Full story
Private firms get cyber role
President Donald Trump signed a national security presidential memorandum directing the National Coordination Center to establish a program that will authorize vetted U.S. companies to conduct cyber surveillance operations and cyber effects operations against foreign transnational criminal organizations, or TCOs, that target American citizens, businesses and critical infrastructure.
“authorize vetted U.S. companies to conduct cyber surveillance and cyber effects operations”
The memo says the program will run under joint Justice Department and DHS oversight, with two program executive directors—one designated by the attorney general and one by the secretary of the Department of Homeland Security—coordinating before approving any cyber operation.

The program executive directors are barred from approving operations expected to produce critical outcomes, defined as actions likely to cause loss of life, serious injury, or conduct that rises to the level of use of force or armed attack under international law.
A fact sheet accompanying the Thursday memo listed ransomware, sextortion schemes, phishing campaigns, financial fraud, and impersonation scams as activities eligible for private-sector security firms to target.
The Guardian described the policy shift as giving private companies “limited cyber operations at the direction of the US government,” while directing DHS, through the homeland security taskforce’s national coordination center, to create a program “to conduct specific cyber operations that disrupt foreign TCOs.”
Oversight, vetting, and limits
The memo framework requires participating companies to be vetted and to operate under federal direction and oversight, with the Departments of Justice and Homeland Security providing oversight of the program.
The program executive directors must provide mandatory written approval before any operation may proceed, and the memo directs them to work with the Homeland Security Council to finalize consensus operating procedures within 60 days.
Participating companies must post a bond or escrow requirement of at least $1 million, which companies risk forfeiting if they fall out of compliance with their government contract.
The Guardian quoted the memo’s definition of cyber effects as “the potential manipulation, disruption, denial, degradation or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems.”
The Record from Recorded Future News said the memorandum makes clear that officials will not sanction any operation that results in either the loss of life or “rise to the level of use of force or armed attack under international law.”
Stakes for companies and policy
The memo’s structure is designed to incorporate “the ingenuity of the private sector” into federal efforts to counter cyber-enabled crime, with the White House saying it will enhance the ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens.
“myriad legal challenges and perils”
The Guardian reported that the DHS and the White House did not immediately respond to requests for additional details about the program, even as the policy shift creates a framework for companies to enter into agreements with other private entities and federal, state, local, tribal and territorial agencies.
Cybersecurity Dive described the program as introducing “myriad legal challenges and perils,” noting that the new policy could expand the U.S. government’s ability to disrupt criminal groups’ cybercrime activities while also blurring the line between government foreign policy activities and businesses’ commercial activities.
The memo also sets a boundary around “Critical Outcomes,” and the program’s leaders cannot authorize surveillance or disruption operations that would kill or seriously injure people or constitute the use of force or an armed attack under international law.
In a statement quoted by the Record from Recorded Future News, Congressman Bennie Thompson (D-MS) said, “the proper venue to address this challenge is through the Administration working with Congress to ensure the necessary authorities, legal procedures, and resources are in place rather than a presidential memorandum that raises as many questions as it answers.”




