Cybersecurity Tech Accord update principles limiting offensive operations in cyberspace
At the Summit for Democracy in March 2023, members of the Cybersecurity Tech Accord, with the support of other industry players, released a set of principles to guide the technology industry to help curb the dangerous and rapidly growing market of cyber mercenaries1. For the purposes of this document, the term “cyber mercenaries” is defined as companies – or occasionally individuals – dedicated to developing, selling, and supporting offensive cyber capabilities which enable their clients – often governments – to access the networks, computers, phones, or internet-connected devices in ways that violate human rights and undermine democratic principles.
Today, members and supporters are reaffirming and updating these principles, through which to emphasise and adapt to the changing nature of the threat presented by cyber mercenaries, and to call on governments to accelerate joint action through which to tackle the challenges this industry creates.
In our original principles, the Cybersecurity Tech Accord looked to challenge the risks being created by companies developing and selling offensive cyber capabilities and services, often involving the cultivation and proliferation of “zero-day” exploits and malicious software that undermines the security of peaceful technology, and which have been widely used to violate human rights and democratic principles online. At a high level, the five principles charged companies to:
- Take steps to counter cyber mercenaries’ use of products and services to harm people;
- Identify ways to actively counter the cyber mercenary market;
- Invest in cybersecurity awareness of customers, users and the general public;
- Protect customers and users by maintaining the integrity and security of products and services;
- Develop processes for handling valid legal requests for information.
Since 2023, progress has been made towards tackling the cyber mercenary threat, with platform providers identifying and dismantling ‘command-and-control’ infrastructure for irresponsible actors, device manufacturers updating security practices to harden systems, and impacted companies taking legal action against some of the worst offenders in the offensive cyber market2. Participants and partners to the Cybersecurity Tech Accord have expanded our intelligence sharing on the evolving nature of the threat, and rolled-out schemes to notify and support users affected. Governments around the world have also committed to taking joint action, including through the Joint Statement on efforts to counter the proliferation and misuse of commercial spyware, and Pall Mall Process on tackling the proliferation and irresponsible use of commercial cyber intrusion capabilities3,4.
However, so far, efforts to tackle the threats presented by cyber mercenaries have not succeeded in slowing the growth of the market5, or the spread of the harms that the misuse of these capabilities can create6. As the demand by States for increasingly intrusive cyber offensive capabilities increases (both for legitimate and illegitimate purposes)7, and the use of agentic AI raises the risk profile for threat actors across all different levels of maturity8, the Cybersecurity Tech Accord recognises that the challenge presented by cyber mercenaries is continuing to get worse.
As such, we, as signatories of the Cybersecurity Tech Accord, with the support of other industry players, are reaffirming our commitment to the existing principles to curb cyber mercenaries, are updating these to reflect the changing landscape for cyber mercenaries and are redoubling our efforts towards their implementation.
Cybersecurity Tech Accord signatories and other industry partners support the following principles that reflect good practices:
- Take steps to counter cyber mercenaries’ use of products and services to harm people
- Conduct human rights due diligence in line with the United Nations Guiding Principles on Business and Human Rights to identify risks and mitigations related to possible misuse of products and services by cyber mercenaries.
- Issue cease and desist letters and/ or take other lawful action against cyber mercenaries, as appropriate.
- Share information with each other, industry peers, as well as with researchers and civil society partners on cyber mercenary attacks, as well as identified trends, and potential mitigations, as appropriate.
- Encourage the uptake of enhanced cybersecurity practices through which to harden existing and legacy digital systems that are likely to be increasingly targeted through the use of agentic AI capabilities and expansion of the cyber mercenaries market.
2. Identify ways to actively counter the cyber mercenary market
- Ensure compliance with legal restrictions targeting the cyber mercenary market, including the national and regional sanctions, export-control and designation regimes
- Promote wider compliance with international human rights standards and laws and increase awareness on how to prevent products and services from being misused to commit human rights abuses informed by existing governmental guidance (e.g., the U.S. Department of State Guidance on Implementing the “UN Guiding Principles”).
- Advocate for the development, adoption, and use of coordinated governance frameworks, policy guidelines, and regulation to effectively limit export and import of, and investments in information technology products and services used and developed by cyber mercenaries.
3. Invest in cybersecurity awareness of customers, users and the general public
- Increase public awareness and education on the issue of cyber mercenaries, as well as possible remedies by providing customers and users with appropriate resources, guidance, and tools to ensure that they can protect themselves online and build their overall cyber resilience.
- Help customers and users improve cybersecurity practices and resilience in partnership with civil society organizations committed to building capacity, such as those supporting particularly targeted groups.
- Expand the use of AI-enabled defensive cyber capabilities through which to automate the identification and response to activity by cyber mercenaries across products, platforms and services. Responsible, risk-based use of AI enabled cyber offensive capabilities should be done with appropriate safeguards, including with testing, human oversight, privacy and security controls, and accountability measures in place.
4. Protect customers and users by maintaining the integrity and security of products and services
- Develop and deploy tools to detect patterns of behaviour associated with malicious activity by cyber mercenaries to increase protections of products and services.
- Maintain and promote strong encryption for products and services as feasible and not knowingly weaken the security of customers and users to facilitate electronic surveillance or access by cyber mercenaries.
- Notify customers and users whose accounts are reasonably believed to have been targeted by cyber mercenaries where feasible and as appropriate.
- Endeavour to appropriately harden AI and next generation systems, through their design and development against the enhanced threat presented by AI-enabled offensive cyber mercenary actors.
- Urge the responsible disclosure of vulnerabilities by governments and threat researchers to technology providers, recognising the greater opportunity for agentic AI systems to uncover critical risks in digital systems.
5. Develop processes for handling valid legal requests for information
- Establish and maintain processes to ensure government agencies and law enforcement authorities can submit lawful requests for information in accordance with applicable laws and international standards, including their human rights obligations.
- Establish and maintain processes to safeguard such processes from attempted exploitation by cyber mercenaries and other bad actors.
- Increase transparency of the law enforcement requests process, such as by making the number of requests companies receive public.
References:
- https://cybertechaccord.org/new-industry-principles-to-curb-cyber-mercenaries/
- https://cyberscoop.com/predator-spyware-infrastructure-taken-down/
- https://2021-2025.state.gov/joint-statement-on-efforts-to-counter-the-proliferation-and-misuse-of-commercial-spyware/
- https://www.gov.uk/government/publications/the-pall-mall-process-declaration-tackling-the-proliferation-and-irresponsible-use-of-commercial-cyber-intrusion-capabilities
- https://digitalfrontlines.io/2025/01/30/hackers-cyber-mercenaries/#emerging-efforts
- https://www.hks.harvard.edu/centers/carr-ryan/our-work/carr-ryan-commentary/spyware-cases-europe-and-africa-spotlight-privacy
- https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review
- https://www.atlanticcouncil.org/dispatches/hackers-using-ai-just-found-a-zero-day-the-spyware-industry-is-watching/
