
The United States has had enough in cyberspace. The White House has now created a program under which American companies can conduct offensive cyber operations against ransomware gangs and other ‘cyber-enabled transnational criminal organizations.’
Australia should look closely at the experiment.
No one can know whether this idea will work. After all, adversaries’ cyber operations have only become more frequent and the consequences more severe in the eight years since the White House unleashed US Cyber Command. Its persistent offensive engagement was supposed to lead to diminished attacks and cyber stability, but here we are again.
Despite that, widening the task is worth trying. Allowing a small number of vetted companies to disrupt adversaries, under government control, is a worthwhile experiment. These operations are not meant to be ‘hacking back’ but longer term surveillance and disruption to frustrate their operations.
I would have hated this idea 10 or 15 years ago, when I argued the US should forgo its pre-eminent offence to prioritise defence above all else. I thought it would all rebound against us, leading to more attacks than we could stomach. But, rather than prioritise defence, the government instead decided to ‘balance’ it with offence. And now here we are.
Policymakers have to make decisions for the world of today and tomorrow, not the one that might have been prevented.
Critics have a range of reasonable objections to the White House plan. Some suggest these operations might be escalatory, fuelling an arms race. Those arguments can be dismissed. The more worrying concerns are about implementation.
The risk of escalation or an arms race should be the least concern with outsourcing non-state offensive operations. Critics should not blame the victims for fighting back.
These criminal groups operate with near impunity, often given sanctuary by Russia, Iran and China, and are unafraid of prosecution, even as they target the most vulnerable among us, attacking schools and hospitals during a pandemic. It cannot be a policy priority to worry whether Russian cronies get upset because their criminal enterprises got disrupted.
Implementation presents a larger set of issues. The devil is truly in the details, as my colleague Erica Lonergan has highlighted.
The White House is wisely not just outsourcing to privateers but creating an entire institutional framework. The co-executive directors (policymakers from the departments of Justice and Homeland Security) will vet and contract with companies and approve and retain operational control of their activities. Companies will have to report their activities to the government and can be ejected from the program if they fail to live up to standards.
Handling such a novel and challenging program would be hard for any government, much less one so thoroughly DOGEd and short of quality staff. As Ron Deibert earlier argued, ‘the new policy would take place in the context of an administration that has systematically weakened oversight and compliance offices across the government.’ Three vitally important parts of government highlight the challenge: the Department of Justice is removing staff seen as enemies of the president; the Department of Homeland Security (DHS) is obsessed with border security; while DHS’s Cybersecurity and Infrastructure Security Agency has been drained of talent.
The US Congress must commit to reporting and oversight to ensure these authorised cyber companies – many of which will be staffed with veterans of the same organisations meant to oversee them – cannot capture their ostensible regulators.
Given these American limitations, other nations in the Five Eyes pact, such as Britain or Australia, may actually be better positioned to conduct these experiments in authorised private offensive cyber operations than the US is.
In addition, the White House must set out criteria to measure both success and failure. Without clear metrics, supporters of this policy can continually assert they have nearly won and just need to be a bit more aggressive, needing a bit longer leash. That playbook worked in neither Vietnam nor Afghanistan. Nor, so far, has it worked for the Pentagon’s plan for persistent offensive engagement by US Cyber Command.
So, sure, let’s allow the private sector to get into the counter-offensive game as well, but only with very specific criteria to know when it is working and when it is making things worse. The White House (and Congress) must be ready to cancel the program if it gets out of control or is not clearly succeeding.
Lastly, as Jake Williams and others have pointed out, anyone conducting these operations is doing so at substantial personal legal risk. The United States may not prosecute them, but that wouldn’t stop Russia or China issuing an Interpol Red Notice or an EU prosecutor issuing arrest warrants when some mission impinges on EU sovereignty. Still, as long as everyone has their eyes wide open to the risk, this is more of a personal, not policy, issue.
Relying on the offence is not a long-term plan.
Defenders cannot counterattack their way to a more secure cyberspace: there are too many adversaries pursuing too many easy pickings. But offence might meaningfully reduce depredations in the short term. Policymakers and defenders must use any respite to shift advantages from attackers to defenders, at scale.
In the meantime, a controlled, well-overseen plan to disrupt cybercriminals’ attacks is an experiment worth trying.
Leave a comment