US Opens Offensive Cyber Operations to Vetted Private Firms

US policy will allow vetted private firms to conduct limited offensive cyber operations against foreign criminal groups under direct federal supervision.

Aug 14, 2026 - 05:08
 2
US Opens Offensive Cyber Operations to Vetted Private Firms
Image Credit: Chatgpt

The U.S. government is creating a program that will allow vetted private companies to participate in offensive cyber operations against foreign criminal organisations, expanding the private sector’s role beyond traditional cybersecurity defence.

President Donald Trump signed a national security presidential memorandum on Aug. 12 directing the federal government to establish the program. Participating U.S. companies will be allowed to conduct cyber surveillance and disruptive operations against designated foreign cyber-enabled transnational criminal organisations, but only under federal direction and supervision.

Private firms could join offensive cyber operations

The program will be managed through the Homeland Security Task Force’s National Coordination Centre and overseen jointly by officials from the Justice Department and Department of Homeland Security.

The memorandum defines cyber surveillance operations as activities intended to collect intelligence from targeted systems, including access obtained without the system owner’s authorisation. A separate category, called cyber effects operations, can involve manipulating, disrupting, denying, degrading or destroying information systems, networks or information stored on them.

Those authorities do not amount to a general permission for companies to attack hackers independently. Every operation conducted under the program must be carried out on behalf of the U.S. government and under its supervision, according to the memorandum.

The two federal program directors will review proposed operations and must provide written approval and direction before a participating company can act. The program is also required to coordinate operations across federal law enforcement, national security agencies and other parts of the government.

Companies will face vetting and financial requirements

The administration has given officials 60 days to establish operating procedures and eligibility standards. Companies seeking to participate will be evaluated on factors including technical capabilities, previous cyber operations, facility security, personnel vetting, competence and reliability.

The rules are supposed to accommodate both large companies with significant technical capacity and smaller firms that may be better suited to specialised assignments.

The Justice Department and Homeland Security will also be able to require participating companies to maintain a bond or escrow account of at least $1 million. That money could be forfeited if a company fails to comply with its contractual obligations under the program.

Companies will be reviewed at least annually to determine whether they should remain eligible. They will also be required to report information about their operations to the government.

Safeguards aim to protect U.S. people and systems

The memorandum requires the program to operate in accordance with the Constitution, federal law and applicable international obligations. It specifically references Section 1030 of Title 18, the federal computer crime statute commonly associated with unauthorised computer access.

Additional procedures must address situations in which an operation unintentionally reaches a U.S. person, a computer system located in the United States or a system controlled by a U.S. person. If that happens, the participating company must stop the affected activity, carry out required minimisation procedures and immediately notify the National Coordination Centre.

Companies must also alert the government if they discover an imminent cyberattack against U.S. critical infrastructure. Similar reporting is required if an approved operation could result in what the memorandum calls a critical outcome, including serious injury, loss of life or activity that could rise to the level of an armed attack under international law.

The policy stops short of unrestricted hackback

The framework represents a significant expansion of the federal government’s ability to use private cybersecurity capabilities. Still, it does not authorise companies to independently retaliate against attackers encountered in the course of normal business operations.

Outside the program, companies remain subject to existing U.S. computer crime laws. Activities authorised through the new framework must rely on federal legal authorities and remain under government operational control.

The White House said the initiative is aimed at foreign organisations responsible for cyber-enabled crimes targeting Americans, including ransomware, phishing, financial fraud, impersonation scams and sextortion.

The administration argues that private cybersecurity companies possess technical expertise that has not been fully used in efforts to disrupt criminal networks operating overseas. The new framework is intended to allow that expertise to be applied directly against selected targets while keeping final authority with the federal government.

Details of the program are still being developed

Important operational questions remain unanswered while the government develops its implementation guidance. The memorandum includes a classified annex covering parts of the targeting and operational process, meaning some details about how missions will be selected and coordinated are not public.

Private-sector participation in offensive cyber activity has long raised concerns about unintended consequences, escalation and coordination with other government operations. The administration’s framework attempts to address those risks by requiring centralised approval and direct federal supervision rather than granting companies independent authority to retaliate.

The program directors must submit an initial status report within 180 days of the memorandum and provide additional reports annually. Until the operating procedures are completed and companies are admitted, the policy remains a framework for future operations rather than an open authorisation for private firms to begin conducting cyberattacks on their own.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Shivangi Yadav Shivangi Yadav reports on startups, technology policy, and other significant technology-focused developments in India for TechAmerica.Ai. She previously worked as a research intern at ORF.