The episode reveals a structural shift toward permission-based operational models, where access and capability are not determined by technical proficiency alone but by explicit, revocable permissions from state or corporate authorities. This model is illustrated by the recent U.S. federal initiative authorizing select private cybersecurity firms to conduct offensive operations against foreign criminal organizations—an approach that mirrors the historical "letter of marque" by granting a new legal status rather than developing new technologies. Parallel dynamics are visible in the IT service provider space, with vendors such as Microsoft moving to strictly time-bound, role-scoped delegated admin permissions that can be revoked or altered unilaterally.
The most consequential development is the August 12 presidential memorandum authorizing private U.S. companies, under contract with the Department of Justice or Homeland Security, to perform cyber surveillance and effect operations against specified foreign criminal targets. Firms must pass technical, security, and personnel vetting, declare outside contracts, and post a $1 million bond forfeitable upon non-compliance. Every action requires written dual approval by program directors. Importantly, the legal basis relies not on statutory change but on an executive memorandum that grants a temporary agency status to participants, a mechanism untested in court and revocable with any change in administration.
Related developments reinforce the thesis of permission-based dependency. Microsoft’s overhaul of its partner governance—removing perpetual global admin rights in favor of time-limited, role-based permissions—has made MSPs’ delivery capabilities contingent on timely recognition and acceptance of new terms set by Microsoft. Amid this, operational pressure is rising as AI-driven vulnerability finding systems, like those used by Microsoft and cataloged in the NIST National Vulnerability Database, are producing flaw volumes that outpace existing tracking infrastructure. Together, these shifts make permissions and vendor terms—not technical gaps—the central variable in the sustainability of service lines.
For MSPs and IT leaders, the practical implications are clear: operational continuity is increasingly determined by upstream permissions and the specificity of contractual terms rather than local technical controls. Vendor dependence has expanded beyond product functionality to include granular, revocable access rights shaped by external schedules and policies. Effective risk management now requires tracking the origin, mechanism, and expiration of every operational permission, establishing owner accountability, and proactively reviewing vendor and governmental agreements. Organizations failing to systematize this will face unplanned service interruptions and remediation costs dictated by external authorities.
00:00 The Bond and the Vetting
04:31 Congress Grants Those
07:47 Whose Permission Are You On?
11:05 Why Do We Care?
Supported by:
💼 All Our Sponsors
MSP Radio is supported by our partners:
ABC Solutions · CometBackup · Guardz · HaloPSA · LogMeIn · OpenText · Pax8 · Proofpoint · Rythmz · ScalePad · TimeZest · Transit AI · USecure
Supporting the IT services community through insights, analysis, and transparency.
🚀 Join Business of Tech Plus
Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.
👉 https://businessof.tech/plus
🎧 Subscribe to the Business of Tech
Want the show on your favorite podcast app or prefer the written versions of each story?
📲 https://www.businessof.tech/subscribe
📰 Story Links & Sources
Looking for the links from today’s stories?
Every episode script — with full source links — is posted at:
🎙 Want to Be a Guest?
Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:
💬 https://www.podmatch.com/hostdetailpreview/businessoftech
🔗 Follow Business of Tech
LinkedIn: https://www.linkedin.com/company/28908079
YouTube: https://youtube.com/mspradio
Bluesky: https://bsky.app/profile/businessof.tech
Instagram: https://www.instagram.com/mspradio
TikTok: https://www.tiktok.com/@businessoftech
Facebook: https://www.facebook.com/mspradionews
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
[00:00:02] The United States used to hire private ship captains to attack enemy vessels and keep a share of what they took. Not Navy, businessmen with a government license. That license made them privateers. Without it, the exact same voyage, the same ship, the same crew made them pirates. The government started issuing that paper again. This time, the ships are private cybersecurity firms and the sea is somebody else's network.
[00:00:30] This is the Business of Tech. I'm Dave Solt. The federal government has spent decades telling private companies that hacking back is illegal. It just started handing out exceptions. We'll start with the memorandum itself. On August 12th, the president signed a national security presidential memorandum titled Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.
[00:00:56] It directs the National Coordination Center to build a program authorizing private American companies to conduct two things, cyber surveillance operations and cyber effects operations. The second of which means breaking into and disrupting somebody else's systems. The targets are foreign criminal organizations running ransomware, financial fraud, and the scam compounds behind pig butchering.
[00:01:23] The reporting is consistent across CyberScoop, the Register, and TechCrunch, all three working from the memo, and an accompanying White House fact sheet. Now the qualifications, because they are specific. A company has to sign a contract with either the Justice Department or the Department of Homeland Security. It has to clear vetting on technical proficiency, on facility security, and on personnel reliability.
[00:01:48] It has to disclose every outside contractual relationship tied to the program. It has to post a bond or escrow of at least $1 million, which it forfeits if it falls out of compliance. It gets evaluated annually. And before any single operation runs, it needs written approval from two program executive directors, one at Justice, one at Homeland Security. Operating procedures are due within 60 days.
