Private Sector Cybercrime Disruption: Compatible with Statecraft? | #cybercrime | #infosec

Whilst much of the debate has centred on the US, it should be noted that there is already a country that has a process of cyber deputisation on its statute. A country widely regarded as a champion of responsible cyber behaviour. That country is Singapore, which implemented such a process in amendments to its equivalent of the CMA in 2013 and subsequently transferred it to Section 23 of its Cybersecurity Act in 2018. The Act allows for firms or individuals to conduct disruptive cyber operations ‘by a certificate under the Minister’s hand’, enabling actions ‘necessary to prevent, detect or counter any threat to a computer or computer system.’ There is no public-reporting mechanism and it is unclear if the measure has been used. Nonetheless, the option is there, available if required at an opportune moment.
Compatibility with Responsible Cyber Statecraft?
Whilst deputisation would come with legal risks for the deputised firm, the process could be compatible with international law. On paper, Articles II, III and IV of the Budapest Convention are potential impediments; Article II, in particular, compels signatories to criminalise non-state ‘access to the whole or any part of a computer system without right’. However, it does not define what ‘without right’ means. This suggests that a formalised deputisation process that bestowed temporary and restricted rights on the private sector could be compatible with the Convention.
Similarly, Article V of the (non-binding) UN Articles on Responsibility of States for Internationally Wrongful Acts (ARSIWA) allows non-state actors to conduct operations if they have been ‘empowered by the law of that State’ in a ‘particular instance’.
Norms and messaging also matter. Indeed, any move to deputise the private sector would need to be cautious of the potential to inadvertently imitate or legitimise the chaotic practices of adversaries. Strict legitimacy and proportionality would need to be enforced through any authorisation and hand-on-shoulder mechanism. Additionally, (some) transparency would be important: a Singapore Plus approach. This should not necessarily require granular publicly released details of operations, but could, for instance, involve routine public or Parliamentary notifications akin to disclosure of the number of thwarted terrorist incidents.
Arguably, being a ‘responsible’ state cyber actor necessitates a balancing-act: taking all possible measures to protect national security, social order and livelihoods, but doing so in a proportionate way in which the means do not undermine the ends. Done carefully, there could be a role for deputised activity that avoids bargain-bucket hack-back, piracy or privateering.

