A petard was a small explosive charge used in Medieval and Renaissance siege warfare to blast open fortified gates. Because it had to be placed by hand against the enemy’s defenses, it was as dangerous to the engineer deploying it as to the target itself. Shakespeare immortalized the device in Hamlet with the phrase “hoist with his own petard,” meaning destroyed by one’s own instrument.
Today, military secrecy occupies a similarly paradoxical position. Secrecy protects intelligence sources, operational plans, cryptographic systems, and technological innovations from hostile powers. Surprise has won countless battles, and the preservation of genuine military secrets remains indispensable to strategic success. Yet secrecy possesses a dangerous duality. Like many institutional mechanisms, it can gradually drift from its original purpose. A classification system established to protect military capabilities may, over time, begin protecting the institutions responsible for producing them. Information is withheld not because disclosure would strengthen an adversary, but because it might embarrass an agency, expose serious mistakes, or invite unwelcome scrutiny.
This functional drift carries profound consequences. Engineering advances through the discovery and correction of defects. Effective military systems development thus depends upon honest feedback from testing, operational experience, and combat. When secrecy suppresses that feedback, it no longer strengthens the institution. It weakens its capacity to learn. Decision-makers begin acting upon increasingly incomplete information, deficiencies persist longer than they should, and optimistic assumptions replace empirical assessment.
This article examines this degenerative process through three major American defense programs: the Patriot PAC-3 missile defense system, the F-35 fighter aircraft, and the Ford-class aircraft carrier. Although these programs differ dramatically in mission and technology, they illustrate a common institutional pattern. The question is not whether any one system succeeds or fails. It is whether secrecy, when detached from its original purpose, can become the very instrument by which military effectiveness is diminished. In Shakespeare’s unforgettable metaphor, the institution risks becoming hoist with its own petard.
The Secrecy Degeneration Model
Institutional mechanisms rarely become dysfunctional overnight. More commonly, they undergo a gradual process of functional drift, in which a mechanism designed for one purpose slowly acquires another. Each individual decision to withhold information may appear reasonable in isolation, yet the cumulative effect is to transform the purpose of the mechanism itself. Secrecy is particularly susceptible to this evolution because its exercise is, by definition, shielded from public scrutiny.
As major weapons programs mature, the role of secrecy may expand beyond operational necessity. Developmental setbacks, cost overruns, schedule delays, and performance shortfalls exist within the same classified environment that protects genuine military capabilities. Distinguishing information whose disclosure would aid an adversary from information whose disclosure would merely embarrass an institution becomes increasingly difficult. The boundary between operational security and institutional protection begins to blur.
Once that boundary becomes ambiguous, organizational incentives exert a subtle but powerful influence. Managers naturally wish to protect programs into which years of effort and billions of dollars have been invested. Agencies seek to preserve budgets and political support. Contractors seek to maintain production and future contracts. These incentives don’t necessarily involve fraud or bad faith. Yet collectively they encourage an ever broader application of secrecy, one that increasingly shields the program itself rather than the military capability it was intended to produce.
The greatest casualty of this process is feedback integrity. Every engineering discipline depends upon the rapid discovery and correction of deficiencies. Military systems become more effective because testing exposes weaknesses that designers can remedy. Modern weapons systems are among the most complex machines ever constructed, making candid feedback evaluation especially important. When secrecy begins restricting criticism, independent review, or the dissemination of unfavorable test results beyond what operational security requires, organizations lose their ability to learn efficiently. Errors persist longer, optimistic assumptions replace empirical evidence, and the institution gradually becomes less capable of distinguishing demonstrated performance from aspirational performance.
Secrecy degeneration is not inevitable, nor does every classified program follow this path. Nevertheless, the progression is sufficiently common to warrant recognition as a recurring institutional risk. The following table summarizes this evolution from secrecy that protects the mission to secrecy that progressively protects the institution itself.

The essential question regarding secrecy is therefore what it protects. The classification system that safeguards national security can, through gradual functional drift, become a barrier to important institutional learning. When that occurs, secrecy ceases to be a strategic asset and begins to resemble Shakespeare’s petard, an instrument that ultimately harms the very institution it was intended to defend.
Patriot PAC-3: Kinematic Limits and the Cost of Secrecy
Few military technologies illustrate the complexity of modern warfare better than missile defense. The Patriot PAC-3 system represents decades of engineering investment aimed at one of the most demanding tasks in military technology: detecting, tracking, discriminating, and intercepting high-speed ballistic missiles under combat conditions. Every successful interception requires the coordinated performance of sophisticated radar systems, command-and-control software, guidance algorithms, communications networks, and interceptor missiles operating within seconds. Much of this technology is appropriately classified because detailed disclosure would assist potential adversaries in developing countermeasures.

