Technoecologies - Florian Hoof - The Sysadmin State: On the Politics of Digital Trust and Security

The Sysadmin State: On the Politics of Digital Trust and Security

Florian Hoof

Arc_tech_H_03
The Pionen data center, situated in an underground Cold War-era nuclear bunker in Stockholm, became known for hosting WikiLeaks servers after they were banned from Amazon AWS, and later Sci-Hub servers until Elsevier sued the Swedish company operating the facility (photographed in 2009). Photo: Antony Antony/Flickr.
Technoecologies
November 2025

Instead of trusting users to do the right thing, we verify that they are doing the right thing.1
—John Kindervag, No More Chewy Centers: Introducing the Zero Trust Model of Information Security.

In the science fiction television series Silo (2023–current), the Earth's surface has become uninhabitable. Humanity lives in circular underground silos, and survives only because a vast machine provides them with constant supplies of electricity, water, food, and breathable air.2 As securing critical infrastructure is crucial for survival, the influence of janitors and system administrators—those who best understand and maintain it—steadily grows over generations. Finally, they transform the silo into an authoritarian surveillance state. In failed silos, the survivors retreat to the safest place—the fortified concrete bunker that houses the central data center, the once-vital hub that sustained life by controlling air circulation and food production. 

In this society, everything is governed by the possibility of an apocalyptic future caused by security breaches and system collapse. The social fabric and its architecture are conceived as fortification structures designed to withstand the worst imaginable event. In this sense, Silo can be understood as a “sysadmin state,” governed by rules and protocols established by system administrators. This strict set of rules seeks to mitigate the “true uncertainty” inherent in the silo’s conditions, and is accepted because it appears to be the only viable means of maintaining trust amid apocalyptic circumstances.3 Yet such trust comes at a price: the sysadmin’s control ensures the survival of the remaining population, but is achieved at the cost of significantly curtailed civil liberties.

Screenshot of “Accelerating Speed to Power,” a map of US data center demand capacity by county (0–>3500 MW), showing facilities currently in operation or under construction and connecting fiber optic cables. Source: National Renewable Energy Laboratory.
 

Silo is available on Apple TV+, a digital rights management-protected streaming platform that provides access to clusters of fortified data centers worldwide via fiber-optic cables.4 Like Silo, the design of these global media infrastructures takes possible hostile attacks into account through redundancy and resilience measures. Without data centers, financial transactions, state administration, and food logistics would collapse. The supply of electricity, water, and food would halt. The contemporary digital network industry is fundamentally organized around the prevention of data center outages or breakdowns. A major outage, such as the AWS incident at the Northern Virginia data center cluster in October 2025, can undermine the perception of digital infrastructure as reliable and trustworthy.5 The production of digital trust, however, is a deeply material process: The largest data center in Frankfurt, Germany, for instance, stores 480,000 liters of diesel onsite, enough to power backup generators for forty-eight hours in case of emergency. After that, they would rely on a supply contract with an oil refinery. But by that point, the chief manager of the data center is confident that civil unrest and riots would likely occur outside the data center.6 This “worst-case scenario” aligns with predictions that urban centers would descend into chaos within three days without a functioning digital network.7

A fortified data center in Frankfurt. Photo by author.

Politics of Organizing and Securing Circulation

Though Silo seems far-fetched, it illustrates how society’s digitization encompasses more than disruption, innovation, surveillance, and control. It also underscores the profound dependence of modern societies on digital infrastructures, for which there is no viable alternative but to place trust in their continued operation. Within this context, security providers and cybersecurity experts assume a crucial—and inherently political—role: they are tasked with maintaining the stability of these infrastructures while simultaneously presenting their practices as efforts to generate and sustain trust in the digital realm. This position grants them significant authority to define what constitutes security, to determine how it can be enhanced, and to prescribe necessary measures.

The cybersecurity industry describes its work in terms of “cyber security architectures,” “data silos,” “software fortresses,” or “castle-and-moat security models.” These architectural references should not be taken at face value; they are employed as a discursive strategy to build trust by transferring the “aura” of architectural robustness to entities such as software or hardware solutions.8 This echoes the long history of fortification architecture, which has always represented a built compromise between the openness necessary for commerce and the enclosure required for rulers to secure a territory’s sovereignty.9 The negotiation and materialization of such compromises has been a site of constant political contestation, shaping the distribution of power and authority.

