executive-ordertrade-pressNewsThe Broadside1 min read

White House authorizes offensive cyber ops by private firms

The vetting framework is spelled out. The liability framework when an offensive op goes sideways isn't, and "destroy" remains undefined under international law.


TL;DR

The White House signed a memorandum Wednesday authorizing vetted U.S. cybersecurity firms to conduct offensive operations (including disrupting, degrading, and destroying foreign adversary networks) under supervision of the Justice and Homeland Security departments. The memo also permits participating companies to enter commercial agreements with other private entities, effectively creating a market for government-supervised offensive cyber services. Unresolved: the liability framework for firms when operations produce collateral effects, and how the "destroy" authorization comports with international law.

White House authorizes offensive cyber ops by private firms
Editorial illustration · drawn by The Broadside

The memorandum President Trump signed Wednesday doesn't invent private-sector involvement in offensive cyber, the FBI has contracted firms for botnet takedowns for years. What's new is the scope and the explicit authorization: DOJ and DHS will vet companies and supervise operations that can "manipulate," "degrade," "disrupt," and "destroy" foreign adversary networks.

The "destroy" verb is the hardest to square with existing frameworks. Botnet takedowns disable infrastructure temporarily; destroying a foreign network raises international-law questions the memo punts on, forbidding only operations that "rise to the level of use of forced or armed attack." That's a high bar with substantial gray area beneath it. The commercial-agreement provision is equally significant: authorized firms can cut side deals with other private entities, federal agencies, and state governments. A company vetted by DOJ could sell offensive cyber services to a state, creating a market where the federal government certifies the vendor but doesn't control every engagement.

For compliance directors and security leads at firms in the federal contracting ecosystem, the immediate question is whether their organization wants in. Offensive capability changes a company's risk profile (insurance, export controls, retaliation exposure) in ways the memo doesn't address. The program executive directors have 60 days to draft screening standards. The liability question gets answered later, if at all.


Published ·Deep Fathom