Skip to content

Product1 publisher3 min readPublished

White House lets vetted firms hack back and leaves liability blank for 60 days

A presidential memorandum drops the court-approval requirement for private offensive cyber operations. The procedures that would define legal exposure are not due for two months.

The Product Desk · Product desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • The White House last week issued a presidential memorandum that allows vetted private companies to initiate cyberattacks against hacker groups.
  • The memorandum reversed previous government policy, which prohibited companies from initiating such cyberattacks without a court's approval.
  • On the point of liability the memo says nothing, and it does not offer much, if any, legal shield, though experts argue it should.
  • Procedures that should resolve unresolved questions in the memo are due in 60 days.
  • The memorandum reads: "American businesses' innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace. Thus, it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime."

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

The White House issued a presidential memorandum last week allowing vetted private companies to initiate cyberattacks against hacker groups, reversing prior policy that prohibited companies from doing so without a court's approval [1][2]. On liability, according to Fast Company's reading of the document, the memo says nothing, and the procedures meant to resolve the open questions are due in 60 days [3][4].

The stated rationale is capacity. "American businesses' innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace," the memorandum reads, adding that it is US policy "to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime" [5]. Over the next two months the government will fill in requirements companies must meet [6], which is the same window as the 60-day procedures deadline [19].

That window is the problem for anyone deciding whether to volunteer. The memo offers little if any legal shield, and questions such as what happens if an employee is arrested by a foreign government in connection with an authorized attack are unlikely to be addressed [3][7]. "Sending someone into this environment with ambiguous government backing and figuring out their status after they are arrested would be irresponsible," said Eric O'Neill, a cybersecurity expert and former FBI operative, who added that "U.S. authorization does not magically erase another country's laws" [8]. Jud Dressler, who heads the Risk Operations Center at cyber risk firm Resilience, told Fast Company the memo grants private firms no special rights and that "there is no explicit legal entitlement to government assistance," with arrest risk, extradition requests and becoming a target to be treated as real operational risk [9][10].

There is also confusion about who holds the keyboard. "One section has federal personnel conducting the operations, another has the companies doing it, and the procedures that should resolve it are due in 60 days," said Rob T. Lee, chief AI officer at the SANS Institute. "Until then, nobody can price the personal risk" [11].

Durable protection would have to come from Congress. The memo arrived days after a cyber letters of marque bill was proposed in both chambers, introduced by Republicans Mike Lee in the Senate and Tim Burchett in the House, which would let the president commission private hackers [12]. Until something passes, civil and criminal protections for participating companies are theoretical [13].

The case for private operators is visibility: it is private-sector infrastructure that international attackers hit and use, and firms including Google, Microsoft and Cloudflare see attacks before federal agencies do [14]. In February, Google disrupted a global cyber espionage campaign known as Gridtide by revoking API access [15]. "No government on earth can revoke a Google Sheets API key," Lee said [16]. Dressler notes the government cannot monitor private networks without specific legal authority [17].

Speed is the weaker part of the pitch. The memo requires two Executive Directors, one at Justice and one at Homeland Security, to give written approval on every operations package before a company acts, inside an interagency deconfliction loop [18], which means at least two sign-offs per package [20]. "That is not faster than an interagency process," Lee said. "It is one, with a contractor attached" [18].

What to watch over the next 60 days: whether the procedures assign operations to federal personnel or company employees, whether they include any indemnification or consular commitment for staff detained abroad, and whether the letters of marque bill advances far enough to convert theoretical protection into statute [11][13].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories