The U.S. government has formally authorized private cybersecurity firms to conduct offensive cyber operations against transnational criminal networks, acting under government direction and oversight. President Trump signed a national security memorandum on August 13, establishing a program to leverage the private sector's capabilities in combating cybercrime.
The new program, managed by the National Coordination Center, encompasses both intelligence gathering, termed "Cyber Surveillance Operations," and active disruption of criminal infrastructure, referred to as "Cyber Effects Operations." This initiative formalizes a strategy outlined in the White House's Cyber Strategy for America, which aimed to utilize the private sector as an offensive cyber instrument.
According to the memorandum, the policy's intent is to employ all instruments of national power, including the private sector's innovative capabilities, to combat cybercrime. This partnership with vetted U.S. companies, subject to federal government direction and oversight, is expected to enhance the nation's ability to counter threats from "Cyber-Enabled Transnational Criminal Organizations" and combat various predatory schemes against American citizens.
The program specifically targets foreign groups engaged in cyber-enabled crime against U.S. interests. It explicitly excludes entities that are institutional parts of foreign governments or wholly operated under foreign government direction, aiming to distinguish criminal networks from nation-state adversaries. The memorandum clarifies that a group is presumed not to be government-directed unless clear intelligence indicates otherwise.
A "Cyber Effects Operation" is defined as activity conducted through information technology infrastructure that results in the manipulation, disruption, denial, degradation, or destruction of information systems, networks, or associated infrastructure.
Each operation requires co-approval in writing from executive directors within the Department of Justice and the Department of Homeland Security before any action is taken. Operations that could lead to "Critical Outcomes" necessitate additional authorization beyond these program executive directors, acknowledging that certain cyber actions may fall under the laws of armed conflict.
Participating companies must undergo rigorous vetting, demonstrate technical proficiency, and submit to annual evaluations. They are also required to maintain a bond or escrow of at least $1 million, which can be forfeited if contract terms are violated. Operational procedures are slated to be finalized within 60 days.
The Department of Justice will review any operation that involves a U.S. person or raises domestic constitutional questions. A key legal consideration for the program is whether the Computer Fraud and Abuse Act (CFAA) exemption for lawfully authorized government investigative activities extends to private companies operating under government contracts. Legal analysis suggests this exemption likely applies when companies act under direct government direction, but not for independent offensive operations without such oversight. To address this, the memorandum emphasizes explicit government control at every stage, requiring written approval for all operations, immediate cessation and notification for any unintended contact with a U.S. person or system, and continuous involvement from the Justice Department.






