
Why in the News
A US presidential memorandum allows vetted private companies to participate in government-authorised offensive cyber operations against overseas transnational criminal organisations (TCOs).
Note: Vetted private firms are privately owned companies that have passed thorough background checks by a client, usually a government agency, to prove they are safe, reliable, and qualified to do sensitive work
What does the memorandum allow?
- Private participation: Selected firms can conduct hacking operations under government supervision.
- Permitted actions: Operations may include entering, disabling or destroying criminal networks’ systems.
- Oversight: Firms require government contracts, security vetting and supervision.
- Targets: Criminal organisations attacking US persons or interests, excluding entities formally controlled by foreign governments.
Key Concepts
- TCO: Criminal network operating across national borders.
- Offensive cyber operation: Entering, disrupting or destroying another computer system.
- Attribution: Identifying the actor responsible for a cyberattack.
- Hacktivist: Non-state actor conducting cyber operations for political or ideological purposes.
Why is it controversial?
- Misattribution: Attacks may hit innocent third-party systems.
- Collateral damage: Destructive operations can affect infrastructure in other countries.
- Escalation: Private hacking can trigger cross-border conflicts.
- Accountability: Commercial actors may have weaker accountability than state agencies.
- Proxy problem: It resembles the private or proxy cyber models the US has criticised in China and Russia.
Implications for India
- India has no publicly declared offensive cyber doctrine.
- Sections 43 and 66 of the IT Act, 2000 criminalise unauthorised access and damage.
- Compromised Indian servers could become staging infrastructure for foreign cyber operations.
- India continues to advocate state responsibility and opposition to cyber proxies at the UN.
Prelims Pointers
- CERT-In: National agency for cyber incident response.
- NCIIPC: Protects Critical Information Infrastructure.
- I4C: Coordinates India’s response to cybercrime.
- Defence Cyber Agency: Handles cyber operations for the armed forces.
- Section 70B, IT Act: Provides the statutory basis for CERT-In.
[2022, GS3, 10 marks] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.”
[2017] In India, it is legally mandatory for which of the following to report on cyber security incidents?
1.Service providers
2.Intermediaries
3.Corporate bodies
Select the correct answer using the code given below:
[A] .1 and 2 only
[B] .2 and 3 only
[C] 1 and 3 only
[D] 1, 2 and 3 only