Risk alert

US opens a controlled role for private firms in cross-border cyber operations

A White House memorandum creates a program allowing approved US private firms, under government control and oversight, to conduct reconnaissance and cyber effects operations against foreign criminal networks.

The US government has moved private cybersecurity firms from a supporting role toward controlled operational participation. A White House memorandum directs the creation of a program under which approved US firms may conduct cyber reconnaissance and cyber effects operations against foreign criminal organizations, subject to government control, oversight, and written approval for each action.

A new operational opening for private security firms

The memorandum directs a national coordination center to create a program for approved US private companies to conduct cyber reconnaissance and cyber effects operations against transnational foreign cybercrime organizations. This goes beyond ordinary threat-intelligence sharing. The document places firms under government control and oversight and requires written approval for individual operations. The Verge reported that the arrangement would let private companies monitor and disrupt criminal networks within a federal authorization framework.

Authority is coupled with operational controls

The memorandum ties participation to concrete safeguards. Procedures must be established within 60 days, company eligibility must be reviewed at least annually, and each operation needs case-specific written approval. Activities must stop if they inadvertently affect US persons. The document also limits outcomes that could cause death, serious injury, or amount to a use of force under international law. A March executive order had called for incorporating commercial cyber capabilities and intelligence; the new memorandum turns that direction into an actionable program.

Liability questions may constrain adoption

The strongest countercase is that government oversight may not automatically remove private-sector legal and civil exposure. Lawfare argues that, absent clearer congressional authorization and liability protections, the CFAA and state computer-crime laws may still apply. Preemption, oversight, and liability for harm to innocent third parties also remain unresolved. The program is therefore established, but its practical scale will depend on implementation details.

What to watch next

Watch for observable evidence: whether the coordination center publishes admission criteria, participating firms, and a case-approval process within the 60-day window; whether formally authorized operations emerge; and whether Congress, DOJ, or regulators issue additional rules on liability, data handling, and cross-border coordination. Those developments would clarify whether the program can become a durable commercial market.

Sources