The program aims to tap private-sector cyber talent and resources, while raising new questions about oversight and the risks facing participating companies.

President Donald Trump signed a presidential memorandum on Aug. 12 that looks to enlist private-sector companies to help launch cyberattacks abroad against transnational criminal organizations (TCOs).

The memo directs the Homeland Security Task Force’s National Coordination Center (NCC) to create a program to conduct specific cyber operations that disrupt foreign TCOs. The private sector would “help conduct these cyber operations under the direction, control, and authority of the U.S. Government,” according to a White House fact sheet.

“The American private sector is the most innovative and technologically advanced in the world – which provides a critical offensive cyber advantage for the United States,” the White House said in the fact sheet.

“By partnering with vetted U.S. companies, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” it adds.

Participating companies would need to sign contracts with the Department of Justice or the Department of Homeland Security and “undergo rigorous vetting.”

Participating companies would also be able to enter into agreements with other companies to receive threat information. They could also sign agreements with federal, state, local, tribal, and territorial agencies to identify threats “in a manner that enables them to propose cyber operations to the NCC that address those threats,” the memo says.

The departments of Justice and Homeland Security have 60 days to issue procedures covering company vetting, oversight, and annual evaluations. The memo says both large and small companies may participate if they meet the program’s standards.

The departments also have 180 days to produce a report detailing the status of the program and submit it to Stephen Miller, the assistant to the president and deputy chief of staff for policy and homeland security advisor, and Sean Cairncross, the national cyber director.

“As the memo itself suggests, bringing in the private sector for offensive operations isn’t a brand-new concept – and frankly, our nation’s adversaries have relied on third-parties for years to execute cyberattacks with built-in plausible deniability,” Gary Barlet, public sector chief technology officer at cybersecurity company Illumio, told MeriTalk.

“The reality is that the private sector has access to more talent and resources and not necessarily the same constraints,” he added.

However, Barlet said that turning to the private sector for cyber help “introduces a whole new set of questions.”

For instance, Barlet said, “Does empowering private companies turn them into legitimate targets or combatants in the eyes of foreign states?”

“Some would argue they are already in the crosshairs, so giving them a path to fight back makes sense,” he said. “The potential benefits outweigh the risks, but we need to go into this eyes wide open – there will be friction, grey areas, and unintended consequences we can’t fully predict yet.”

Read More About