The U.S. government is creating a program that will allow vetted American companies to participate in federally directed cyber operations against foreign criminal organizations — expanding the private sector’s role from cyber defense toward active disruption.

WHAT’S HAPPENING

President Donald Trump signed a National Security Presidential Memorandum on August 12 directing the government to create a program that brings vetted U.S. companies into cyber operations targeting foreign cyber-enabled transnational criminal organizations. (The White House)

The program will be run through the National Coordination Center and overseen jointly by the Department of Justice and Department of Homeland Security.

Participating companies may be involved in cyber surveillance operations as well as cyber effects operations capable of manipulating, disrupting, degrading or destroying targeted computer systems, networks or data. (The White House)

This is not permission for companies to independently attack suspected hackers. Operations must be conducted under federal direction and oversight, and individual operations require written government approval before action can be taken. (The White House)

WHY IT MATTERS

For years, private cybersecurity companies have largely focused on protecting networks, detecting attacks and helping organizations recover after breaches.

This program creates a pathway for selected companies to participate more directly in disrupting the infrastructure used by foreign criminal groups.

The administration argues that private companies possess technical capabilities, speed and expertise that could strengthen U.S. efforts against ransomware, financial fraud and other international cybercrime. (The White House)

But offensive cyber operations also introduce risks.

Cyber attribution can be difficult, infrastructure can be shared by multiple parties, and actions taken against systems overseas can create legal, diplomatic or retaliation concerns. Those risks are part of why the memorandum requires federal supervision and additional safeguards.

WHO BENEFITS

U.S. law enforcement gains access to additional private-sector cybersecurity expertise and capabilities.

Cybersecurity companies that qualify for the program could gain a new role in government cyber operations.

Businesses and individuals targeted by ransomware and international cybercrime could benefit if operations successfully disrupt criminal infrastructure before additional attacks occur.

WHO LOSES

Foreign cybercriminal organizations targeted by the program could face disruption of their networks, infrastructure and data.

Participating companies also take on new risks. Offensive operations can carry greater legal, operational and cybersecurity consequences than traditional defensive work.

There is also the possibility of unintended effects if a target is incorrectly identified or criminal infrastructure overlaps with legitimate systems.

WHAT HAPPENS NEXT

The government has 60 days from the August 12 memorandum to establish detailed operating procedures, including technical standards, company vetting, target identification and safeguards for operations. (The White House)

Companies may also be required to maintain a bond or escrow of at least $1 million, which can be forfeited for violating their contractual requirements. Every proposed operation must receive government review and written approval. (The White House)

The biggest question will be how aggressively the program is ultimately used.

The United States is not simply asking private companies to build better cyber defenses.

It is creating a framework for some of them to help the government go after the networks behind the attacks.

Stay Sharp

Subscribe to follow the Trend newsletter and more.

Have a tip or idea?

Pass along insights or story ideas on AI, startups, and business. Focused on signal over noise, impact over headlines. Facts. Trends. Consequences. Always.