Key Takeaways
- The National Coordination Center will supervise private-sector cyber operations against foreign cyber-enabled criminal groups.
- Participating Companies will face federal vetting, written approvals, reporting duties, and potential financial penalties.
- The program moves public-private cyber cooperation beyond threat sharing and defense into government-controlled disruption.
President Donald J. Trump has directed the Federal Government to establish a program allowing vetted United States companies to conduct cyber surveillance and disruptive cyber operations against foreign criminal organizations.
The August 12 White House memorandum places the program within the National Coordination Center, or NCC. Participating Companies will operate under federal authority, control, and oversight rather than pursuing targets independently.
That distinction matters. The policy is not a general authorization for private companies to “hack back” after an intrusion. Each operation will be part of a lawful federal law-enforcement, protective, intelligence, or investigatory activity. Co-Executive Directors from the Department of Justice and the Department of Homeland Security will review proposed operations, coordinate with each other, and issue written approval before activity begins.
A Cyber Surveillance Operation may involve accessing a target’s systems without the owner’s authorization to collect intelligence while remaining undetected. A Cyber Effects Operation can manipulate, disrupt, deny, degrade, or destroy information, networks, and digitally controlled infrastructure. These definitions move the program well beyond conventional defensive services such as monitoring, incident response, and vulnerability management.
The eligible targets are foreign Cyber-Enabled Transnational Criminal Organizations, or CE-TCOs, that attack United States people, government bodies, interests, or businesses. Groups that are institutional parts of foreign governments, or wholly directed by them, fall outside the stated definition. The memorandum initially assumes a group is not government-controlled unless clear intelligence establishes that connection.
Attribution in cyberspace is rarely tidy, as criminal infrastructure can be shared, rented, compromised, or quietly tolerated by state authorities. Separating an independent criminal enterprise from a state-directed operation will therefore be one of the NCC’s more consequential responsibilities.
To manage that risk, the forthcoming procedures will include an adjudicatory framework for target selection and operational deconfliction across federal law enforcement, the Department of State, the Department of the Treasury, the Department of War, the Department of Justice, and the United States Intelligence Community. Some details are contained in a classified annex.
Implementation guidance is due within 60 days. It will establish standards covering technical proficiency, operational experience, facility security, personnel vetting, competence, and reliability. The eligibility model is supposed to accommodate both large businesses with substantial capacity and smaller companies suited to specialized assignments.
No Participating Companies have been identified. Recorded Future, Microsoft, and Palo Alto Networks illustrate the kinds of vendors active in threat intelligence, disruption support, and incident response, but the memorandum does not say that any of them will participate. Nor will vendors run the policy. The NCC and federal departments retain operational control.
Companies may be required to maintain a bond or escrow of at least $1 million, subject to forfeiture for contractual noncompliance. They will also disclose relevant commercial relationships, meet reporting requirements, and undergo reviews at least annually.
What happens when an approved operation crosses an unexpected boundary? The memorandum requires a company to stop, perform minimization, and notify the NCC immediately if it unintentionally reaches a United States person, a system located in the United States, or a system controlled by a United States person. The NCC must then notify the Department of Justice.
Operations also stop short of “Critical Outcomes.” The memorandum uses that term for activity likely to cause death or serious injury, or rise to the level of force or armed attack under international law. Participating Companies must report an imminent attack on United States critical infrastructure or a reasonable belief that an operation could produce such an outcome.
The policy builds on a broader shift toward treating ransomware and online fraud as components of transnational organized crime. The White House’s 2023 strategy called for stronger information flows to fusion centers and deeper coordination against ransomware and cyber-enabled fraud. The UN Convention on Cybercrime, Justice Department policy, and INTERPOL guidance similarly emphasize cross-border information exchange, capacity development, and public-private cooperation.
For business leaders, the immediate task is preparation rather than participation. Security providers considering the program will need to assess governance, personnel clearance, insurance, contracting, logging, evidence handling, and international exposure. Other enterprises should review how threat information collected during ordinary operations could be shared with Participating Companies. NIST Cybersecurity Framework 2.0 remains useful for baseline resilience, but this initiative adds a different layer: private technical capability deployed as an instrument of supervised federal action.
⬇️