ARTICLE
21 January 2022

Being A White-Hat Hacker Just Got Tougher: U.S. Commerce Department Issues New Cybersecurity Export Controls On Intrusion And Surveillance Tools (Updated)

F
Fenwick
Contributor
Fenwick logo
Fenwick provides comprehensive legal services to leading technology and life sciences companies — at every stage of their lifecycle — and the investors that partner with them. For more than four decades, Fenwick has helped some of the world's most recognized companies become and remain market leaders. Visit fenwick.com to learn more.
BIS has published new export controls on certain cybersecurity items that ban the export or resale of hacking tools to authoritarian regimes, and it created a new license exception for those items.
United States International Law
To print this article, all you need is to be registered or login on Mondaq.com.

The U.S. Department of Commerce's Bureau of Industry and Security (BIS) has published new export controls on certain cybersecurity items that ban the export or resale of hacking tools to authoritarian regimes, and it created a new license exception for those items.

The new regulations aim at tightening export controls on cybersecurity tools, including intrusion software, internet protocol network communications surveillance, and related technology that could be used by threat actors to conduct malicious cyber activities and surveillance.

BIS requested public comments for potential revision before the effective date of the interim rule. In December 2021, BIS published 12 sets of comments from industry, summarized in this article.

BIS contends that these controls are narrowly drawn, focusing on specific cyber-intrusion and network surveillance equipment, software and technology, and, when combined with the new license exception, that they should have limited impact. The rule adopts cybersecurity controls previously agreed to at the multilateral Wassenaar Arrangement, bringing U.S. controls into alignment with those already adopted by the European Union and other jurisdictions.

However, network infrastructure manufacturers, cybersecurity software and service providers, IT forensics firms, bug bounty programs and those engaged in vulnerability testing and research may feel the impact of the rule.

Further, exports to national security concern countries such as China and Russia will be highly restricted, and companies dealing with Cypress, Israel and Taiwan will have to navigate new restrictions, notwithstanding those countries' stronger relationships with the U.S.

To learn more, read the full article.

Updated from our October 2021 alert and published in the February 2022 issue of The Computer & Internet Lawyer.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

ARTICLE
21 January 2022

Being A White-Hat Hacker Just Got Tougher: U.S. Commerce Department Issues New Cybersecurity Export Controls On Intrusion And Surveillance Tools (Updated)

United States International Law
Contributor
Fenwick logo
Fenwick provides comprehensive legal services to leading technology and life sciences companies — at every stage of their lifecycle — and the investors that partner with them. For more than four decades, Fenwick has helped some of the world's most recognized companies become and remain market leaders. Visit fenwick.com to learn more.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More