Fast Company
Follow
The White House wants private companies to hack cybercriminals. What could go wrong?
The White House recently changed federal hacking policy, allowing vetted private companies to conduct cyberattacks against hacker groups without prior court approval. This new presidential memorandum reverses previous policy prohibiting such actions. The government aims to leverage private sector innovation to combat cybercrime. However, critical details regarding legal protections for these companies remain unclear. Experts express concern about companies facing charges in foreign jurisdictions, as U.S. authorization does not override other countries' laws. There is no explicit legal entitlement to government assistance, and participating firms must consider personnel exposure and arrest risks as operational dangers. Congress is considering a cyber letters of marque bill that could grant more explicit legal protections. The memo is also vague on whether company employees or embedded government officials will conduct the operations. Private firms offer advantages in visibility and speed, as they often detect attacks before government agencies and possess unique access to disrupt them. However, the approval process for operations involves multiple layers, potentially negating speed advantages. Private companies might also inadvertently compromise larger intelligence operations by acting on tactical successes without a broader intelligence view. A significant fear is the potential escalation of global cyberwarfare due to sanctioned hacking, despite de-escalation guidelines. Other countries may follow this precedent, potentially with fewer restrictions. The memo also raises concerns about commercial interests influencing target nominations and a lack of clarity on oversight for attribution errors. Ultimately, experts worry this policy change sets a dangerous precedent, potentially opening a Pandora's Box of unforeseen consequences.