This tension between the need to fortify and secure and the long-term sociopolitical impact of the measures taken regularly resurfaces as a site of political contestation when new, large-scale technical systems are introduced. One of the theoretical cornerstones of the ecological, anti-nuclear movement in Germany during the 1970s, for instance, was Robert Jungk’s book The New Tyranny: How Nuclear Power Enslaves Us (originally Der Atom-Staat. Vom Fortschritt in die Unmenschlichkeit, or literally “The Nuclear State: From Progress to Inhumanity”).10 Jungk wrote not about anxieties relating to potential nuclear catastrophes or associated risks, but rather, the fear of having to control specific zones within society, such as nuclear power plants and nuclear waste silos. He believed that this would slowly transform society into a police state because nuclear power technology requires such a high level of security. This idea was not limited to activists, but even reached the US Congress, whose 1977 “Nuclear Proliferation and Safeguards” report states that experts disagree “as to whether a safeguards program can be adequate for security without fundamentally infringing upon civil liberties.”11 The report also acknowledges the potential for “a gradual erosion of civil liberties” if measures to protect nuclear infrastructure are strengthened.12

While the nuclear state sought to draw a strict line between society and its fortified nuclear infrastructures, contemporary global digital societies thrive on the proliferation and entanglement of digital networks with everyday life. The organizational structures of these two societies may have changed, but the fundamental tension between openness and enclosure persists. One recent manifestation of the contemporary sysadmin state can be seen in the US Department of Government Efficiency’s (DOGE) unprecedented attack on the American administrative state, when it leveraged digital security architectures to gain rapid and largely unrestricted access to protected databases, or so-called data silos within federal agencies. Ideology alone cannot explain how DOGE implemented its plan so quickly and with such minimal (or at least, ineffective) resistance. Just as historical fortresses negotiated the tension between openness and enclosure, contemporary digital administrative architectures mediate between accessibility and security. In recent years, these infrastructures have been adapted to evolving cybersecurity and digital trust paradigms that have paradoxically enabled the very conditions for the rapid penetrations they were designed to prevent.

Bernard Shuman, SAGE direction center diagram. Illustration in Robert R. Everett et al., “SAGE Overview,” IEEE Annals of the History of Computing 5, no. 4 (October 1983): 326.

Digital Security: Fortresses, Silos, Closed Systems

The cybersecurity systems in place today are the result of historical shifts that began in the 1950s and 1960s. During this period, the prevailing paradigms of security and trust were shaped by bureaucratic approaches to computing. Early conceptions of computer security centered on physically securing mainframe computers within closed and fortified environments. This framework became foundational to the development of the first digitized government agencies in the United States, and was particularly important to the US military, which adopted this philosophy to protect the chain of command responsible for launching ballistic nuclear missiles. From the mid-1950s, IBM constructed closed, tightly controlled computing systems for US defense and intelligence—most famously SAGE (1958) and the HARVEST cryptanalytic system (1962). Historians explain these practices, with reference to RAND’s 1967 report on “Security and Privacy in Computer Systems,” as the government’s preference for secure, closed architectures rather than open networks.13

Digital infrastructure for missile control terminals was designed to resemble underground bunker facilities. Access was only possible via computer terminals located in protected rooms that could only be accessed with keycards bearing necessary security clearance. The goal was to achieve IT security by isolating the computer systems from the outside world. But despite all of these physical and digital walls, a door was still necessary to allow for a minimum level of communication and exchange between various infrastructural sites. Thus, IBM was commissioned to develop a data-specific access system which is still in use today, consisting of four levels ranging from “unclassified” to “top secret” that regulate read and write access.

The concept of digital fortification formed the backbone of the earliest digitally defined bureaucratic processes of the US federal administration. During this time, the idea that secure computer systems could be built using the right technologies prevailed. One would only need to implement a “closed secure environment” that could be trusted.14 This epistemology of fortification—the very idea that computer security is attainable—became the ideal model for approaching cyberattacks and hackers in the years to come.

DRM’s “Control Architecture.” Illustration in Rod Schultz, “The Many Facades of DRM,” 2012.

