The Presidential Memo on Combating Transnational Cybercrime: Implications for Industry and Government | #cybercrime | #infosec


The Trump administration expressed an early desire for the United States to adopt a more aggressive posture against adversaries in cyberspace and to unleash the private sector as part of this fight. Last week, the administration published a presidential memorandum that makes this intent a policy by authorizing private companies to directly combat cyber-enabled criminal organizations in cyberspace. In clear alignment with the 2026 U.S. National Cyber Strategy, the memorandum reflects a hardened posture by the United States in cyberspace, amounting to a renewed effort to deter, degrade, and disrupt its adversaries. However, it lacks key details that will make or break the effort, including important questions around authorities, legal protections for companies, and target sets, exposing diverging risk appetites between the administration and private sector.

The Scope of the Cybercrime Problem

By some estimates, the United States loses over $20 billion annually to cybercrime. Designated a national security threat in the 2023 U.S. National Cyber Strategy, cybercrime undermines the U.S. economy and society and public trust in institutions. Some of the victims of these crimes are big businesses with the capability to return fire, and many are champing at the bit to do so. These companies own and operate vast infrastructure, and in some cases, effectively possess state-grade intelligence capabilities. They argue that they should not be kept on the sidelines when they could help.

As the problem has grown, so has the appetite for widening the slate of tools available to retaliate. The most recent cyber policy discussions have fiercely debated the right vehicle for harnessing private sector capabilities, up to and including cyber “letters of marque”—a concept going back to the 1800s whereby Congress could authorize private shipowners to combat vessels and capture their goods.

In some ways, this initiative is not particularly new. Private actors have long signed contracts with the federal government for offensive cyber operations, whether providing capabilities, access, or effects (meaning physical or cognitive outcomes from cyber operations) within their own infrastructure. Some of the bigger companies have already taken independent action to combat criminal actors in cyberspace: Google recently set up a threat disruption unit to “actively shape the outcome of adversary behaviors,” while Microsoft has a Digital Crimes Unit that legally disrupts and dismantles adversary infrastructure. But these efforts have been legally limited. The new memorandum is a qualified, initial step toward unleashing these industry partners to do far more.

The Cybercrime Threat Landscape and Diverging Private Sector Risk Appetites

Some of the key targets outlined in the memo reflect where private sector offensive cyber operations could provide much-needed speed and scale of effect. This includes targeting traditional cybercrime groups, such as ransomware groups, that are usually associated with serious and organized crime; less sophisticated cyber criminals that conduct high-volume cybercrime and cyber-enabled fraud; and cyber scam compounds in East Asia that have proliferated in recent years. This is where the private sector has been pushing to take more action—specifically, against low-risk actors—and it is well-established to do so for defensive purposes, such as dismantling cybercriminal infrastructure, taking down malicious websites, monitoring for fraudulent accounts and other abuses of company services, and seizing cryptocurrencies. But this is where their authorities would stop—the memo expressly forbids going after state-associated groups.

However, the line between state and criminal actors has become increasingly blurred over the last five to 10 years in cyberspace, with different degrees of association. Some criminal groups are directly state-funded, others state-directed, others coerced, and so on. The Russian cyber ecosystem in particular has extensive crossover between criminal groups and state-sponsored activity, but North Korean state actors also conduct cybercrime to evade sanctions, and moonlighters in the Chinese cyber ecosystem often conduct cybercrime on the side for personal financial gain. Even the cyber scam compounds are thought to have explicit ties to, or at least tacit approval from, the Cambodian and Thai ruling elite. Parsing the distinction could take months of painstaking intelligence work to clarify, risking missing an operational window between when companies discover malicious activity and when the U.S. government gives its approval to act.

There is also a real risk of divergence between the Trump administration and private sector regarding risk appetite. In policy discussions, companies have persistently raised their concerns at legal liability risk—primarily the Computer Fraud and Abuse Act, which criminalizes unauthorized access to computer systems—particularly where an operation may result in an unintended consequence or harm. Moreover, these same companies have also raised serious concerns about the risk of retribution against their staff, particularly from cartels. This is where the program’s scope risks being a problem.

Critically, looking at who this administration includes within the term “transnational criminal organizations” effectively asks the private sector to deploy its capabilities against “narco-terrorists,” including Mexican cartels that have been known to use spyware, malware, and cryptocurrencies, among other technologies and services, to enable their activities. However, “narco-terrorism” is already considered by many in the foreign policy and national security communities as an overexpansion of national security authority and capabilities, having resulted in legal challenges and deaths. These concerns will only be compounded by involving private companies, who might consider targeting with cyber operations cartels to be beyond their acceptable risk thresholds. Some companies may sign up for the program for patriotic reasons, then reconsider whether they believe narco-terrorists fall within the bounds of national security threats.

