Washington has spent two decades telling companies to defend, report, and wait for federal agencies to respond. A national security memorandum signed on August 12, 2026 changes that arrangement for the first time: vetted private companies can now be authorized to conduct offensive cyber operations against foreign criminal groups, under direct federal control. For an industry built around defense, that is a structural shift, not a policy footnote.

What the memorandum actually authorizes

The Presidential Memorandum, titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” directs the Homeland Security Task Force’s National Coordination Center to stand up a formal program that can approve private companies to act against what the memorandum defines as Cyber-Enabled Transnational Criminal Organizations, or CE-TCOs: foreign groups that run cyber-enabled crime against the United States but are not part of a foreign state apparatus. That distinction matters. The program is built for ransomware crews, sextortion rings, phishing operations, financial fraud networks, and impersonation scams, according to the White House fact sheet, not for nation-state intrusion sets, which stay inside existing intelligence and military authorities.

The memorandum splits authorized activity into two categories. A Cyber Surveillance Operation allows an approved company to access a target’s systems without authorization to collect intelligence. A Cyber Effects Operation goes further, permitting activity that causes “manipulation, disruption, denial, degradation, or destruction” of systems or infrastructure. Both categories require written sign-off from two co-Executive Directors, one from the Department of Justice and one from the Department of Homeland Security, before a company can act.

Media Partner

Web3 x AI Fusion — Media Partner

The guardrails, on paper

Participation is not open registration. Companies must go through a vetting process the White House describes as covering technical proficiency, facility security, and personnel screening, and must post a bond or escrow of at least $1 million that is forfeited for non-compliance. The memorandum also requires the program to comply with “the Constitution and all other applicable laws and international obligations,” and sets a 60-day clock for the Justice and Homeland Security departments to publish the implementing guidance and operating procedures that will turn this framework into something companies can actually apply for. Annual reviews and an initial 180-day status report are built into the structure.

The policy builds on Executive Order 14390, signed in March 2026, which set earlier groundwork for a more aggressive federal posture on cyber-enabled crime. The White House frames the expansion as a response to scale: Americans reported more than $20.8 billion in losses to cyber-enabled crime in 2025, hitting seniors, children, and low-income families hardest through ransomware, phishing, financial fraud, sextortion, and impersonation schemes, per the fact sheet. It also arrives against a backdrop of a federal cyber-defense agency that has been operating with a reduced mandate, a tension CyberTech has covered before: Washington is asking the private sector to do more offense at the same time its own defensive coordination arm has less capacity to do less.

What it means for the security leader

The immediate operational impact on most enterprises is limited. This program authorizes companies to go on offense against criminal infrastructure; it does not change what a CISO’s own team is permitted to do, and unauthorized “hack back” by anyone outside the program remains illegal under the Computer Fraud and Abuse Act exactly as it was on August 11.

The exposure to watch is indirect. Security vendors, incident-response firms, and threat-intel providers now have a live path to apply for a program that lets them act offensively on a client’s behalf, with federal sign-off and a compliance bond attached. Any enterprise that works with a vendor considering participation should be asking now, not after the 60-day implementing guidance lands, what that means for the vendor’s liability posture, for shared threat intelligence that might feed a government-directed operation, and for contract language that assumes the vendor stays purely defensive. A vendor that becomes a Participating Company under this program is operating under a different legal and operational profile than one that only monitors and remediates.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

There is also a precedent question worth tracking. The framework formalizes something the security industry has debated for years under the banner of “active defense”: whether private companies should ever be allowed to act offensively against attackers. This memorandum answers that question with a qualified yes, inside a narrow, federally supervised lane, for criminal (not state) targets like the ransomware crews that have shut down production lines and disrupted operations at US companies this year. Whether that lane stays narrow, or widens as the program matures, will shape how enterprises think about vendor risk for the rest of the decade.

How this differs from what already exists

Enterprises already work with the FBI and CISA on a voluntary basis: sharing indicators, reporting intrusions, and occasionally supporting a takedown after the fact. What the memorandum creates is different in kind, not degree. It is a standing program with an application process, a bond requirement, and legal authorization for a private company to initiate action against infrastructure it does not own, rather than waiting to be asked for help after the fact. Legal teams that have spent years drawing a hard line at “we do not touch attacker infrastructure” now have to account for the possibility that a vendor in their supply chain draws that line somewhere else.

What to do next

Security leaders should treat the next 60 days as the window that matters. When the Justice and Homeland Security departments publish their implementing guidance, read it for two things: the scope of what a Participating Company can do on a client’s behalf, and whether any of your current vendors, IR retainers, or threat-intel subscriptions intersect with the program. Until then, the safest move is a direct question to every vendor with offensive-capable tooling: are you applying, and if so, what changes in our contract, our data-sharing terms, and our incident-response runbook. Procurement and legal should be looped in alongside security, since this is as much a contracts question as a technical one. A policy this new deserves scrutiny before it becomes routine, not after.

Source: The White House