Published Security3 min read
Trump memo licenses private firms to run offensive 'Cyber Effects Operations'
A memo signed Wednesday lets agencies hire vetted firms to disrupt criminal networks, backed by a $1 million bond. The stated prohibitions cover loss of life and armed attack, not collateral damage.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- President Donald Trump has authorized government agencies to contract private cybersecurity firms to conduct operations against cyber-enabled transnational criminal organizations.
- The policy was confirmed in a memo signed on Wednesday, and had been hinted at earlier this year.
- The memo allows participating companies to support national operations, including cyber surveillance and technical disruptions of criminal networks.
- The policy permits "Cyber Effects Operations," which involve manipulating, disrupting, or destroying information systems and networks.
- Cyber Effects Operations are distinct from cyber surveillance, but the memo acknowledges that surveillance missions may also cause system disruptions.
Compiled by The WatchSomething wrong?How this is made
Why it matters
President Donald Trump has signed a memo authorizing government agencies to contract private cybersecurity firms to conduct operations against cyber-enabled transnational criminal organizations, according to The Register as relayed by SC Media [1][2][12]. The practical effect is a new vendor category: companies paid to reach into other people's systems on behalf of the United States, with a bond posted against misbehaviour [4][9].
The memo permits what it calls "Cyber Effects Operations," defined as manipulating, disrupting, or destroying information systems and networks [4]. It treats those operations as distinct from cyber surveillance, while acknowledging that surveillance missions may themselves cause system disruptions [5]. That acknowledgement is the interesting part. It concedes that the line between watching a network and breaking it is not clean in practice, which is precisely the line a contract, an inspector general, or a plaintiff's lawyer would later have to adjudicate.
The guardrails, as described, are procedural and financial. Participating firms must pass rigorous vetting and follow strict operational procedures, which are to be developed within 60 days [7][8]. They must demonstrate technical capability annually [8]. They must post a $1 million bond or escrow, forfeitable if they violate their contract [9]. Operations that cause loss of life or serious injury, or that would constitute armed attacks under international law, are prohibited [10]. The Justice Department is to authorize operations touching US residents or raising domestic legal questions [11].
Note what the target definition does and does not cover: cyber-enabled transnational criminal organizations, explicitly excluding entities directly linked to foreign governments [6]. That exclusion is the escalation control, and it puts the weight of the entire policy on attribution. Ransomware crews with tolerated or ambiguous state relationships are the hard case, and a contractor whose annual qualification depends on demonstrated capability is not a neutral party in deciding whether a given target is a criminal gang or an arm of a state.
Then there is the bystander problem. Criminal infrastructure does not sit in a dedicated building; it sits on hosting, in cloud tenancies, behind CDNs and inside compromised networks belonging to companies that did nothing. The stated prohibitions are set at the level of death, serious injury and armed attack [10]. In the material available, the safeguards do not describe a remedy for a third party whose systems are disrupted, and the $1 million bond is forfeitable for contract violation rather than payable to anyone harmed [13]. If your servers are downstream of a takedown, your recourse appears to be with the government that authorized it, not with the vendor that executed it.
What to watch over the next 60 days: the operational procedures themselves [7]. Specifically, whether they require pre-operation collateral assessment, whether they impose a notification duty to owners of transited or affected infrastructure, whether the vetting standard is disclosed or classified, and how a "contract violation" that triggers bond forfeiture is defined [9]. Also watch the Justice Department's authorization role [11], which is the only named check in the summary with an institution attached to it, and the first list of approved firms, since a licensed hack-back market prices itself around who gets in. SC Media characterizes the initiative as a significant shift in US cybersecurity policy [12]; the shift becomes measurable only when the procedures are published.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
President Donald Trump has authorized government agencies to contract private cybersecurity firms to conduct operations against cyber-enabled transnational criminal organizations.
- [2]
The policy was confirmed in a memo signed on Wednesday, and had been hinted at earlier this year.
- [3]
The memo allows participating companies to support national operations, including cyber surveillance and technical disruptions of criminal networks.
- [4]
The policy permits "Cyber Effects Operations," which involve manipulating, disrupting, or destroying information systems and networks.
- [5]
Cyber Effects Operations are distinct from cyber surveillance, but the memo acknowledges that surveillance missions may also cause system disruptions.
- [6]
The definition of cyber-enabled transnational criminal organizations excludes entities directly linked to foreign governments.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- scworld.comSC StaffAug 13Trump allows private companies to conduct cyber operations against criminals
Cited in this coverage: The Register, reported by SC Media (scworld.com)
Cited in this coverage: SC Media (scworld.com)
Additional citations
- The Register, reported by SC Media



