CV): Mapping the specific, fragile links discovered via tactical exploitation (e.g., a unique courier, a specific chemical supplier, a local corrupt official).
Aggregate Critical Requirements (CR): Systematically grouping these vulnerabilities to understand the baseline capabilities the network must possess to function.
Derive the Center of Gravity (COG): Mathematically reverse-engineering the true structural center of gravity based on those requirements.
While I operated on the periphery of this specific D Squadron COG work, the cross-pollination of these ideas proved vital to the wider doctrinal synthesis. At this time, I was at AWG serving as the senior advisor on intelligence and sensitive activities, and later, as an operational and senior operational troop advisor. During this specific period, I was still actively participating in SOF targeting processes in Iraq.
PART IV: The Attack the Network Methodology (2009–2011)
This collective effort culminated when I authored the four-part AWG Attack the Network Methodology series, published between 2009 through 2011.
My role was to capture the operational genius of the Mosul fusion cells, the interagency link-analysis frameworks, and the D Squadron COG breakthroughs, synthesizing them into a single, repeatable, and unclassified playbook for the broader force. The resulting framework established the three operational pillars that balanced kinetic operations with long-term stabilization: Support the Friendlies, Influence the Neutrals, and Neutralize the Adversary.
AtN Part 1: Oil Spot Methodology
Summary: This paper translated classic counterinsurgency population-centric security into a network-targeting reality. It established the methodology for creating secure, persistent pockets of stable influence (the "oil spot") and systematically expanding that stability outward.
Impactful Takeaway: True network disruption requires a spatial anchor. You cannot map an invisible network from a distant fort. You need a physical anchor on the ground to make the unseen enemy visible. You cannot effectively map or attack an elusive threat network without first fixing your presence inside a defined population center; the security of the physical human terrain dictates your ability to isolate the threat from its local sanctuary.
AtN Part 2: Network Analysis and Target Development
Summary: This paper introduced analytical tools to deconstruct asymmetric organizations into functional components. It moves beyond standard "link analysis" (lines on a board) to evaluate the actual roles, dynamics, and workflows that an insurgent network requires to sustain its operational momentum.
Impactful Takeaway: A target is not a person; it is a critical vulnerability within a process. Effective target development focuses less on a specific personality's rank and more on finding the fragile bottlenecks—such as logistical lines, financial conduits, or specialized technical skillsets—whose disruption collapses the network's system.
AtN Part 3: Network Modeling and ISR Synchronization
Summary: This paper tied structural analysis directly to collection execution. It blended Center of Gravity (COG) and Critical Vulnerability analysis into detailed, real-world “Observable Indicators” that collection assets can watch. It re-introduced the Modified Intelligence Synchronization Matrices (MISM) to ensure that technical and human sensors are explicitly mapped to expected enemy network behaviors.
Impactful Takeaway: Collection must be driven by explicit enemy vulnerabilities, not asset availability. Intelligence, Surveillance, and Reconnaissance (ISR) elements must be synchronized around specific, physical triggers that indicate an adversary network is attempting to adapt or recover.
AtN Part 4: Assessing Network Operations and Effects
Summary: The final paper addressed the "so what" metrics of success in asymmetric environments. It outlines how to measure operations by looking past standard, deceptive kinetic metrics (like body counts or caches found) to evaluate systemic, non-lethal, and second-order impacts on the network's capability and the population's posture.
Impactful Takeaway: The measure of effectiveness is how the network responds, not what you destroyed. A successful raid that removes an insurgent node is a failure if the network instantly adapts or regenerates; true disruption is only achieved when friendly operations permanently fracture the network's internal trust, communication flow, and access to the human terrain.
Author Note: Strategic and Intellectual Foundations.
The analytical framework and my involvement in AtN were heavily shaped by the overlapping strategic doctrines pioneered by General David Petraeus and Lieutenant General Michael Flynn during the height of the post-9/11 conflicts. General Petraeus’s modernization and operationalization of the "Oil Spot" theory into the doctrine of "Clear, Hold, Build" fundamentally reframed how I viewed security. It demonstrated that counterinsurgency is not an exercise in temporary conventional forces’ sweeps of their battlespace, but a systematic approach to securing population-centric nodes, expanding outward to bleed into one another and deny the enemy sanctuary. Complementing this approach was LTG Flynn’s seminal 2010 thesis, “Fixing Intel,” which radically challenged the military's myopic focus on "Red" threat networks at the expense of the "White" population and civilian infrastructure. Together, these concepts served as the primary intellectual catalysts for my transition from localized, tactical kinetic actions to advanced, multi-layered targeting methodologies. By combining Petraeus's expanding security rings and Flynn's demand for holistic human-terrain mapping, I intended for the AtN Methodologies to treat the operational environment not as a series of isolated targets, but as a vast, interconnected ecosystem that must be comprehensively understood to be effectively disrupted.
Lessons Learned for Modern Public Safety:
Reverse-Engineer Large-Scale Public Threats From the Bottom Up: When confronting complex emergencies—such as an active cyber-extortion campaign or a coordinated supply-chain failure—do not waste time guessing the top-level "Center of Gravity" in the abstract. Instead, look at the concrete disruptions occurring on the ground. Map the fragile, observable points of failure, group those requirements together, and reverse-engineer exactly what systemic capability the threat network relies on to operate.
