• Research
  • Emissary
  • About
  • Experts
Carnegie Global logoCarnegie lettermark logo
DemocracyIran
  • Donate
{
  "authors": [
    "Tim Maurer",
    "Wyatt Hoffman"
  ],
  "type": "other",
  "centerAffiliationAll": "dc",
  "centers": [
    "Carnegie Endowment for International Peace"
  ],
  "collections": [
    "Cyber and Digital Policy"
  ],
  "englishNewsletterAll": "ctw",
  "nonEnglishNewsletterAll": "",
  "primaryCenter": "Carnegie Endowment for International Peace",
  "programAffiliation": "TIA",
  "programs": [
    "Technology and International Affairs"
  ],
  "projects": [],
  "regions": [
    "Iran"
  ],
  "topics": [
    "Security",
    "Technology"
  ]
}

Source: Getty

Other

The Privatization of Security and the Market for Cyber Tools and Services

A look at the emerging and expanding gaps in the governance of private cybersecurity companies and activities and the ways forward and policy options for governments.

Link Copied
By Tim Maurer and Wyatt Hoffman
Published on Aug 23, 2019
Program mobile hero image

Program

Technology and International Affairs

The Technology and International Affairs Program develops insights to address the governance challenges and large-scale risks of new technologies. Our experts identify actionable best practices and incentives for industry and government leaders on artificial intelligence, cyber threats, cloud security, countering influence operations, reducing the risk of biotechnologies, and ensuring global digital inclusion.

Learn More

Source: Geneva Centre for Security Sector Governance

Abstract

This paper seeks to identify the emerging and expanding gaps in the governance of private cybersecurity companies and activities and to explore ways forward and policy options for governments. First, it explores the characteristics of typical cyber operations and challenges related to their conduct by private actors. Thereafter, it addresses the governance challenges around cybersecurity and three main departure points for regulation: the fact that geographic scope does not limit cybersecurity companies, that cyber operations can slide from defensive to offensive very quickly; and that cybersecurity services are often exported for the purpose of (or with the knowledge they will be) violating human rights. This section will also integrate perspectives of international law. Finally, the paper lays out suggestions for policy options in relation to international law and existing international normative frameworks. In conclusion, the paper offers a framework and way forward as food for thought in order to address cybersecurity operations in relation to PMSCs.

Read Full Text

This analysis was originally published by the Geneva Centre for Security Sector Governance.

About the Authors

Tim Maurer

Former Senior Fellow, Technology and International Affairs Program

Dr. Tim Maurer was a senior fellow in Carnegie’s Technology and International Affairs program.

Wyatt Hoffman

Former Senior Research Analyst, Cyber Policy Initiative

Wyatt Hoffman was a senior research analyst with the Nuclear Policy Program and the Cyber Policy Initiative at the Carnegie Endowment for International Peace.

Authors

Tim Maurer
Former Senior Fellow, Technology and International Affairs Program
Tim Maurer
Wyatt Hoffman
Former Senior Research Analyst, Cyber Policy Initiative
SecurityTechnologyIran

Carnegie does not take institutional positions on public policy issues; the views represented herein are those of the author(s) and do not necessarily reflect the views of Carnegie, its staff, or its trustees.

More Work from Carnegie Endowment for International Peace

  • Article
    Continental Asia and the Rise of Portfolio Politics

    Continental Asia—the overland space from Türkiye to China—has emerged as a critical geopolitical arena, yet receives less attention than its maritime counterpart, the Indo-Pacific. While Continental Asian states are cast as objects of great power competition, they are exhibiting growing agency through “portfolio politics”: strategically diversifying partnerships across sectors to pursue national goals.

      Jennifer B. Murtazashvili

  • Commentary
    The Unresolved Challenges in U.S.–India Semiconductor Cooperation

    The U.S.–India semiconductor cooperation story is well-stocked with top-level strategic intent. What remains unresolved, however, are some underlying challenges that will determine whether the cooperation actually functions. Three such friction points stand out.

      Shruti Mittal

  • Tiananmen Gate with US and Chinese flags
    Commentary
    Emissary
    Trump and Xi Should Tackle a Previously Impossible AI Conversation

    Previous dialogues ended in failure. This time could be different.

      Scott Singer

  • Trump and others walking down a red carpet, with Air Force One in the background
    Commentary
    Emissary
    “China Doesn’t Do Anything for Free”

    Why the outcomes of the U.S.-China meetings may be limited.


      Aaron David Miller, David Rennie

  • A drone flies in front of an Iranian flag in southern Tehran, Iran
    Article
    The Unintended Consequences of Iran’s Asymmetric Strategy and America’s AI War

    The Iran war is unique in the scope and scale of asymmetric warfare and AI-enabled conflict. These will test the limits of protecting civilians.

      Steve Feldstein

Get more news and analysis from
Carnegie Endowment for International Peace
Carnegie global logo, stacked
1779 Massachusetts Avenue NWWashington, DC, 20036-2103Phone: 202 483 7600
  • Research
  • Emissary
  • About
  • Experts
  • Donate
  • Programs
  • Events
  • Blogs
  • Podcasts
  • Contact
  • Annual Reports
  • Careers
  • Privacy
  • For Media
  • Government Resources
Get more news and analysis from
Carnegie Endowment for International Peace
© 2026 Carnegie Endowment for International Peace. All rights reserved.