US President Donald Trump has signed a memorandum aimed at giving private companies the authority to carry out offensive cyber-attacks against foreign “criminal” entities.
The president signed the national security presidential memorandum directing his administration to “leverage the capability and innovation of the private sector to help conduct these cyber operations under the direction, control and authority of US government,” according to White House.
This major policy shift gives the private sector a role traditionally reserved for government agencies, essentially deputising private companies in the fight against online crime, reports Guardian.
Rather than granting unlimited hacking capabilities, the memorandum authorises “limited cyber operations at the direction of the US government”.
In a fact sheet about the memorandum, the White House cited ransomware attacks, financial fraud, and other crimes conducted by foreign-based criminal organisations, referred to in the document as “transnational criminal organisations” (TCOs).
International concern over cyber-attacks has intensified following the release of highly powerful artificial intelligence models, which have demonstrated the ability to hack into outdated security systems.
Earlier this year, hackers targeted critical infrastructure systems in several US states, resulting in disruptions at water facilities.
The memorandum establishes a framework encouraging private sector companies to enter into agreements with other private entities, as well as federal, state, local, tribal, and territorial agencies, to gather threat information on TCOs and propose cyber operations to address those threats.
Additionally, the memorandum directs the Department of Homeland Security (DHS), through the homeland security taskforce’s national coordination centre, to create a programme to “conduct specific cyber operations that disrupt foreign TCOs”. The programme will be overseen by both DHS and Department of Justice.
Under the supervision of the federal government, participating companies will have to be vetted before they can conduct “cyber surveillance operations” and “cyber effects operations” against specified targets.
According to the memorandum, “cyber effects” includes the potential manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident on them.
Vetted participating companies will also be required to maintain a bond or escrow of at least $1 million.
The concept of private sector involvement in cyber operations against criminal and other targets is not new, but it has previously encountered controversy over fears of escalation, inadvertent consequences, and inter-agency coordination issues.
Legal experts have raised questions regarding the risks companies might face as they enmesh themselves in international digital conflicts. The Trump administration has previously pledged to give private firms a larger role in cybersecurity.
A national cybersecurity policy released in March stated that the government would create incentives to “unleash the private sector” against foreign adversaries. The DHS and White House did not immediately respond to requests for additional details about the programme.





