CISOOnline

Hack-back programs could expose your security vendors

For multinationals, the exposure also runs inward. China’s Data Security Law bars providing data stored in China to foreign law enforcement without approval and compels cooperation with Chinese security authorities. Chinese law can bar a vendor’s China-based staff from supporting the American program their employer joined, and expose those employees personally for perceived cooperation. Employee travel protocol now belongs in the risk register.

What the unpublished rules have to solve

The memorandum never mentions artificial intelligence, and one silence carries operational weight. The text directs the NCC to use automation to streamline the program. Crowell & Moring names the failure mode. Agentic tooling compresses the interval between an approved action and an unintended effect. An autonomous operation can exceed its parameters at machine speed, exposing the vendor to bond forfeiture and civil claims before a human intervenes. Whether the October rules require human supervision at execution will materially affect that exposure. It then travels the same four ways to the vendor’s customers. The definition of a Cyber Effects Operation also reaches industrial control systems and embedded controllers, which raises the same collateral question for connected physical systems.

The program’s constraints are real. Dual written approval, the Critical Outcome prohibitions, and the minimization rules impose substantially tighter controls than an unrestricted hack-back regime. And nobody can yet say whether the program will shrink cybercrime losses or grow them; the operation-level data that settles the question is precisely what the memorandum keeps classified. However, both points stand, and neither changes the allocation. Whatever the program achieves against criminal networks, the residual legal, insurance, and market risk sits with private companies, and much of it sits with companies that never joined.



Source link