Top 5 This Week

Related Posts

White House launches program to let vetted U.S. companies run government‑directed cyber surveillance and disruption operations

The White House on Aug. 12 ordered creation of a federally overseen program that will allow vetted U.S. private companies to perform cyber surveillance and cyber effects operations against foreign transnational criminal organizations (TCOs), the administration said in a presidential memorandum.

Key takeaways

  • The White House directed the National Coordination Center to create a program allowing vetted U.S. companies to conduct government‑directed cyber surveillance and cyber effects operations against foreign transnational criminal organizations.
  • The Program will be overseen by co‑Executive Directors from DOJ and DHS, require contractual vetting, and prohibit operations that would cause "Critical Outcomes."
  • The memorandum sets procedural and legal guardrails but leaves open several operational and oversight questions, including company selection, attribution safeguards and Congressional review.

What the memorandum does

The memorandum tasks the Homeland Security Task Force’s National Coordination Center (NCC) with building, managing and maintaining a Program to authorize Participating Companies to carry out two types of operations under federal control and oversight: Cyber Surveillance Operations and Cyber Effects Operations. The directive frames the effort as an expansion of tools to fight transnational cyber‑enabled crime — including ransomware, phishing, impersonation, financial fraud and sextortion campaigns that target Americans.

Program oversight will be split between two co‑Executive Directors: one designated by the Attorney General from the Department of Justice (DOJ) and one designated by the Secretary of Homeland Security from the Department of Homeland Security (DHS). The Program Executive Directors will approve operations after coordinating with each other, though they are explicitly barred from approving operations that would cause so‑called “Critical Outcomes” — actions likely to cause loss of life, serious injury, or to rise to the level of use of force or armed attack under international law.

Eligibility, safeguards and procedural requirements

The memorandum requires Participating Companies to enter contractual agreements with DOJ or DHS and subjects them to “rigorous vetting” and performance standards. Within 60 days the Program Executive Directors, working with the Homeland Security Council, must issue consensus operating procedures that set minimum standards for technical proficiency, security, personnel vetting and other factors. The procedures are to allow participation by both large and smaller firms.

Other notable requirements spelled out in the document include:

  • Companies must disclose contractual relationships with private entities and with federal, state, local, tribal and territorial agencies that supply threat information to inform proposed operations.
  • DOJ and DHS may require Participating Companies to maintain a bond or escrow of not less than $1 million, forfeitable for contract non‑compliance.
  • Operations must comply with the Constitution, U.S. law (including the Computer Fraud and Abuse Act, 18 U.S.C. §1030, as cited in the memorandum) and applicable international obligations.
  • If a company discovers it has unintentionally targeted a U.S. person, U.S.‑resident system, or a system under U.S. person control, the company must stop, run minimization procedures and notify the NCC, which then notifies DOJ.

Role for private companies and intelligence sharing

The memorandum envisions Participating Companies forming commercial agreements with other private entities to receive threat information gathered in the normal course of business and with government agencies that identify CE‑TCO threats. Those companies may then propose operations to the NCC that address those threats, but any operational action will be conducted exclusively on behalf of and under supervision of the federal government.

Reactions and concerns documented in reporting

Coverage from multiple outlets noted the shift in U.S. cyber policy toward expanded private‑sector operational roles and recorded a mix of support and caution from the cybersecurity community. Some observers welcomed broader public‑private collaboration for disrupting criminal networks. Others warned about attribution challenges and escalation risks when offensive cyber tools are used.

For example, reporting referenced comments by cybersecurity practitioners stressing that reliable attribution of criminal actors is difficult and errors could produce harmful outcomes. Independent researchers also cautioned that offensive operations — even when aimed at criminal infrastructure — risk affecting state‑linked systems and provoking interstate escalation. Those reactions were reported by news outlets summarizing commentary from cybersecurity professionals; the memorandum itself does not contain outside commentary.

Context: why the administration says this is necessary

The memorandum cites the March 2026 Executive Order on combating cybercrime and frames the private sector as an underused source of technical capacity and speed. White House materials and subsequent reporting highlighted FBI data showing American consumers reported losing more than $20.8 billion to cyber‑enabled crime in 2025; the memorandum frames the program as a tool to reduce such harms by targeting foreign CE‑TCOs that perpetrate frauds against U.S. persons and businesses.

The memorandum requires program activities to be carried out in accordance with the Constitution and applicable law, and it directs the executive branch to produce implementing procedures within 60 days. But several important details remain unresolved in the public documents and media reports:

  • Which specific companies will be accepted into the Program, and how the vetting process will be applied in practice.
  • The exact legal authorities under which particular operations will be justified and how those authorities will be coordinated across DOJ and DHS for investigative, protective, or intelligence purposes.
  • How the Program will mitigate risks of misattribution or unintended collateral effects on third‑party or state‑linked infrastructure that could raise escalation or international law concerns.
  • How transparency, Congressional oversight and reporting back to the public will be handled, including whether and how classified elements will be reviewed by independent bodies.

Practical implications for U.S. companies and the public

For companies, participation would mean entering a contractual relationship with a federal department, subjecting them to government control of operations and to vetting, bonds and annual reviews. Firms that gather threat intelligence as part of their business could play a more direct role in proposing and informing government‑directed operations. For the public, the administration presents the program as an effort to reduce the direct financial harms that cybercrime causes U.S. consumers and businesses.

Timeline and next steps

  1. Aug. 12, 2026: Presidential memorandum directing establishment of the Program (date as stated in the White House notice).
  2. Within 60 days: Program Executive Directors must issue consensus operating procedures in coordination with the Homeland Security Council.
  3. Following issuance of procedures: the NCC will begin vetting companies, negotiating contracts with DOJ or DHS, and accepting proposed operations that meet the agreed standards and legal requirements.

What remains to watch

Watch for the operating procedures the Program Executive Directors publish, announcements of initial Participating Companies, details on the bond/escrow requirements and any Congressional or judicial review that might arise. Media reports and cybersecurity experts’ commentary will be key to tracking how the program handles attribution, oversight and international risk.

“This memorandum shall be implemented consistent with applicable law and subject to the availability of appropriations.”

That phrase, included in the White House notice, underscores that many operational and legal constraints will depend on subsequent agency guidance and on available resources. The administration has signaled the intent to use private‑sector capabilities to supplement federal authorities; how that balance will work in practice is now a matter of detail and oversight to be defined in the coming months.

Popular Articles