Cyber effects operations defined as manipulation or destruction of target systems
President Trump on Wednesday signed a memorandum that enlists vetted private-sector companies in cyber surveillance and effects operations against transnational criminal organizations, the Wall Street Journal reported. The Journal described the memorandum as part of a shift in U.S. cyber strategy that “has been changing” away from a primarily defensive posture.
The memorandum directs the National Coordination Center to create a program that will conduct “cyber surveillance operations” and “cyber effects operations” against foreign cyber-enabled transnational criminal organizations, with those operations carried out under the control and oversight of the federal government.
“This memorandum expands the fight against TCO-perpetrated cybercrime by incorporating the ingenuity of the private sector,” the document states.
The memorandum characterizes the partnership as one in which vetted United States companies operate “subject to the direction and oversight of the Federal Government.” According to the memorandum, “By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens.”
The memorandum defines a cyber effects operation as activity conducted in or through IT infrastructure “that results in the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon.”
The Wall Street Journal reported the memorandum on Wednesday. The Journal reported in November that the Trump administration’s National Cyber Strategy would shift “from primarily focusing on online defenses to actively going after nation-state hackers to deter attacks before they happen,” according to reporting by Angus Loten.
The Journal observed that the private sector has historically occupied a different role in cybercrime. “The private sector’s role in cybercrime has been mostly that of victim,” the Journal reported. “Risks notwithstanding, its enlistment in broader cyber operations should expand the government’s arsenal in a dramatic way.”
The Journal also reported that the federal government’s posture toward offensive operations has evolved. “There was a time when federal officials were disinclined to endorse the idea of offensive cyber operations, but that has been changing,” the Journal reported.
The memorandum was reported by Steven Rosenbush of the Journal’s CIO Journal team.