Experts debate Access-as-a-Service spyware industry
Atlantic Council panel discusses NSO Group's Pegasus, the Access-as-a-Service surveillance industry, and its national security and human rights implications.
This is a policy discussion piece from the Atlantic Council's Cyber Statecraft Initiative, featuring a panel of five experts discussing the commercial spyware and "Access-as-a-Service" (AaaS) industry roughly one year after the US Commerce Department added NSO Group and three other companies to its Entity List. The article references NSO Group's Pegasus spyware being used by foreign governments to target journalists, activists, and even US diplomats and Embassy staff in Uganda, as well as reporting that the FBI briefly considered but ultimately declined to license Pegasus for domestic use.
The panelists—drawn from Citizen Lab, the Atlantic Council, the Norwegian Institute of International Affairs, MITRE, and Copenhagen Business School—explore how commercial surveillance and offensive cyber capabilities (including zero-day exploits) are packaged and sold to state and non-state customers, blurring lines between domestic and foreign surveillance, and between government and corporate data collection. They discuss the national security risks posed to the US and allies, the difficulty of regulating a globalized and increasingly professionalized industry, and calls for the US and EU to develop norms and enforcement mechanisms against abusive vendors.
This is an opinion/analysis piece rather than an incident report — there are no specific IOCs, exploited vulnerabilities, or newly disclosed malware. It is included here as background threat-landscape context on the commercial spyware and hack-for-hire ecosystem, referencing known past cases (NSO Group/Pegasus, Project Raven, targeting of Omar Abdulaziz) rather than a new campaign.
Mentioned in this report
Source reporting: https://www.atlanticcouncil.org/content-series/the-5x5/the-5x5-the-rise-of-cyber-surveillance-and-the-access-as-a-service-industry
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free