Non-participants inherit risks of Trump's hack-back program
Trump's August 12 memorandum launches a 'Participating Companies' program for offensive cyber operations overseen by the DOJ and DHS. Participants get only untested CFAA protection without civil immunity, and risks extend to companies not in the program.
- DOJ and DHS must approve each operation in writing; bond from $1 million
- Protection rests on untested reading of the CFAA law-enforcement exception
- No civil immunity, no protection from state laws or foreign jurisdictions
- Risks for non-participants: outages, no disclosure, insurance exclusions
Read next
Policy