Key Challenges and Implications for the U.S. Government

Under which authorities these industry actors would operate is still up for debate. Traditionally, offensive cyber operations are either authorized under Title 10 (military, and specifically Cyber Command) or Title 50 (intelligence community operations). This ensures that U.S. offensive cyber operations do not adversely impact the U.S. government’s statutory functions and goals, and that they adhere to the legal requirements in U.S. code. This program reports into the Department of Justice (DOJ) and Department of Homeland Security (DHS). While the FBI (under the DOJ) and the DHS’s Office of Intelligence and Analysis have Title 50 authorities, neither has Title 10. Plus, some of these activities could be construed more as law enforcement actions than military activities. Getting legal authorities right is critical to the program’s success, as it is to reassuring companies of minimized legal risk.

Related to authorities, some mechanism for deconfliction will need to be in place before these operations start. This will be vital to prevent companies from inadvertently disrupting U.S. intelligence, military, or allied cyber operations against the same target sets, noting that the program includes both surveillance operations and cyber effects operations. This will need to take place in a way that does not break classification rules, and if done correctly, could bring about more effective visibility for the U.S. government into how threat actors are exploiting cyberspace.

The memo also offers an opportunity to transform the United States’ overly rigid offensive cyber supply chains, which comprise the various private firms that provide capabilities or technical exploits to the U.S. government. The current system has long been considered stagnant in locking out boutique firms or start-ups—costing the United States important agility and strategic advantage relative to China in particular, which has successfully built up its own ecosystem of private suppliers. Containing language that explicitly enables participation by “smaller, more agile companies” compared to the usual defense primes, the memo sends an important signal to the market and may help stimulate much-needed competition, especially where the program can reduce barriers to entry for small start-ups.

Recommendations

It is a pivotal moment for security in cyberspace. State actors are ramping up activity, as we have seen with the likely Iranian attacks on U.S. water facilities, while high-profile cybercriminal incidents are impacting more sectors across the U.S. economy and society, such as schools. U.S. government actors have their hands full and should make use of industry’s talent and hunger to help. Addressing these recommendations will help make this program a success:

  • S. government interlocutors should remove the ambiguity around which cyber actors are in and out of bounds by creating a whitelist of potential targets and sharing the intelligence with participating companies.
  • Congress should establish an initial blanket legal protection for companies that sign up for this program, then reevaluate what legal protections are healthy and necessary after one year.
  • The DOJ and FBI should have contingency plans in place for cases in which companies find themselves targeted by organized crime or cartels, including measures to protect the physical and cyber safety of employees.
  • The White House should ensure Congress is on board with the program and work with congressional leadership to establish which committees have jurisdiction over these activities. Is it the Homeland Security Committees, via DHS, or the Justice Committees via DOJ, or the intelligence committees because of the potential overlap with intelligence operations? If the answer is “all of the above,” how will members of Congress prevent topics falling through the jurisdictional seams?
  • Similarly, the White House, preferably the Office of the National Cyber Director, should set up metrics for evaluating whether the executive branch governance of this program is adequate or logical, and, at the end of year one, establish whether the DHS and DOJ are the right points of oversight or whether shifting oversight to the director of national intelligence would make more sense.
  • The DOJ and DHS should ensure that smaller actors have a chance to participate, as intended, by lowering the bar for smaller firms to engage with the government and helping them navigate these new regulations and contracts.
  • Finally, the White House should use this program to enhance S. deterrence in cyberspace by ensuring that public-facing officials talk about the intent to amplify U.S. capabilities to hunt and disrupt cyber actors.

Conclusion

Cybercrime and cyber-enabled fraud pose long-standing threats to U.S. national security and the economy. The intention for the private sector to conduct offensive cyber operations against such actors will be welcomed by many in the policymaker and operational spheres and builds upon what some companies have already been doing. The program will not be without obstacles, though, not least in the form of operational and legal hurdles and the challenge of aligning between private sector and administration risk appetites. The sensible way forward would be through a pilot program, such as seizing criminal cryptocurrency wallets, which cyber specialists have already suggested.

Unleashing the prowess and unique capabilities of the U.S. private sector could yield much longer-term benefits for U.S. offensive cyber supply chains and capability pipelines—a much-needed transformation that would ultimately strengthen the United States’ longer-term strategic advantage in cyberspace relative to peer competitors such as China. This approach may even go so far as to help reestablish U.S. deterrence in cyberspace: Enhancing the scale, speed, and sophistication of U.S. operations against cybercriminal actors will send important signals to state adversaries, too.

Nikita Shah is s senior fellow with the Intelligence, National Security, and Technology Program at the Center for Strategic and International Studies (CSIS) in Washington, D.C. Emily Harding is director of the Intelligence, National Security, and Technology Program and vice president of the Defense and Security Department at CSIS.



Click Here For The Original Source.

——————————————————–

..........

.

.