US President Donald Trump on August 12 ordered the creation of a program that will bring vetted private US companies into offensive cyber operations against foreign criminal groups. The presidential memorandum places those operations under the control and supervision of the US government and requires US federal officials to approve each one.

The program is not a general license for companies to retaliate against anyone who attacks them. Participating companies must contract with either the US Department of Justice or the US Department of Homeland Security, pass government vetting and act only within an approved operation.

What the program authorizes

The memorandum creates two categories of activity: Cyber Surveillance Operations and Cyber Effects Operations. Surveillance operations involve accessing systems without the owner's authorization to collect intelligence while intending to remain undetected. Effects operations can manipulate, disrupt, deny, degrade or destroy systems, networks, infrastructure or the information stored on them.

The permitted targets are foreign cyber-enabled transnational criminal organizations that attack US people, government bodies or interests. TechCrunch reported that the policy represents the first US program of this kind but stops short of letting companies hack back against any threat on their own initiative. The memorandum calls the contractors “Participating Companies”; “cyber privateers” is an analogy used in coverage of the policy, not the program's official name.

Office buildings beside racks of computer servers (illustrative image)
Officials from the US Department of Justice and the US Department of Homeland Security will jointly review proposed operations. (Illustrative image) Photo by Brett Sayles on Pexels

Every operation requires written approval

The National Coordination Center will manage the program. One executive director appointed by the US attorney general and another appointed by the US homeland security secretary must coordinate before approving an operation. Every cyber operations package requires their written approval and direction before a company may act.

The program directors have 60 days from August 12 to establish operating procedures covering company eligibility, personnel checks, target identification, reporting and coordination with other US agencies. Those procedures must allow the departments to make a bond or escrow of at least US$1 million a contractual condition, with the money forfeited for noncompliance. The program directors must issue a status report within 180 days and annually after that.

Target rules depend on difficult attribution judgments

The memorandum defines an eligible target as a foreign group that conducts cyber-enabled crime against the US government, a US person or US interests. The group cannot be an institutional part of a foreign government or operate wholly under one government's direction. The policy nevertheless presumes a group is independent unless clear intelligence establishes such a connection.

Operations that exceed an approved scope must stop if they unintentionally reach a US person, a system in the United States or a system controlled by a US person. The company must minimize the effects and immediately notify the National Coordination Center, which must alert the US Department of Justice. The two program directors also cannot approve an operation likely to cause death, serious injury, a use of force or an armed attack under international law.

Parts of the workflow and target-review framework must conform to a classified annex, so the public document does not disclose the full evidence threshold for selecting a target. It also does not explain how officials will assess groups that have informal relationships with foreign governments but are not wholly directed by them.

US authority does not settle cross-border liability

The memorandum says the National Coordination Center must run the program in accordance with the US Constitution, applicable laws, US international obligations and Section 1030 of Title 18 of the US Code, the country's main federal computer-access statute. It does not amend that statute or give private companies a general exemption. Instead, it places approved actions under US government authority and supervision.

Cybersecurity Dive reported that former US Cyber Command lawyer Gary Corn said the US government would remain accountable under international law, while former US homeland security official Paul Rosenzweig warned that an operation could pass through systems subject to several countries' jurisdiction. Corn also said coordinating private missions with classified US military and intelligence operations could be harder than resolving conflicts among government agencies alone.

Hunter Strategy executive Jake Williams told TechCrunch that participating Americans could face accusations or detention abroad even if a foreign government's allegations were false. The memorandum does not address how courts or law-enforcement agencies outside the United States might assess the conduct, leaving companies and personnel exposed to legal judgments in other jurisdictions.

Safeguards have not been tested

The public memorandum sets deadlines and guardrails, but it does not identify any participating company or approved mission. APPI News could not find public evidence by August 17 that a company had joined the program or that an operation had begun.

The implementing procedures were still pending at the time of writing. Until they are released, the practical vetting threshold, the evidence required to confirm a target and the handling of effects on third-country systems remain unknown. The memorandum requires annual status reports but does not say whether the US government will publish them.