Skip to content

Security4 publishers3 min readPublished

Trump memo authorizes private-sector cyberattacks, and your vendor list is now a policy question

The Washington Post and The Record report the memo puts cyber firms on the offensive against criminals. The details are absent so far; the procurement questions are not.

The Watch · Security desk

What happened

  • A presidential memo issued last week directed the Department of Homeland Security to establish a program authorising private companies to conduct cyber operations against so-called "Cyber-Enabled Transnational Crime Organisations" (CE-TCOs). The memo sets out the broad shape of the arrangement and a classified annex further details the logistics.
  • The policy shift is that private companies will be authorised to conduct cyber operations that were previously restricted to state entities.
  • The authorised operations include what the memo calls "cyber surveillance" (intelligence gathering operations) and "cyber effects" operations (intended to manipulate or to cause disruption).
  • CE-TCOs are defined as foreign groups conducting cyber-enabled crime against US persons or interests that are not part of, or operated by, a foreign government.
  • The process the memo describes for identifying CE-TCOs to target is, in Seriously Risky Business's assessment, "ridiculously broad": targets can be identified either by private sector entities or by any "federal, state, local, tribal, and territorial" agency.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Last week a presidential memo directed the Department of Homeland Security to establish a program authorising private companies to run cyber operations against what it calls "Cyber-Enabled Transnational Crime Organisations", with the broad arrangement in the memo and the logistics in a classified annex [1]. It hands private firms two things previously restricted to state entities: "cyber surveillance", which the memo treats as intelligence gathering, and "cyber effects", intended to manipulate or cause disruption [2][3].

The target definition is the first boundary. A CE-TCO is a foreign group conducting cyber-enabled crime against US persons or interests that is not part of, or operated by, a foreign government [4]. Someone has to make that call before an operation rather than after it, and the set of parties allowed to nominate targets is wide: private sector entities, plus any "federal, state, local, tribal, and territorial" agency [5]. That is six classes of nominator feeding a review process staffed by two departments [16]. Tom Uren, writing in Seriously Risky Business, calls the identification process "ridiculously broad" and argues nomination authority should sit only with agencies that actually respond to scams or cybercrime [5][6].

Three controls sit between a nomination and a packet reaching someone's infrastructure [17]. Companies are vetted first, on "appropriate levels of technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence, reliability, and other factors" [7]. Participants then write their own operations packages, which program directors at the Departments of Justice and Homeland Security assess before execution [8]. The stated tests at that stage are narrow: the operation must not interfere with other US government activities, must not kill anyone, and must not be equivalent to an armed attack under international law [9]. Each participant also posts a USD$1 million bond, forfeited if it breaks its contract conditions [10].

Read those three tests as an operator, not as a lawyer. They constrain outcomes at the extreme end. They say nothing on their face about collateral disruption to third-party hosting, transit providers or victims sharing infrastructure with a target, which is where cybercrime takedowns usually create their mess.

The rationale is capacity rather than ideology. Uren's account is that the FBI can only tackle the highest-priority groups, NSA is focussed on foreign intelligence and Cyber Command on the nexus between warfare and cyber [13], leaving hundreds of uncontested groups working on Americans [14].

The objections already on record are escalation from accidentally hacking a foreign government, and foreign governments targeting employees of the companies in the program [11]. Uren considers both overblown, pointing out that even WannaCry and NotPetya produced no significant problems for the governments behind them [12]. Note the substitution in that argument: it measures consequences borne by states, and the retaliation risk here lands on named staff at commercial firms.

What to watch. The classified annex holds the logistics [1], so the operative rules are not public and the memo text is not a complete compliance picture. Watch whether nomination authority is narrowed from every tier of government [5] to agencies with a cybercrime remit [6]. Watch the first forfeiture, because the USD$1 million bond [10] is the only stated financial consequence, and it is a contract penalty rather than a liability regime for third parties. And if your firm is in scope, or shares infrastructure with plausible targets, the useful question is which of your people would be individually identifiable in a program filing.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories