US memo outlines role for private firms in disrupting foreign cybercrime networks
President Donald Trump has authorized US government agencies to hire private cybersecurity companies for intelligence-gathering and disruption operations against certain foreign cybercrime groups.A me...
President Donald Trump has authorized US government agencies to hire private cybersecurity companies for intelligence-gathering and disruption operations against certain foreign cybercrime groups.
A memorandum signed this week creates a framework for contractors to support operations against “cyber-enabled transnational criminal organizations.” The targets are defined as foreign groups conducting cybercrime against the US government, American individuals or US interests. Organizations acting directly for, or entirely on behalf of, foreign governments are excluded from the program.
Surveillance and disruption
The policy distinguishes between cyber surveillance and “Cyber Effects Operations.” The latter may include manipulating, disrupting, denying or degrading information systems, networks, infrastructure and data controlled through those systems. The memo also recognizes that surveillance activity may itself require limited interference with systems.
Participating companies will be subject to government vetting, detailed operating procedures and recurring technical evaluations. Those procedures are expected to be developed within 60 days by program executives working with the Homeland Security Council. Officials are also instructed to make opportunities available to both major contractors and smaller companies with specialized capabilities.
The Justice Department will participate in approving operations, particularly where US residents or domestic legal issues are involved. Contractors may not conduct activity likely to cause death or serious injury, or operations that could qualify as an armed attack under international law. Each company must maintain at least $1 million in bond or escrow, which can be forfeited for contractual violations.
Legal questions remain
The initiative follows the administration’s March cybersecurity strategy, which called for stronger public-private cooperation to identify and disrupt hostile networks. Legal analysts had previously questioned whether existing US law would permit private companies to conduct hack-back operations.
The Computer Fraud and Abuse Act generally prohibits unauthorized access to computer systems. One provision exempts certain authorized investigative, protective and intelligence activities conducted by government agencies, but courts have not established whether that protection extends to private contractors working under government direction. Lawyers have also warned that civil liability could remain even if criminal enforcement priorities change.
The program therefore represents a significant adjustment in US cyber policy, while leaving important questions about oversight, liability and international consequences unresolved. US allies and the cybersecurity industry are likely to watch how the framework is implemented and whether companies choose to participate.
