Section 1604
Digital privateers have been operating since at least 2011. We need a coordination framework.
The final part of the Architectures of Cyber Power series. New here? Start with Part 1, Part 2, Part 3, Part 4, and Part 5.
In Part 5, I left you with a Swiss researcher named Roman Hüssy. In June 2013, Microsoft’s lawyers won a court order, seized about four thousand internet addresses to kill a botnet called Citadel, and drove straight over three hundred servers that belonged to Hüssy and were helping other researchers defend against Citadel. Hüssy had earlier built a list so this exact thing would stop happening. The list was a private registry of which good guys were already quietly sitting on which addresses, so nobody would knock out a good guy’s operation by accident. Microsoft did not check the list. Nobody in that story broke a rule because there were no rules to break. Checking the list was optional (not even a norm), so nobody checked it. And that is precisely the problem.
That was one actor swinging alone. The act itself is what I call the Disrupt Doctrine and defined back in Part 4. The Disrupt Doctrine is when someone reaches into a machine they don’t own, one that’s doing something bad, and makes it stop doing the bad thing. Three kinds of actor run the Disrupt Doctrine today. Software companies under a civil complaint: sue the operators of the criminal infrastructure, and a judge signs an order letting you seize the addresses they run it from (Microsoft, out of Redmond, has been at this since 2011; Google and AWS joined more recently). A police force under a warrant (since 2021 the FBI has been reaching into privately owned American mail servers and home routers to pull malicious code back out of them). A military under authorities most of us have never read (Cyber Command doing Cyber Command things). None of them has ever been required to tell the others they were coming.
This summer, the US Senate proposed welding two of them together.
The letter
History already ran a version of this at sea. Yes yes, back to the sea stories. My comfort zone.
When a state needed naval power it could not afford to build, it wrote a private captain a letter of marque, which was a license to go take enemy ships (mostly merchant vessels) and keep the proceeds. Cheap, fast, effective, and on someone else’s payroll. Outsourcing at its finest. It worked right up until the privateer became impossible to distinguish from the pirate, and the great powers got tired enough of the ambiguity that they abolished the practice in the Declaration of Paris in 1856.
When I was a kid, my dream was to become a pirate. I wasn’t interested in those boring firemen or astronaut clichés. Then someone burst my bubble and told me pirates were the bad guys (were they, though?), so I learned about Sir Francis Drake and Queen Elizabeth I and decided to become a privateer instead. Then someone burst my bubble again and informed me that letters of marque were 150 years out of vogue. Only then did I decide to join the Navy, solely as my last resort.
And in June 2026, a US Senator went ahead and started writing the letter.
A few weeks ago, Senator Roger Wicker (R-MS) introduced the Senate’s version of the National Defense Authorization Act (the annual bill that sets what the Pentagon can do and spend) for fiscal 2027. Section 1604 is titled “Scaling Cyberspace Access Generation and Maintenance Capabilities,” which is Pentagon for: pay a company to break into computers and stay there. The text authorizes the Secretary of Defense to contract with a private firm to conduct a cyber operation “for the sole purpose of access generation and maintenance using contractor owned, contractor operated means, under the operational authority of the Commander of United States Cyber Command.”
Contractor owned and contractor operated. The infrastructure belongs to the company, the hands on the keyboard belong to the company, and Cyber Command, the military’s cyber warfighting arm out at Fort Meade, holds the leash.
An honest caveat (the same one I gave Germany in Part 4): this is a bill, not a law. Introduced June 15, reported out of Armed Services as S. Rept. 119-127, with a procedural motion filed on June 24 to push it toward a floor vote. It is proposed language. It can be amended or stripped. It has not passed. I am reading a draft and so are you.
Why it exists, and why people hate it
The reason it exists is not mysterious and it is not corrupt. Cyber Command cannot hire its way to the scale it needs against China. The talent sits in the private sector, it costs more than a GS-13 makes (a mid-career federal salary), and the gap keeps growing. That’s the honest engine underneath Section 1604, and it’s why some version of this will probably survive.
The reaction came fast and loud, and I heard it from every corner of the community. Privateers! Hackers for hire! Anarchy! Nick Leiserson, at the security policy nonprofit Institute for Security and Technology, raised the cleanest argument: the monopoly on the legitimate use of force belongs to the state (thank you, Weber, Hobbes, and Bodin). He is correct, of course. It is the reason you cannot (legally) hire a militia to settle a property line. Japan built an oversight committee to protect that line. Germany is still fighting about the Trennungsgebot (its constitutional wall between the police and the spies) to protect it. And a bill that lets a contractor conduct military operations does take a heavy step across that line.