Digital Trust: Monitoring, Detection, Response

In the 2000s, commercial digital networks expanded into civilian life. These networks moved beyond the isolated chains of command found in the military and mainframe computer systems within large corporations. As a result, the concept of the closed computer system and the idea that absolute computer security existed—let alone was achievable—began to lose credibility.15 New attempts, such as digital rights management (DRM) systems, tried to preserve the idea of security through fortification to prevent intellectual property theft. Initially, DRM systems for satellite TV were based on a combination of hardware and software. However, they gradually turned into pure software solutions.16 Rod Schultz, an engineer involved in developing Apple’s FairPlay DRM system, describes DRMs as a “control architecture” that creates security through barriers and renewability: “It must be designed to withstand attacks, adapt to attacks, and avoid catastrophic failure when attacked.”17

Unlike the bunker architecture of data silos, Schultz argues that well-designed DRMs have “very fuzzy boundaries” and “very non-standard interfaces.”18 Instead of relying on physical walls or hardwired circuits, DRM programmers construct digital barriers through complex and redundant code, often inflated by the multiplication of basic logical functions. From a software engineering perspective, this layer of code is considered poorly designed. However, its inherent fuzziness hinders hackers from precisely targeting the code. Consequently, it enhances protection by providing IT security teams a timely advantage in the ongoing race against cyber attackers. But it also transforms the fortification of digital infrastructure into a continuous process. Groups of IT specialists henceforth replaced concrete walls, constantly adapting and changing the modular code structure to stabilize its barriers. 

In a way, DRMs are a symptom of an IT security paradigm that can no longer fulfil its promises. It is a transitional solution—a compromise that attempted to stabilize a security paradigm that was becoming obsolete. The final “Jericho moment” of the fortification approach to digital security occurred in 2004 when companies such as Airbus, Boeing, BP, Deutsche Bank, IBM, Hewlett Packard, and Motorola formed the Jericho Forum to define and promote “de-perimeterization,” or the removal of a boundary between an organization and the outside world. Towards these ends, they sought new ways to protect open, networked data architectures, and in collaboration with the consulting firm Forrester Research, developed the “zero trust” concept, which offered a completely different approach to achieving digital security.19 For open digital networks, they argued that the existing concept—which went by the slogan “trust but verify”—is no longer effective. This concept is based on the idea that digital infrastructures can be fortified to the point that they can be treated as secure environments, regulating correctly who gets in and who doesn’t. In line with their new slogan, “never trust, always verify,” zero trust treats all digital network components, technological and human, as potential security risks. 

Trust in controllable digital environments has therefore been replaced by general suspicion, turning the concept of a fortress and its idea of total computer security upside down. Data silos and their surrounding firewalls have been torn down and replaced by comprehensive monitoring and authorization database systems. Zero trust architecture (ZTA) links rigid identification systems to individual user accounts with different permissions to access certain digital services or infrastructures. A monitoring system continuously records all activities, with automated AI systems and external IT security service providers scanning network communications for suspicious behavior patterns in real time. In cases of suspicious activity, there can be automatic system lockdowns, or IT security administrators can block access to specific areas on the network. 

The shift towards zero trust has significantly altered the basic structure of digital networks. IT systems within corporations and public administrations are no longer closed systems of potentially trustworthy resources: they are temporary chains of actions that must be constantly monitored to establish trustworthiness. Since at least 2021, the zero trust concept has been the new standard for digital security in the US federal government and administration. In May 2021 and January 2022, Joe Biden signed an executive order and a memorandum to deploy the zero trust concept in response to an increase in cyberattacks from China.20 This resulted in the “Federal Zero Trust Strategy,” which now informs the cybersecurity efforts of US federal agencies.21

“CISA’s Zero Trust Maturity Model Pillars.” Diagram in Cybersecurity and Infrastructure Security Agency, Zero Trust Architecture Implementation – Fiscal Year 2024 Report to Congress, January 29, 2025.

