President Trump has introduced a plan for private businesses to play a role in countering foreign cybercriminals. A recent memo outlines a program allowing select U.S. companies to target cyber threats identified by the government. Traditionally, government agencies handle such operations.
The memorandum lacks clarity on how private firms could assume roles like spying or conducting disruptive cyber actions usually reserved for government. While U.S. laws prohibit hacking, certain exceptions permit law enforcement activities. This new directive doesn’t alter those laws but requires participating firms to have federal contracts.
This initiative marks a change in the private sector’s approach to cyberspace. It aims to empower some private businesses to disrupt entities labeled as cybercriminals or gather intelligence on them. According to Joshua Steinman, former senior director for cyber policy under Trump, potential targets include organized crime and individuals involved in illicit activities.
Following Trump’s administration’s rise, Republicans proposed legislation for ‘cyber privateers’, a concept inspired by historic naval practices, to combat foreign hackers. Although the memorandum stops short of this, supporters of the idea have shown approval.
“There’s a range of potential targets … like organized crime … people doing money laundering or other criminal activity,” said Joshua Steinman.
The interest from companies is uncertain. Traditionally, private businesses assist the government in cyber efforts as contractors. However, this new scheme presents them with the opportunity to play a more direct role.
According to Arthur Tellis, formerly of the Department of Defense, private companies may excel in surveillance over actual disruption of criminal groups. Their involvement could involve contracts with the Department of Justice or Homeland Security, including rigorous vetting and financial obligations.
The memo gives DOJ and DHS two months to resolve pending legal and procedural queries. Industry experts, like Stacy O’Mara from Armadin cybersecurity, express doubts, citing legal uncertainties.
“There are all these other components that are still outstanding,” O’Mara said.
Industry Concerns
Critics in the cybersecurity field argue against this approach. Paul Rosenzweig, former deputy assistant for homeland security policy, opposes the idea, citing legal and practical challenges for private actors hacking foreign entities.
The memo does not permit attacks against other governments, but foreign cybercriminals often exist between state-sponsored and independent status, risking diplomatic tensions.
Some cybersecurity professionals, like Chris Wysopal from Veracode, avoid involvement due to potential liabilities, fearing unintended consequences of wide-ranging attacks.
“You don’t want to have collateral damage when your blast radius is too big,” Wysopal warned.
The Growing Threat of Cyberattacks
Cyberattacks cost Americans billions annually, targeting both private and public sectors. These threats can steal data and demand ransom.
Cyberattacks pose national security risks, such as recent coordinated efforts linked to foreign entities targeting Minnesota’s water services.
Steinman suggests the private sector’s contribution might enhance the country’s cyber offense, provided cautious implementation.
“The point of this is to get started,” Steinman noted, expressing confidence in the government’s measured approach.
Yet, experts like Wysopal remain skeptical, highlighting that offensive efforts may not entirely resolve cybercrime risks.
“I don’t think you can sort of offense your way to security,” he remarked.
