In a first, US will allow some private firms to carry out cyberattacks
The new order sweeps away decades of existing U.S. cybersecurity policy prohibiting private companies from conducting 'hack back' attacks or offensive cyber operations.
The US government's decision to permit certain private firms to carry out cyberattacks marks a significant shift in its cybersecurity policy. For decades, the US has maintained a stance that prohibits private companies from engaging in "hack back" attacks or offensive cyber operations, deeming such actions too risky and potentially destabilizing. By allowing select private firms to conduct cyberattacks, the US is effectively acknowledging that the traditional approach may no longer be sufficient in addressing the evolving threat landscape.
This change in policy is likely driven by the increasing sophistication and frequency of cyber threats, which have made it challenging for governments to keep pace. By empowering private companies to take proactive measures, the US aims to augment its cybersecurity capabilities and deter adversaries. However, this new approach also raises concerns about accountability, oversight, and the potential for unintended consequences. As the US navigates this uncharted territory, it will be crucial to strike a balance between leveraging the expertise of private firms and maintaining effective controls to prevent escalation.
As the industry watches this development unfold, key questions arise: Which private firms will be granted permission to conduct cyberattacks, and under what conditions? How will the US ensure that these operations are coordinated and controlled to avoid misattribution or escalation? What implications will this policy have for the global cybersecurity landscape, and how will other nations respond? The answers to these questions will shape the future of cybersecurity and have far-reaching consequences for the technology industry.
Originally reported by techcrunch.com. NewsChannels adds analysis for technology readers.