The Donald Trump administration is now encouraging U.S. companies to carry out their own cyberattacks against hackers abroad, in a move that, according to White House officials, could help counter threats such as ransomware (malicious software). Former government officials and cybersecurity experts, however, warn that the new policy could cause chaos.
Under a national security memorandum signed by Trump late Wednesday night, selected companies will be able to work with the Departments of Justice and Homeland Security to launch, under specific conditions, cyberattacks against cybercrime groups operating outside the United States.
These operations may include both monitoring criminal networks and specific forms of cyberattacks aimed at disrupting, manipulating or destroying information systems and networks, including both digital and physical infrastructure.
It is not yet known which companies, if any, will participate in the program. It nevertheless represents a radical shift in U.S. cybersecurity policy over recent decades. Both Republican and Democratic administrations had until now prioritized strengthening companies’ defenses, leaving offensive cyber operations to the armed forces and intelligence agencies.
The idea of direct private-sector involvement in offensive cyber operations has been discussed for years, but until now it had never been publicly adopted by a U.S. presidential administration. The concerns relate to the risk of triggering new cyber conflicts, questions of legal liability and international law for U.S. businesses, as well as unforeseen consequences that could lead to escalation.
The new memorandum does not directly address many of these concerns, but states that the policy aims to harness the “ingenuity of the private sector” to limit the ever-increasing cost of cyberattacks.
Who will be allowed to conduct cyberattacks
The new policy does not provide for unchecked action by companies in cyberspace. Companies participating in the program will first have to undergo a vetting process, sign a contract with the government that will provide for fines of $1 million for violations, and obtain written approval from officials at the Departments of Justice and Homeland Security before each attack.
Companies whose actions are likely to cause loss of human life or serious injury will not be allowed to participate, nor will actions that could be considered “use of force or an armed attack under international law.”
Former officials and experts point out, however, that accurately assessing the consequences of an offensive cyber operation is not always easy.
The White House did not respond to questions about the memorandum, apart from noting that the operations would be conducted “based on intelligence from the agencies.”
Amanda Naylor, director of cybersecurity policy at the National Security Council, which drafted the memorandum together with the Office of the National Cyber Director, said the new policy would “give the United States new tools to protect Americans from cybercrime and fraud.”
The fear of an uncontrolled digital war
Many former government officials and cybersecurity company executives are concerned that the new model will be difficult to implement and could further complicate the already unpredictable world of modern cyberwarfare.
A former senior U.S. intelligence official pointed out, among other things, to The New York Times that companies approved for the program could potentially carry out actions that go beyond even the authorities of government security agencies themselves.
Trump’s decision is accompanied by a classified annex that establishes the procedure for ensuring that cyberattacks by private companies do not conflict with operations already being conducted by the federal government.
The memorandum also clarifies that the targets will be transnational criminal organizations considered independent of foreign governments, unless there is clear intelligence demonstrating such a connection.
This is precisely one of the biggest challenges posed by the new policy.
Nick Carr, head of threat analysis at Microsoft and a former cybersecurity official, told The New York Times that his biggest concern is how difficult it is to determine who is actually behind a criminal cyberattack and how few organizations can do so consistently and accurately — even among government agencies.
At the same time, it often remains unclear whether a criminal hacker group, such as a Russian-speaking cybercrime gang, is connected to a foreign government or occasionally cooperates with intelligence agencies.
Michael Garcia, a former deputy policy chief at the U.S. Cybersecurity and Infrastructure Security Agency (CISA), noted that despite improvements in the ability to identify perpetrators in recent years, the process remains imperfect and concealing one’s true identity continues to be an extremely effective tactic.
The role of Artificial Intelligence
Some former officials believe that the government is attempting to address a problem that has become unsustainable and will probably worsen in the short term because of artificial intelligence.
“The current pace of cyber operations is not sustainable for the military alone,” said Mikey Eoyang, a former Pentagon official who oversaw the use of military cyber weapons during the Biden administration.
Eoyang, now a visiting professor at Carnegie Mellon University, estimated that the program’s success will depend on the classified procedures for selecting companies and approving targets.
The U.S. adopts a model reminiscent of China and Russia
To some extent, the new policy brings the U.S. closer to the model followed by some of its main cyber adversaries, such as China and Russia, where intelligence agencies have for years used private-sector hackers to advance national security objectives.
U.S. defense technology companies already work with the NSA and U.S. Cyber Command, but until now this cooperation has mainly involved providing hacking tools, intelligence and expertise, rather than companies directly participating in the operations themselves.
Dakota Cary, an expert on China’s cyberattack ecosystem, told the Times that historically Beijing copied various U.S. practices in the field of cybersecurity, whereas now the opposite appears to be happening. “In many ways, China’s hacking capability today comes from the fact that it copied our educational system,” he said. “Now it seems the U.S. is interested in copying the Chinese system, giving private-sector hackers a state role.”
It remains unclear, however, which companies will want to participate, as lawyers point out that the program carries significant business and legal risks.
Vanessa Le, a partner at Latham & Watkins and an adviser to businesses on geopolitical risk, raised the question of how a publicly traded company could manage the increased operational risk to itself and its clients if it conducts “counter-hacking” attacks with the backing of, or at the direction of, the U.S. government, as well as how and when it would be required to disclose such activity.
Ask me anything
Explore related questions