The US government wants companies to start cracking down on hackers

The US government wants companies to start cracking down on hackers

The US government has a new approach to cybersecurity.

Ryan Hines / Android Authority

TL; DR

  • The US is developing a program that would allow vetted private companies to conduct offensive cyber operations against foreign criminal groups.
  • Transactions require federal approval and oversight, and participating firms may put up at least $1 million in escrow.
  • The policy marks a major shift from the US position that private companies can protect against hackers but not attack them.

If you think cybersecurity companies should avoid hackers instead of looking for a fight, the US government would beg to differ. The president’s new memorandum allows US companies to conduct offensive cyber operations against foreign criminal groups if the government calls the shots.

as reported TechCrunchof the Trump administration memorandum private companies create a federal program that can conduct both surveillance and disruptive cyber operations against foreign cyber-enabled criminal organizations. The goal is to combat threats such as ransomware, fraud, and other cybercrimes targeting Americans.

Companies aren’t given a digital license to just mess around. Each operation requires written authorization from program directors at the Department of Justice and the Department of Homeland Security, and the firms operate under federal oversight. Participating companies may be required to put up at least $1 million in a bond or escrow account, which could be forfeited if they violate the rules.

The powers are still quite significant. The memorandum authorizes operations to manipulate, disrupt, degrade or destroy computer systems and data, and surveillance operations may include surreptitious access to systems without the owner’s permission to gather intelligence.

There are fences. The program targets foreign criminal groups, not governments, and companies must cease and report any operation that accidentally targets a US person or US system. The exact rule book is yet to be finalized, with officials given 60 days to establish operating procedures.

The move represents a major departure from the US government’s traditional position that private companies can protect against hackers, but not attack themselves. Cybersecurity veteran Jake Williams said TechCrunch The plan was “half-baked,” warning that Americans could face legal challenges or charges from foreign governments when traveling abroad.

Thank you for being a part of our community. Please read our Feedback Policy before posting.

Leave a Reply

Your email address will not be published. Required fields are marked *