Every terminal missile defense system is ultimately constrained by the immutable laws of physics. A PAC-3 interceptor is not pursuing a stationary target but attempting to collide with a warhead closing at several kilometers per second. Success depends upon predicting the future position of the incoming warhead and maneuvering the interceptor onto a collision course within a rapidly shrinking engagement envelope.
Every interceptor possesses finite kinematic performance. Its maximum speed, lateral acceleration, seeker field of view, and control authority define a finite maneuver envelope. When an incoming warhead executes unexpected terminal maneuvers, the interceptor must generate additional lateral acceleration to establish a new intercept solution. If the required maneuver exceeds the interceptor’s remaining kinematic margin, successful interception becomes physically impossible regardless of software quality, radar performance, or operator skill.
These physical constraints are compounded by time. Detection, target discrimination, command processing, interceptor launch, and terminal guidance all consume valuable seconds while the target continues closing. Every second lost reduces the interceptor’s available maneuvering space, creating a narrowing vulnerability window imposed not by engineering deficiencies alone but by the fundamental physics of pursuit and interception. Once an adversary develops a reasonable estimate of an interceptor’s practical maneuver limits, through intelligence collection, engineering analysis, or combat observation, it can refine terminal maneuver profiles, penetration aids, and salvo tactics to reduce the probability of interception.
Evaluating how well the Patriot system functions within these physical constraints presents a different challenge. The difficulty arises not from protecting the system’s technical design, but from independently assessing its operational effectiveness. Detailed engagement data are frequently classified and unavailable for independent examination. After-action assessments are often conducted within the same institutional framework responsible for the program itself. As a consequence, public understanding of interceptor performance frequently depends upon official statements rather than independent technical analysis.
Evidence from the recent Iran conflict suggests that Iranian missile development has increasingly emphasized penetration strategies intended to challenge the kinematic limits of modern missile defenses. The successful penetration of some defended targets is consistent with the proposition that offensive missile designers are exploiting the finite maneuver envelope of terminal interceptors. Yet the detailed radar tracks, interceptor telemetry, engagement timelines, and post-engagement analyses necessary to determine precisely why individual interceptions succeeded or failed remain largely classified. Without access to the underlying engagement data, outside analysts cannot determine whether observed penetrations resulted primarily from unavoidable physical limits, engineering deficiencies, operational decisions, statistical variation, or increasingly sophisticated offensive tactics. The result is a growing gap between official assessments of Patriot performance and the independent evidence available to evaluate those assessments.
The implications extend well beyond engineering. Accurate feedback is essential for sound strategic decision making. If senior civilian leaders develop an overly optimistic assessment of defensive capabilities, then deterrence, force posture, alliance commitments, escalation decisions, and civil defense planning may all rest upon inaccurate assumptions. Preserving feedback integrity is therefore not merely an engineering requirement but a strategic necessity. A system that obscures its own operational limitations risks misleading not only the public but also the decision-makers responsible for national security.
The F-35: Combat Performance Without Clear Program Validation
The recent Iran conflict illustrates a broader challenge in evaluating highly classified military systems. The F-35 is designed around capabilities that are intentionally concealed, including low observability, electronic warfare, sensor fusion, and mission software. Consequently, many of the characteristics that determine combat effectiveness remain inaccessible to independent technical evaluation.

Public reporting indicates that Israeli F-35I aircraft participated extensively in the campaign against Iran. Yet the operational details necessary to evaluate the aircraft’s performance remain largely classified. Public reports identify aircraft participation and targets struck but provide little information regarding attack geometry, weapon release ranges, radar detection, electronic warfare interactions, missile engagements, sortie generation, or mission abort rates. As a result, independent analysts cannot determine the extent to which mission success depended upon the F-35’s low-observable characteristics, stand-off precision weapons, suppression of enemy air defenses, electronic warfare, or the combined effect of these capabilities.
The opacity extends beyond Israeli operations. Despite the prominent U.S. naval role in the Iran campaign, remarkably little publicly verifiable information has emerged regarding the operational employment of U.S. Navy F-35C aircraft. If they participated in strike or support missions, the details remain largely unavailable. Consequently, independent analysts cannot assess their contribution, if any, to the campaign.
