President Trump aims to involve private companies in combating foreign cybercriminals. A government memo proposes that certain U.S. businesses be authorized to target cyber threats identified by government agencies. Traditionally, such tasks were exclusive to federal operations.
Shift to Private Sector Involvement
U.S. anti-hacking laws generally prevent unauthorized hacks, except under government allowance. The new policy doesn’t modify these laws but requires private companies to secure contracts with the federal government. This represents a significant shift from current private sector roles, where businesses act as support rather than direct cyber operatives.
The memo highlights potential targets for private operations, such as organized crime and money laundering networks. However, it stops short of granting full autonomy to companies, attracting both interest and skepticism from cybersecurity experts.
Potential for New Collaborations
Joshua Steinman, a former National Security Council senior director, suggested this policy could encourage smaller firms and startups to seek government contracts. Arthur Tellis, an ex-Department of Defense staffer, noted that companies might excel in intelligence gathering rather than offensive cyber actions.
Participating firms must undergo stringent vetting processes and could be required to post financial bonds. Upon approval, they might undertake network disruptions as outlined by government standards.
Concerns from Cybersecurity Experts
Critics like Paul Rosenzweig argue the plan introduces risks and unresolved legal challenges for private companies hacking abroad. The lack of clarity around the vetting process and potential legal conflicts remains a concern.
Critics also worry about unintended consequences. Chris Wysopal, a cybersecurity firm co-founder, warned about the risk of collateral damage during attacks. He stressed the importance of avoiding incidents that could disrupt essential services, like transport or healthcare systems.
Addressing Cyber Threats
Cyberattacks cost Americans billions annually. Threat actors often target personal data or critical infrastructure, demanding ransoms to prevent data leaks. Ransomware attacks and online scams remain prevalent, posing both financial and national security threats.
Minnesota recently faced a cyberattack on its water systems, reportedly linked to Iran. Steinman believes private sector agility could enhance U.S. cyber capabilities, but says such initiatives must proceed cautiously.
Wysopal and others argue that bolstering defensive measures is more effective than offensive actions. They caution against viewing offensive capabilities as a standalone solution to cybercrime.

Maryland Court Rules Against Digital Advertising Tax
Cyberattack Shakes Suisun City: Community Faces Lingering Questions
Senate Investigation into Child Safety on Roblox
Apple’s $250 Million Settlement Over Delayed AI Features: What iPhone Users Should Know
Apple Watch Series 11 Now Available at Record Low Price
Bernie Sanders Advocates for Medicare for All with New Study Support