A new era in US cybersecurity has begun with a presidential memorandum that allows vetted private companies to conduct cyber operations under federal control against foreign cybercrime gangs. The initiative, managed by the National Coordination Center (NCC), marks a significant shift towards a more collaborative approach between the government and the private sector.
The program authorizes participating companies to execute “cyber surveillance operations” and “cyber effects operations” targeting foreign cyber-enabled transnational criminal organizations (TCOs). Cyber surveillance operations focus on covertly accessing systems to collect intelligence, while cyber effects operations cover actions that disrupt, degrade, or destroy adversary information systems and infrastructure. This means that US companies can now work closely with the government to gather vital threat intelligence and take down malicious actors.
To participate in this program, companies must undergo rigorous vetting and sign formal contracts with the Department of Justice (DOJ) or the Department of Homeland Security (DHS). These contracts may require a bond or escrow of at least $1 million, which will be forfeited if a company fails to comply with operational requirements. This is an important measure to ensure accountability and responsibility among participating companies.
The directive establishes clear boundaries for authorized activity, explicitly barring operations that result in “critical outcomes.” This means that no action can be taken that may cause loss of life, serious injury, or rise to the level of a use of force or armed attack under international law. Operational controls require written approval from the executive directors before any company takes action on a cyber package.
Target selection is restricted to non-state criminal groups, though foreign entities are assumed to be independent of foreign governments unless clear intelligence proves otherwise. The White House has also emphasized strict safeguards regarding domestic targets and US persons, with contractors required to immediately cease operations if they discover an accidental breach.
This new program matters because it acknowledges the growing threat posed by foreign cybercrime gangs and recognizes that cooperation between the government and private sector is essential in combating this menace. By allowing vetted companies to work closely with the government, we can expect more effective and efficient operations against these malicious actors. As the cybersecurity landscape continues to evolve, this initiative represents a significant step forward in protecting national security and keeping our digital infrastructure safe.
The practical takeaway for readers is that this program highlights the importance of collaboration between the private sector and government agencies in combating cyber threats. It also underscores the need for companies to be vigilant about cybersecurity risks and work closely with their stakeholders to ensure they are aware of potential vulnerabilities. As we move forward, it’s essential to stay informed about emerging threats and best practices for mitigating them.
Source: SecurityWeek — 2026-08-13