Offensive ops crosses new threshold for private companies
Duncan Greatwood, chief executive officer at Xage Security, said following the case last month of suspected Chinese hackers deploying an AI system to carry out sophisticated cyberattacks on Taiwan, it’s clear that we have crossed a threshold that cannot be uncrossed.“Leveraging the American private sector for offensive operations can absolutely make us more formidable, but it does not lessen the need for domestic defensive readiness,” said Greatwood.Greatwood said defensively, it’s imperative that public and private sector organizations adopt an approach that protects vulnerable assets and limits the “blast radius” when a breach does occur. On the offensive side, Greatwood said while the U.S. and its allies will want to avoid runaway geopolitical escalation, if the U.S. never responds to cyberattacks it risks the opposite problem of enabling attackers, and their supporters, to operate with impunity.Chris Jacob, Field CISO at Securonix, said while he wants to see cybercriminal organizations disrupted, he also wants the security professionals supporting that work protected from unrealistic expectations and unnecessary exposure.“Asking private-sector teams to move closer to offensive cyber operations adjusts the risk they carry personally and professionally, and companies considering that role should go into it with all bases covered,” said Jacob.Anurag Gurtu, co-founder and CEO at Airrived, said while it makes strategic sense to have private companies involved in hacking operations, the government must define the targets and rules of engagement.“Private industry can pull the trigger,” said Gurtu. “Government must decide where to aim.”Gurtu said liability must be crystal clear: If a private company attacks the wrong target under government authorization, who owns the mistake?“We’re rapidly moving toward autonomous cyber agents fighting autonomous cyber agents at machine speed,” said Gurtu. “The future of cyber isn’t just defense. It’s governed offense. Get the governance right, and we dramatically increase the cost of cybercrime. Get it wrong, and we dramatically increase the cost of a mistake.”Omer Ninburg, co-founder and CTO at Novee, said involving the private sector can make sense because companies often have specialized expertise, infrastructure, and visibility that government agencies do not. But Ninburg said collaboration on takedowns or asset seizures is very different from allowing a private actor to conduct an offensive operation.Ninburg pointed out that a government sign-off grants permission, it does not necessarily grant control: that distinction becomes critical if autonomous systems are eventually used.“Attribution is rarely certain because adversaries route attacks through infrastructure belonging to legitimate organizations and plant false flags,” said Ninburg. “At machine speed, an operation could act on an outdated or incorrect assumption before a human has time to intervene. A precise strike against the wrong target is still the wrong strike, only faster and potentially repeated in parallel.”
Click Here For The Original Source.