Attack the Vulnerability in the Process, Not Just the Symptom: To disrupt a sophisticated adversary, whether it is a terrorist cell or an organized civil disruption network, public safety leaders must look past specific individuals. Disruption should target process bottlenecks—such as the specialized fencing operation, the specific encrypted communication tool, or the financial pipeline. Eliminating a single bad actor does nothing if the underlying logistical process remains intact.
Measure Success by Systemic Disruption, Not Attrition Stats: True safety is measured by how an adversarial network reacts, not by simple statistics like total arrests made or pieces of equipment seized. If a police department clears out a local drug gang but another emerges blocks away within hours, the operation has failed to achieve strategic effect. True victory occurs when public safety interventions permanently shatter the internal trust, funding channels, and community access of the illicit network.
PART V: RECOGNITION, INSTITUTIONALIZATION, AND DOCTRINAL LEGACY
Once published by the AWG, the AtN Methodology papers spread rapidly across the defense enterprise, driving curriculum updates and influencing official joint manuals:
The JFHQ Commander's Handbook for Attack the Network: Recognizing my role as the principal author of the AWG framework, I was retained as a core advisor to the Joint Force Headquarters (JFHQ) for the drafting of the official Joint Chiefs of Staff AtN Handbook, migrating these concepts directly into the upper echelons of Joint Command planning.
The JIEDDO ISR Top-Off Course (2010–2012): The four-part AWG papers served as the foundational backbone for this high-priority pre-deployment program, ensuring that thousands of operators and intelligence analysts were trained in network-disruption logic before setting foot in theater.
Joint Publication (JP) 3-15.1 & ATP 3-37.2: The foundational definitions of network nodes, links, and systemic target development were permanently institutionalized within official Army and Joint Publications, cementing the transition from device-centric targeting to full-spectrum network engagement.
Furthermore, during this timeframe, I was selected to serve as an invited guest speaker and advisor to NATO on their Counter-Insurgency Operations doctrine forum.
Lessons Learned for Modern Public Safety:
Codify Field Innovation into Repeatable Playbooks: The lessons learned from a major disaster or complex criminal investigation cannot simply reside in the heads of the individuals who lived through it. Emergency managers, fire chiefs, and corporate risk officers must capture real-world operational triumphs and institutionalize them into unclassified, repeatable, and easily read handbooks. Training programs must be continuously updated so that frontline supervisors inherit hard-won field logic before a crisis hits.
Focus on the How, not so much on the Why: Frequently, I see our federal and state policies for emergency preparedness and response focusing on structured, hierarchical organization and broad principals rather than practical application. Our community leaders need focused tools derived from lessons learned, more than they need a definition or understanding of a role, branch, or policy guideline. If your “battle books” are dense, narrative chapters describing roles and responsibilities, but do not provide tools and examples of what to do when an incident occurs, then it will not be useful when it really matters.
CONCLUSION
The evolution of the Attack the Network methodology demonstrates that decentralized, chaotic human threats cannot be defeated through purely reactive or administrative management. The framework survived the transition from the battlefield to institutional doctrine because it was built by a community of practitioners who faced the chaos firsthand.
By preserving the contributions of the early innovators, the tactical fusion cells, the D Squadron strategists, and the many leaders who fought, adapted, and never gave up passing on lessons learned, the defense community ensures that the hard-won operational art of the GWOT remains a lasting blueprint for bringing structural clarity to chaos.
About the Author:
Tod Langley is the co-founder and Chief Executive Officer of Crisis Response Leader Training (CRLT), Inc., an organization dedicated to equipping first responders, emergency managers, agency directors, and corporate security executives with the advanced decision-making frameworks required to manage high-consequence disasters and complex threats.
A former U.S. Army National Guard Infantry enlisted Soldier, active-duty Army Infantry and Military Intelligence officer, and senior consultant with extensive experience at the tip of the spear in Special Operations and asymmetrical environments, Tod held the positions of squad and platoon leader, company executive officer, company and troop command, and detachment command. He served as a senior Observer Controller (OC) at the National Training Center (NTC) during the foundational years of the Global War on Terror. Tod then became a sensitive activity asset for the Department of Defense. He later served as a senior intelligence and operational advisor within the Asymmetric Warfare Group (AWG), where he was the principal author of the definitive, four-part AWG Attack the Network (AtN) Methodology series. His work pioneered the military’s transition from localized, device-centric targeting to full-spectrum network engagement. Much later, Tod was also an operator within the Intelligence Community blending his tactical skills with targeting knowledge to conduct Hight Threat Meetings against terrorists, and then, became the senior cadre for selection and training.
Throughout his career, Tod bridged the gap between field exploitation and strategic execution, advising Joint Force Headquarters (JFHQ), the Joint IED Defeat Organization (JIEDDO), and international partners, including serving as an invited guest speaker and advisor to NATO on Counter-Insurgency Operations doctrine. Today, he translates these hard-won tactical and strategic lessons from the battlefield into actionable, resilient blueprints for civil leaders tasked with protecting critical infrastructure and ensuring public safety. Tod was a senior advisor on the formation of Incident Command System training for several major cities, and continues providing that support, through CRLT, to numerous clients at the federal, state, local government level, as well as to individual facilities and corporate leaders.



Comments