The Trump administration's decision to enlist private companies in cyberattacks against foreign cybercriminals marks a significant policy shift, raising both excitement and concerns. This move empowers vetted companies to engage in hacking operations, traditionally the domain of US law enforcement, spy, and military agencies. While the program aims to address the billions of dollars in annual losses caused by foreign criminal groups, it also introduces a complex web of legal and ethical considerations.
One of the primary concerns is the potential for chaos and coordination issues. With numerous private firms now involved, ensuring a unified and controlled approach becomes challenging. As Andrew Schoka, a former Army officer at US Cyber Command, warns, the risk lies in the absence of clear federal-level direction, leading to a proliferation of cyber privateers operating without a centralized framework. This lack of coordination could result in a fragmented and potentially ineffective response to cyber threats.
On the other hand, advocates argue that this initiative can free up government resources. The overwhelming presence of Chinese government-backed hackers, as noted by former FBI director Christopher Wray, highlights the need for additional support. By engaging the private sector, the US can enhance its capabilities to counter cybercriminals, allowing federal agencies like the FBI and Cyber Command to focus on more strategic challenges, such as nation-state adversaries.
However, the devil is in the details. Cynthia Kaiser, a former senior FBI cyber official, emphasizes the importance of liability protections, government oversight, and addressing concerns related to the use of US infrastructure. The potential consequences of a government-sanctioned hacking operation going awry, as mentioned by Chris Wysopal, a cybersecurity expert, underscore the need for meticulous planning and safeguards. Additionally, the risk of foreign governments targeting company employees traveling abroad adds another layer of complexity.
Furthermore, the memo's lack of a clear process for safeguarding civil liberties raises concerns. Jason Kikta, a former Cyber Command official, points out the absence of a defined oversight mechanism for political appointees' decisions. While defenders argue that DOJ and DHS authorities still play a role, the order's emphasis on shifting liability to companies leaves room for potential legal challenges and ethical dilemmas.
In conclusion, the Trump administration's initiative to involve private companies in cyberattacks against foreign cybercriminals presents a double-edged sword. While it offers the potential for enhanced capabilities and resource optimization, it also introduces legal, ethical, and coordination challenges. Balancing these factors will be crucial in determining the success and sustainability of this novel approach to cybersecurity.