Exploring the Regulation of Commercial Cyber Intrusion Capabilities’ Proliferation and Misuse

Authors

  • Murdoch Watney University of Johannesburg

DOI:

https://doi.org/10.34190/iccws.20.1.3150

Keywords:

threat of unrestraint commercial cyber intrusion industry proliferation, commercial cyber intrusion capabilities; misuse of commercial intrusion capabilities; United States executive order on the prohibition of commercial spyware; Pall Mall Process on cyber intrusion tools.

Abstract

The commercial cyber intrusion industry has grown prolifically without any legal constraints for many years. Many governments and private clients contributed to the cyber intrusion capabilities’ proliferation by paying millions of dollars to private companies for a variety of covert offensive cyber capabilities. The risk it presented to national security, rule of law and human rights’ protection was not anticipated. Unchecked commercialisation of intrusion capabilities made its way to malicious state and non-state threat actors who would not have had access to it had it not been for the commercialisation. The harm resulting from the commercial development, selling, export and use of intrusion capabilities have contributed to make an already insecure digital ecosystem even less safe. Governments are exploring the regulation of commercial intrusion capabilities. The United States (US) government issued an executive order (EO) in 2023 banning the buying, export and use of commercial spyware on a domestic level that presents a risk to national security, rule of law, and human rights. Countries, such as the US, France and the United Kingdom (UK), took initiatives on a global level. The US issued a joint statement aimed at reigning in the proliferation of commercial spyware whereas France and the UK launched the Palm Mall Process in 2024 focussing on establishing norms that can serve as guidelines for the development and use of commercial intrusion capabilities. The discussion explores the necessity to regulate the commercial intrusion industry to ensure that digital intrusion capabilities are used in a responsible and human rights’ respecting manner. The aim of regulating commercial intrusion capabilities is to make the digital ecosystem safer. The discussion evaluates the effectiveness of the initiatives to restrain the commercial intrusion industry, and prevent the misuse of these capabilities. The misuse of commercial intrusion capabilities constitutes an ongoing threat. Governments and companies must broaden their focus beyond controlling the commercial intrusion industry. They must extend their attention to cyber resilience and risk mitigation, and aim at having the necessary cybersecurity measures in place to prevent, detect, respond and recover from the malicious or irresponsible use of intrusion capabilities.

Downloads

Published

24-03-2025