Trump Signs Memo to Enhance Private Sector Role in Combating Cybercrime
President Donald Trump has signed a national security memorandum that outlines a significant expansion of the private sector's role in assisting law enforcement agencies in conducting offensive hacking operations against transnational criminal organizations (TCOs). The move is aimed at bolstering the fight against cyber-enabled crimes, including sustained fraud campaigns perpetrated by these groups.
The memorandum, signed on Wednesday, mandates the creation of a federal coordination center that will oversee the authorization of private sector companies to participate in cyber surveillance and effects operations against foreign cyber-enabled TCOs. These operations will be conducted under the supervision and control of the federal government as part of lawful investigatory, protective, or intelligence operations carried out by federal law enforcement agencies.
Participating Companies to Undergo Rigorous Vetting
To participate in this program, private sector companies will be required to sign contracts with either the Justice Department or the Department of Homeland Security, undergoing a rigorous vetting process. Additionally, these companies will be allowed to enter into commercial agreements with other private sector entities to receive threat information. Their agreements with federal, state, and local governments will focus on identifying threats and proposing cyber operations to the coordination center to address these threats.
The program is designed to adhere to existing laws, including the Computer Fraud and Abuse Act, the primary federal anti-hacking statute. The memorandum also emphasizes the need for oversight to assess companies' technical proficiency, ensuring that both small and large companies can participate, and requiring regular reporting to federal officials.
Reaction to the Memo
The move has sparked a range of reactions within the cybersecurity community. Some have expressed concern about granting the private sector too much latitude in offensive operations, fearing it could set a dangerous precedent that might lead to wider chaos in cyberspace. Others have welcomed the development, seeing it as a necessary step to leverage the expertise of the private sector in combating cybercrime.
Former Cyber Command official Jason Kitka criticized the memorandum, describing it as "a perpetual motion machine for billable threats" in a social media post. In contrast, Josh Steinman, a former top White House cyber official during Trump's first term and co-founder of Galvanick, applauded the move. Chris Wysopal, co-founder of Veracode and a pioneer in the field of cybersecurity, characterized the memo as "a pretty big shift in US cyber policy," though he noted it stops short of going as far as other "hack back" proposals.
Background and Context
The idea of involving the private sector more deeply in offensive cyber operations is not new. There have been sentiments, particularly in conservative circles, to authorize "letters of marque" for private-sector cyber firms, similar to those issued to early U.S. sea privateers. The concept suggests that the government could rely more heavily on private sector cyber experts to conduct offensive operations. However, this approach has been met with deep concern within cyber circles due to the potential risks and the fear of setting a dangerous precedent.
The memorandum comes as a follow-up to a fraud-focused executive order issued in March, which the White House described as only the first step in combating TCO-perpetrated cybercrime. The current move is seen as an expansion of the fight against these crimes, leveraging the ingenuity of the private sector to enhance the government's capabilities in cyber surveillance and effects operations.
Source: CyberScoop