The United States has long relied on private companies to defend against cybercrime. Under a new program called for in an August 2026 White House memorandum, companies can now go on the offensive. This initiative could give the United States a powerful new tool against criminal groups that target businesses, critical infrastructure operators, and Americans through ransomware and scam attacks. But permitting private companies to pursue offensive cyber operations also creates risks of collateral damage, legal liability, and unintended escalation. The administration should therefore use the memorandum’s implementation process to establish rigorous guardrails for attribution, collateral impacts, international coordination, and congressional oversight.
In its Expanding Capabilities to Combat Transnational Cyber-Enabled Crime memorandum, the Trump administration directs the National Coordination Center (NCC) to create a program authorizing vetted U.S. companies to conduct offensive cyber operations against foreign cyber-enabled transnational criminal organizations. The memorandum establishes several safeguards, including mandatory vetting, contractual agreements, Department of Justice (DOJ) and Department of Homeland Security (DHS) oversight, and strict operational procedures. It also requires compliance with U.S. law and international obligations and directs federal agencies to create detailed processes for participation, target identification, deconfliction, and operational review. The administration should build on these requirements by ensuring that the resulting rules are specific, predictable, and rigorous enough to manage the risks inherent in offensive cyber operations.
First, the administration should use the forthcoming DOJ and DHS procedures to establish a predictable authorization framework for conducting operations rather than leaving key decisions to case-by-case discretion. The memo already mandates minimum participation criteria, standardized rubrics, and written approval for every operation. The implementation procedures should therefore specify how those requirements will be applied in practice, including the factors agencies will weigh in approving missions, the operational boundaries companies must observe, and the circumstances that trigger review by senior federal officials. Publishing sufficiently detailed guidance would reduce uncertainty for participating companies and allow them to assess in advance whether proposed operations are likely to qualify for authorization.
Second, federal officials should strengthen the memorandum’s assessment framework by establishing a strict process for evaluating the risks of misattribution and unintentional escalation. The memo limits eligible targets to foreign groups that are not institutional parts of foreign governments or wholly operated under their direction, but determining those relationships can become difficult when criminal organizations operate alongside or receive support from state actors. Implementation guidance should require agencies to assess the basis for attribution, including intelligence provided by participating companies, and seek additional corroboration where a target may have links to a foreign government. Proposed operations involving uncertain attribution, suspected government ties, or a significant risk of retaliation should receive heightened review.
The administration should also expand safeguards against collateral effects, particularly when operations could affect critical infrastructure. Although the program will target foreign criminal groups, those groups may rely on compromised U.S. networks to conduct their operations, creating risks that offensive actions could disrupt legitimate systems. The memorandum already requires participating companies to cease activity and notify the government if they unintentionally target a U.S. person or a domestic information system. Agencies such as the Cybersecurity and Infrastructure Security Agency should participate in reviews to assess the likelihood of spillover or retaliatory effects on essential services, helping ensure that efforts to disrupt criminal activity do not inadvertently disrupt critical infrastructure.
These assessments should also consider whether an operation could affect critical infrastructure located in another country. The memorandum requires operational deconfliction with the Department of State and compliance with international obligations, but offensive cyber operations can still create diplomatic risks when they affect legitimate foreign systems. Requiring advance consent from foreign governments for every operation could undermine the program’s speed and effectiveness. Still, operations that could affect foreign infrastructure should receive a case-by-case assessment of the host country’s interests and sovereignty, as well as applicable international law. Where appropriate, the U.S. government should coordinate with foreign governments to reduce the risk of disrupting legitimate systems or triggering diplomatic tensions.
Finally, Congress should establish long-term oversight of the program. Although the memorandum requires an annual report on the program’s status to executive branch officials, Congress should establish statutory reporting requirements that provide greater visibility into its scope and effectiveness. Reports should include the number and types of operations conducted, along with evidence of the program’s effectiveness in disrupting transnational criminal organizations. Congress should also clarify the legal boundaries of private-sector offensive cyber activity and establish appropriate liability protections for companies acting within federally authorized operations. These measures would give participating companies greater certainty while ensuring that the program does not expand beyond its intended purpose without legislative review.
The administration’s decision to leverage private-sector cyber capabilities marks a long-awaited step toward enabling a valuable new tool against transnational cybercrime. But the program’s success will depend on whether its implementation rules can harness those capabilities without creating new risks. By strengthening the memorandum’s requirements with rigorous standards for attribution, escalation, collateral effects, and international coordination and pairing them with durable congressional oversight, the United States can make offensive cyber operations a more effective tool against criminal organizations without undermining U.S. national security or public trust.
Click Here For The Original Source.
