The Trump administration has issued a National Security Presidential Memorandum authorizing private security firms to conduct offensive cyber operations against overseas criminal organizations. The program, managed by the National Coordination Center under the Homeland Security Task Force, marks the first time the US government has formally delegated offensive cyber authority to the private sector.
Under the memorandum, vetted security companies can conduct surveillance and disruption operations against Transnational Criminal Organizations (TCOs) that target US interests. The definition covers any foreign group conducting cyber-enabled crime against the US government, US persons, or US interests that is not acting as an institutional arm of a foreign government. Eligible targets include ransomware gangs, sextortion networks, phishing operations, financial fraud rings, and impersonation scams.
The authorized actions fall into two categories: Cyber Surveillance Operations (monitoring and intelligence gathering) and Cyber Effects Operations (active disruption). Companies may use tactics including deploying spyware, destroying criminal data and systems, launching DDoS attacks, and using encryption to lock targets out of their own infrastructure. However, operations must not result in what the memorandum defines as “Critical Outcomes” — loss of life, serious injury, or actions that rise to the level of armed attack under international law.
How it works
Security firms must be vetted by the Departments of Justice and Homeland Security against minimum standards covering technical proficiency, proven cyber operations experience, facility security, personnel vetting, and reliability. Each participating firm must deposit $1 million into an escrow account that is forfeited if the company breaches its contractual obligations.
The memorandum gives DOJ and DHS 60 days to deliver detailed operational guidelines. This means the program is not yet active — the framework is established but the specifics of how firms apply, how operations are approved, and how oversight works are still being worked out.
What makes this different from existing arrangements is the removal of case-by-case prior approval. Currently, if the government wants a private firm to conduct an offensive cyber operation, it requires separate legal authorization for each action. This memorandum establishes a standing framework where vetted firms can operate within defined parameters without needing fresh approval for every individual action.
Industry reaction
The response from security researchers has been mixed. Kevin Beaumont noted a potential conflict of interest, observing that “a lot of companies have made a lot of money from ransomware, so putting them in charge of stopping it seems optimistic.” Others have raised concerns about accountability and oversight — what happens when a private firm’s operation causes unintended collateral damage, and who bears responsibility?
Supporters argue that government cyber operations are too slow and resource-constrained to keep up with the scale of transnational cybercrime. Private firms, particularly those already running threat intelligence and incident response operations, have the infrastructure and expertise to act faster. The question is whether the incentive structure works: a firm that earns money responding to ransomware attacks also has a financial interest in keeping ransomware viable.
What this means
For organizations defending against cybercrime, the near-term impact is probably minimal. The program is still in the rulemaking phase with 60 days before operational guidelines are published. Even after that, the number of vetted firms and the scope of their operations will take time to scale.
The longer-term implications are significant. This establishes a legal framework for private offensive cyber operations that could outlast the current administration. Future administrations could expand or contract the program, but the precedent of delegating offensive authority to the private sector is now set. For security teams, the key takeaway is that the line between public and private sector cyber operations is blurring, which will create new questions about liability, attribution, and oversight that the industry has not fully grappled with.
Practical concerns for defenders
If you work in security operations, this program creates a few things to watch. First, the legal landscape around offensive actions is about to get more complicated. Private security firms conducting operations overseas may operate in different jurisdictions with different laws, and the results of their actions could affect networks or systems that defenders are trying to protect. Incident responders may find themselves dealing with fallout from private-sector offensive operations they did not know about and cannot control.
Second, the escrow and vetting requirements are a high barrier to entry. The $1 million deposit and DOJ/DHS vetting process will limit participation to well-funded, established firms. That reduces the risk of fly-by-night operators abusing the authority, but it also concentrates offensive capability in a small number of companies. Whether that concentration is a net positive or negative for the overall security landscape depends on how well those companies are managed and audited over time.
Third, the memorandum’s restriction on “Critical Outcomes” creates a gray zone. Loss of life and armed attack are clear red lines, but there is a lot of room between those and minor disruption. What counts as acceptable collateral damage when disrupting a ransomware gang’s infrastructure? Who decides, and what recourse exists if a private firm oversteps? The 60-day rulemaking period is supposed to answer these questions, but the answers will likely be tested in practice before they are fully settled.