Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
cybersecurity-regulationcritical-infrastructure-threatai-platform-security

U.S. Cyber Policy Emphasizes Private-Sector Defense Partnerships Over Offensive Hacking

Updated 3mo agoFirst seen Mar 17, 20267 sources

The U.S. government signaled that private industry is not expected to conduct offensive cyber operations on the government's behalf, even as the new national cyber strategy calls for stronger collaboration with commercial partners. National Cyber Director Sean Cairncross said the administration wants to use private-sector capabilities for information sharing, threat intelligence, and defensive support, while offensive action remains the responsibility of agencies that already hold that authority, including the NSA, CIA, FBI, and U.S. Cyber Command.

The same policy direction is reflected in the Energy Department's planned first-ever cyber strategy, which is intended to align with the national strategy and focus on protecting the energy grid through stronger public-private coordination. Energy officials said the plan will prioritize getting timely, actionable information to operators, improving the sector's security resilience, and investing in AI for cyber defense to counter adversaries using AI-enabled offensive capabilities against critical infrastructure.

Share:
U.S. Cyber Policy Emphasizes Private-Sector Defense Partnerships Over Offensive Hacking
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 24, 20263mo ago

Google launches threat disruption unit at RSAC

Google publicly launched a new threat disruption unit within its threat intelligence organization at the RSAC Conference. The company said the unit will use intelligence, legal processes, infrastructure takedowns, public exposure of threat actors, and product improvements to proactively impede adversaries without engaging in 'hacking back.'

Google launches threat disruption unit, stops short of calling it ‘offensive’ - Nextgov/FCW
Mar 19, 20263mo ago

Trump cyber officials reject 'letters of marque' and private-sector hack back

Senior administration cyber officials said the new national cyber strategy does not contemplate cyber 'letters of marque' or authorizing private companies to hack on the government's behalf. At the Prague Cyber Security Conference and McCrary Cyber Summit, they said industry's role is to provide visibility and support for government-led actions against criminal and state-backed actors.

Mar 17, 20263mo ago

FBI urges victims to report incidents to support joint cyber disruption operations

FBI Cyber Division head Brett Leatherman said the bureau's joint sequenced operations to degrade adversaries often begin when victim organizations report incidents to the FBI. He urged organizations to include contacting their local FBI field office in breach-response plans, saying the benefits outweigh liability concerns.

National cyber director says private sector should not conduct offensive cyber operations

At a McCrary Institute event, National Cyber Director Sean Cairncross said the U.S. government does not envision private companies carrying out offensive cyber actions on its behalf. He said industry should instead contribute threat intelligence, technical visibility, and defensive support while agencies with existing legal authority handle offensive operations.

DOE says it is preparing its first cybersecurity strategy for the energy sector

A senior Department of Energy cybersecurity official said the department is developing its first strategic plan focused on protecting the energy grid. The strategy is intended to complement the recently published national cyber strategy and emphasize resilience, public-private partnership, and AI investment for defense of critical energy infrastructure.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

26 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Affected products
1 linked
Whatsapp
Organizations
23 linked
Citizen LabLawfareAmazon Web ServicesMicrosoft CorporationGoogleParagon SolutionsCisco SystemsiSoonWorld Liberty FinancialSiemensCandiruRecorded FutureNSO GroupIntellexaMeta PlatformsAppleStrykerBloombergHacking TeamDarkMatterMcCrary InstituteCyberbitGamma Group
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.