Backdoor Politics: Eliminating Information Silos

On March 20, 2025, Donald Trump issued an executive order titled “Stopping Waste, Fraud, and Abuse by Eliminating Information Silos,” granting DOGE “full and prompt access to all unclassified agency records, data, software systems, and information technology systems.”22 Rather than walking in through the front door of the state authorities, DOGE entered through the digital backdoors of the government’s centralized IT security architecture. This gave DOGE instant access to the most important sites of the digital administration, including the Enterprise Data Solution (EDS) Portal of the General Services Administration’s (GSA) Central Service Unit and its GSA.gov interface.

The EDS Portal serves as a central platform for identity and access management across the US federal government, enabling access to digital services and databases from all departments. It implements the “identity” and “data” pillars of the Zero Trust Maturity Model (ZTMM), which guides federal cybersecurity practices under the Cybersecurity and Infrastructure Security Agency (CISA), and provides the “cross-cutting capabilities” required by the model.23 This includes centralized access, monitoring, and analytical capabilities for all government data stored onsite and offsite in external data centers, encompassing digitized documents, official correspondence, and databases from the health, social security, and pension insurance systems. With administrative privileges on the portal, DOGE could therefore operate independently of state administration employees. They analyzed datasets using data crawlers and chatbots and modified other users’ or agencies’ access permissions, effectively cutting them off from central IT systems. Consequently, DOGE halted wage payments, froze project budgets, and disabled service credit cards.24 From this perspective, government agencies were less groups of employees than interconnected databases managed through a centralized identity system.

While employees across the US government attempted to resist the actions of DOGE, their subsumption within a zero trust architecture rendered their efforts futile. However, what was able to resist DOGE’s efforts was a decades-old software language and coding culture that was still being used by certain facets of the government. COBOL is a programming language first developed in the late 1950s which many databases managed by the US government were written in, including its social security system. These datasets proved to be robust data silos because training data for the AI models that DOGE was using to identify undesirable projects and employees consisted largely of other, more recent programming languages—not COBOL. As a result, they could not be quickly converted and made accessible. 

Despite these minor barriers, DOGE identified digital infrastructures as the great equalizer, overcoming the multitude of organizational structures and work cultures within government bureaucracy. This approach stems from a mindset of system administrators, one which views an organization not based on its concrete actions and activities, but as a centralized, functional structure. In this way, chatbots and other AI-supported big data processes can operate like digital chainsaws, cutting up existing data stocks and shutting down structures with little consideration. The central IT security system, originally designed to safeguard the integrity of democratic institutions, has become a threat to democracy itself. 

The Digital Trust Complex

The Jericho Forum developed its zero trust security model in the early 2000s. This period was characterized by naive enthusiasm for new media and the dot-com boom economy. Zero trust promised to resolve the inherent contradiction between the digital age’s ideology of interoperability, transparency, and open access, and the necessity of digital security and trust. It aimed to transcend the historical paradox of openness and enclosure once and for all, promising to provide the necessary granularity to monitor and organize circulation, distinguishing between good and bad, and diminishing the latter. To fulfill this promise, system administrators adopt the gaze of zero trust, of total mistrust and suspicion. As a strategy of countering and isolating internal threats as quickly as possible, zero trust only works as long as the sovereign is a benevolent Leviathan. However, when the sovereign becomes a tyrant, zero trust can seamlessly merge with a political ideology that views all state bodies with suspicion.

The politics of digital trust extend beyond what has been described as a surveillance or control society. They are outcomes and components of a broader epistemological system of discourses, practices, and infrastructures that fundamentally organize digital society. The role of the digital trust complex and its system administrators is not merely to “repair and maintain” the digital networks our societies increasingly rely on, but to secure them.25 Building digital trust and securing media technology is primarily about organizing expectations, uncertainties, and fears. Securitizing the digital realm is not focused on fixing something broken or surveilling and controlling the present or past. Rather, it is focused on organizing the future. System administrators anticipate potential threats in order to ensure that their systems continue to run without interruption. These efforts give rise to specific digital politics that impact societies at their core.

Notes
1

John Kindervag, No More Chewy Centers: Introducing the Zero Trust Model of Information Security (Cambridge, MA: Forrester Research, September 14, 2010; updated September 17, 2010), 9.

2

Paul N. Edwards, A Vast Machine: Computer Models, Climate Data, and the Politics of Global Warming (Cambridge, MA: MIT Press, 2010).

