The White House has issued a National Security Presidential Memorandum (NSPM) on August 12, authorizing federal law enforcement agencies to partner with private companies in conducting offensive cyber operations against foreign threat actors targeting the United States. This directive expands upon an Executive Order from March, which mandated aggressive measures by government agencies to combat cyber-enabled crime affecting Americans.
The NSPM acknowledges the private sector's advanced technological capabilities, which it states have been historically underutilized in efforts to disrupt cybercriminal networks. The new memorandum aims to integrate these capabilities into such operations.
To oversee these activities, the Homeland Security Task Force’s National Coordination Center (NCC) will establish a program led by two Executive Directors from the Department of Justice and the Department of Homeland Security. This framework will allow private sector companies to form agreements with other firms and government bodies at federal, state, and local levels. These agreements will facilitate intelligence gathering on transnational cybercrime groups and the proposal of cyber operations designed to disrupt their activities.
The memorandum specifies that "rigorous procedures" will be implemented for the review and execution of "limited" cyber operations, which will always be conducted under the direct supervision of the U.S. government. It also emphasizes that the program will adhere to the U.S. Constitution, relevant laws, and international agreements.
The White House justifies this expanded approach by citing the significant financial damage inflicted on American businesses and individuals by cyberattacks. In 2025, American consumers reportedly lost over $20.8 billion to cyber-enabled crime, with 73% of U.S. adults experiencing some form of online scam or attack. The administration argues that "every available tool" must be deployed to counter these transnational cyber threats.
The cybersecurity community has offered mixed reactions to the NSPM. Chris Wysopal, co-founder of Veracode, characterized the policy as a "big shift" in U.S. cyber strategy, noting it represents a significant expansion of the private sector's role in offensive cyber operations, even if not explicitly "hack back" actions.
However, concerns have been raised regarding the risks associated with private sector involvement in offensive cyber strikes. These include the potential for misidentification of targets and the possibility of escalating cyber hostilities rather than deterring them. Nick Carr, technical director for the Microsoft Threat Intelligence Center (MSTIC) team and former chief technical analyst at CISA, highlighted the inherent difficulty in accurately attributing cybercrime, even for government agencies. He expressed concern that many organizations frequently make errors in attribution, though he suggested the new program could mitigate this by improving attribution work.
Dr. Lukasz Olejnik, an independent cybersecurity and privacy researcher, cautioned that authorizing the destruction of cyber-controlled infrastructure could inadvertently affect state-linked systems, potentially increasing the risk of interstate escalation and conflict.
The United Kingdom has also moved to facilitate offensive cyber actions to disrupt cybercriminal groups, establishing the National Cyber Force (NCF) in 2020. In 2023, the UK government published principles for the NCF's use of these capabilities, stressing that such measures would be deployed sparingly, only when other responses are less effective.