[00:02:17] And hold on to that bond figure, because a million dollars is the floor, and in federal contracting terms it is close to nothing. It is not there to cover damages. It is there to make sure whoever posts it is a real company with something to lose. Then set two other numbers beside that. In a single recent cycle, Microsoft shipped fixes for 421 flaws in one patch Tuesday, including a Windows Zero day already being exploited.
[00:02:45] And Microsoft has said why the number keeps climbing. It is running a system of more than 100 AI agents across its own code, finding defects faster than people ever did. And it has told customers to expect the volume to keep going up. That is one vendor, one month, and the number is rising on purpose. And the system that keeps track of those flaws is being rebuilt because it cannot keep up.
[00:03:09] NIST has said it wants to overhaul the National Vulnerability Database, which is the federal catalog the entire security industry indexes against, specifically for the volume and pace that AI is bringing to it. So, a government standing up a license capability to go on offense, a defect count that fills a catalog faster than the catalog can be maintained, and a plan to rebuild the catalog rather than reduce what goes into it. Those three things only fit together one way. And it starts with a question nobody asked.
[00:03:39] What exactly is being handed out here? If you're listening to this and you haven't hit follow yet, on Apple Podcasts, search Business of Tech. It takes five seconds and you'll get the next episode automatically. This episode is brought to you by Control Map. Growing MSPs are using Control Map to build recurring revenue by expanding their GRC services.
[00:04:02] Starting now, Control Map is offering a free plan for MSPs looking to get started with providing compliance as a service. Create a free account and run an assessment. Track key items like policies, risks, and evidence in one place. It's a practical way to prove value to a client before deciding to expand your compliance offering. Try Control Map for free today. Visit scalepad.com slash Dave to get started. That's scalepad.com slash Dave.
[00:04:33] Everything in that program, the bond, the vetting, the annual review, the written approval before a single operation runs, is built around the assumption that the ability to attack is rare and needs to be carefully handed out. That assumption expired. Around the same time, OpenAI released a model called GPT-5.6 Cyber, built specifically for security work, with its refusal behavior deliberately loosened, and a reported 95% completion rate on advanced cybersecurity tasks.
[00:05:02] That is a commercial product. And Wired has been documenting a growing run of incidents where AI agents conduct intrusions on their own. Not a person using a tool, but software carrying out the attack chain without anyone directing each step. So the capability is not scarce. It is purchasable, and in some cases it is already loose. What remains scarce is permission. And that is the thing the government just started issuing. Understand what the legal theory here actually is.
[00:05:32] The reason breaking into a criminal's group's servers has been off the table for private companies is the Computer Fraud and Abuse Act, which turns on authorization. The memo's answer is that participating companies operate as a part of the lawful investigatory and protective operations carried out by federal law enforcement. They are acting as the government's agent, so the access is authorized. That's the entire mechanism. Not new technology, a new legal status.
[00:06:01] And note what the memo does not do. Earlier proposals to let private companies hack back would have amended the Computer Fraud and Abuse Act outright. This one leaves the statute untouched and requires the program to comply with it. The theory is that the agency relationship makes the access lawful. That theory has never been tested in court. Which raises the question of who is allowed to grant that status. And the answer is written down.
[00:06:31] Article 1, Section 8 of the Constitution lists the powers of Congress. Laws 11 reads, To declare war, grant letters of mark and reprisal, and make rules concerning captures on land and water. A letter of mark is a government license authorizing a private party to conduct force that would otherwise be a crime.
[00:06:53] That is the historical instrument and is named, explicitly by name, as a power of the legislature sitting in the same sentence as the power to declare war. The framers put licensed private force in Congress's hands deliberately. And this is not a comparison I'm reaching for. People in policy circles have spent years openly calling for cyber letters of mark by name. That is the thing that was asked for. This is not that.
[00:07:23] This was not done by Congress. It was not even done by executive order. It was done by presidential memorandum, which is a thinner instrument still, and it lasts precisely as long as the administration that signed it. Permission is the scarce good, and it's being rented, not owned. Which is a fine observation about Washington, until you check whose name is on the permissions underneath your own service lines.
[00:07:50] Here is where that lands on you, and it's not where you'd expect. Clear one thing first. You are not the exposed party here. In 2021, the Supreme Court decided a case called Van Buren, and it read the Computer Fraud and Abuse Act narrowly. The question is whether the gate is up or down for you, not whether you had a good reason for walking through it. If you have credentials and access, using them is not a federal crime.
