A National Security Presidential Memorandum went out Thursday. It directs the National Coordination Center to stand up a program, names Justice and Homeland Security as overseers, and gives them sixty days to write the rules. As Ars Technica read it, this is the first time the federal government has authorized private companies to conduct offensive cyber operations against hackers overseas.
The accompanying fact sheet names the targets: ransomware, sextortion, phishing campaigns, financial fraud, impersonation scams. The memo names the verbs — Cyber Surveillance Operations and Cyber Effects Operations. It permits spyware. It does not rule out destroying a target's data, locking it behind encryption, or knocking it offline with a denial-of-service attack. A vetted contractor may now do, under federal authority, most of what the program exists to punish.
The guardrails are not decorative. Participants have to clear vetting by Justice and Homeland Security. Operations may not produce "Critical Outcomes" — loss of life, serious injury, or anything rising to the level of use of force or armed attack under international law. Each company posts a $1 million escrow deposit, forfeited if it breaches its contract.
None of those is the binding constraint. The eligibility test is.
any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests, and that is not an institutional part of a foreign government or wholly operated under a foreign government's direction.National Security Presidential Memorandum
Every clause there is checkable until the last one. Whether a crew is "an institutional part of a foreign government or wholly operated under a foreign government's direction" is not a fact about its infrastructure or its victims. It is a claim about the private relationship between a criminal group and a state — and that relationship is the thing the most dangerous targets are built to obscure. Russian ransomware crews are tolerated, sometimes tasked, rarely commanded. The word carrying the whole memo is "wholly."
That word separates a law-enforcement action from an operation against a state proxy, which is to say it separates a contract dispute from an international incident. Attribution of that depth takes months of intelligence work and usually resolves to a probability, not an answer. The program needs the answer first, from a company whose exposure if it guesses wrong is a forfeited million dollars.
Attribution takes months and ends in a probability. The program needs it in advance.
Kevin Beaumont, who has spent five years inside the ransomware problem, granted the premise and then aimed at the incentives:
The biggest problem I've had with fighting ransomware over the past 5 years is private cyber companies basically lobbying for nothing to change. A lot of companies have made a lot of money, so putting them in charge of stopping it seems optimistic.Kevin Beaumont
He is right, and that is the objection that will get argued for the next sixty days, because it is the one you can legislate against. Compensation structures are writable. Clawbacks are writable. Conflict-of-interest rules are writable. No rule makes attribution fast.
In sixty days Justice and Homeland Security publish the minimum standards, and the memo already tells you what they will cover: technical proficiency, proven performance of cyber operations, facility security, personnel vetting, reliability. All of it about whether a company can run the operation. None of it about who it is allowed to run the operation against. That question is the one the escrow account is quietly pricing at a million dollars, and it is not a vendor-qualification problem.