This ambiguity is itself significant. One of the F-35’s principal design objectives is to enable survivable operations against sophisticated integrated air-defense systems. Yet the Iran conflict has produced little publicly verifiable evidence demonstrating how that capability contributed to operational success. The absence of such evidence does not imply that the aircraft failed to perform as designed. Rather, it means that one of the program’s most costly and technologically sophisticated capabilities remains largely unvalidated in the public domain.
The evaluation problem extends beyond combat operations. Publicly available readiness statistics have shown persistent availability challenges within the F-35 fleet, with mission-capable and fully mission-capable rates remaining well below program objectives. These figures do not measure combat effectiveness, but they do constrain the number of aircraft immediately available for sustained operations and illustrate that important aspects of fleet performance remain matters of continuing concern.
Thus, the public, and most Members of Congress outside the intelligence and armed services oversight process, lack sufficient publicly available information to independently assess the operational efficacy of the F-35 during the Iran war. Assessment necessarily depends upon classified briefings and official representations rather than publicly verifiable evidence.
The F-35 therefore illustrates the central thesis of this article. Modern military secrecy protects legitimate operational information, but it also restricts the independent feedback necessary for rigorous public evaluation. When empirical validation becomes inaccessible, accountability increasingly rests upon institutional trust rather than independently verifiable evidence. In the Secrecy Degeneration model, this erosion of independent feedback represents a potential degradation of the learning processes upon which effective engineering, procurement, and strategic decision-making ultimately depend.
USS Gerald R. Ford — Secrecy Degeneration and the Inversion of Accountability
The USS Gerald R. Ford (CVN-78) was conceived as the United States Navy’s next-generation aircraft carrier, incorporating a remarkable concentration of revolutionary technologies, including the Electromagnetic Aircraft Launch System (EMALS), Advanced Arresting Gear (AAG), Dual Band Radar, Advanced Weapons Elevators, extensive automation, redesigned damage-control systems, and a reduced-crew operating concept. Collectively, these innovations promised higher sortie generation, improved survivability, reduced manpower requirements, and lower lifetime operating costs.

Instead, the lead ship experienced years of developmental delays, engineering redesign, extensive post-shakedown modifications, and substantial cost growth as many of these technologies failed to mature as originally anticipated. The Navy ultimately devoted years of additional testing, engineering remediation, and operational workups before declaring the ship fully operational. Despite all this remedial work, the Ford experienced serious difficulties in its sanitary systems and suffered from an internal fire that caused it to be withdrawn from its recent deployment to the Mideast.
The strongest evidence of Ford-class design immaturity, however, lies not in any individual malfunction aboard the lead ship but in the propagation of engineering corrections throughout the class. Construction of USS John F. Kennedy (CVN-79) began before many of the Ford’s defining technologies had completed realistic operational testing. As deficiencies emerged aboard the lead ship, design modifications, rework, deferred capability, revised construction sequences, and additional engineering effort became necessary on the follow-on carriers. Although workforce shortages, supply-chain disruption, F-35C integration, and other factors also contributed to later schedule delays, the persistence of difficulties involving EMALS, Advanced Arresting Gear, Advanced Weapons Elevators, and related systems demonstrates that the Ford’s developmental problems extended well beyond an unusually difficult commissioning period.
At nearly every stage of this troubled program, independent evaluation has been constrained by security classification and limited official disclosure. GAO reports, congressional testimony, Inspector General investigations, and Navy budget documents have documented significant technical and schedule problems, but the detailed engineering evidence required to independently assess reliability, failure modes, corrective design changes, operational limitations, and long-term effectiveness has generally remained unavailable outside government. The public has largely received conclusions rather than the underlying engineering data.
The importance of this informational opacity became particularly evident during the Ford’s deployment in support of operations against Iran. Fire and flooding have historically represented the two greatest existential threats to an aircraft carrier. When a fire occurred aboard the Gerald R. Ford during the deployment, the Navy acknowledged the incident and reported that it had been contained. Subsequent public reporting cited allegations that the ship’s fire suppression system failed to operate as intended, requiring prolonged manual firefighting by the crew.
The Navy has not confirmed those allegations and has stated that the investigation remains ongoing, while acknowledging that flight operations did not resume for approximately two days following the incident. Independent observers therefore cannot determine whether the event reflected equipment failure, procedural shortcomings, isolated malfunction, or broader engineering issues because the technical findings remain unavailable. One of the carrier’s most critical survivability systems thus became another example in which independent engineering evaluation yielded to institutional assurance.
