Key Takeaways
- The White House has issued a memorandum authorizing a program that lets vetted private U.S. cybersecurity firms conduct active cyber operations—including surveillance and disruption—against transnational criminal organizations.
- Operations will be overseen by the National Coordination Center (NCC) and require prior written approval from the Department of Justice and Department of Homeland Security.
- Permitted activities include “cyber surveillance” (information gathering without owner consent) and “cyber influence” (disruption, damage, or disabling of systems), but actions likely to cause death, serious injury, or constitute a use of force under international law are prohibited.
- The framework expressly encourages participation of small, agile companies, recognizing that adversaries operate at startup speed.
- Israeli cybersecurity firms may benefit because many are already incorporated in the United States, giving them a potential structural advantage in meeting eligibility criteria.
- Beyond direct offensive work, the program creates demand for intelligence, data, automation, auditing, and control‑layer technologies—areas where Israeli firms are strong.
- Participating companies must satisfy federal standards such as FedRAMP certification and adhere to yet‑to‑be‑finalized procedures covering security, approval processes, and liability allocation.
- Industry leaders highlight both the opportunity to integrate private‑sector speed and innovation with government authority and the unresolved questions of responsibility, risk, and diplomatic fallout if operations cause unintended harm.
Overview of the New White House Program
The Biden administration has moved to formalize a partnership between the U.S. government and private cybersecurity firms through a White House memorandum that establishes a program allowing selected American companies to conduct active cyber operations against transnational criminal organizations. The initiative is designed to harness the speed, technological sophistication, and innovative capacity of the private sector to counter fraud, cybercrime, and threats targeting U.S. citizens, businesses, and national security. By sanctioning activities such as intelligence gathering and the disruption or disabling of malicious computer systems, the government hopes to close the capability gap that has often left state actors lagging behind nimble cybercriminal groups.
Management and Oversight Structure
Administered by the National Coordination Center (NCC), the program will place participating firms under a rigorous vetting process coordinated by the Department of Justice (DOJ) and the Department of Homeland Security (DHS). Each operation must receive prior written approval before execution, ensuring that all actions are undertaken on behalf of the U.S. government and under its legal authority. This centralized approval mechanism aims to maintain governmental control while still permitting the agility and expertise that private contractors bring to the table.
Permitted Activities and Legal Limits
The memorandum delineates two primary categories of allowable actions. “Cyber surveillance operations” enable firms to collect information and intelligence from target systems without the owners’ authorization. “Cyber influence operations” cover a broader set of tactics, including the manipulation, disruption, prevention, damage, or disabling of information systems and infrastructure critical to criminal enterprises. Importantly, the framework sets clear boundaries: any activity likely to cause death or serious injury, or that would qualify as a use of force or an armed attack under international law, cannot be authorized. These limits are intended to prevent escalation into kinetic conflict while still permitting robust defensive cyber measures.
Implications for Small and Agile Firms
A notable feature of the memorandum is its explicit encouragement of small, agile companies to participate. Lee Moser, founding partner at Protego Ventures, highlights that this is the first U.S. security document to mandate the inclusion of lesser‑sized players, not only established giants. She argues that the directive reflects a recognition that adversaries evolve at the pace of startups, necessitating a defense posture that can match that velocity. By lowering barriers to entry, the program seeks to democratize access to government‑backed cyber operations and foster a more diverse ecosystem of providers.
Opportunities for Israeli Companies
Although the current eligibility language limits participation to private American companies, Moser notes that many Israeli cybersecurity firms are incorporated in the United States from inception, unlike their European or Asian counterparts that often remain locally domiciled. This pre‑existing U.S. legal presence could give Israeli entities a stronger starting position when the final participation criteria are published within the next 60 days. Beyond direct offensive roles, Moser sees a substantial market for Israeli expertise in the intelligence and data layer—areas where the Israeli industry excels—allowing firms to contribute threat intelligence that informs proposed operations.
Views from Industry Leaders
Arik Kleinstein of Glilot Capital views the memorandum as a significant shift in how the U.S. government perceives the role of private cybersecurity contractors. He anticipates that the framework will primarily benefit mature companies with proven track records of working with U.S. agencies and meeting stringent security, compliance, and trust standards. Kleinstein also raises fundamental concerns about responsibility and risk: when a private firm conducts an active operation against foreign infrastructure, the distinction between a legitimate anti‑crime measure and an incident with diplomatic or national‑security repercussions can become blurred. Determining liability for unintended damage, third‑party effects, or potential retaliation will be a critical challenge for policymakers.
Shay Michel of Merlin Ventures frames the development as a collaborative model that preserves American sovereign control while leveraging allied innovation. He emphasizes that Israel’s cyber capabilities have been forged under real, operational threats rather than theoretical scenarios, making its firms valuable partners. Michel argues that the memorandum offers a template where the U.S. retains authority and oversight, while trusted private contributors supply speed, expertise, and cutting‑edge technology.
Gil Geron, CEO of Orca Security, links the initiative to the broader impact of artificial intelligence on cyber conflict. He notes that attackers increasingly employ AI to accelerate tasks that once required considerable time and resources, outpacing traditional government responses. By enlisting private‑sector AI‑driven capabilities, the U.S. acknowledges that state actors alone cannot match the velocity of modern cyber threats. Geron also posits that AI may ultimately benefit defenders more than attackers, given the expanding attack surface posed by the proliferation of internet‑connected assets, services, and systems.
Responsibility, Risk, and AI Considerations
Across the commentary, a recurring theme is the need to clarify who bears responsibility if an operation causes unintended harm, affects neutral parties, or provokes retaliation. The forthcoming procedural guidelines—expected within two months—will have to define eligibility requirements, security standards, approval workflows, and the division of liability between the government and participating firms. Moreover, as AI becomes integral to both offensive and defensive cyber tools, the program will need to address ethical use, transparency, and accountability for algorithm‑driven actions that could amplify both the potency and unpredictability of operations.
Next Steps and Outlook
The transition from a White House memorandum to an operational framework remains pending. Detailed participation procedures, slated for release within 60 days, will clarify the precise criteria for company vetting, the mechanics of obtaining operational approvals, and the oversight mechanisms that will govern ongoing activities. If the model matures into a permanent operating paradigm, it could reshape how the United States combats cybercrime by institutionalizing a public‑private partnership model that blends governmental authority with private‑sector agility. For Israeli cybersecurity firms, the development opens a range of opportunities—not only in direct offensive roles but also in ancillary markets such as threat intelligence, data analytics, automation, auditing, and control‑layer technologies—provided they can navigate the evolving regulatory landscape and satisfy the stringent federal requirements that will accompany the program.

