Put Private Cyber Power Under Public Command
The White House is right to mobilize vetted U.S. companies against foreign cybercriminal networks—as long as target selection, legal authority, and accountability remain unmistakably federal.
America has spent years asking companies to spot foreign cybercriminals, absorb their attacks, and pass the evidence to a government that often moves on a different clock. The new White House directive changes that equation.
The presidential memorandum directs the National Coordination Center to build a program in which vetted U.S. companies can conduct cyber surveillance and cyber effects operations against foreign cyber-enabled transnational criminal organizations. Those operations would be performed on behalf of, under the supervision of, and through the lawful authorities of the Federal Government.
CodeAIntel supports this direction. Foreign ransomware crews, scam compounds, extortion networks, and their infrastructure do not become less dangerous because their servers sit outside U.S. jurisdiction. Private firms already hold exceptional telemetry, technical talent, and operational capacity. Putting that capability to work against criminal networks is overdue.
But the strongest part of this policy is not that private companies may act. It is that, under this program, they may act only inside a government-controlled system. This is not a license for corporate retaliation. It is an attempt to combine private execution with public authority.
The policy's central idea is disciplined integration: private capability, federal authorization, and a foreign criminal target inside one controlled chain.
This is not private hack back
The distinction matters. The memorandum does not amend the Computer Fraud and Abuse Act, grant companies general immunity, authorize any named contractor, or permit businesses to strike whoever they believe attacked them. It directs a presidential program to be built under existing government authorities and applicable law.
Two program executive directors—one designated by the Attorney General and one by the Secretary of Homeland Security—must coordinate approvals. Every cyber operations package requires their review, written approval, and direction before action. Participating companies must enter government contracts, undergo rigorous vetting, disclose relevant commercial relationships, and follow operating procedures that are still to be written.
That architecture is the right one. A victim company should not be investigator, judge, and operator in its own case. Attribution is too uncertain, shared infrastructure is too common, and the consequences can cross borders instantly. Target selection and sovereign risk must remain government decisions.
Evidence can originate in the private sector. Authority cannot. Every operation must pass through legal and federal decision points before execution.
Defense alone leaves the business model intact
The case for action begins with the asymmetry. Defenders can block an address, reset credentials, restore a system, and warn the next target. The criminal organization can change infrastructure, rotate identities, recruit new operators, and resume the same fraud from another jurisdiction.
The scale is no longer abstract. The FBI's 2025 Internet Crime Report recorded more than one million complaints and approximately $20.9 billion in reported losses. The White House identifies ransomware, phishing, impersonation, financial fraud, and sextortion as recurring TCO activity. The March executive order on cybercrime and predatory schemes already called for law-enforcement, diplomatic, economic, and potential offensive action. This memorandum supplies a mechanism for bringing private technical capacity into that response.
That is strategically sound: deterrence grows when criminal operators must account for the possibility that infrastructure, access, data, and operational continuity can be taken away—not merely observed and reported.
The objective should be persistent disruption of the criminal business system: deny infrastructure, expose dependencies, preserve evidence, support arrests and seizures, and force operators to spend more time rebuilding than victimizing. A government-directed program can connect those technical effects to prosecutions, sanctions, financial action, diplomacy, and victim protection in a way that isolated corporate defense cannot.
The guardrails are operational controls
Support for the policy does not require pretending that offensive cyber activity is easy. It requires evaluating whether the control system is designed for the actual failure modes.
The public memorandum contains several important safeguards. Operations must comply with the Constitution, Federal law, international obligations, and 18 U.S.C. § 1030. Activity involving a U.S. person or otherwise implicating U.S. legal obligations requires Department of Justice review and any necessary judicial or other authorization. If an operation unintentionally reaches a U.S. person, a U.S.-resident system, or a system controlled by a U.S. person, the company must stop, minimize, and immediately notify the NCC, which must notify DOJ.
