Cyber Focus: Cybersecurity, National Security, and Critical Infrastructure

← Cyber Focus: Cybersecurity, National Security, and Critical Infrastructure18 aug · 15 min

Private Sector Cyber Offense: What the New White House Memo Does—and Doesn't Do with Mike McLaughlin

Private Sector Cyber Offense: What the New White House Memo Does—and Doesn't Do with Mike McLaughlin18 aug15 min

A new White House memorandum aims to bring the private sector more directly into cyber operations against transnational criminal organizations. But turning that policy goal into practice raises immediate questions about legal authority, liability, deconfliction and the risks companies could assume by participating.

In this edition of Cyber Focus: To the Point, Frank Cilluffo talks with Mike McLaughlin about what the memorandum does—and does not do—under existing law, what needs to be resolved during the 60-day implementation window, and where private-sector capabilities may be most useful without interfering with ongoing military, intelligence or law-enforcement operations.

Main Topics Covered

Private-sector cyber offense Legal authority and liability Deconfliction with government operations Risks for participating companies The 60-day implementation window Where private-sector capabilities may fit Key Quotes

"The [National Security Presidential Memorandum] isn't actually creating an authority; it's creating a record… that the administration or federal law enforcement can point to and say we gave you very clear authority… and if you step outside of that, you're on your own. — Mike McLaughlin

"Deconfliction is a big problem because when you're dealing with the National Security Agency and the CIA and the FBI and US Cyber Command and CNMF and, you know, US SOCOM, and then you bring in ASD from Australia or GCHQ from the UK, and we're trying to deconflict all of this blue activity in cyberspace, it's really challenging." — Mike McLaughlin

"If we start contracting with companies to conduct offensive operations, those companies become combatants." — Mike McLaughlin

"For me, if the authorized target set are cryptocurrency wallets or keys or on-chain infrastructure that's being used to support transnational criminal organizations, that's an area that the private sector can cleanly operate without risking running afoul of traditional intelligence community activities, law enforcement operations, or military cyber operations." — Mike McLaughlin

Relevant Links and Resources

White House national security presidential memorandum National Cybersecurity Strategy Computer Fraud and Abuse Act (CFAA) Buchanan Ingersoll Rooney — Mike McLaughlin Guest Bio

Mike McLaughlin co-leads the cyber practice at Buchanan Ingersoll Rooney. He previously served in government roles involving U.S. Cyber Command and the Cyber National Mission Force.