Donald Trump signed a memo on Wednesday that aims to give private companies the power to carry out offensive cyber-attacks against foreign criminal entities.
The president signed a national security presidential memorandum directing his administration to “leverage the capability and innovation of the private sector to help conduct these cyber operations under the direction, control and authority of the US government”, the White House said.
The policy shift gives the private sector a role that has traditionally been reserved for government agencies, essentially deputizing companies in the fight against crime online. Trump’s memo does not give private firms unlimited ability to conduct hacking operations, but instead would authorize “limited cyber operations at the direction of the US government”.
International concern over cyber-attacks has grown after the release of increasingly powerful artificial intelligence models, which have shown that they can hack into outdated security systems. In the US, hackers targeted critical infrastructure systems in several states earlier this year, resulting in disruptions at water facilities.
The White House, in a fact sheet about the memo, cited ransomware attacks, financial frauds and other crimes run by foreign-based criminal organizations, referred to in the memo as “transnational criminal organizations” (TCOs).
The Trump administration has previously vowed to give private firms a larger role in cybersecurity operations. A national cybersecurity policy released in March stated that the government would create incentives to “unleash the private sector” against foreign adversaries. These plans have faced questions from legal experts on what sort of risks companies could face as they enmesh themselves in international digital conflicts.
The memo, released on Wednesday, creates a framework that encourages private sector companies to enter into agreements with other private entities, as well as federal, state, local, tribal and territorial agencies, to gather threat information on transnational criminal organizations and propose cyber operations to address those threats, the White House added.
The memo directs the Department of Homeland Security (DHS), through the homeland security taskforce’s national coordination center, to create a program “to conduct specific cyber operations that disrupt foreign TCOs” that will be overseen by the DHS and the Department of Justice.
Under the supervision of the federal government, participating companies, once vetted, will conduct “cyber surveillance operations” and “cyber effects operations” against specified targets, according to the memo.
“Cyber effects includes the potential manipulation, disruption, denial, degradation or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon,” according to the memo.
Participating companies will have to maintain a bond or escrow of at least $1m, according to the memo.
The idea of private sector firms participating in cyber operations against criminal and other targets is not new but has encountered controversy in the past over fears of escalation, inadvertent consequences and inter-agency coordination issues.
The DHS and the White House did not immediately respond to requests for additional details about the program.