[00:08:17] The vulnerability researchers poking at software nobody gave them permission to touch have a real problem with this statute. You do not. But look at where your permission actually comes from, because it isn't where most providers assume. When you check a client's Microsoft tenant for configuration drift, your client did not authorize that. Your client cannot authorize that. They don't own the system. Microsoft does, and Microsoft grants your access through the Partner Program on Microsoft's terms,
[00:08:46] and rewrites those terms when it decides to. It already did. Delegated admin privileges used to hand a partner global administrator rights on a client tenant with no expiration. Microsoft killed that model, stopped issuing it for new customers, and for partners who hadn't moved, automatically created a replacement relationship with eight default roles, and stripped the old access 30 days later. Every provider running Microsoft work today runs it on a permission that is role-scoped, time-bound,
[00:09:15] expires within two years, and gets regranted or doesn't. That is not a criticism of Microsoft. The old model was genuinely dangerous. It is an observation about who holds the deed. Your ability to deliver most of what you sell is a permission, granted from above, revocable, on terms you did not negotiate and cannot appeal. Which is the same sentence as the memorandum.
[00:09:41] A bonded license to operate, issued by an authority that can withdraw it, sitting on top of a capability the holder already had. The government just made that structure visible at the scale of the state. It's been sitting on your desk the whole time. So here's the choice. Know whose permission you actually run on. Go service line by service line and name the vendor that grants the access underneath each one, and what happens to that line when the terms change.
[00:10:08] Or keep operating a business whose right to function is a paragraph in somebody else's agreement that you did not write, did not negotiate, and have never read. And once you've written that list down, it stops being a legal question and becomes a Tuesday morning one. Here's a reality every MSP knows. Native Microsoft 365 security leaves gaps. Those gaps land on your desk. Proofpoint 365 Total Protection closes them.
[00:10:37] It's an MSP-first platform that unifies Microsoft 365 security backup and compliance into one integrated console. High security efficacy, less operational friction, and multi-tenant management that scales as you grow. Protect clients against modern threats and stop stitching point tools together. Built on Hornet security, now part of Proofpoint. See it at proofpoint-total-protection.com
[00:11:07] Why do we care? Because a permission with an expiration date is an operational asset. And in most shops, nobody owns it. You already tracked certificate expiry and license renewals because an outage taught you to once. And the permission underneath each service line has exactly the same property. It expires, it gets rewritten, and you find out from a portal notification somebody may or may not have read. Put it on the same register with the same named owner and the same review cadence.
[00:11:36] So what to consider? Build the register before you need it and keep it boring. One row per service line, four columns. What you deliver, which vendor grants the access underneath it, what the mechanism is. Delegated admin, API key, partner program membership, reseller agreement, and when it expires or can be changed. Most shops can fill this out in an afternoon, and have never once been asked to. The value isn't the document. It's discovering which two or three lines have no answer in column three.
[00:12:07] Put a clock on the permissions that already have one. Granular delegated admin relationships run for a fixed term of up to two years and then stop working unless they're regranted, and the client can terminate them at any point. That is a scheduled service interruption sitting in your delivery model with no ticket attached to it. Whoever owns your renewals calendar should own those too. On the same cadence, with the same lead time, you'd give a certificate.
[00:12:34] Make what changes for us a standing question in vendor reviews, not a reaction to an announcement. When Microsoft retired the old delegated admin model, partners who hadn't moved had a replacement relationship created for them, and the old access stripped 30 days later. That was well signposted, and it caught some people because nobody's job was to read it. Assign that reading. And widen it because your security vendors are moving towards you as fast as the terms are.
[00:13:01] CrowdStrike is now pushing Quiltworks, its frontier AI risk protection, down into the S&B channel. Which means the enterprise security firms whose profile matches everything that the new federal program requires are also the firms arriving in your stack. These two facts are unrelated today. Ask anyway, at renewal, in writing. What are you party to? And what would we be downstream of? And picture the provider who did this.
[00:13:28] When the terms change, and they will, that shop already knows which clients are affected, which service lines touch it, and what the remediation costs. On the day of the announcement, instead of the day of the outage. They send one email. Everyone else spends a weekend figuring it out. If this trend continues within 12 to 18 months, the operational risk that takes a provider down won't be a breach or a failed backup. It'll be a permission that it got expired, got rescoped, or got withdrawn on a vendor's schedule.
[00:13:56] And the shops that survive it cleanly will be the ones who had a name and a date next to every one of them before it happened. This is the business of tech. Tired of being told your business isn't big enough? The Small Biz Thoughts community is built on a different idea. Profitable is enough. No grow or die pressure. No exit-obsessed noise. Just MSP operators building sustainable businesses on their own terms. Together.
[00:14:26] See what that looks like at smallbizthoughts.org Interested in advertising? Head to mspradio.com slash engage. The Business of Tech is written and produced by me, Dave Solberg, under ethics guidelines posted at businessof.tech. Thanks for listening. I'll see you on the next episode. Proud member of the MSP Radio Network. Proud member of the WP Radio Network. You won't have the right to launch this.