The directive also requires interagency deconfliction, annual re-evaluation of participating companies, and reporting by operators. Immediate notification is required if a company discovers an imminent cyberattack against U.S. critical infrastructure or reasonably believes an approved operation may result in a Critical Outcome. The government may require a bond or escrow of at least $1 million, subject to forfeiture for contractual noncompliance.
Most importantly, the two program directors may not approve an operation likely to cause death or serious injury, or rise to the level of a use of force or armed attack under international law. The public text does not identify a higher approval route for such “Critical Outcomes.” That unresolved boundary should remain a boundary—not an invitation to infer hidden permission.
The program earns legitimacy by enforcing boundaries in the workflow: validate the target, protect U.S. equities, stop on overreach, and withhold critical outcomes from routine approval.
The 60-day procedures will decide whether this works
The memorandum is a directive, not a completed operating program. The executive directors have 60 days to establish consensus procedures; calculated from the memorandum's August 12 date, the calendar target is October 11. Their quality will determine whether this becomes a disciplined national capability or an expensive source of ambiguity.
Five requirements deserve particular attention.
Set a high target-confidence standard. The cyber-enabled TCO definition assumes a foreign group is not part of, or wholly directed by, a foreign government unless clear intelligence establishes otherwise. That creates proxy-attribution and escalation risk. Record confidence, alternatives, infrastructure ownership, and possible state ties before approval.
Make deconfliction auditable. Infrastructure may be under FBI surveillance, tied to intelligence collection, hosted in a partner country, or shared with innocent users. The process must be able to stop a feasible action when another U.S. interest outweighs it.
Control contractor incentives. A company may receive threat information, propose an operation, and then operate under a government contract. Separate evidence validation, approval, execution, and after-action assessment so no contractor grades its own targeting case.
Model consequences, not just compliance. A $1 million bond may discipline ordinary noncompliance, but it cannot price a major cross-border mistake. Liability, insurance, access suspension, evidence preservation, and accountability should scale with potential harm.
Give oversight an external line of sight. A status report is due within 180 days—the calculated calendar target is February 8, 2027—and annually thereafter. The memorandum requires submission to two executive officials; the public text does not promise public or congressional reporting. Operational details can stay classified while appropriate overseers receive aggregate measures of compliance, collateral effects, suspensions, and remediation.
What defenders should expect
This program is aimed at foreign criminal networks, but enterprise security teams will still touch its evidence chain. Threat information collected during normal business activity may be shared through participating companies. State, local, tribal, and territorial agencies may identify threats. An approved operation may generate evidence relevant to victims, infrastructure owners, financial institutions, and incident responders.
Organizations should prepare to preserve provenance. Record when telemetry was collected, which customer or system boundaries apply, how indicators were validated, and what legal restrictions govern disclosure. Keep raw evidence separate from analytical judgment. If information may support a federal operation, chain of custody and source reliability matter as much as speed.
Security leaders should also maintain a hard line between normal defensive activity and program-authorized action. The memorandum says companies may continue other lawful defensive operations, but anything authorized through this program remains under federal oversight, control, and legal authority. A contract is not a general permission slip.
Enterprise telemetry can become national operational evidence only when provenance, legal restrictions, validation, and federal control remain intact.
A capability worth building
The United States should not accept a cybercrime model in which Americans absorb the losses while foreign criminal organizations keep the initiative. Nor should it answer that problem by normalizing uncontrolled private retaliation.
This memorandum chooses the stronger middle path: mobilize private capability without privatizing sovereign power. It recognizes that companies can contribute speed, visibility, and specialized expertise, while government must own the target, legal basis, interagency consequences, and decision to act.
The policy is ambitious, necessary, and more disciplined than the phrase “private offensive cyber” suggests. Its success should be judged by concrete outcomes: criminal infrastructure disrupted, victims protected, evidence preserved, operators brought to justice, collateral harm avoided, and every action traceable to a lawful public decision.
Move fast against the networks. Move carefully across the boundary. Private cyber power belongs under public command.






