At DefCon this year, I listened to a presentation about the Pall Mall Process—an international initiative launched by the UK and France to tackle "the proliferation and irresponsible use of commercial cyber intrusion capabilities." As someone who's spent years in offensive security research, I was curious about how this framework would affect our industry.
But the more I dug into the documentation, including the recently published consultation summary, the more I became convinced we're watching the construction of a solution to a problem that hasn't been properly defined—while avoiding the actual issue.
The Pall Mall Process claims to address surveillance abuse against "journalists, activists, human rights defenders, and government officials." The poster child is NSO Group's Pegasus being used to spy on journalist Jamal Khashoggi before his murder. It's a compelling narrative, but we've seen no empirical evidence that commercial tools are making the problem worse.
Look at the actual language in their founding declaration:
"The growing commercial market enabling the development, facilitation, purchase, and use of commercially available cyber intrusion capabilities raises questions and concerns over its impact on national security, human rights and fundamental freedoms..."
"Without international and meaningful multi-stakeholder action, the growth, diversification, and insufficient oversight of this market raises the likelihood of increased targeting for profit... It also risks facilitating the spread of potentially destructive or disruptive cyber capabilities... This trend risks contributing to unintentional escalation in cyberspace."
"These threats, including to cyber stability, human rights, national security, and digital security at large, are expected to increase over the coming years."
Hold on—we're building international regulatory frameworks because something "raises questions" and "risks facilitating" problems? Since when do we make policy based on concerns and maybes? Since forever..
In the hundreds of pages of Pall Mall documentation, nowhere do they provide:
Baseline metrics of surveillance abuse before the commercial market expanded
Trend data showing increasing abuse over time
Quantitative evidence that commercial tools cause more harm than actor-developed alternatives
Comparative analysis of abuse patterns
Measurable success metrics for their proposed solutions
Instead, we get vague language like threats that "are expected to increase" and victims that are "significant and growing." The declaration is littered with "may," "risks," and "expected to"—we're making policy on soft statements like this when we need empirical data!
Buried in the consultation summary is this noteworthy mention: "Governments represented the main driver of irresponsible activity across the market for CCICs as the primary customers of the vendors."
Let that sink in. The document also acknowledges that governments are the primary drivers of the problem they're trying to solve. It gets worse: "State actors have increasingly offered higher prices, incentivizing the growth of the industry."
So governments create demand by offering premium prices, which incentivizes vendors to exist, which creates tools that governments then abuse. The logical response would be to address government behavior, right?
Wrong. The entire framework focuses on voluntary vendor regulation while asking those same governments to self-regulate.
This reminds us of how Purdue Pharma tried to solve OxyContin abuse by making pills tamper-resistant. The result? Users migrated to unregulated heroin, making the problem deadlier and attribution nearly impossible.
What actually worked in the opioid crisis was Prescription Drug Monitoring Programs (PDMPs)—comprehensive, mandatory reporting of all transactions that created visibility into patterns and enabled early intervention. Success came from transparency and tracking, not from making individual components marginally harder to obtain.
The Pall Mall Process is making the same mistake. Instead of creating visibility into who's surveilling whom and why, it's trying to make commercial tools slightly harder to acquire. But authoritarian governments that want surveillance capabilities will simply:
Develop in-house alternatives
Turn to underground markets
Open-source their tools to avoid reporting requirements
Move operations to non-participating jurisdictions
Every one of these alternatives gives us less visibility into surveillance activities, not more.
Speaking of open source, the Pall Mall Process explicitly excludes "noncommercial intrusion capabilities, such as the free Metasploit framework" and "dual-intent tools, such as Cobalt Strike."
Think about the incentive structure this creates:
Commercial vendors: Face reporting requirements, export controls, and compliance burdens
Open source alternatives: Complete regulatory bypass
Bad actors: Clear incentive to either use existing open source tools or open source their capabilities
A caveat to this is that incentivizing open source development to avoid regulatory reporting might actually help the cybersecurity industry in unexpected ways.
When offensive capabilities are open source, several interesting dynamics emerge:
Transparency by Design: Unlike commercial tools where capabilities are hidden behind NDAs and black-box licensing, open source offensive tools are completely transparent. Every technique, every exploit, every methodology is visible to defenders. This means security teams can study attack methods, develop countermeasures, and build detection signatures without reverse engineering.
Democratized Defense: Security researchers worldwide can analyze, critique, and improve upon offensive techniques. The result is often faster defensive innovation than when capabilities are locked in proprietary systems. When Metasploit releases a new module, the entire defensive community can immediately understand and prepare for that attack vector.
Quality Through Scrutiny: Open source offensive tools undergo constant peer review. Bugs, unreliable exploits, and poorly coded modules get identified and fixed quickly. This actually makes the tools more reliable for legitimate penetration testing while potentially making them less attractive for sustained covert operations that require stealth and persistence.
The consultation acknowledged that many of the worst offensive capabilities are already freely available. Cobalt Strike, while technically commercial, is so widely pirated that it's effectively open source. Many nation-state attack frameworks are built on publicly available tools and techniques.
If the Pall Mall Process successfully constrains commercial vendors, it might accidentally accelerate the exact proliferation it's trying to prevent—just in a form that's completely invisible to regulators.
The consultation revealed something telling: "existing reputational damage to the industry had made little change to overall business practices, and only impacting profits could affect market change." Translation: marginal friction doesn't work.
But here's a thought experiment: Would we accept making offensive tools slightly easier to access if doing so made every transaction completely transparent and traceable?
I'd argue yes. Visibility often matters more than friction—especially when sophisticated actors have unlimited alternative pathways.
If the goal is protecting journalists, activists, and dissidents from surveillance abuse, are we addressing the root cause or the symptoms?
The root cause is authoritarian governments abusing surveillance powers. Commercial spyware is just one tool in their arsenal. Remove commercial tools tomorrow, and those same governments will either build alternatives or acquire them through gray markets—with far less transparency than the current commercial ecosystem provides.
Both the US and UK already have robust enforcement mechanisms for addressing bad actors: sanctions, export controls, and entity listings. These tools work already (for commercial entties doing business in these countries).
What we're witnessing is security theater—the appearance of addressing human rights abuses while actually:
Legitimizing government surveillance through "responsible use" frameworks
Avoiding confrontation with the actual problem actors
The fundamental contradiction is trying to solve a governance problem (abuse of power) with a technology regulation approach (controlling tools), while excluding the governments causing the problem from any meaningful constraints.
If we actually wanted to address surveillance abuse, here's what a serious framework might look like:
Mandatory Transparency: Real-time reporting of all surveillance tool acquisitions and deployments, with public oversight mechanisms similar to PDMPs.
Empirical Baselines: Establish measurable metrics for surveillance abuse before implementing solutions.
Enforcement Mechanisms: Use existing sanctions and export control tools against governments that abuse surveillance powers, not just vendors.
I'm not arguing that commercial spyware regulation is inherently wrong. I'm arguing that the current approach is solving the wrong problem in the wrong way, potentially making surveillance abuse less visible and harder to track.
If the Pall Mall Process wants to protect human rights, it needs to start with honest analysis of what's actually happening, who's causing harm, and what interventions would actually reduce that harm rather than just displacing it.
The security research community wants to protect legitimate research while addressing real threats. But we need frameworks based on evidence, not assumptions—and solutions that address root causes, not just symptoms.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.