Critical Infrastructure Security, Government Regulations, Government security

White House looks to engage private sector in offensive hacking ops

Internet Code Hack Background

President Donald Trump issued a national security memorandum on Aug. 12 that said select companies could work with the federal government on offensive hacking operations to take down pervasive cyber threat groups that threaten the U.S. economy.

While companies such as Microsoft and Google have worked closely with the government for several years, the memorandum expands the program and marks a change in policy from the one that existed for many years in which military and intelligences agencies primarily conducted offensive hacking operations.

Companies selected for the program will work closely with the Justice and Homeland Security departments and be subject to $1 million fines for violations of the program.

Having private sector companies more involved in cyber operations has been discussed for some time, but was largely not pursued because the prevailing consensus was that it could inflame the cyber threat landscape and escalate threats.

Some security pros still feel that way.

“Endorsing private companies to conduct offensive cyberactivity is far more likely to increase criminal, and potentially nation-state, activity than deter it,” said Tim Mackey, head of software supply chain risk strategy at Black Duck. “Without careful governance and control, individuals with access to sophisticated surveillance technologies could easily abuse that access and engage in surveillance efforts for personal gain. Unfortunately, one message this memo does send to adversaries is that the U.S. government needs private companies and their capabilities to defend against cyberattacks.”

On the other hand, Kevin Surace, chief executive officer at TokenCore, said it makes sense to involve the private sector provided the selected companies operate as authorized partners of the government, not as independent cyber privateers.

Surace said private companies often possess the talent, specialized tools, global infrastructure, and visibility into malicious activity that government agencies cannot easily replicate. The government already relies extensively on contractors for cyber expertise, so Surace said the strategic question is not whether private expertise should be involved, but who selects the targets, authorizes the operation, sets the limits, and accepts responsibility when something goes wrong.

“Those responsibilities must remain with the government,” said Surace. “Military, intelligence, and law enforcement agencies should control attribution, target selection, legal authorization, coordination with allies, and escalation decisions. Approved companies can then contribute intelligence, infrastructure access, technical capabilities, and operational personnel within a clearly defined mission.”

Offensive ops crosses new threshold for private companies

Duncan Greatwood, chief executive officer at Xage Security, said following the case last month of suspected Chinese hackers deploying an AI system to carry out sophisticated cyberattacks on Taiwan, it’s clear that we have crossed a threshold that cannot be uncrossed.

“Leveraging the American private sector for offensive operations can absolutely make us more formidable, but it does not lessen the need for domestic defensive readiness,” said Greatwood.

Greatwood said defensively, it’s imperative that public and private sector organizations adopt an approach that protects vulnerable assets and limits the “blast radius” when a breach does occur. 

On the offensive side, Greatwood said while the U.S. and its allies will want to avoid runaway geopolitical escalation, if the U.S. never responds to cyberattacks it risks the opposite problem of enabling attackers, and their supporters, to operate with impunity.

Chris Jacob, Field CISO at Securonix, said while he wants to see cybercriminal organizations disrupted, he also wants the security professionals supporting that work protected from unrealistic expectations and unnecessary exposure.

“Asking private-sector teams to move closer to offensive cyber operations adjusts the risk they carry personally and professionally, and companies considering that role should go into it with all bases covered,” said Jacob.

Anurag Gurtu, co-founder and CEO at Airrived, said while it makes strategic sense to have private companies involved in hacking operations, the government must define the targets and rules of engagement.

“Private industry can pull the trigger,” said Gurtu. “Government must decide where to aim.”

Gurtu said liability must be crystal clear: If a private company attacks the wrong target under government authorization, who owns the mistake?

“We’re rapidly moving toward autonomous cyber agents fighting autonomous cyber agents at machine speed,” said Gurtu. “The future of cyber isn’t just defense. It’s governed offense. Get the governance right, and we dramatically increase the cost of cybercrime. Get it wrong, and we dramatically increase the cost of a mistake.”

Omer Ninburg, co-founder and CTO at Novee, said involving the private sector can make sense because companies often have specialized expertise, infrastructure, and visibility that government agencies do not. But Ninburg said collaboration on takedowns or asset seizures is very different from allowing a private actor to conduct an offensive operation.

Ninburg pointed out that a government sign-off grants permission, it does not necessarily grant control: that distinction becomes critical if autonomous systems are eventually used.

“Attribution is rarely certain because adversaries route attacks through infrastructure belonging to legitimate organizations and plant false flags,” said Ninburg. “At machine speed, an operation could act on an outdated or incorrect assumption before a human has time to intervene. A precise strike against the wrong target is still the wrong strike, only faster and potentially repeated in parallel.”

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds