Security1 distinct publisher3 min readPublished
The memo tells DHS to vet and license firms for cyber surveillance and disruption against foreign crime groups. Contractors will be making state-grade attribution calls backed by a $1 million bond and little else.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
A CE-TCO designation rests on three conditions: the group is foreign, it is committing cyber-enabled crime against US persons or interests, and it is not part of or operated by a foreign government [4]. That last condition is the hardest call in attribution work, and here it gets made twice before anything runs: once by the company writing the operations package, then by program directors at Justice and Homeland Security, who also check that the operation will not interfere with other US government activity, will not kill anyone, and will not amount to an armed attack under international law [6].
The funnel into that gate is wide. Nominations can come from private sector entities or from any federal, state, local, tribal or territorial agency [5], which is six classes of nominator feeding two departments of approvers [1]. Tom Uren, who writes Seriously Risky Business, calls the nomination process ridiculously broad and would restrict it to agencies that actually respond to scams and cybercrime [7].
The capacity gap behind the memo is real. Policing has had limited impact on this category of crime, so the government moved toward disruption and cyber operations [14], and those operations are rationed: the FBI takes only the highest-priority groups, NSA is pointed at foreign intelligence, and Cyber Command works the warfare nexus [10]. Uren's count is hundreds of crews nobody is contesting [11].
Critics, in Uren's summary, raise two objections: an accidental hit on a foreign government triggering escalation, and foreign governments going after employees of participating companies [12]. Uren thinks both are overblown, citing WannaCry and NotPetya, neither of which brought significant consequences for the governments behind them [13]. That comparison is about states absorbing the fallout of state operations, which is a different question from what a foreign service does to the identifiable staff of a licensed contractor.
What is published amounts to three controls: vetting on technical proficiency, proven performance, facility security and personnel vetting [8]; pre-execution approval [6]; and a USD$1 million bond forfeited if the firm breaks its contract conditions [9], [2]. All three run toward the government. The memo does not describe any immunity or liability shield for a participating company; the bond is a remedy the government holds, not cover a firm can point to when a misidentified third party comes looking [3].
The logistics sit in a classified annex [2]. So when scam infrastructure goes dark next year, the people reading the wire outside the program have no way to separate a licensed cyber effects operation from a federal takedown or from one crew hitting another [3]. Attribution confusion runs in both directions here: outward at the targets, and inward at everyone else trying to interpret a disruption.
Ranked by verification strength, evidence, and original report placement.
A presidential memo issued last week directed the Department of Homeland Security to establish a program authorising private companies to conduct cyber operations against "Cyber-Enabled Transnational Crime Organisations" (CE-TCOs).
The memo sets out the broad shape of the arrangement, and a classified annex further details the logistics.
The policy shift is that private companies will be authorised to conduct cyber operations previously restricted to state entities, including "cyber surveillance" (intelligence gathering) and "cyber effects" operations intended to manipulate or cause disruption.
CE-TCOs are defined as foreign groups conducting cyber-enabled crime against US persons or interests that are not part of, or operated by, a foreign government.
CE-TCOs to be targeted can be identified either by private sector entities or by any "federal, state, local, tribal, and territorial" agency.
Participating companies develop their own cyber operations packages, which must be approved by the government before execution; program directors at the Departments of Justice and Homeland Security assess whether proposed operations would interfere with other US government activities, kill anyone, or be equivalent to an armed attack under international law.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
invest
Washington licenses private hacking, and hands the contractor the liability1 distinct publisher
product
White House lets vetted firms hack back and leaves liability blank for 60 days1 distinct publisher
security
FBI names Nanjing contractor behind 300-victim Check Point Quantum Gateway campaign1 distinct publisher
product
After Arup, a face on a video call is not a credential1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One reader of an unpublished document
The mechanism details — the bond, the quoted vetting language, the three approval tests — read like faithful lifts from the memo, and that is what keeps this respectable. But nothing here is checkable: the memo is not linked or reproduced, the annex with the logistics is classified, and only Tom Uren's newsletter has looked. The capacity argument that justifies the whole scheme, hundreds of uncontested criminal groups, is an assertion with no tally behind it.
Authorised on paper, nobody licensed yet
A presidential directive is close to the strongest possible starting gun, and it is all that has fired. DHS has been told to build the program; no company has been vetted, no package approved, no operation run, and Seriously Risky Business flags that even the money question — who pays these firms — is unanswered. Adoption here is a mandate without a single named participant.
Guardrails praised before anyone tests them
The overstatement runs in an unusual direction. Rather than inflating the danger, the reporting inflates the reassurance: a memo whose operating details are classified is called "surprisingly measured", and the risk of a contractor hitting a government network is dismissed on the strength of two state-launched worms from a decade ago. Three safeguards described on paper are being credited as though they had survived contact with a live operation, and the one guardrail the piece does question — who may nominate a target — is the one it calls ridiculously broad.
An industry newsletter arguing for its industry's new market
This is advocacy and says so — "the right idea" is in the headline, "we think" recurs throughout. The piece is a sponsored edition of a commercial security newsletter written by and for the offensive-and-defensive cyber trade, which is exactly the constituency that would be vetted, licensed and paid under this memo. That does not make the reporting wrong; it does explain why the framing lands on capacity gaps and profits rather than on liability, oversight, or the absence of any named critic.
Trust the mechanics, hold the verdict
Split your confidence. That the memo exists and contains a bond, a vetting bar and a two-department approval step is well worth believing — the quotations are specific and the outlet knows this beat. Whether the scheme is measured, safe or workable is one analyst's judgment on an unreleased document with a classified annex, unconfirmed by any second party and untested by anything that has actually happened.