Trump enlists private sector for offensive cyber operations | #cybercrime | #infosec


In a newly published memorandum, US president Donald Trump has given federal law enforcement and national security agencies the go ahead to work with private sector cyber security companies on offensive cyber operations. 

The memorandum comes in the wake of an Executive Order (EO) signed earlier this year, Combating Cyber Crime, Fraud, and Predatory Schemes Against American Citizens, that directed the US government to take a series of actions to combat digital crime, and will supposedly expand the fight against transnational criminal organisations (TCOs) by drawing on the expertise of the private sector.

The memo describes the US private sector as the “most innovative and technologically advanced in the world” that could help secure a “critical offensive cyber advantage”, but decried that its capabilities have been underutilised in efforts to disrupt cyber crime.

“It is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cyber crime,” the memorandum reads. “By partnering with vetted United States companies subject to the direction and oversight of the federal government, we will enhance our ability to counter TCO threats and combat transnational cyber crime, fraud, and other predatory schemes against American citizens.”

The memorandum directs the National Coordination Center (NCC) – set up in 2025 – to establish a new programme that will allow rigorously vetted participating companies to conduct what Washington describes as cyber surveillance and cyber effects operations against TCOs under the control and oversight of the government.  

This process will be overseen by co-executive directors appointed through the Department of Justice (DoJ) and the Department of Homeland Security (DHS), who will ultimately sign off on any real-world actions.

Companies participating in the programme will be held to a set of minimum standards in areas such as technical proficiency, proven performance of cyber operations, facility security and personnel vetting, among other things. The programme aims to recruit a spread of large cyber firms with critical capacity and smaller, more agile businesses that may be better suited to specialised or discrete operations. 

Skepticism 

Ben Bernstein, a cyber security adviser at Huntress – which was founded by ex-federal cyber operatives – said that while public-private collaboration was welcome given governments seem unable to fight cyber crime on their own, he had concerns about how the programme would play out in the real world. 

“When you look at the operational reality of green-lighting private offensive ops, you hit two massive roadblocks: collateral damage and bureaucratic lag,” he said. “Threat actors don’t launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network.  

“That makes it practically impossible to ‘strike back’ without taking out innocent bystanders. Plus, adversary infrastructure is incredibly ephemeral, often burning down in a matter of hours. By the time a vetted firm submits a target, sits through the DoJ and DHS deconfliction reviews, and finally gets a green light, they’ll be shooting at ghosts. Expecting government bureaucracy to move at the speed of modern ransomware operators is wildly optimistic.” 

Jake Williams, a faculty member at IANS Research and a former NSA hacker, described the strategy as “half-baked”, adding: “Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas [and] the allegations that an American participated in these ops need not be true. The programme even existing creates top cover for such an accusation.

“Separately, the programme seems as though it was written to be abused. It’s not clear how targeting would be established. If intelligence was 100% on a target being a TCO, then why not use existing legal authorities and existing government operators?” he added.



Click Here For The Original Source.

——————————————————–

..........

.

.