All that being said, the bill draws a fence, just not the one everyone thinks. The layperson will notice that contractors are limited to “access generation and maintenance,” which sounds like the boring half of the job. Break in and stay in while the government keeps the part where things break. One former senior cyber official pointed out to Breaking Defense that the entire SolarWinds campaign (the Russian intrusion that sat undetected inside a dozen federal agencies for months and, when revealed, tanked SolarWinds’ stock price) was pretty much all access generation. Breaking in and staying in actually covers most of a cyber operation. That fence goes around nearly the entire domain.
So that fence is decoration. But there is a real fence hiding in the draft language.
The only key in this story with a paper trail
Section 1604 requires that the work be done “under direct Federal Government oversight of a civilian employee of the Federal Government or a member of the Armed Forces, with cleared civilian employees of the Department of Defense or cleared members of the Armed Forces present at all times.” When feasible, in government facilities. So, less privateer and more deputization.
Within ten days of signing any such contract, the Secretary must tell the congressional defense committees the date, the scope, the terms, and the name of the company. Within forty-eight hours of the start of any operation, and again at the end of it, the Secretary must report the target, the nature of the access, the duration, the contractor who did it, and the name of the specific federal employee who stood there and watched them do it. Quarterly briefings on top of that, plus a final report. The whole authority expires on December 31, 2030. For a document drafted by a defense committee, that is a suspicious amount of paperwork, and I mean that as praise.
Now go back to Microsoft. On June 24, its Digital Crimes Unit walked into a US court, won its order, and knocked out more than two hundred of the internet addresses that two password-stealing malware families used to run infected machines. Four continents, one afternoon. No congressional notification or forty-eight-hour report. No named federal employee standing behind the analyst. Certainly no sunsets. A civil complaint, a judge’s signature, and a private company switches off a couple hundred domains it does not own. You and I only know it happened because the company published a blog post about it (which means somebody inside Microsoft assessed it was good for marketing and better for the stock price).
So Leiserson’s objection about the monopoly on force currently points at the only instrument in this story that has to write down what it did.
I am not claiming that Section 1604 is good policy. The access-generation fence is decorative, and putting an offensive military capability onto a contractor’s own infrastructure offloads something a democracy is supposed to keep. But if your objection to 1604 is that it lets a private company reach into machines on behalf of the state, you are about fifteen years late, and you should be far angrier about the instrument that does the same thing and doesn’t have to tell anybody about it.
Cyber letters of marque have been circulating in our networks since at least 2011, and this Senate bill is the first document in the whole story that even attempts to write down what one of our privateers did, when, and for what purpose.
The verdict about the Disrupt Doctrine and how we’re running it
The distributed model of the Disrupt Doctrine is not the thing that’s broken here. A standing, many-handed response force, allied governments and capable companies breaking criminal infrastructure faster than it regrows, is a genuinely good thing. We actually run this exact system elsewhere and we’re safer for it.
Extradition moves a suspect across a dozen borders on a shared legal spine. Every country names a central authority, and Interpol wires the notices between them. The anti-money-laundering system does the same for dirty money. The Financial Action Task Force writes the rulebook that most of the world’s banks now follow, and the Egmont Group plugs the financial-intelligence units of more than a hundred countries into each other so a single transfer can be traced across every border it touches. Both systems run on a shared registry, shared norms, coordinated behavior, and somebody whose job description says, “Pick up the phone and call our friends whenever we need to take action.”
Aim that machinery at infrastructure instead of at fugitives and funds and you have a truly formidable Disrupt Doctrine. Break criminal servers often enough and cheaply enough and the business stops paying for itself. We have proven the breaking works. Fifteen years of Microsoft takedowns, Operation Endgame, the Alaska botnet case. What nobody has built is the coordination desk.
The desk is wildly unglamorous, and I think that’s why nobody has built it. Nobody gets a new agency out of it or a fancy building, and certainly no flag-waving press release announcing that we shut down three teenagers in Topeka who were laundering the latest meme coin through our Wi-Fi-enabled washing machines. It takes a list, and a phone number, and some poor soul whose entire job is to make sure people talk to each other when a lawyer in Redmond, a prosecutor in Alaska, and a colonel at Fort Meade all want to take down the same server. Nobody gets a medal for that job, and nobody throws a ticker tape parade because the takedown worked without nuking vulnerability researchers along the way.
Hüssy built the list thirteen years ago and nobody had to call him. Section 1604 would make exactly one contractor, on exactly one pilot program, report the name of the person who stood in the room and watched. That is the high-water mark of accountability in this entire series.
So: six parts on cyber power, a doctrine named and defended, and I still think active disruption is good policy. It would just be a whole lot more effective with global coordination.
Somebody has to answer the phone, and it should be us.
If you’re enjoying A Discipline of Seeing, it would mean the world to me if you shared it with others. Please use the button below to send my Substack to someone who might find my work interesting. Thanks!
— Brandon


