US Govt Wants Private Cyber Companies to Join the Fight Against Foreign Adversaries

Under the new programme, participating companies will be authorised to conduct cyber surveillance operations and cyber effects operations against designated foreign criminal organisations.

US Govt Wants Private Cyber Companies to Join the Fight Against Foreign Adversaries
(Image-Magnific)

The White House will now allow vetted US private-sector companies to conduct cyber operations against foreign criminal organisations.

President Donald Trump signed the presidential memorandum on August 12, directing the National Coordination Center (NCC) to establish and manage the programme.

The White House said transnational criminal organisations are conducting sustained cyber campaigns involving fraud and other crimes that threaten American citizens and national security.

The memorandum argues that the government has not fully used the capabilities of private companies to identify and disrupt these networks.

“The American private sector is the most innovative and technologically advanced in the world,” the memorandum states, adding that its “scale, speed, and capacity secure a critical offensive cyber advantage for the United States.”

Cybersecurity experts in the US that The Left Shift has spoken with welcome the move. US firms are likely to welcome the opportunity to join the fight against cyberattacks originating overseas. Many see the memorandum as a potential precedent that could encourage other countries to adopt similar public-private models for tackling cybercrime.

However, they also raise concerns about how far private companies will be allowed to go, who will be held accountable if an operation causes unintended damage, and whether offensive cyber actions could trigger retaliation against the companies involved.

Some experts believe the joint operations will be against state-sponsored cyberattacks originating in countries such as Iran or North Korea, where US firms have very few or no operations.

Under the new programme, participating companies will be authorised to conduct cyber surveillance operations and cyber effects operations against designated foreign criminal organisations.

These can include gathering intelligence from computer systems and, under government direction, activities designed to manipulate, disrupt, degrade or destroy information systems and infrastructure.

The companies will not operate independently. They must be vetted and operate under the control and oversight of the federal government. The Department of Justice and Department of Homeland Security will jointly oversee the programme, with operations requiring government approval before they can proceed.

The White House also said the initiative will allow participating companies to receive threat information from private-sector organisations and government agencies to help identify potential targets.