3

Frank H. Knight, Risk, Uncertainty, and Profit (New York: Houghton Mifflin, 1921), 20.

4

Nicole Starosielski, The Undersea Network (Durham, NC: Duke University Press, 2015); Lisa Parks and Nicole Starosielski, eds., Signal Traffic: Critical Studies of Media Infrastructures (Urbana: University of Illinois Press, 2015).

5

The AWS outage on October 20, 2025, caused by a DNS failure in the US-EAST-1 data center cluster in Northern Virginia, disrupted services such as Snapchat, Delta, Venmo, and Fortnite for an extended period of approximately two to six hours.

6

Data center manager, discussion with author, May 25, 2022.

7

Leonard Schliesser, Blackout: Challenges and Preparedness, CSS Analyse No. 353 (Zurich: Center for Security Studies, ETH Zurich, 2024), ; E. H. Wohlenberg, “New York Blackout Looting, 1977,” Economic Geography 58, no. 1 (1982): 29–44.

8

The metaphorical use of “architecture” in the digital security industry illustrates that digital trust and security are not merely technological outcomes, but components of a broader epistemological system of discourses, practices, and infrastructures that fundamentally “organize” digital society. Reinhold Martin, The Organizational Complex: Architecture, Media, and Corporate Space (Cambridge, MA: MIT Press, 2003); Timon Beyes et al., eds., The Oxford Handbook of Media, Technology, and Organization Studies (Oxford University Press, 2020).

9

Michel Foucault, Security, Territory, Population: Lectures at the Collège de France, 1977–1978, ed. Michel Senellart, trans. Graham Burchell (New York: Palgrave Macmillan, 2009).

10

Robert Jungk, Der Atom Staat: Vom Fortschritt in die Unmenschlichkeit (Munich: Kindler, 1977). Robert Jungk, The New Tyranny: How Nuclear Power Enslaves Us (New York: Warner Books, 1979).

11

Office of Technology Assessment, Nuclear Proliferation and Safeguards (Washington, DC: U.S. Government Printing Office, June 1977), 17.

12

Office of Technology Assessment, Nuclear Proliferation and Safeguards, 18.

13

Willis H. Ware, Security and Privacy in Computer Systems, RAND Paper P-3544 (Santa Monica: RAND Corporation, April 1967). Donald MacKenzie, “Logic Machines, and Trust,” in Mechanizing Proof: Computing, Risk, and Trust (Cambridge, MA: MIT Press, 2001), 257–98.

14

James P. Anderson, Computer Security Technology Planning Study (United States Air Force Electronic Systems Division, 1972), 128.

15

Rebecca Slayton and Brian Clarke, “Trusting Infrastructure: The Emergence of Computer Security Incident Response, 1989–2005,” Technology and Culture 61, no. 1 (January 2020): 173–206.

16

Florian Hoof, “Liveness Formats: A Historical Perspective on Live Sports Broadcasting,” in Format Matters, ed. Marek Jankovic et al. (Lüneburg: Meson Press, 2020), 81–103.

17

Rod Schultz, “The Many Facades of DRM,” 2012, online PDF, accessed September 30, 2025, , 3.

18

Schultz, “Many Facades of DRM,” 3.

19

Kindervag, No More Chewy Centers.

20

White House, “Executive Order on Improving the Nation’s Cybersecurity,” May 12, 2021, ; Shalanda D. Young to the heads of executive departments and agencies, January 26, 2022, memorandum, Executive Office of the President, .

21

Cybersecurity and Infrastructure Security Agency, Federal Zero Trust Strategy (Washington, DC: CISA, 2022), .

22

White House, “Executive Order on Stopping Waste, Fraud, and Abuse by Eliminating Information Silos,” March 20, 2025, .

23

Cybersecurity and Infrastructure Security Agency, Zero Trust Architecture Implementation – Fiscal Year 2024 Report to Congress (Washington, DC: U.S. Department of Homeland Security, January 29, 2025).

24

Makena Kelly et al., “Inside Elon Musk’s ‘Digital Coup’,” Wired, March 13, 2025, .

25

Stephen Graham and Nigel Thrift, “Out of Order: Understanding Repair and Maintenance,” Theory, Culture & Society 24, no. 3 (May 2007): 1–25.







Advertisement