President Donald Trump has authorized government agencies to hire private cybersecurity companies to conduct offensive operations against cyber-enabled transnational criminal organizations, according to a memo signed Wednesday and reported by The Register. The policy allows participating firms to support national operations against criminals, including cyber surveillance and technical disruptions of their networks. The move represents a significant shift in US cybersecurity policy, formally enlisting the private sector to carry out government-directed offensive cyber activities.
The memo defines allowable operations in two categories: cyber surveillance missions designed for intelligence gathering while remaining undetected, and "Cyber Effects Operations" that can cause "the manipulation, disruption, denial, degradation, or destruction" of information systems, networks, physical or virtual infrastructure, or data residing on them. The policy targets any foreign group conducting cyber-enabled crime against the US government, US persons, or US interests, but crucially excludes entities directly associated with or operating wholly on behalf of foreign governments. Companies must maintain a bond or escrow of at least $1 million, which they'll forfeit if they violate contract terms. They're also prohibited from executing operations that could result in loss of life, serious injury, or actions that could be seen as an armed attack under international law.
Participating companies will undergo "rigorous vetting" and must prove their technical capabilities through annual evaluations, the memo states. Program managers must ensure operational procedures create opportunities for both highly resourced, large organizations and "smaller, more agile companies" that may prove useful for specialized or discrete tasks. The Justice Department will authorize operations, particularly those targeting US residents or raising domestic legal issues. Operational procedures are to be drawn up within 60 days and codified by program executive directors working with the Homeland Security Council.
Legal experts have debated whether the US Computer Fraud and Abuse Act might need amendment before American companies can legally offer such services, though the strategy document doesn't mention legislative changes. However, Title 18 of the US Code, § 1030(f), says the CFAA doesn't prohibit lawfully authorized investigative, protective, or intelligence activity by US government agencies or intelligence agencies. Lawyers from Jenner & Block noted in a Lawfare analysis that participating companies might be protected when acting under government contracts and direction, though no court has determined whether that exemption covers private companies doing such work. Because the government will draw up procedures and direct the companies' involvement, the work may fall within the CFAA exemption. US allies will certainly be monitoring the private sector program's success and its take-up from the companies it looks to attract, according to cyber and tech research fellow Gareth Mott at the Royal United Services Institute. The question for corporate decision-makers isn't whether offensive cyber capabilities will matter in the next decade, but whether accepting government direction in exchange for legal cover represents an acceptable trade-off against reputational risk and geopolitical entanglement. Smaller firms may find the annual vetting burden and million-dollar bond requirement prohibitive, potentially concentrating this new capability among the very largest players despite the policy's stated intent to include agile specialists.

