19 September 2026

Curbing the proliferation of commercial spyware starts at the demand-side

Clingendael Institute | Myrthe de Boon

Commercial spyware tools like NSO Group's Pegasus and Paragon's Graphite enable states to conduct intrusive offensive cyber operations, threatening international security and fundamental human rights. Initiatives like the United Kingdom and France-led Pall Mall Process aim to establish multi-stakeholder governance frameworks for cyber intrusion capabilities. Industry codes of practice remain fundamentally insufficient without rigorous demand-side procurement oversight, authorization mechanisms, and strict state accountability.

Voluntary norm-generating initiatives routinely suffer from a severe implementation deficit between formal commitments and domestic enforcement practices. Enforcement gaps persist worldwide. Within the European Union, robust legal architecture exists on paper yet fails in practice when national political will is absent. The targeting of figures like European Parliament President Roberta Metsola and former Taiwanese President Tsai Ing-Wen illustrates the expanding reach of unregulated market proliferation. Effective governance requires combining domestic legislative reforms with geographically representative global capacity-building measures to prevent vendor relocation to permissive jurisdictions.

Comment

Commercial cyber intrusion platforms like Cytrox's Predator lower the technical threshold for state-sponsored espionage, enabling resource-constrained foreign intelligence services to conduct targeted standoff collection without developing bespoke exploitation frameworks. This democratisation of zero-day exploits expands the threat surface for sovereign institutions, as demonstrated by the compromise of European Parliament President Roberta Metsola. The reliance on off-the-shelf surveillance tools shifts the intelligence balance from high-end national technical means toward outsourced, commercial capabilities.

This commercialisation fragments traditional counterintelligence oversight, as target selection is governed by client state legal mandates rather than vendor end-user license agreements. Consequently, counter-espionage agencies face heightened friction in attributing intrusions, particularly when commercial vendors like NSO Group route target traffic through multi-jurisdictional proxy infrastructure.

Strategic Question for Discussion
If commercial surveillance vendors like NSO Group continue routing targeted traffic through multi-jurisdictional proxy networks, does traditional counterintelligence attribution still hold, or does it collapse into legal ambiguity?
The pattern suggests that multi-jurisdictional proxy routing permanently degrades rapid technical attribution, forcing counterintelligence services to rely more heavily on signal metadata and HUMINT corroboration. While technical forensics can identify the underlying commercial framework, assigning state responsibility becomes protracted when client command-and-control infrastructure is intentionally obfuscated across foreign server networks.
Share your assessment in the comments below.