GitHub signs on to industry principles targeting cyber mercenary operations

GitHub has joined 40 other companies in endorsing a new set of principles from the Cybersecurity Tech Accord aimed at limiting offensive operations in cyberspace. The principles are designed to push back against cyber mercenaries — private-sector actors that conduct offensive cyber operations for governments or other paying clients, often by stockpiling and selling exploits and surveillance tools.

The effort aligns with the broader goal stated in the White House National Cybersecurity Strategy: shifting the burden of defending cyberspace away from individuals and smaller organizations and onto the companies best positioned to reduce systemic risk.

The endorsed principles commit signatory companies to:

  • Take steps to counter cyber mercenaries’ use of their products and services to harm people
  • Identify ways to actively counter the cyber mercenary market
  • Invest in cybersecurity awareness for customers, users and the general public
  • Protect customers and users by maintaining product and service integrity and security
  • Develop processes for handling valid legal requests for information

For GitHub, the endorsement builds on prior technical and policy work. On the product side, the company points to its security tooling and secure development practices, funding for open source security projects, and adherence to trust-and-safety principles. GitHub also highlights its protection of legitimate security researchers, who often act as a counterweight to exploit markets.

GitHub’s legal engagement on the issue predates the new principles. In 2020, the company joined an amicus brief in NSO v. WhatsApp opposing the expansion of foreign sovereign immunity to private cyber-surveillance firms acting on behalf of foreign governments. The company says it remains committed to working with governments, civil society and like-minded organizations to keep digital technologies aligned with democratic values and human rights.

GitHub is urging other companies to endorse the principles and join the effort against the cyber mercenary market.