By Michael Daniel, President and CEO, Cyber Threat Alliance
The Administration recently released a Presidential Memorandum entitled Expanding Capabilities to Combat Transnational Cyber-Enabled Crime – The White House and it is intended to boost the US government’s offensive cyber operations capability. The Memorandum directs the heads of the National Coordination Center to enter into contracts with private sector companies to conduct cyber surveillance operations and cyber effects operations. The memo states that companies will act as agents of the US government operating under the direction and control of the NCC and subject to substantial coordination requirements. This policy is a relatively novel one, taking a non-traditional approach to offensive operation capacity. A logical question is what factors caused the Administration to adopt such a policy.
Many factors constrain our cyber operations, but one of those constraints is capacity – having enough skilled personnel in place to conduct the operations. One approach to address that shortfall would be to increase the number of law enforcement or military personnel assigned to the task. Given the reductions to cyber personnel and the government’s challenges in hiring skilled personnel, simply increasing government staff for this mission would be challenging. But if increasing government personnel is infeasible, the Justice and Defense Departments could hire contractors to augment the FBI, NSA, and Cyber Command without any additional policy required; they have decades of experience using this approach. Another approach would be to enlist the private sector through concepts like “hackback” and issuing letters of marque. Yet, this policy doesn’t go in that direction either. It states that participating companies would be acting under the strict direction and control of the Federal government through a contract, which is hardly crying havoc and letting slip the cyber dogs of war to paraphrase Shakespeare.
So why has the Administration taken this approach? The accompanying press release doesn’t actually explain the Administration’s reasoning, so I will make some guesses, none of which are mutually exclusive.
One reason could be that the potential participating companies don’t want to just provide bodies to work in government facilities. They might only want to carry out these activities from their own offices using their own equipment and tools. While I do not believe that private sector companies necessarily have *better* offensive cyber tools than the government, potential participants may be more familiar with their own tools and able to use them more effectively outside of government facilities.
Another reason could be that the potential participating companies would be able to retain access to information from partners that they would not be able to access if they were integrated into government agencies. By keeping the relationship with the government at a contractual arms-length, the participating companies could retain information not otherwise available. This additional information might help make the operations more effective.
A third reason might be signaling. By issuing a high-profile policy, the US government sends a signal to the cybersecurity community, criminal groups, and foreign governments that we are increasing our offensive capacity and are more serious about imposing costs. It carries more “oomph” than an announcement that the FBI is hiring more contractors and elevates the priority of the activities.
Finally, the decisionmakers overseeing cyber activities could believe that getting Congress to authorize hackback or to issue letters of marque would create more problems than it solves. Enough electrons have been spilled on this topic, and I won’t repeat the well-worn (threadbare?) arguments here, but the operators in the US government probably want more control over operational activities than hackback or letters of marque approach would provide and they don’t want any of the numerous downsides.
If these conjectures are true, this new policy could be seen as a novel attempt to increase offensive capacity within the overall constraints. However, just because the policy might be reasonable doesn’t mean it will be successful. The list of unanswered questions is quite long, based on my own thinking and the commentary in my various chat groups. These questions range from how much risk companies would take on by participating in this program to whether enough companies would sign up to make a difference to whether the National Coordination Center has the capacity to manage this program. This list will continue to grow as more people review the new policy. If the Administration wants to make this policy successful, it will have to develop clear answers to these and many other questions. I’ll be very interested to hear more.
