executive-ordertrade-pressNewsThe Broadside2 min read

Trump memo lets vetted firms launch offensive cyber ops

Six months after the White House explicitly disavowed hack-back, a presidential memorandum opens the door to precisely that, under DOJ and DHS sign-off.


TL;DR

A presidential memorandum released late Wednesday authorizes vetted U.S. companies to conduct offensive cyber operations and surveillance against transnational cybercrime organizations, subject to advance written approval from DOJ and DHS. The memorandum prohibits operations that would cause loss of life or constitute an armed attack under international law. Participating firms face a $1 million penalty per violation of the operational framework. The move reverses the administration's own March position, when National Cyber Director Sean Cairncross said the White House was "not interested in fighting pirates with pirates."

The memorandum is the operational follow-through on an executive order from March that ordered agencies to get more aggressive against transnational cybercrime, but it lands in direct tension with what senior White House officials were saying about private-sector hack-back just five months ago.

At the Prague Cyber Security Conference in March, ONCD senior adviser Thomas Lind told European officials the administration was not considering cyber letters of marque. "We're not interested in fighting pirates with pirates," Lind said. National Cyber Director Sean Cairncross added the same week that "private sector, industry or companies engaging in cyber offensive campaigns, that's not what we're talking about." The memorandum now says precisely the opposite: vetted firms will conduct offensive operations, albeit under government sign-off.

The framework, in outline

Participating companies sign contracts with DOJ or DHS, undergo vetting, and receive access to threat intelligence. Every operation requires a written review-and-approval package before action. Operations that cause loss of life or "rise to the level of use of force or armed attack under international law" are off-limits. Violations carry a $1 million civil penalty per instance. The companies also get liability protection against foreign legal action, though cybersecurity experts quoted by The Record questioned how effective that shield would be if a foreign government decided to extradite an employee anyway, citing the recent arrest in Italy of a Chinese national accused of offensive cyber work.

What's missing

The memorandum is silent on what happens when a cybercrime target is entangled with a nation-state group, a scenario that's increasingly the norm. State Department officials have already tied Southeast Asian scam-center operators to Chinese government projects, and DOJ indictments have named government officials in Cambodia and Myanmar. The memo provides no rule of engagement for that gray zone.

For the compliance and legal teams at firms weighing participation, the questions start with liability and don't stop. The $1 million penalty per violation is a blunt instrument with no gradation. The "written approval" mechanism is undefined. And the gap between what Cairncross said in March and what the memo authorizes in August will make it hard for any firm to assess whether the policy is stable or still evolving.


Published ·Deep Fathom