Washington is preparing to give vetted US cybersecurity firms a role in offensive operations against foreign cybercriminal groups.
President Donald Trump signed a National Security Presidential Memorandum on Wednesday directing the federal government to establish a program under which vetted U.S. firms could conduct cyber surveillance and “cyber effects” operations against foreign cyber-enabled transnational criminal organizations (TCOs).
The memo acknowledges that the “American private sector is the most innovative and technologically advanced in the world,” but that its capabilities have “historically been underutilized” in efforts to disrupt criminal networks. The White House said American consumers reported more than $20.8 billion in losses from cyber-enabled crime in 2025, with 73% of US adults experiencing some form of online scam.
How the program operates
The program, managed by the Homeland Security Task Force’s National Coordination Center (NCC) and overseen by co-Executive Directors from the DOJ and DHS, allows “Participating Companies” to conduct both surveillance and effects operations. Under the memo, “Cyber Effects Operation” includes the potential “manipulation, disruption, denial, degradation, or destruction of information systems, networks, [and] physical or virtual infrastructure.”
To qualify, firms must contract with the federal government and undergo rigorous vetting. The DOJ or DHS may also require participating companies to maintain a bond or escrow of at least $1 million, forfeitable for contractual noncompliance.
The NCC has 60 days to establish operating procedures, and every proposed operation requires written approval, ensuring “any resulting operational action will be exclusively conducted on behalf of and under the supervision of the Federal Government.”
The risk calculus
Despite the government oversight, the initiative has drawn skepticism from cybersecurity veterans. The concept, described by Ari Redbord of TRM Labs as effectively granting “cyber letters of marque,” resurrects fears about escalation and collateral damage, according to Bloomberg’s report.
“Avoiding collateral damage is extremely hard,” warned Pareekh Jain, CEO of Pareekh Consulting, per CSO, noting that criminals often “hide inside real company networks, hack smart home devices, and rent standard cloud servers using stolen credit cards.”
Microsoft’s Nick Carr highlighted the core issue of attribution, stating: “My biggest concern with private sector offensive action vs crime… is just how difficult attribution in criminal operations is… People are regularly and willingly wrong on pretty important incidents.”
The memorandum does not expressly grant participating companies immunity or indemnification. However, that does not establish that contractors will bear all liability; the allocation of risk may depend on government contracts, implementing procedures, insurance coverage, and applicable law.
For cybersecurity firms considering participation, the unresolved questions include responsibility for collateral damage, incorrect attribution, retaliation, and operations affecting third-party infrastructure. CISOs should also examine whether threat intelligence shared with participating companies could later support government-approved surveillance or disruption operations.
More detail should emerge when the NCC publishes its operating procedures, which are due within 60 days. Until then, liability, indemnification, data use, and insurance coverage remain open questions.
Read more: Autonomous AI Defense: It’s Time to Take AI Off the Leash examines the risks and potential benefits of allowing defensive systems to act with less human intervention.