The same informational opacity characterizes the ship’s broader operational employment. Following years of developmental testing and engineering remediation, remarkably little publicly available information has emerged concerning the operational performance of the Ford’s defining technologies during combat operations. Independent analysts cannot evaluate sortie-generation rates, the sustained reliability of EMALS and Advanced Arresting Gear, the performance of Advanced Weapons Elevators, the effectiveness of the ship’s integrated combat systems, or the operational consequences of years of engineering remediation. Even relatively straightforward questions, such as why the Navy’s newest aircraft carrier deployed without F-35C aircraft, cannot be answered confidently from publicly available information. Several explanations remain plausible, including air-wing composition, phased F-35 integration, modernization schedules, logistics, operational planning, or classified considerations. The available evidence does not permit independent observers to determine which factors were decisive.
The cumulative effect of extensive classification and restricted disclosure is to transform engineering questions into questions of institutional trust. As the underlying evidence becomes inaccessible, empirical verification gives way to reliance upon official assurances that deficiencies have been corrected, systems have matured, and operational capabilities have been validated. Secrecy degeneration produces an inversion of accountability. A naval program intended to defend the United States gradually becomes one that the United States must defend.
Conclusion
The case studies presented in this article indicate that Secrecy Degeneration is no longer a hypothetical concern but an emerging characteristic of modern U.S. defense acquisition. Patriot PAC-3, the F-35, and the Ford-class carrier differ dramatically in mission, technology, and organizational context, yet all reveal the same underlying pattern. As security classification expands, the evidence necessary for independent engineering evaluation progressively disappears from public view. The resulting vacuum is filled not by empirical validation but by questionable institutional assurance.
The implications extend well beyond today’s programs. The United States is investing hundreds of billions of dollars in a new generation of strategic systems, including the Sentinel intercontinental ballistic missile replacement, the B-21 Raider stealth bomber, and the proposed Golden Dome missile defense architecture. These programs will be even more software-intensive, more AI-enabled, more networked, and more highly classified than their predecessors. Unless new institutional safeguards are developed, they will face the same structural tendency toward Secrecy Degeneration described in the preceding case studies.
The solution, however, is not to reduce legitimate military secrecy. Modern warfare demands the protection of operational capabilities, technical vulnerabilities, intelligence sources, and tactical methods. Security classification is therefore indispensable. The question is not whether secrecy should exist, but whether democratic institutions can preserve rigorous engineering accountability under conditions of necessary secrecy.
Engineering earns trust by measurement, testing, replication, independent review, adversarial evaluation, and continuous correction of error. These activities generate earned, verifiable trust. Ultimately, Secrecy Degeneration is a trust-allocation problem. It progressively replaces earned trust, generated through independent empirical validation, with imputed trust, generated through institutional authority. Excessive reliance on imputed trust becomes dangerous when it becomes the dominant mechanism by which society evaluates the performance of its most complex and expensive defense systems.
History demonstrates that complex systems improve through criticism, measurement, replication, and independent verification. Democracies have repeatedly recognized this principle by creating institutions that generate justified trust: independent financial auditing, scientific peer review, judicial review, aviation accident investigation, and nuclear safety regulation all exist because society understands that confidence is strongest when it is continuously tested.
Thus, the next generation of highly classified defense systems requires new institutional mechanisms that preserve effective engineering feedback without compromising legitimate military secrecy. Independent technical review, adversarial evaluation, protected engineering audits, and the systematic declassification of historical engineering evidence illustrate the kinds of innovations that may be required. The objective is not greater public disclosure of sensitive military information, but the preservation of reliable validation where direct public observation is impossible.
The preservation of military superiority depends not only upon technological innovation but also upon the integrity of the feedback systems that distinguish success from failure. A democracy that cannot independently evaluate its most consequential defense technologies risks weakening the very engineering processes upon which its security depends. The challenge before democratic societies is therefore not simply to protect military secrets, but to ensure that secrecy itself does not progressively undermine the empirical foundations of technological excellence and public trust.
The original military petard was an explosive device that could accidentally detonate beneath the engineer who employed it. Secrecy Degeneration presents a modern equivalent danger. Secrecy remains indispensable to national defense, but when it progressively suppresses the independent feedback upon which engineering success depends, it erodes the very capabilities it was intended to protect. The greatest danger is not that our adversaries will learn too much, but that we ourselves will learn too little. When that occurs, we will have become hoist by our own security petard.
















-1024x683.jpg)


