Published Security3 min read
Private firms get a lane into US offensive cyber, and CISOs inherit the paperwork
A memorandum signed August 12 lets federal law enforcement run offensive operations with private companies. The published framework covers review procedures. It says nothing about who pays when it goes wrong.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- The White House authorized federal law enforcement agencies to collaborate with private firms in conducting offensive cyber strikes on foreign threat actors targeting the US, via a National Security Presidential Memorandum signed by President Donald Trump on August 12.
- The NSPM noted that although the American private sector is "the most innovative and technologically advanced in the world," its capabilities have "historically been underutilized" in efforts to identify and disrupt criminal networks operating in cyberspace.
- The Homeland Security Task Force's National Coordination Center will set up a program to oversee these operations, headed by two Executive Directors from the Department of Justice and the Department of Homeland Security.
- The memorandum establishes a framework in which private sector companies that wish to participate can enter into agreements with other firms as well as federal, state and local government bodies to gather threat intelligence on transnational cybercrime groups and propose cyber operations designed to disrupt those threat actors.
- The memorandum said "rigorous procedures" will be established for the review and conduct of "limited" cyber operations, which will only be conducted under the direction of the US government.
Compiled by The WatchSomething wrong?How this is made
Why it matters
President Donald Trump signed a National Security Presidential Memorandum on August 12 authorizing federal law enforcement agencies to collaborate with private firms on offensive cyber strikes against foreign threat actors targeting the US [1]. The operational question for most security leaders is not whether their company will ever run a disruption operation, but that a new category of government relationship now exists for their vendors, their insurers and their general counsel to ask about.
The mechanics are administrative before they are kinetic. The Homeland Security Task Force's National Coordination Center will stand up a program to oversee the operations, led by two Executive Directors drawn from the Department of Justice and the Department of Homeland Security [3]. Companies that want in can enter agreements with other firms and with federal, state and local government bodies to collect threat intelligence on transnational cybercrime groups and to propose operations to disrupt them [4]. The memorandum promises "rigorous procedures" for reviewing and conducting "limited" operations, which it says will be conducted only under US government direction [5], and states the program will comply with the Constitution, US law and relevant international agreements [6]. The stated rationale is that private sector capability has "historically been underutilized" against criminal networks in cyberspace [2]; the supporting numbers are $20.8bn in reported losses by American consumers to cyber-enabled crime in 2025 and 73% of US adults having experienced an online scam or attack [7][8]. It builds on a March executive order directing agencies to take "rigorous actions" against cyber-enabled crime, roughly five months earlier [9][10].
Chris Wysopal, co-founder of Veracode, called it a "big shift" on X, and "not exactly 'hack back,' but definitely a major expansion of the private sector's role in offensive cyber operations" [11]. The sharper objection is attribution. Nick Carr, technical director for the Microsoft Threat Intelligence Center and formerly chief technical analyst at CISA, wrote on X that his biggest concern is "just how difficult attribution in criminal operations is, and how few organizations can repeatably do it right (including certain gov agencies)," adding that people are "regularly and willingly wrong on pretty important incidents" [12]. Carr said better program design for attribution could mitigate that [13]. Independent researcher Lukasz Olejnik warned on X that authority to destroy criminal-controlled infrastructure can reach state-linked systems, raising interstate escalation risk [14]. Others in the field have raised misidentified targets and escalation instead of deterrence [15].
Here is where it lands on a desk that never signs anything. The published account of the memorandum describes oversight, review procedures and a legal-compliance commitment [3][5][6], but does not describe how liability, indemnification or insurance coverage would be allocated if a limited operation hits the wrong host [16]. Because participants can contract with each other as well as with government [4], the threat intelligence provider, MDR vendor or incident response retainer already in the stack may become a program participant without that being a procurement question anyone has asked. Contract review, cyber policy wording on hostile action, and vendor questionnaires are all cheaper to update before an operation than after one.
What to watch: whether the National Coordination Center publishes the review procedures and names the two Executive Directors [3][5]; whether participation is disclosable by vendors under existing agreements [4]; and whether the US follows the UK, which created its National Cyber Force in 2020 and published principles in 2023 stating it would rarely deploy such capabilities where other responses fit better [17][18].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The White House authorized federal law enforcement agencies to collaborate with private firms in conducting offensive cyber strikes on foreign threat actors targeting the US, via a National Security Presidential Memorandum signed by President Donald Trump on August 12.
ReportedView cited source - [2]
The NSPM noted that although the American private sector is "the most innovative and technologically advanced in the world," its capabilities have "historically been underutilized" in efforts to identify and disrupt criminal networks operating in cyberspace.
ReportedView cited source - [3]
The Homeland Security Task Force's National Coordination Center will set up a program to oversee these operations, headed by two Executive Directors from the Department of Justice and the Department of Homeland Security.
ReportedView cited source - [4]
The memorandum establishes a framework in which private sector companies that wish to participate can enter into agreements with other firms as well as federal, state and local government bodies to gather threat intelligence on transnational cybercrime groups and propose cyber operations designed to disrupt those threat actors.
ReportedView cited source - [5]
The memorandum said "rigorous procedures" will be established for the review and conduct of "limited" cyber operations, which will only be conducted under the direction of the US government.
ReportedView cited source - [6]
The memorandum added that the program will ensure compliance with the US Constitution and laws, as well as relevant international agreements.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- infosecurity-magazine.comAug 13Trump Authorizes Private Sector Participation in Offensive Cyber Operations
Additional citations
- Chris Wysopal on X, as reported by Infosecurity Magazine
- Nick Carr on X, as reported by Infosecurity Magazine
- Lukasz Olejnik on X, as reported by Infosecurity Magazine



