President Trump recently signed a national security presidential memorandum that enables federal law enforcement agencies to collaborate with private technology firms in executing offensive cyber operations against foreign criminal organizations and international adversaries. This directive empowers vetted private-sector technology companies to operate under direct federal supervision, allowing them to propose, coordinate, and carry out targeted cyber actions.
This decision signifies a marked change in the United States’ cyber policy, as it formally invites private industry into areas that had traditionally been the domain of government entities alone. The memorandum’s implications could significantly reshape how the United States approaches cybersecurity threats, particularly those that emanate from organized crime and hostile nation-state actors.
### A Coalition for Action
Kyle Hanslovan, the CEO and co-founder of Huntress, expressed support for this new policy. He emphasized that the increasing sophistication of organized cybercrime and adversarial nation-states necessitates a robust partnership between public and private sectors. Hanslovan stated, “When you add the reality of AI-powered autonomous threats, the only viable solution is a stronger coalition of the willing, which we are eager to support.” This collaboration could potentially enhance the United States’ ability to counter increasingly complex cyber threats.
Hanslovan pointed to two major aspects that he believes are critical for the success of this initiative. Firstly, he underscored the importance of utilizing hyperscalers—large-scale cloud service providers—for their vast intelligence data and security research labs like Huntress for their operational agility. These resources could significantly disrupt adversarial efforts. Secondly, he noted the necessity of a deconfliction process, which would prevent private-sector operations from undermining long-term investigations that often yield public arrests and geopolitical negotiations. Consequently, he shared an optimistic outlook that this initiative represents a progressive step by the U.S. government in its efforts to combat cyber threats to democracy and economic integrity.
### Caution Amidst Optimism
However, not all experts are entirely on board with this initiative. Ben Bernstein, cybersecurity advisor at Huntress, has openly expressed reservations regarding the operational implications of private companies conducting offensive operations. He highlighted significant hurdles that could arise, particularly concerning collateral damage and bureaucratic delays. “Threat actors don’t launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network,” he pointed out. This complexity makes it nearly impossible to launch effective counter-attacks without risking harm to innocent parties.
Bernstein further elaborated that the transient nature of adversary infrastructure complicates the matter. Cybercriminal networks can quickly relocate or alternate targets, meaning that by the time a vetted company gets approval for countermeasures, the threat may have already dissipated. “Expecting government bureaucracy to move at the speed of modern ransomware operators is wildly optimistic,” he remarked.
### Potential Fallout for Cybersecurity
Tim Mackey, the head of software supply chain risk strategy at Black Duck, took a more cautionary stance regarding the new memorandum. He suggested that while the intent may be to bolster cybersecurity, endorsing private companies to engage in offensive operations could paradoxically escalate criminal activity. “Ignoring the reality that it’s difficult to identify the source of cybercriminal activity is dangerous,” he warned. Without stringent governance, individuals with access to sophisticated surveillance technologies might misuse their powers for personal gain, potentially leading to an increase in cybersecurity risks.
Mackey also pointed out that this memorandum sends a problematic message to adversaries: it underscores the U.S. government’s reliance on private companies to combat cyberattacks, which could embolden foreign adversaries to intensify their activities.
As this new policy rolls out, it will likely spark widespread discussion within the cybersecurity community. Experts will need to address tough questions surrounding the governance, vetting, and deconfliction of offensive cyber operations conducted by private firms, particularly in terms of ongoing law enforcement and intelligence initiatives.
In conclusion, while the memorandum signed by President Trump aims to enhance the United States’ capacity to deal with cyber threats, it presents unique challenges and requires careful consideration of its broader implications for global cybersecurity and national security strategies. The dialogue surrounding these developments will undoubtedly continue as stakeholders assess both the opportunities and risks inherent in this new collaborative framework.