THEMETASEC

Cybersecurity News, Aggregated

You don’t have to join the hack-back program to inherit its risk

CSO Online · 1 hour ago Breach

The obvious question about Washington’s new private offensive cyber program is which security vendors will join it. The CSO question is what happens to you when one of your vendors does. The August 12 National Security Presidential Memorandum, “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” directs the National Coordination Center to build a program for vetted “Participating Companies.” The Justice Department and the Department of Homeland Security run it jointly, and two co-executive directors must approve every operation in writing. Once the directors sign, a participating company can run covert access intended to stay undetected (Cyber Surveillance Operations) or manipulation, disruption, degradation, or destruction of systems (Cyber Effects Operations). The memorandum directs the operating procedures to authorize the Department of Justice (DOJ) and the Department of Homeland Security (DHS) to require a forfeitable bond of at least $1 million as a contract condition. Those procedures, which govern day-to-day execution, remain unpublished. They are due in mid-October, 60 days after signing. The White House fact sheet frames the program as consumer protection, citing more than $20.8 billion in American losses to cyber-enabled crime in 2025. The frame that matters to a CSO is different. The memorandum moves sovereign activity onto commercial infrastructure while leaving substantial residual liability in private hands. It behaves like a risk-transfer contract, except that most of the parties bearing the risk never signed it. The shield is thinner than the authorization The program’s criminal protection rests on one untested reading of one statutory clause. The Computer Fraud and Abuse Act (CFFA) exempts “lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency” at 18 U.S.C. 1030(f), and the memorandum styles every operation as federal law enforcement activity to fit inside that exemption. Congress wrote that exemption for law enforcement agencies. No court has ruled on whether it stretches to a private company operating under contract. A statute can create that protection outright. The Active Cyber Defense Certainty Act would have given companies an affirmative defense against CFAA charges for hacking back, but Congress never passed it. A presidential memorandum cannot amend a statute. In Little v. Barreme, the Supreme Court held that a presidential order did not protect an officer from damages when the seizure exceeded congressional authority. What the memorandum withholds runs longer than what it grants. Crowell & Moring’s client alert counts the gaps: no civil safe harbor, so CFAA civil suits by collateral victims remain live; no preemption of state anti-hacking law; no protection under foreign law; no indemnification. Section 5(c) then closes the other direction, creating no right or benefit enforceable against the United States. A participating firm holds an unadjudicated criminal theory, while civil, state, foreign, and contractual exposure sits outside the shield. The same government-control language that supports the domestic CFAA theory also strengthens the case for attributing the operations to the United States internationally. Under Article 8 of the International Law Commission’s state-responsibility articles, private conduct is attributed to a state when that conduct follows the state’s instructions or runs under its direction and control. Both propositions hold at once, and that is the problem for a company more than for a government. The stronger the control record supporting the vendor’s CFAA defense, the more readily a foreign ministry can treat that vendor’s work as an official act of the United States. Non-participation is not an exemption Most security organizations will file this under someone else’s problem. The exposure reaches them four ways. Substrate. Criminal groups rent and compromise the same clouds, content delivery networks, and SaaS platforms your workloads sit on. An approved effects operation against that infrastructure can surface in your environment as an unexplained outage. The memorandum anticipates the event: its implementing guidance orders a participating company to cease, minimize, and notify when an operation unintentionally reaches a system in the United States or under American control. Governments do not write cleanup procedures for events they consider remote. Section 5(c) then gives the affected company no remedy under the memorandum itself, which routes any claim into ordinary law and ordinary cost. Silence. Participating companies must disclose their commercial agreements to the NCC, not to their customers. The memorandum creates no customer-disclosure obligation, so the burden falls on the buyer to extract a written representation and on the vendor to decide whether to give one. The Cloud Security Alliance draws the conclusion plainly: absent a standard attestation, vendor nationality itself becomes a rational procurement screen for foreign buyers. Coverage. Lloyd’s market bulletin Y5381 requires its syndicates to carry state-backed cyberattack exclusions in standalone cyber policies, and the standard clauses key attribution to government determinations. A retaliation event or a collateral loss from a government-directed operation