The White House has created a federal program for private companies to enter foreign computer systems, remain undetected, collect intelligence, and manipulate or disrupt infrastructure. The operators will work under government contracts, government supervision, and written mission approval.
That last sentence is the legal architecture. Washington spent years debating whether companies should be allowed to “hack back” on their own. The new presidential memorandum chooses a different machine: vetted contractors carrying out federal operations through the National Coordination Center, using federal authority against foreign cyber-enabled criminal organizations.
from policy sentence to operating program
The administration’s March cyber strategy promised incentives for private companies to “identify and disrupt adversary networks.” At the time, Lawfare’s analysis found the language consequential but incomplete. The strategy did not explicitly authorize independent companies to operate on foreign networks, and the Computer Fraud and Abuse Act still made unauthorized access a legal minefield.
The August memorandum fills in the operating model. The National Coordination Center will maintain a roster of Participating Companies contracted through the Department of Justice or Department of Homeland Security. Two executive directors, one from each department, will approve operations after coordinating with each other. Every package requires written approval and direction before action begins.
The companies do not receive a general license to strike. They become instruments of a named federal operation. Section 2 says resulting action will be conducted exclusively on behalf of and under the supervision of the government. Section 3 requires target adjudication, cross-agency deconfliction, standardized mission packages, reporting, annual reviews, and immediate shutdown procedures when an operation crosses its approved boundary.
the verbs are unusually blunt
The memorandum defines two classes of operation.
A Cyber Surveillance Operation means unauthorized access undertaken to collect information or intelligence while intending to remain undetected. The definition includes manipulation or temporary disruption needed to enable collection, provided it is not intended to damage physical or virtual infrastructure.
A Cyber Effects Operation can manipulate, disrupt, deny, degrade, or destroy information systems, networks, data, embedded controllers, or infrastructure controlled by computers. These are terms of force, written into a program aimed at criminal organizations rather than institutional parts of foreign governments.
The target boundary has its own instability. A foreign group is presumed independent from a foreign government unless clear intelligence establishes a state connection. That presumption lets the program move against criminal infrastructure without proving a clean organizational chart first. It also places heavy weight on attribution and deconfliction. Ransomware crews, access brokers, intelligence cutouts, bulletproof hosts, compromised routers, and innocent cloud tenants routinely occupy the same technical terrain.
The memorandum accounts for some of that mess. A company must stop, minimize, and report when an operation unintentionally reaches a US person, a system in the United States, or a system controlled by a US person. Operations likely to cause death, serious injury, a use of force, or an armed attack count as “Critical Outcomes” and sit outside the ordinary approval authority of the two program directors.
a market for proposed operations
The contracting layer extends beyond firms waiting for federal tasking. Participating Companies may sign commercial agreements with private entities that supply threat information gathered during ordinary business. They may also contract with federal, state, local, tribal, and territorial agencies that identify threats. Those inputs can become proposed operations submitted to the NCC.
That creates a pipeline:
- a platform, bank, hosting provider, security vendor, or public agency observes criminal activity;
- a participating operator turns that intelligence into a surveillance or effects proposal;
- the NCC adjudicates the target and deconflicts the operation across law enforcement, State, Treasury, the Department of War, and the intelligence community;
- DOJ and DHS provide written approval and direction;
- the contractor enters, watches, manipulates, disrupts, or destroys within the approved envelope;
- reporting returns to the NCC.
The government owns command authority. Private firms supply talent, tooling, access patterns, speed, and capacity. The memorandum even directs the eligibility process to include both large companies and smaller firms suited to specialized tasks. A bond or escrow of at least $1 million can be required and forfeited for contractual noncompliance. That number is a weak proxy for the damage a botched operation could cause, but it makes one thing explicit: restraint will be enforced partly through procurement machinery.
oversight lives mostly inside the machine
The memorandum contains substantial process and little public visibility. The operating procedures will conform to a classified annex. Annual reports go to senior White House cyber officials, with no publication requirement in the text. Target packages receive review from program directors and, when US persons or legal obligations are implicated, the Department of Justice and any necessary judicial authority.
Those are meaningful controls. They remain executive controls. The public cannot inspect the targeting rubric, deconfliction record, success criteria, collateral effects, contractor roster, or failure history from the memorandum alone.
The program also blurs familiar accountability lines. A federal employee acting under statutory authority sits inside public-service rules, inspector-general systems, records laws, appropriations, and a recognizable command structure. A contractor can carry the same operational effect while its exploit chain, personnel, subcontractors, insurance, investors, and commercial threat feeds remain corporate assets. The mission is sovereign. Much of the capability is proprietary.
Previous active-defense proposals tried to carve exceptions into the CFAA for victims pursuing attackers. The new model routes around that broad immunity debate by binding selected companies to government authority. It avoids a free-for-all while creating a rarer institution: a supervised private offensive cyber corps assembled through contracts.
the operator class will shape the doctrine
The first implementation rules will decide who can enter this market and what counts as competent performance. Technical proficiency and prior operational experience sound neutral until the eligible pool is examined. Firms already serving intelligence, defense, and law enforcement possess the facilities, clearances, classified workflows, and contracting staff to qualify quickly. Smaller offensive-security shops may have sharper operators and far less compliance machinery.
The resulting roster will influence which operations appear feasible. A company built around threat intelligence will propose surveillance. A firm with takedown infrastructure will see disruption paths. An exploit developer will see persistence and access. Procurement buys capacity and selects the institutional imagination applied to a target.
The White House has turned an old argument about corporate self-defense into a new argument about delegated state force. The decisive controls now sit in target packages, classified procedures, contract terms, attribution standards, and abort logic. The code matters. The paperwork decides where it runs.