AI-Generated · inclusionai/ring-2.6-1t

The US has formally authorized private companies to carry out offensive cyber operations

Trump has signed a presidential memorandum that creates a formal framework for private companies to conduct offensive cyber operations against transnational criminal organizations. The program's structure is public; its boundaries are not.

The US has formally authorized private companies to carry out offensive cyber operations
U.S. Air Force Capt. Yareem Lee, deputy branch chief with Pacific Air Forces Headquarters Offensive Cyber Operations, collaborates on cyber defense tactics during a cyber defense exercise at Exercise Balikatan 2026, April 2026. This file image illustrates the U.S. military's offensive cyber operations capability — the same domain the article discusses regarding new authorization for private companies.
Photo: U.S. Air Force photo by Senior Airman Raina Dale, Public Domain

On August 12, President Trump signed a National Security Presidential Memorandum authorizing vetted private US companies to conduct offensive cyber operations against foreign transnational criminal organizations. The memo establishes a framework in which private sector companies can enter into agreements — with federal agencies and with each other — to gather threat intelligence on transnational criminal organizations and propose cyber operations against them, all under the direction and oversight of the federal government.

The memorandum authorizes vetted companies to conduct operations against foreign transnational criminal organizations under federal government direction and oversight. The program operates out of a National Coordination Center and is led by two Program Executive Directors drawn from the Department of Justice and the Department of Homeland Security. Participating companies must maintain a $1 million surety bond and undergo rigorous vetting before they are authorized to conduct either Cyber Surveillance Operations or Cyber Effects Operations.]

Operations must be approved by the Program Executive Directors before execution and are barred from causing what the memo defines as Critical Outcomes. The specific thresholds that separate a permissible cyber effect from a Critical Outcome are not detailed in the public text of the memorandum.

What the NSPM describes, then, is not a bug bounty or a threat-sharing arrangement. It is a licensing structure for offensive cyber capability — one in which private companies are authorized to strike at targets on behalf of, and under the supervision of, the US government. There is a long American tradition, dating to the Constitution itself, of authorizing private parties to exercise what would otherwise be sovereign power: letters of marque, private military contractors, government contractors operating surveillance aircraft. But the cyber domain introduces a difference in kind rather than simply in scale. A private military contractor operates in physical space, subject to the rules of engagement and the laws of armed conflict. A Cyber Effects Operation operates against infrastructure that may span multiple jurisdictions, may be entangled with civilian systems, and may produce cascading effects that are difficult to predict or contain.

The question of what happens when a private actor’s offensive operation produces unintended consequences in a third country’s networks is one the memorandum gestures toward through its oversight requirements but does not fully resolve. The framework also allows companies to propose operations, not merely to execute assignments handed down by the government — which introduces an additional layer of complexity. Companies are identifying targets and developing proposals for authorization, much as a defense contractor might propose a weapons system to the Pentagon rather than simply following a general’s order.

Private sector companies can enter into agreements with both private and federal entities to gather threat intelligence on transnational criminal organizations, with operations limited to those approved by the Program Executive Directors and barred from causing Critical Outcomes. The language of “Cyber Effects Operations” is notably broad. In the cybersecurity field, “effects” can range from disrupting a command-and-control server to degrading an adversary’s operational capability, and the line between a proportionate disruption and an unacknowledged offensive action is not always bright.

What makes this development genuinely significant is not merely that private companies will be hacking criminal networks — many already do in an ad hoc fashion, and the cybersecurity industry has long argued that defense is structurally disadvantaged against criminal actors who move faster than government procurement cycles allow. What is new is the formalization: the creation of a standing program with an institutional structure, an approval process, and a legal framework that acknowledges private offensive cyber capability as a legitimate instrument of state policy. Whether this proves to be a more effective tool against transnational cybercrime or a template for further blurring the line between government action and private strike capability will depend almost entirely on the details that are not yet public — the specific authorities granted, the oversight mechanisms that function in practice, and the criteria by which Critical Outcomes are defined and enforced.

Sources