Key Takeaways
- The President’s memorandum creates a voluntary framework for vetted U.S. companies to conduct offensive cyber operations only against foreign cyber‑enabled transnational criminal organizations, under direct federal supervision.
- The Department of Justice (DOJ) and the Department of Homeland Security (DHS) will vet firms, approve each mission in writing, and retain operational control; the program is not a blanket “right to hack.”
- Approved contractors may collect intelligence or disrupt, degrade, manipulate, or destroy the systems of target criminal networks, but must include safeguards to avoid unintended effects on U.S. persons or domestic systems.
- Participation raises legal, liability, and reputational questions, including potential exposure to foreign law, contractor indemnification, insurance needs, and risk of retaliation against firms that also serve private‑sector clients.
- DOJ and DHS have 60 days to define eligibility, approval procedures, reporting, security, and oversight requirements, leaving several open issues such as attribution, coordination with military/intelligence efforts, and protection of employee‑level risk.
Overview of the Presidential Memorandum
The President issued a memorandum titled “Expanding Capabilities to Combat Transnational Cyber‑Enabled Crime” that directs the federal government to establish a structured program whereby vetted U.S. companies can support government‑led cyber operations. The initiative is aimed at foreign cyber‑enabled transnational criminal organizations—such as ransomware syndicates, illicit marketplace operators, and other networks that use cyber tools for profit—but explicitly excludes operations against entities that are part of, or wholly directed by, foreign governments. By framing the effort as a contractor‑based model, the administration seeks to augment existing law‑enforcement and intelligence capacities without creating a new independent private authority to hack.
Eligibility and Vetting Process
Under the memorandum, DOJ and DHS are tasked with developing, within 60 days, the criteria for firm eligibility, the mission‑approval process, security standards, reporting obligations, and oversight mechanisms. Only companies that successfully pass a vetting review by these departments will be permitted to participate. Each approved operation must receive written authorization from the government, and federal officials will retain operational control throughout the activity. This approach mirrors traditional federal contracting but applies it to the sensitive domain of offensive cyber work.
Scope and Limitations of Operations
Participating firms may engage in two primary types of activity: intelligence collection against the targeted criminal networks, and disruptive actions that may degrade, manipulate, or destroy the adversaries’ systems and infrastructure. The memorandum stresses that these actions are permissible only when directed at foreign cyber‑enabled transnational criminal organizations and never against U.S. persons, domestic systems, or foreign‑government‑linked entities. Importantly, the document explicitly states that it does not create a private “right to hack”; any offensive activity must be carried out under the auspices of a federal‑directed operation.
Operational Model and Safeguards
Companies involved will operate as federal contractors, subject to government supervision akin to other defense or intelligence contracts. To mitigate risks of collateral damage, the memorandum includes safeguards requiring contractors to cease or minimize an operation immediately if there is mistaken contact with U.S. persons or domestic systems, and to notify the government promptly. Certain activities that could affect U.S. persons or U.S.-based infrastructure would necessitate additional legal authorization before proceeding. These provisions aim to preserve privacy and civil liberties while allowing aggressive action against overseas criminal actors.
Legal and Policy Context
The program rests on the legal theory that contractors acting under federal direction are executing a government operation, thereby falling within the exemption of 18 U.S.C. § 1030(f) for lawfully authorized investigative, protective, or intelligence activity of federal agencies. This interpretation seeks to sidestep the general prohibition of the Computer Fraud and Abuse Act (CFAA) against unauthorized computer access. Nonetheless, analysts note tension with prior legislative language—such as the FY2022 National Defense Authorization Act, which clarified that coordination with Cyber Command does not authorize private offensive cyber activity abroad—raising questions about how far the new framework can stretch existing authorities without congressional action.
Strategic Rationale and Capacity Gap
The administration justifies the initiative by pointing to a capacity shortfall: U.S. Cyber Command remains principally focused on nation‑state threats and lacks the personnel to pursue the high‑volume, fast‑evolving landscape of foreign cybercrime at scale. Private firms often possess specialized threat‑intelligence capabilities, rapid‑response teams, and niche technical expertise that can be deployed more quickly than building comparable internal government capacity. By harnessing these commercial strengths through a vetted contractor model, the government hopes to disrupt criminal infrastructures “at scale” while preserving the strategic focus of military cyber forces on state‑level adversaries.
Implications for Participating Companies
For firms that choose to join the program, the memorandum introduces a layer of contractual and risk management complexity beyond typical cybersecurity services. Participation will likely involve cost‑reimbursement or similar federal contracts, necessitating robust accounting systems to track and document contract‑specific expenses. Companies must also address liability and indemnification clauses, secure appropriate insurance coverage, and establish protocols for protecting employees who may be implicated in overseas operations. Additionally, because many of these contractors also provide commercial cybersecurity services to private U.S. businesses, there is a concern about potential retaliation—such as cyber‑counterattacks or reputational harm—from criminal groups that perceive the firms as extensions of U.S. government power.
Considerations for CEOs and the Broader Business Community
Most ordinary businesses will not gain a new defensive tool from this memorandum; a firm hit by ransomware, for example, is not suddenly authorized to penetrate or disrupt the attacker’s systems. Instead, the program’s relevance lies in the possibility that a company’s existing cybersecurity vendor or consulting partner could become a vetted contractor conducting offensive work on the government’s behalf. CEOs should therefore evaluate whether their service providers intend to participate, assess any associated risks (including potential blowback or legal exposure), and consider how such activities might affect client trust or contract terms. Transparency about a vendor’s governmental engagements may become a prudent component of third‑party risk management.
Future Steps and Open Questions
The 60‑day window for DOJ and DHS to flesh out the framework leaves several critical issues unresolved. Key questions include how attribution of cyber effects will be communicated and defended, how these operations will be coordinated with ongoing military and intelligence campaigns to avoid duplication or conflict, what liability regime will apply if a contractor inadvertently violates foreign law, and what protections will be afforded to personnel who could face prosecution or extradition requests abroad. Stakeholders will also watch for clarity on the extent to which contractors must adhere to federal information‑security standards, subcontractor flow‑down requirements, and reporting thresholds. Until these details are settled, the program remains a promising yet cautiously watched experiment in blending private‑sector agility with public‑sector authority over offensive cyber missions.

