A security operations centre and a 19th-century field army have the same problem: the people closest to the fight see the truth first, but the authority to act often sits somewhere else. The Prussians solved it on the battlefield with a doctrine they called Auftragstaktik. Most security teams have not solved it at all, and an attacker moving at the speed of a script is exactly the enemy that punishes the gap.
Military foundation
Auftragstaktik — mission command — is the doctrine of leading by intent. A commander tells subordinates what outcome to achieve and why it matters, then leaves the how to the people on the ground. Its opposite, Befehlstaktik, issues detailed orders and expects them followed to the letter. The Prussian and later German armies built a generation of advantage on the first model, because a junior officer who understands the commander's intent can adapt when the plan meets reality — and the plan always meets reality. The unit that has to radio back for permission at every turn moves at the speed of its slowest approval.
The discipline is not the absence of control; it is control exercised through shared understanding rather than micromanagement. Intent is the load-bearing idea. A subordinate who knows the purpose can improvise faithfully; one who has only a checklist can only execute or freeze. The doctrine trades the illusion of central certainty for the reality of decentralised speed, and on a fast-moving battlefield that trade wins.
Cyber application
The modern SOC lives on the wrong side of that trade. Analysts drown in alerts, every meaningful action waits on an escalation chain, and the rigid playbook — do exactly these steps, in this order, then hand off — is Befehlstaktik rendered as a runbook. It is a reasonable design for a slow adversary. It is a losing one against attackers who automate reconnaissance, weaponise newly disclosed vulnerabilities within hours, and run encryption end-to-end faster than a tier-one analyst can finish reading the ticket. When the attack moves at machine speed and the defence moves at approval speed, the gap is the breach.
Mission command reframes the SOC around intent. The analyst on the console is the junior officer who sees the truth first; the organisation's job is to give them the context and the authority to act on it — to isolate a host, kill a session, revoke a credential — without waiting for a chain that the attacker is not waiting for. Automation is not a replacement for that judgement; it is the doctrine applied to the routine. Detection-as-code and orchestrated response handle the cases whose intent is unambiguous, so that human attention is spent where it is genuinely needed. The goal is the same one Auftragstaktik chased: push decisions down to where the information is, and measure the team by how fast a correct decision becomes a correct action.
This is why a state-aware coach matters more than a longer playbook. Guidance framed as intent — here is what is happening and what it threatens — produces an operator who can adapt; guidance framed as steps produces one who stalls the moment the situation leaves the script. The relevant doctrine layer is WAR: not a tactic, but a philosophy of who is trusted to decide.
What you practise
In the range, defence is never a checklist run against a cooperative target — it is a live opponent changing the situation faster than any runbook anticipated. You practise operating on intent: reading what the adversary is trying to achieve, deciding under incomplete information, and acting before the picture is comfortable. You learn where rigid procedure helps and where it freezes you, and you build the judgement that lets you improvise without losing discipline. The AI Coach plays the role of the commander's intent — it tells you what is at stake and why, not which key to press — and reviews afterward how well your decisions matched the situation you were actually in.
All three doctrine layers are present: the command philosophy that decides who acts (WAR), the hands-on craft of the response itself (Ethical Hacking), and the automated, fast-moving threat that makes approval-speed defence untenable (Cyber Crime). The habit you are building is the one Auftragstaktik was invented to instil — to carry the intent so well that you can be trusted to decide alone, at speed, when the plan meets the enemy. Against an adversary who never asks permission, the defender who has learned to act on intent is the only one moving fast enough to matter.