Key Takeaways

  • Donald Trump’s memorandum permits vetted US companies to conduct offensive cyber operations against foreign criminal groups.
  • Participating companies would post a $1m bond, but questions remain over liability, oversight and unintended damage.
  • Ransomware activity linked to Russian-speaking groups is increasing pressure on governments and corporate supply chains.

Donald Trump has opened a new front in US cyber policy by authorizing selected private companies to attack the digital infrastructure used by foreign criminal organizations.

The presidential memorandum directs federal agencies to draw on private-sector expertise when disrupting hostile networks. Participating companies would be deputized by the US government and required to post a $1m bond, which could be forfeited if they exceeded their authority or went rogue, according to The Observer.

This goes considerably further than conventional threat intelligence, incident response or defensive penetration testing. A company operating under the program could be permitted to destroy infrastructure associated with cybercriminals, shifting part of the offensive burden from federal agencies to commercial operators.

A research fellow at the Royal United Services Institute compared the approach to allowing warehouse guards to pursue criminals into the street and attack them on behalf of the state. The analogy captures the central concern: private security personnel would no longer be guarding only their own perimeter.

Attribution in cyberspace is rarely tidy. Criminal groups rent infrastructure, compromise legitimate servers and work through affiliates scattered across several jurisdictions. Some maintain relationships with intelligence agencies or operate with the tolerance of national governments. What happens if a private US operator disrupts a server that also supports legitimate services, or infrastructure connected to a foreign state?

Those questions make the program’s authorization process particularly important. Reporting by TechCrunch characterized the policy as the first US move to let selected private firms carry out cyberattacks. Its practical effect will depend on which companies qualify, how targets are validated and whether federal agencies retain operational control.

Cybersecurity providers including CrowdStrike, Mandiant (Google) and Recorded Future already map adversary infrastructure, track threat groups and support offensive-style simulations. Those capabilities are close to what federal agencies would need, although intelligence gathering and simulation are different from actively disabling systems.

Demand is not difficult to understand. Clop, a Russian-speaking gang, claimed this week that it had stolen large quantities of data from 50 multinational companies, including Shell and Philips. Both companies said they were investigating incidents while playing down the prospect of extensive data theft.

Qilin, meanwhile, targeted Filtronic just over a week ago. Filtronic, based in Sedgefield and listed on London’s Aim index, recently secured a $62m (£46m) contract with Elon Musk’s SpaceX. The manufacturer said it had found no evidence that company, employee or third-party data had been accessed, compromised or exfiltrated, and that operations remained fully functional.

Still, manufacturing creates unusually sharp leverage for extortionists. When a production line stops, revenue can stop with it. The European Union Agency for Cybersecurity (ENISA) reports that more than 70% of organizations experienced at least one ransomware attack in the previous year, underscoring the pervasive nature of these threats.

The US Cybersecurity and Infrastructure Security Agency reports that over 75% of reported significant cyber incidents against US critical infrastructure involve financially motivated criminal groups rather than nation-states. The ransomware-as-a-service model attracts operators displaced by law-enforcement action, including members associated with other established groups who capitalize on lucrative affiliate networks.

The pressure extends beyond individual victims. Attacks involving the Co-op Group, Jaguar Land Rover, and M&S have pushed boards to scrutinize suppliers as well as internal controls. Nextgov reported in April that Washington’s push to counter hackers was already drawing the cybersecurity industry deeper into the offensive operations debate.

That said, commercial participation does not remove government responsibility. Contracts would need tightly defined targets, evidence thresholds, logging requirements, escalation procedures and mechanisms for reporting collateral damage. A $1m bond provides a financial deterrent, but it may look modest beside the diplomatic or economic consequences of striking the wrong network.

Trump’s memorandum could expand the market for adversary mapping and breach simulation, a sector projected by Omdia to grow at over 20% annually through the mid-2020s. Gartner estimates that by 2026, 30% of large enterprises will explicitly factor counter-offensive considerations into their cyber-risk models. Yet the real test will be governance, not technical skill. Private operators can move quickly. The harder task is ensuring they strike only the intended target and stop when their authority ends.