When Companies Become Cyber Combatants
Key Points
- The Trump administration authorized a program that could allow vetted private companies to conduct government-approved cyber operations against foreign cybercrime groups.
- The framework could expand U.S. offensive cyber capacity, but participating organizations would assume legal, operational, reputational, and geopolitical risks, including potential retaliation from threat actors and nation-states.
- IANS Faculty say organizations should evaluate the long-term liability, governance, and workforce implications before participating and establish dedicated operational, legal, and executive oversight structures if they choose to engage.
When Companies Become Cyber Combatants
Private American companies could engage in offensive cyberattacks as part of a new program approved by the Trump administration.
Such companies would cooperate with the Homeland Security and Justice Departments to conduct cyber operations against foreign cybercrime groups. President Trump signed a national security memorandum last week authorizing the program.
Participating companies must be vetted by the government, agree to a contract that can impose fines of $1 million for violations, and must seek approval from the Justice and Homeland Security Departments before conducting an operation.
The initiative will provide the U.S. “new tools to protect Americans from cybercrime and fraud,” according to Amanda Naylor, Director for Cyber Technology Policy at the National Security Council. Acceptable attacks according to the memorandum would include surveillance, disruption, and destruction of systems and infrastructure, both physical and virtual, against criminal networks.
The memorandum says the government will not approve private sector attacks that could lead to injury, death or “rise to the level of use of force or armed attack under international law.”
Big Picture
The U.S. government currently lacks an adequately staffed public cyber workforce compared to throngs of private sector employees, making private partners a force multiplier for these operations, the Trump administration believes.
But private-sector participation would require organizations to prepare personnel for offensive cyber operations that many employees did not anticipate as part of their job responsibilities.
"Because the government’s cyber workforce is relatively small compared with the private sector, this framework could, at least on its face, significantly expand the United States’ capacity to identify, disrupt, and respond to cyber threats. The risk is that the company may be seen as a high-value target because of the sensitive information and government relationships it may have access to.” Lee Kim, IANS Faculty.
At the same time, most private-sector organizations able to operate with the scale and capability the order is seeking likely also must answer to shareholders.
"The memorandum tells us a great deal about what participating companies must do. It tells us considerably less about why a board should conclude that accepting those risks is in the best interest of its shareholders, employees, and customers.” Lisa Perdelwitz, IANS Faculty.
Government support for the program could shift as administrations change or if participation creates ongoing liabilities for the U.S. Protections offered today could be modified or rescinded in the future.
"Unless the program is wildly successful, it's foreseeable that future administrations might rescind the EO underpinning the authority. Doubly so if it is abused, which it inevitably will be. When legal authorities evaporate, you can bet liability will be an issue.” Jake Williams, IANS Faculty.
Still, the order could create new market opportunities for private firms willing to accept the financial, legal, and ethical burdens of supporting government-directed cyber operations.
"It is conceivable that talented people can now form a startup, get a government contract, and benefit economically from their activities in ways that were previously limited to the large Beltway Bandit firms.” Aaron Turner, IANS Faculty.
IANS Faculty Recommendations
- Reinforce that offensive cyber remains off-limits: Make clear to security teams that this framework does not authorize independent "hack back" activity and that any participation would require formal government approval and oversight.
- Evaluate participation as a business risk decision: Involve legal, finance, risk, and executive leadership early to assess liability, insurance implications, reputational exposure, workforce requirements, and potential retaliation risks.
- Establish a dedicated operational structure: If participating, use a compartmentalized team, separate infrastructure, enhanced monitoring, and clearly defined rules of engagement rather than integrating offensive activities into existing security operations.
- Plan for policy and liability shifts: Assume future administrations could modify or rescind the framework and evaluate how disclosure obligations, legal exposure, and accountability would be handled if government support changes.
Authors & Contributors
Tim McCarthy, Author - Security Reporter, IANS News
Although reasonable efforts will be made to ensure the completeness and accuracy of the information contained in our News & blog posts, no liability can be accepted by IANS or our Faculty members for the results of any actions taken by individuals or firms in connection with such information, opinions, or advice.