The Clear, the Muddy, and the Insoluble of the Administration’s Cyber Operations National Security Presidential Memorandum

The administration’s Cyber Operations National Security Presidential Memorandum (NSPM) sets out to enlist private contractors to execute offensive cyber operations against foreign criminal networks. But C-suite executives at companies with the ability to act at scale aren’t likely to take up operations that carry ill-defined legal and operational risks, writes Leonard Bailey.
The Clear, The Muddy, and the Insoluble of the Administration's Cyber Operations National Security Presidential Memorandum

Introduction

The question, “Why hasn’t the private sector seized on periodic campaigns to give U.S. companies more authority to conduct offensive cyber operations against malicious cyber actors?” is a vexing one. But there is a simple answer: C-suite executives of major companies—from CEOs and CFOs to general counsel—will not volunteer for ill-defined legal and operational risks. And over the last decade, the government has done little to resolve the uncertainty that surrounds private entities conducting offensive (and even some defensive) cyber operations, even while proposing legislation authorizing such operations.

I have criticized the Trump Administration’s National Cyber Strategy (NCS) for failing to address that uncertainty. The NCS said little about private-sector cyber operations beyond promising to “unleash the private sector by creating incentives to identify and disrupt adversary networks and scale our national capabilities.” But on August 12, the Administration released the National Security Presidential Memorandum on Expanding Capabilities to Combat Transnational Cyber-Enabled Crime (NSPM), which goes into considerably more detail than the NCS in clarifying those incentives.

The NSPM outlines a framework for augmenting the government’s cyber-operations capacity by enlisting qualified companies to conduct “Cyber Effects Operations” and “Cyber Surveillance Operations” under contract with the Departments of Justice and Homeland Security. It directs the National Coordination Center to leverage the capabilities of the private sector for conducting cyber operations against foreign cyber-enabled transnational criminal organizations. It also encourages contractors to share cyber threat information to enable operations. Per the NSPM, these contractors would act under the direction, control, and authority of the U.S. government.

Collaboration between U.S. companies and the government to combat cyber threats is not new. The U.S. government and the private sector have had commercial arrangements involving cyber operations for many years. Some of those arrangements reportedly contracted the development of cyber analytic and forensic tools for use by federal law enforcement. Other agreements, according to reporting, involved commercial cooperation with law enforcement agencies to produce spyware or exploits. U.S. military branches and the intelligence community also rely on contractors for tool and exploit development. But the NSPM encourages a different type of public-private relationship. In a break from past policy and practice, it seeks to turn private contractors into operators, the proverbial “trigger pullers” who actually execute cyber operations rather than merely furnish tools or services in support of the government.  

This article asks whether the NSPM is likely to succeed in its mission to expand the U.S. government’s cyber capacity by recruiting integral private sector partners. It focuses on whether the NSPM resolves any of the uncertainty that has constrained public-private operational collaboration. Spoiler alert: it does not. The NSPM does something more interesting but equally unproductive: it redistributes the uncertainty, instead of removing it. It is therefore unlikely to convince the most needed companies to turn their cyber operations into effective strategic tools that the government can enlist. 

Related Content

MENU

GET IN TOUCH

Email: [email protected]
Send us a message: Contact

JOIN THE CATALINK MAILING LIST