Published · 3d agoSecurity3 min read
DHS Will License Private Hackers. Read the Authorisation Boundaries Now.
A presidential memo directs DHS to authorise vetted private firms to conduct cyber surveillance and cyber effects operations against foreign criminal groups. The boundaries matter more than the announcement.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- A presidential memo issued last week directed the Department of Homeland Security to establish a program authorising private companies to conduct cyber operations against so-called "Cyber-Enabled Transnational Crime Organisations" (CE-TCOs). The memo sets out the broad shape of the arrangement and a classified annex further details the logistics.
- The policy shift is that private companies will be authorised to conduct cyber operations that were previously restricted to state entities.
- The authorised operations include what the memo calls "cyber surveillance" (intelligence gathering operations) and "cyber effects" operations (intended to manipulate or to cause disruption).
- CE-TCOs are defined as foreign groups conducting cyber-enabled crime against US persons or interests that are not part of, or operated by, a foreign government.
- The process the memo describes for identifying CE-TCOs to target is, in Seriously Risky Business's assessment, "ridiculously broad": targets can be identified either by private sector entities or by any "federal, state, local, tribal, and territorial" agency.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Last week a presidential memo directed the Department of Homeland Security to establish a program authorising private companies to run cyber operations against what it calls "Cyber-Enabled Transnational Crime Organisations", with the broad arrangement in the memo and the logistics in a classified annex [1]. It hands private firms two things previously restricted to state entities: "cyber surveillance", which the memo treats as intelligence gathering, and "cyber effects", intended to manipulate or cause disruption [2][3].
The target definition is the first boundary. A CE-TCO is a foreign group conducting cyber-enabled crime against US persons or interests that is not part of, or operated by, a foreign government [4]. Someone has to make that call before an operation rather than after it, and the set of parties allowed to nominate targets is wide: private sector entities, plus any "federal, state, local, tribal, and territorial" agency [5]. That is six classes of nominator feeding a review process staffed by two departments [16]. Tom Uren, writing in Seriously Risky Business, calls the identification process "ridiculously broad" and argues nomination authority should sit only with agencies that actually respond to scams or cybercrime [5][6].
Three controls sit between a nomination and a packet reaching someone's infrastructure [17]. Companies are vetted first, on "appropriate levels of technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence, reliability, and other factors" [7]. Participants then write their own operations packages, which program directors at the Departments of Justice and Homeland Security assess before execution [8]. The stated tests at that stage are narrow: the operation must not interfere with other US government activities, must not kill anyone, and must not be equivalent to an armed attack under international law [9]. Each participant also posts a USD$1 million bond, forfeited if it breaks its contract conditions [10].
Read those three tests as an operator, not as a lawyer. They constrain outcomes at the extreme end. They say nothing on their face about collateral disruption to third-party hosting, transit providers or victims sharing infrastructure with a target, which is where cybercrime takedowns usually create their mess.
The rationale is capacity rather than ideology. Uren's account is that the FBI can only tackle the highest-priority groups, NSA is focussed on foreign intelligence and Cyber Command on the nexus between warfare and cyber [13], leaving hundreds of uncontested groups working on Americans [14].
The objections already on record are escalation from accidentally hacking a foreign government, and foreign governments targeting employees of the companies in the program [11]. Uren considers both overblown, pointing out that even WannaCry and NotPetya produced no significant problems for the governments behind them [12]. Note the substitution in that argument: it measures consequences borne by states, and the retaliation risk here lands on named staff at commercial firms.
What to watch. The classified annex holds the logistics [1], so the operative rules are not public and the memo text is not a complete compliance picture. Watch whether nomination authority is narrowed from every tier of government [5] to agencies with a cybercrime remit [6]. Watch the first forfeiture, because the USD$1 million bond [10] is the only stated financial consequence, and it is a contract penalty rather than a liability regime for third parties. And if your firm is in scope, or shares infrastructure with plausible targets, the useful question is which of your people would be individually identifiable in a program filing.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A presidential memo issued last week directed the Department of Homeland Security to establish a program authorising private companies to conduct cyber operations against so-called "Cyber-Enabled Transnational Crime Organisations" (CE-TCOs). The memo sets out the broad shape of the arrangement and a classified annex further details the logistics.
ReportedView cited source - [2]
The policy shift is that private companies will be authorised to conduct cyber operations that were previously restricted to state entities.
ReportedView cited source - [3]
The authorised operations include what the memo calls "cyber surveillance" (intelligence gathering operations) and "cyber effects" operations (intended to manipulate or to cause disruption).
ReportedView cited source - [4]
CE-TCOs are defined as foreign groups conducting cyber-enabled crime against US persons or interests that are not part of, or operated by, a foreign government.
ReportedView cited source - [5]
The process the memo describes for identifying CE-TCOs to target is, in Seriously Risky Business's assessment, "ridiculously broad": targets can be identified either by private sector entities or by any "federal, state, local, tribal, and territorial" agency.
- [6]
Seriously Risky Business argues it makes more sense for only agencies that help respond to scams or cybercrime to have authority to nominate CE-TCOs as targets.
Sources & coverage · 3 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- news.risky.biz3d agoSrsly Risky Biz: Trump's Private Hacker Memo Is the Right Idea
Cited in this coverage: Tom Uren, Seriously Risky Business (news.risky.biz)
- arcticwolf.comAdam Marrè2d agoThe Line Between Defense and Offense Just Moved. Here’s What Comes Next.



