President Trump has introduced a provocative program encouraging private companies to counter cybercriminals. A recent memorandum reveals the administration’s plan to allow certain businesses to target foreign hackers identified by the government. Historically, such tasks have fallen under governmental purview.
Details of the Memorandum
The presidential memo does not clearly define how private entities will replace government roles like spying or cyber operations. Current U.S. laws prohibit hacking unless law enforcement is involved, and this memo does not alter these laws. It stipulates that participating companies must have federal government contracts, marking a significant change in private sector involvement in cybersecurity.
If executed, this initiative would enable select U.S. companies to disrupt designated foreign organizations or gather intelligence on them. Joshua Steinman, previously a senior director for cyber policy at the National Security Council, highlighted potential targets such as organized crime and money laundering networks.
Public and Legal Debates
There’s uncertainty about which companies would seize this government invitation. Historically, private firms have cooperated with U.S. authorities mainly as supporting contractors, not as active saboteurs. Arthur Tellis, a former Department of Defense staffer, noted that many might view this as a chance to gain government contracts.
Participating companies would need contracts with the Department of Justice or the Department of Homeland Security. These companies would face rigorous scrutiny, including setting aside $1 million for unmet obligations. Authorized operations could involve accessing and manipulating digital networks. However, specific processes for vetting and target selection are not detailed in the memo.
Stacy O’Mara from the cybersecurity firm Armadin expressed caution, pointing out unresolved legal questions. The memo grants two months for agencies to address these concerns.
Industry Opposition
Some cybersecurity experts criticize the memo. Paul Rosenzweig, a cybersecurity consultant and former homeland security official, believes this approach raises many legal challenges. Chris Wysopal, of the security firm Veracode, worries about liability if operations go awry and mistakenly affect other targets, such as U.S. entities.
Cyberattack Risks
Businesses and utilities face increasing cyber threats, with attackers stealing data or seeking ransom. Cyberattacks not only cause financial loss but also pose national security risks. Recently, Minnesota reported cyberattacks on over 30 water systems, allegedly tied to Iran.
While some industry leaders see potential in the program, others argue it won’t curb cybercrime, emphasizing a persistent cycle of emerging threats. Wysopal commented, “You can’t offense your way to security,” indicating skepticism about the program’s efficacy against the ever-evolving threat landscape.
