executive-ordertrade-pressNewsThe Broadside2 min read

Senate NDAA would authorize contractor offensive cyber operations

The liability problem starts with the undefined phrase: access generation can cover a lot before oversight catches up.


TL;DR

Inside Cybersecurity reports that a Senate fiscal 2027 National Defense Authorization Act provision would let the Defense Department (DoD) contract with private entities to conduct cyber operations for “access generation and maintenance” under U.S. Cyber Command authority. If enacted, it would mark the first explicit contractor authorization for offensive cyber under the DoD umbrella. Defense primes and counsel get the liability problem: vague scope, 48-hour reporting, and no matching House provision yet.

Inside Cybersecurity reports that the Senate fiscal 2027 National Defense Authorization Act (NDAA) contains a provision authorizing the Defense Department to contract with private-sector entities for cyber operations limited to “access generation and maintenance,” using contractor-owned, contractor-operated equipment and personnel under the operational authority of the commander of U.S. Cyber Command. It would also create a Cyber Command pilot to test whether that model is feasible and advisable. That is a quiet sentence with a loud consequence: contractors would move from supporting offensive cyber to conducting the access work themselves, if the language survives conference.

At an Institute for Security and Technology webinar, Nick Leiserson, Jason Kikta and Alex Orleans argued that the bill leaves the central term too open. The problem is not that access development is exotic. Cyber Command already needs access to run operations. The problem is that “access generation and maintenance” can cover preparatory moves that set the risk profile before any later operation is described. For a prime, that is where legal exposure and reputational damage start to separate from the contract description.

The oversight language is thin for the thing being authorized. The measure would require DoD to report to the House and Senate Armed Services committees within 48 hours of the start and conclusion of each contractor-run operation, including the target and nature of access, the government overseer’s identity, and the operation’s duration and status. Kikta’s objection is practical: one cleared civilian or service member watching the engagement may not capture the tools, techniques or intermediate access paths that counsel and commanders need to understand. A later committee notice is a poor substitute for live scoping.

The House bill has no similar provision, according to Leiserson, and more than 700 amendments are pending on the Senate floor. That gives Congress a narrow drafting job with wide consequences. If lawmakers want contractors to become access generators for Cyber Command, they need to define the boundary before primes bid on it. A vague pilot can still produce real operations, real retaliation risk and real liability.


Published ·Deep Fathom