threat_intelligence422 wordsRead on Arc Codex

White House looks to engage private sector in offensive hacking ops

President Donald Trump issued a national security memorandum on Aug. 12 that said select companies could work with the federal government on offensive hacking operations to take down pervasive cyber threat groups that threaten the U.S. economy.While companies such as Microsoft and Google have worked closely with the government for several years, the memorandum expands the program and marks a change in policy from the one that existed for many years in which military and intelligences agencies primarily conducted offensive hacking operations.Companies selected for the program will work closely with the Justice and Homeland Security departments and be subject to $1 million fines for violations of the program.Having private sector companies more involved in cyber operations has been discussed for some time, but was largely not pursued because the prevailing consensus was that it could inflame the cyber threat landscape and escalate threats. Some security pros still feel that way.“Endorsing private companies to conduct offensive cyberactivity is far more likely to increase criminal, and potentially nation-state, activity than deter it,” said Tim Mackey, head of software supply chain risk strategy at Black Duck. “Without careful governance and control, individuals with access to sophisticated surveillance technologies could easily abuse that access and engage in surveillance efforts for personal gain. Unfortunately, one message this memo does send to adversaries is that the U.S. government needs private companies and their capabilities to defend against cyberattacks.”On the other hand, Kevin Surace, chief executive officer at TokenCore, said it makes sense to involve the private sector provided the selected companies operate as authorized partners of the government, not as independent cyber privateers.Surace said private companies often possess the talent, specialized tools, global infrastructure, and visibility into malicious activity that government agencies cannot easily replicate. The government already relies extensively on contractors for cyber expertise, so Surace said the strategic question is not whether private expertise should be involved, but who selects the targets, authorizes the operation, sets the limits, and accepts responsibility when something goes wrong.“Those responsibilities must remain with the government,” said Surace. “Military, intelligence, and law enforcement agencies should control attribution, target selection, legal authorization, coordination with allies, and escalation decisions. Approved companies can then contribute intelligence, infrastructure access, technical capabilities, and operational personnel within a clearly defined mission.” Critical Infrastructure Security, Government Regulations, Government security White House looks to engage private sector in offensive hacking ops (Adobe Stock) Related Events Get daily email updates SC Media's daily must-read of the most current and pressing daily news You can skip this ad in 5 seconds

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.