Trump Authorizes Private Firms in Cyber Operations Against Foreign Criminals

President Donald Trump has signed a presidential memorandum that establishes a framework for private companies to participate in government-led cyber operations targeting foreign criminal organizations. This initiative focuses on cyber-enabled transnational criminal organizations (CE-TCOs) accused of online crimes that harm American citizens and businesses. The National Coordination Center (NCC) is tasked with overseeing and managing this program.

Under this directive, participating companies are authorized to conduct cyber surveillance and cyber effects operations, but only under strict federal government direction, control, and oversight. The Department of Justice and the Department of Homeland Security will jointly supervise the program through designated executive directors.

Cyber surveillance operations involve covert activities aimed at collecting intelligence from computer systems, networks, telecommunications infrastructure, or embedded devices. This includes unauthorized access or exceeding authorized access to remain undetected while gathering information, which may support future operations.

Cyber effects operations are more proactive, aiming to manipulate, disrupt, deny, degrade, or destroy information, systems, networks, or infrastructure managed through information technology. However, the memorandum explicitly prohibits actions likely to cause death, serious injury, or effects that could be considered a use of force or armed attack under international law. Such critical outcomes cannot be approved by the program’s executive directors.

It’s important to note that this policy does not grant companies the freedom to conduct independent hack-back activities. Every operation must undergo thorough review and receive written approval before any action is taken. Companies will operate on behalf of the government, under its lawful authority, ensuring that all activities are conducted within legal boundaries.

The NCC is also responsible for coordinating operations across federal law enforcement, intelligence agencies, and departments responsible for foreign policy, treasury, and defense matters. To participate, companies must enter into contracts with either the Department of Justice or the Department of Homeland Security and undergo comprehensive technical, security, and personnel vetting. The program’s operating procedures are designed to accommodate both large providers and smaller firms specializing in specific areas.

Participating companies are required to disclose relevant commercial relationships and may need to maintain a bond or escrow of at least $1 million, which can be forfeited for non-compliance. Additionally, the policy mandates that companies immediately halt operations, minimize collected data, and notify the NCC if they inadvertently target a U.S. person or system. Any operation implicating constitutional, federal, or international law obligations must undergo Justice Department review and obtain necessary legal or judicial authorization before approval.

The memorandum sets a 60-day deadline for the program’s executive directors to establish operating procedures in collaboration with the Homeland Security Council. They are also required to report on the program within 180 days and annually thereafter.

For cybersecurity defenders and threat intelligence teams, this initiative could provide a formal channel for sharing threat data collected by businesses and proposing government-supervised actions to disrupt criminal infrastructure. The practical impact of this policy will depend on the classified workflows, target selection criteria, legal reviews, and the choice of participating firms.

This development signifies a significant shift in the U.S. government’s approach to combating cybercrime, potentially enhancing the nation’s ability to counteract foreign cyber threats through public-private collaboration. However, it also raises questions about oversight, accountability, and the potential risks associated with involving private entities in offensive cyber operations. As the program unfolds, it will be crucial to monitor its implementation and effectiveness in achieving its intended goals while adhering to legal and ethical standards.