Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Spyware - Nations Commit to Curbing the Spread of Spyware
Spyware Attacks Latest News News & Analysis Positive News

Nations Commit to Curbing the Spread of Spyware

Kirsten DoyleBy Kirsten DoyleApril 9, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Curbing the Spread of Spyware
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Following over a year of work on the agreement, twenty-one nations signed The Pall Mall Process in Paris to govern the use of spyware.   

The Pall Mall Process is an international, multi-stakeholder initiative aimed at identifying and implementing political commitments to counter the proliferation and irresponsible use of commercially available cyber intrusion capabilities—which often manifest as cyber mercenary activity.  

On 3 and 4 April 2025, France and the UK co-hosted the second Pall Mall Process conference in Paris. The event brought 45 States, international organizations, and a broad coalition of private sector actors, civil society representatives, and researchers together. 

During the conference, a groundbreaking code of good practice, initially endorsed by 21 States, was adopted, outlining voluntary political commitments and practical recommendations to address the growing threat.  

A few of the recommendations include: 

  • Finding ways to ban vendors who engaged in illicit behavior 
  • Developing regulations to make sure these technologies are used in necessary, lawful situations 
  • Creating policies that define the use of technology for cybersecurity purposes 
  • Encouraging vendors to publish coordinated vulnerability disclosure procedures 

A Shared Understanding 

The code of good practice reflects a shared understanding of the threat landscape among participating States, and reaffirms the relevance of existing international legal and normative frameworks. It also offers actionable guidance across various political domains.  

The initiative also supports the implementation of the United Nations framework for responsible State behavior in cyberspace and aligns with the principles of the Paris Call for Trust and Security in Cyberspace.  

The Pall Mall Process will continue to promote and disseminate these good practices, while monitoring their implementation over time. 

Serving a Greater Good  

“Many practitioners find spyware use by authorities to be controversial. Ultimately, technology has to serve a greater good purpose, otherwise what’s the point, right?” said Lawrence Pingree, VP of Dispersive.  

“Software providers – whether they provide offense or defense solutions – should have to uphold sanctions on specific countries,” Pingree added. “To me this is a no-brainer. Software providers should also focus on safeguards in the use of and authorization of use of their applications. Application logic, authorizing and Know Your Customer (KYC) steps can really help in validating use, which can validate authorized actions. This initiative seems like a good start to bridging the historical controversy gaps by focusing on advancing disclosure – which is a multi-faceted issue due to the complexities of cybersecurity, especially at the code level.” 

A Lack of Standardized Authorizations 

Evan Dornbush, former NSA cybersecurity expert, commented that the biggest aspect of The Pall Mall Process (PMP) is that governments are, for the first time, openly acknowledging they conduct offensive cyber operations, that they see a strategic advantage to them, and that they are creating a framework as to how to partner with the private sector to ensure they have access to the global pool of talent and products required to operate at peak performance.  

“The challenge here is that CCIC’s – a term that encompasses spyware – though legal to create and sell, may require certain authorizations to use that have never been standardized.  

Dornbush said the PMP seeks to create that framework, but it’s not complete. “What was signed by a few dozen nations is a commitment to adhere to criteria. This phase only applies to government behaviors, and what member nations should or must do.  The process is ongoing. The next phase will address industry criteria, which may shape up to create parallel and bifurcated markets.”If an industry player adheres to the criteria it can sell to the PMP Nations. If it does not, it cannot. Businesses will have to determine how valuable the PMP market is. 

There’s Still a Lot to Process 

“The obvious example here are those companies who sell to customers that target journalists. Continuing to sell in that manner locks out those vendors from selling to PMP Nations,” Dornbush added. “There’s still a lot to process. From the industry side, how can a vendor know what its customers are doing? It’s not like private sector can audit a classified user’s behavior. For example, what happens if a government user acts illegally? What happens if government user uses tech, as was the case with NotPetya, and ends up causing damage to a government’s citizens?” 

Dornbush explained that the laws of one country may not perfectly overlap with the laws of all the others. “Meanwhile, there really is no universal definition of the word ‘responsible’ so determining ‘responsible use’ may continue to be problematic.”  

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The VPN Trap: MuddyWater Upgrades Android Spy Tool for Wartime Espionage

July 22, 20253 Mins Read

WhatsApp Fights Back: NSO Spyware Verdict Ends in $167M Blow

May 8, 20253 Mins Read

Android Spyware Targets Russian Military via Trojanized Mapping App

April 25, 20252 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}