Do the military "cyberwarriors" even have local admin rights on their machines? Do they have the education necessary to think about systems and vulnerabilities and the requisite leeway to use that knowledge, or are they (as I would guess) "highly trained," where "trained" means "good at following a set of procedures"?
I'm not knocking that as part of military culture. I want the people in control of weapons and aircraft, etc. to be great at following orders and the procedures they were trained to follow, and do little else. The ICMB fleet is not a place for improvisation.
But computer security is. It's a creativity-driven field that moves quickly, evolves hourly, and requires intellectual agility. I would imagine that from a locked-down, out-of-date OS with a years-long procurement cycle to buy third-rate software from huge, blundering contractors and no leeway to try new things on a whim, it would be impossible to beat a team of educated, unencumbered civilians in a field like this.
Of course, that's just a caricature of military culture that I'm imagining, but can anyone speak to this?