Bottom line: The U.S. government has authorized the private sector to engage in offensive cyber operations against foreign adversaries, marking a significant shift in U.S. cyber policy.
What's happening: The memo, reportedly written by CISA, allows private companies to engage in hacking operations against North Korea and Iran, with the goal of disrupting their cyber capabilities. The U.S. government has designated North Korea as a “cyber threat” since 2017, while Iran has been a target of U.S. cyber operations since 2019. The memo does not provide specific details on the scope or timeline of the operations.
What to do: Security leaders should review their incident response plans to ensure they are prepared for the potential consequences of private sector involvement in cyber offense. Companies should also consider implementing additional security measures to protect against potential attacks. The U.S. government has not provided guidance on how to conduct these operations, leaving it up to private companies to develop their own protocols.