John Strand, Owner, Black Hills Information Security, Inc.:
“This article is both exciting and concerning at the exact same time. It genuinely feels like the cyber equivalent of letters of marque, where private industry is authorized to conduct specific, targeted operations on behalf of the United States government.
There are a number of questions that immediately come to mind. How will oversight work? What are the limits of these authorities? Who is responsible for ensuring those limits aren’t exceeded? How does this fit within international law? Those are all critical issues that need to be answered before a program like this reaches full maturity.
“That said, it’s also important to acknowledge the strategic reality. Our adversaries are already operating this way. We’ve seen multiple reports of China leveraging private cybersecurity companies to conduct offensive cyber operations. Russia has long relied on so-called private hackers who carry out activities that align with government objectives. When our adversaries embrace a model that we refuse to consider, it can leave the United States at a strategic disadvantage.
“For that reason, I think this is a positive step, particularly for strengthening U.S. offensive cyber capabilities. At the same time, it has to be implemented carefully. Strong oversight and clearly defined legal boundaries are essential if this model is going to be successful.
“There’s another issue that deserves attention as well. If private security companies are going to participate in these operations, what level of legal protection and indemnification will they receive? Before any company signs a contract to perform offensive cyber activities on behalf of the U.S. government, those questions need clear answers.
“There’s a lot to unpack here, and I expect the next 60 to 90 days will determine not only how this proposal evolves, but also how the relationship between government and private industry develops in the offensive cyber space.”
Jeremiah Fowler, Researcher for Black Hills Information Security, Inc.:
"I personally see this as a positive step in combating cybercrime because it recognizes that some of the best technical expertise is outside of the government.
“The private sector cybersecurity community brings a wide range of skill sets and many have dealt with the aftermath and active defense from these threats on a daily basis. Cybercriminals and state sponsored groups have been attacking US companies and assets for years causing billions of dollars in damages and it’s good to see the gloves come off. Cybercriminals have benefited for years from jurisdictional boundaries and the difficulty of pursuing threat actors operating overseas and this program could be a game changer.
“Speed important in terms of cybersecurity and the perception is that government processes can be slowed down by bureaucracy. Criminal infrastructure can appear, move, and disappear in hours so a public-private model could help bridge that gap of speed and efficiency. Another benefit is information sharing. Private companies often see pieces of an attack that government agencies may not see, while law enforcement and intelligence agencies possess information unavailable to the private sector."
Donald McFarlane, Advisory Board Member, Xcape, Inc.:
“This is not cyber vigilantism. It connects private-sector visibility and capability to lawful federal authority and oversight.
“This is a significant evolution of the public-private cyber partnership. We’re moving beyond simply sharing threat intelligence to creating a pathway by which threat information acquired through normal business activities, along with threats identified by state and local government, can feed proposed operations for federal approval.
“Capability is not going to be the scarce resource. Target validation, competing intelligence equities and deconfliction will be. The NCC is going to be busy. The secret’s in the deconfliction.”
Corey Ham, Director of Continuous Pentesting, Black Hills Information Security, Inc.:
"My primary concern is the security of these contractors. Giving more entities access to sensitive information increases the likelihood that it can be compromised. Most of the information we have on Chinese state-sponsored hacking similar to this is from data leaks and breaches affecting contractors like I-Soon, for example. I worry that both nation states and crime groups will compromise the contractors who are targeting them, and access information they should not be able to access, like forensic data from other targets or classified data."






