The United States is preparing to give vetted private cybersecurity companies a direct role in offensive operations against foreign cybercriminal organizations, marking a significant change in how Washington approaches ransomware gangs, online fraud networks and other transnational cyber threats.
President Donald Trump signed a national security memorandum on August 12 directing the Department of Homeland Security to establish a program allowing approved private companies to conduct cyber surveillance and disruptive operations on behalf of the US government. The initiative will operate through the DHS National Coordination Center, with joint oversight from the Department of Homeland Security and Department of Justice. (risky.biz)
Risky Business argues that the underlying idea addresses a genuine weakness in current cybercrime policy: governments have increasingly embraced disruption operations because conventional arrests and prosecutions often struggle against criminals operating from jurisdictions where they are effectively beyond the reach of US law enforcement. The problem is that government agencies do not have enough personnel and technical capacity to pursue every major criminal network. (risky.biz)
This is not ordinary “hack back”The policy does not simply give companies permission to attack whoever hacks them.
Instead, participating companies would operate as government contractors. Firms must be vetted, maintain secure facilities, employ approved personnel and demonstrate sufficient technical expertise. Each operation would require written authorization from government officials specifying what the contractor is permitted to target. (risky.biz)
Participating companies would also need to place $1 million in escrow to cover damages resulting from operations that go wrong. Contractors would face reporting requirements and annual reviews, while operations considered likely to cause loss of life or amount to an armed attack would not normally be authorized. (risky.biz)
The government expects the program to become operational within 60 days of the memorandum.
Cybercrime has become too large for governments aloneThe rationale behind the policy reflects the industrialization of cybercrime.
Ransomware operations, cryptocurrency theft groups, fraud networks and criminal infrastructure providers can operate across numerous countries simultaneously. Servers may exist in one jurisdiction, operators in another and victims across dozens more.
Law enforcement can seize infrastructure and arrest individuals when international cooperation works, but many major operators remain protected by geography or political circumstances.
The US government has consequently moved toward disruption: taking down botnets, seizing domains, confiscating servers and cryptocurrency, and interfering directly with criminal infrastructure.
Private security companies already possess much of the intelligence required for those operations. They track ransomware groups, reverse-engineer malware, identify command-and-control infrastructure and follow criminal cryptocurrency transactions every day.
The new policy attempts to turn some of that private intelligence capability into operational capacity.
Companies could move beyond observing attackersCybersecurity companies traditionally reach a legal boundary when investigations move from observing criminal infrastructure to accessing it.
A threat-intelligence company may know where an attacker operates and understand the infrastructure being used, but accessing or disrupting systems without authorization can itself violate computer crime laws.
Under the new framework, vetted contractors could potentially cross that boundary when specifically authorized by the government.
The memorandum distinguishes between cyber surveillance operations, intended to gather intelligence, and cyber effects operations, which can actively disrupt or degrade criminal infrastructure. (mayerbrown.com)
That could give investigators considerably more freedom to interfere with ransomware infrastructure rather than simply documenting how it works and passing the information to government agencies.
Attribution becomes the biggest problemThe approach carries substantial risk because cyber infrastructure is rarely cleanly separated between attackers and innocent users.
Criminal groups routinely operate through compromised servers, hijacked routers, residential proxies and legitimate cloud services. A server apparently belonging to a ransomware operation might actually be an innocent organization’s compromised machine.
Disrupting the wrong system could therefore cause collateral damage.
The memorandum requires contractors to stop operations and notify authorities if they unintentionally disrupt US systems outside the approved target. It also calls for coordination with other government agencies to avoid interfering with existing operations. (risky.biz)
Risky Business highlights another unresolved problem: international coordination. A US contractor attacking infrastructure associated with a criminal organization could unknowingly interfere with an investigation being conducted by Europol, Interpol or another foreign law-enforcement agency. (risky.biz)
Attribution therefore becomes much more than an intelligence question. Once private organizations are authorized to take disruptive action, attribution errors can produce real legal and diplomatic consequences.
Contractors may inherit considerable legal riskGovernment authorization also does not necessarily eliminate every legal problem for participating companies.
Operations will occur across international borders, where US authorization may not protect employees from prosecution under another country’s laws. Companies could also face lawsuits if their operations damage infrastructure belonging to innocent third parties.
These risks may significantly influence which companies participate.
Large cybersecurity and defense contractors generally have extensive legal departments, secure facilities and experience working with classified government programs. Smaller security companies may possess excellent technical capabilities but lack the financial and legal resources necessary to assume the liability associated with offensive operations.
The final rules issued by the DHS National Coordination Center will therefore determine whether the initiative develops into a broad private-sector cybersecurity program or primarily becomes another market for established government contractors. (risky.biz)
A form of cyber privateeringThe policy has inevitably drawn comparisons with historical privateers: privately operated ships authorized by governments to attack enemy vessels.
The analogy is imperfect because participating cybersecurity companies will not independently select targets or operate outside government control. They will receive specific authorization and operate as contractors.
Still, the comparison captures the broader strategic change.
The United States possesses an enormous private cybersecurity industry containing researchers and threat-intelligence teams that collectively observe far more malicious activity than government agencies could investigate alone. The new policy attempts to transform some of that capability from intelligence gathering into active disruption.
Risky Business argues that this fundamental idea makes sense. Traditional approaches have failed to impose sufficient costs on cybercriminal organizations, while government disruption teams simply cannot pursue every target themselves. (risky.biz)
The difficult part will be building enough oversight to prevent that additional capability from creating new problems.
Offensive cybersecurity is becoming a public-private activityIf successful, the initiative could significantly change the relationship between government and the cybersecurity industry.
Private firms already provide governments with threat intelligence, incident response, malware research and forensic expertise. Under this model, some of those companies would move one step further and participate directly in operations intended to disable criminal infrastructure.
That could increase the number of ransomware gangs, botnets and fraud networks the United States is capable of targeting simultaneously.
But greater capacity also creates greater responsibility. Contractors will need reliable attribution, carefully defined targets, strong operational security and mechanisms for limiting collateral damage. Governments will need to coordinate operations internationally and determine who ultimately carries responsibility when something goes wrong.
The Trump administration’s memorandum therefore does not simply authorize companies to “hack the hackers.” It proposes something considerably more structured:a government-controlled market for private offensive cyber capability. (Federal News Network)
Whether that becomes an effective extension of law enforcement or an operational and legal minefield will depend heavily on the rules DHS develops over the next two months. But the strategic direction is clear: Washington increasingly believes cybercrime has grown too large for government hackers and investigators to fight alone.