executive-ordertrade-pressNewsThe Broadside1 min read

Trump Offensive Cyber Memo Silent on Contractor Liability

The program asks private companies to act as government proxies in offensive operations but leaves them exposed to civil suits, foreign prosecution, and loss of CISA 2015 protections.


TL;DR

President Trump's Aug. 12 national security memorandum directs DHS and DOJ to create a program letting vetted cybersecurity companies conduct offensive cyber operations against transnational criminal groups under government supervision. Participating firms must post a $1 million bond and operate under written government approval. But the memo includes no civil liability shield, and former DOJ cyber official Leonard Bailey warns companies risk losing CISA 2015 protections by acting as government proxies, buying, as he put it, "a lot of risk without much protection."

The memorandum (the implementation vehicle for Trump's March cybercrime executive order) envisions private firms conducting cyber surveillance and effects operations under contract, with written approval from the directors of DHS and DOJ, through a National Coordination Center. The White House framed it as a force-multiplier against cyber-enabled transnational criminal organizations. What it didn't frame is who pays when an operation misfires.

Leonard Bailey, who spent 16 years at DOJ before leaving as head of the cybersecurity unit in the Criminal Division's computer crime section, told an IST webinar on Aug. 24 that the memo leaves contractors in a worse legal position than they'd occupy on their own. Under the Cybersecurity Information Sharing Act of 2015, private companies that share threat data with the government enjoy specific liability protections. By converting private actors into government proxies, Bailey argued, the program may strip those shields away. Law firm Venable raised the same concern in an Aug. 19 blog post.

IST's Jason Kikta called the $1 million bond requirement "an entry price" for takedowns of digital infrastructure that is "worthless for both parties." If a targeted criminal group retaliates, Kikta noted, the blowback will likely hit the contractor's customers first, a dynamic he described as a potential "death spiral."

Then there's the subcontracting risk. Jen Ellis of NextJen Security warned that prime contractors may push the actual operational work "downhill to hungrier companies that are perhaps a little bit less legally cautious or legally mature." The result, she said, could be a gray market with minimal oversight carrying the same risks.

The program's operational details remain under development. For now, the asymmetry is the story: the government is asking private companies to carry offensive fire and offering them an unshielded position and a bond that wouldn't cover the legal fees.


Published ·Deep Fathom