puts the claim directly into state-backed exclusion analysis. Pipelines. The memorandum invites participating companies to buy threat information from private entities and propose operations built on it. Threat intelligence you share with ISACs, government channels, or commercial platforms can feed an offensive proposal wherever the receiving party’s contractual rights permit that use. The memorandum overrides none of those contracts, so their use restrictions are the only controls you have. Review them for residual liability and customer-notification duties before your telemetry becomes targeting data. China has already run the retaliation playbook The sharpest market evidence predates the memorandum, which is exactly what makes it evidence. Reuters reported in January 2026 that Beijing had directed Chinese firms to stop using cybersecurity software from roughly 15 American and Israeli vendors. In February, Reuters reported that Palo Alto Networks softened its own attribution of a Chinese espionage campaign over concerns that its personnel in China or its clients elsewhere faced retaliation. On August 6, six days before the signing, the Cyberspace Administration of China opened a formal cybersecurity review of Palo Alto’s products, the mechanism whose best-known precedent ended with Micron barred from Chinese critical-infrastructure procurement. The program caused none of that; the sequence began seven months before it existed. The point runs the other way. Beijing operates a demonstrated regulatory and procurement playbook for converting cyber-policy friction into named-company commercial pressure, and the memorandum enlarges the set of American firms within its reach. Chinese state media is already collapsing the distinction Washington spent two decades drawing between contractor hacking and lawful practice, framing the program as America bringing previously covert operations into the open. For multinationals, the exposure also runs inward. China’s Data Security Law bars providing data stored in China to foreign law enforcement without approval and compels cooperation with Chinese security authorities. Chinese law can bar a vendor’s China-based staff from supporting the American program their employer joined, and expose those employees personally for perceived cooperation. Employee travel protocol now belongs in the risk register. What the unpublished rules have to solve The memorandum never mentions artificial intelligence, and one silence carries operational weight. The text directs the NCC to use automation to streamline the program. Crowell & Moring names the failure mode. Agentic tooling compresses the interval between an approved action and an unintended effect. An autonomous operation can exceed its parameters at machine speed, exposing the vendor to bond forfeiture and civil claims before a human intervenes. Whether the October rules require human supervision at execution will materially affect that exposure. It then travels the same four ways to the vendor’s customers. The definition of a Cyber Effects Operation also reaches industrial control systems and embedded controllers, which raises the same collateral question for connected physical systems. The program’s constraints are real. Dual written approval, the Critical Outcome prohibitions, and the minimization rules impose substantially tighter controls than an unrestricted hack-back regime. And nobody can yet say whether the program will shrink cybercrime losses or grow them; the operation-level data that settles the question is precisely what the memorandum keeps classified. However, both points stand, and neither changes the allocation. Whatever the program achieves against criminal networks, the residual legal, insurance, and market risk sits with private companies, and much of it sits with companies that never joined. Five questions belong on the board’s agenda before the operating rules are published: Which of our critical security, cloud, identity, and incident-response vendors intend to participate, and will they represent that status in writing to the extent the law allows? Can each participating vendor segregate our data from its operations work, and will it contract to that segregation? Which representations to customers, regulators, and insurers become incomplete if a vendor participates and we do not know? What does our cyber policy pay on a retaliatory state-backed attack, an accidental American-directed effect, and a shared-cloud outage? Ask before the reservation-of-rights letter arrives. Which employees, affiliates, and joint ventures in China or other rival jurisdictions connect to participating vendors, and what does their travel protocol require? Watch two documents next: the operating procedures, and the Cyber Letters of Marque and Reprisal Act, introduced July 15 as S. 5000 and H.R. 9697. Section 8 of the House bill bars any cause of action against a letter holder for acts the letter expressly authorizes, which would supply a statutory civil shield the memorandum does not contain, and an executive instrument cannot create. Participation is a decision your vendors get to make. Treat the memorandum as the risk-transfer instrument it is: The government authorizes the operation, and much of the residual legal, insurance, and commercial exposure stays private, including with companies that never signed anything.

Read full story at CSO Online →