US President Trump has signed a landmark national security presidential memorandum that fundamentally alters the American approach to digital warfare. This directive authorizes federal law enforcement agencies to partner with vetted private technology firms to execute offensive cyber operations against foreign criminal organizations and international adversaries. Under this new framework, private sector specialists will work under direct government supervision to propose, coordinate, and carry out targeted actions intended to degrade enemy infrastructure.[1]
In expert comment, Kyle Hanslovan, CEO and co-founder of Huntress, argues that such close public-private collaboration is no longer optional given the rising sophistication of nation-state actors and AI-powered autonomous threats. He supports creating a "stronger coalition of the willing" to protect Western interests. Hanslovan believes the program’s success depends on hyperscalers' intelligence data and the agility of specialist research labs. He stresses the importance of a deconfliction process to ensure private firms do not jeopardize long-term federal operations that lead to arrests and geopolitical negotiations. "If done correctly, I believe it will ultimately slow the illegal transfer of wealth and knowledge from Western civilization," he stated.
While supportive of the concept, Ben Bernstein, a cybersecurity advisor at Huntress, expressed significant reservations about the operational reality of "green-lighting" private offensive strikes. He identified collateral damage and bureaucratic delay as major obstacles. Bernstein noted that threat actors frequently use compromised, innocent infrastructure such as hospital networks to hide their tracks, making it difficult to strike back without hitting bystanders. He warned that adversary systems are often ephemeral. "By the time a vetted firm submits a target, sits through the DOJ and DHS deconfliction reviews, and finally gets a green light, they’ll be shooting at ghosts," Bernstein remarked.
The founder and CEO of BlackFog, Darren Williams, noted that while the policy marks a shift toward active disruption, taking systems offline is not a permanent solution. He argued that criminals can simply rebuild infrastructure and change tactics. Williams suggested the focus must remain on data security, as modern cybercrime centers on monetizing stolen information. He advised that organizations should prioritize "detecting and blocking data exfiltration in real time" rather than relying solely on the disruption of external criminal networks.
The policy has also faced criticism regarding its potential for abuse and the message it sends to the international community. Tim Mackey, head of software supply chain risk strategy at Black Duck, warned that endorsing private offensive cyber activity could increase, rather than deter, criminal and nation-state aggression. He expressed concern that individuals with access to sophisticated surveillance tools might use them for personal gain without rigorous oversight. Mackey concluded that the memorandum sends a message to adversaries that "the US government needs private companies and their capabilities to defend against cyberattacks."
[1] https://www.cybersecurityintelligence.com/blog/us-enlists-the-private-sector-for-cyber-attacks-9640.html
This article is shared at no charge for educational and informational purposes only.
Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization. We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC). For questions, comments, or assistance, please contact the office directly at 1-844-492-7225 or feedback@redskyalliance.com
- Reporting: https://www.redskyalliance.org/
- Website: https://www.redskyalliance.com/
- LinkedIn: https://www.linkedin.com/company/64265941
Weekly Cyber Intelligence Briefings:
REDSHORTS - Weekly Cyber Intelligence Briefings
https://attendee.gotowebinar.com/register/7855487668891299929
[1] https://www.cybersecurityintelligence.com/blog/us-enlists-the-private-sector-for-cyber-attacks-9640.html
Comments