Published
- 21 min read
The New US Private Cyber Program Needs Public Boundaries
Stay Safe Online Without Making It Your Second Job
The Digital Fortress (Second Edition)
A warm, plain-English guide for people with real lives and finite patience. Learn the handful of habits that genuinely protect your money, accounts, and family, and get honest permission to ignore the rest.
For People Who Cannot Afford to Get Privacy Wrong
The Anonymity Playbook (Second Edition)
A practitioner’s field manual for journalists protecting sources, whistleblowers, and activists. It explains how the surveillance actually works, what each technique costs you, and exactly where it fails.
Write, Ship, and Maintain Code Without Shipping Vulnerabilities
Secure Software Development
A hands-on security guide for developers and IT professionals who ship real software. Build, deploy, and maintain secure systems without slowing down or drowning in theory.
Use AI Coding Agents Without Losing Control of Your Codebase
The Secure Harness
A calm, practical guide to letting agents do useful work inside boundaries you set, enforce, and audit. Ships with 15 copy-pasteable artifacts: hook scripts, permission configs, release gates, and MCP templates.
Stop Shipping Demos. Start Shipping Systems.
The AI Native Engineer
Sixteen hands-on chapters, one real product. Grow it from a single model call into a retrieved, tool-using, observable, production-grade system, with evaluation treated as a habit from the first feature.
A security company sees a ransomware server stealing from American hospitals. It has the talent to enter that server, watch the operators, and perhaps shut part of the network down. Until now, the company’s ordinary legal choices have stopped well short of crossing into someone else’s machine. A new White House memorandum proposes a route across that line, but only while the company is acting for the federal government under written approval and supervision.
That distinction matters. Headlines have called the plan permission for private firms to “hack back.” The memorandum signed on 12 August 2026 describes something narrower and more consequential: a government-run contracting program for cyber surveillance and disruptive operations against foreign criminal organisations. It does not give a breached company a licence to chase whoever attacked it.
As of 17 August 2026, the programme’s operating procedures do not yet exist in public. The Department of Justice and Department of Homeland Security have 60 days from the memorandum’s date to write them. Those rules will decide whether this becomes a disciplined extension of federal operations or a fast approval lane built around confident guesses.
The programme deserves a fair hearing because the problem is real. Criminal infrastructure moves quickly, private providers often see parts of it first, and government disruption can arrive after victims have already paid. It also deserves hard scrutiny. The same speed that makes private capability attractive can turn a mistaken identity, a shared server, or a vague approval into someone else’s outage.
What the memorandum actually changes
The order creates a programme inside the National Coordination Center, or NCC. Two executive directors, one chosen by the attorney general and one by the homeland security secretary, would supervise it. A participating American company would need a contract with Justice or Homeland Security, pass vetting, follow programme procedures, and receive written approval for every operation before acting.
The White House text defines two kinds of work. A “Cyber Surveillance Operation” can enter a target system without the owner’s permission, remain hidden, and collect intelligence. A “Cyber Effects Operation” can manipulate, disrupt, deny, degrade, or destroy systems, networks, infrastructure, or information. In ordinary language, one watches inside the target; the other changes or breaks something there.
Those definitions remove any doubt about the ambition. This is more than sharing indicators, seizing a domain through court process, or filtering hostile traffic at a company’s own edge. A contractor could be approved to enter foreign systems and could later be approved to interfere with them. The operation would be conducted on behalf of the United States and under federal supervision.
The public document adds several controls. Participating companies may be required to keep a bond or escrow of at least $1 million, subject to forfeiture for contractual non-compliance. They face review at least once a year. If an operation accidentally reaches a US person, a system in the United States, or a system controlled by a US person, the company must stop, minimise what it has collected, and notify the NCC, which must notify Justice.
Operations likely to cause death, serious injury, or consequences rising to an armed attack under international law fall into a category called “Critical Outcomes.” The two programme directors cannot approve those. The memorandum also requires coordination across law enforcement, State, Treasury, the Department of War, Justice, and the intelligence community. That coordination is meant to stop one American operation from colliding with another.
All of this makes the label “private hack-back” misleading. Federal News Network reported on 14 August that the plan does not let a company retaliate when breached. The government selects and approves operations, while a contracted firm supplies capability. The better comparison is a private contractor carrying out a government mission, with the unusually important detail that the mission happens through networks owned by people who may never know it occurred.
The paperwork still leaves a large blank space. The public memorandum orders operating procedures within 60 days and points to a classified annex for parts of the workflow. Until those procedures appear, nobody outside the programme can assess how target confidence is measured, how collateral systems are mapped, how errors are investigated, or what an approval actually permits. A promise of oversight is the start of a control, not evidence that the control works.
Why “under government supervision” carries so much weight
A ransomware payment can pass through layers of rented servers, compromised routers, relays, resellers, and accounts opened with stolen identities. The machine that answers an investigator’s connection may belong to a criminal group. It may also belong to a small business whose forgotten server was taken over, a cloud customer sharing hardware with others, or a provider in a country that sees the operation through its own criminal law.
That is why defenders have traditionally drawn a bright boundary around systems they own or have permission to test. Inside the boundary, they can isolate a device, block traffic, preserve logs, plant decoy documents, or rebuild a server. Beyond it, the same keystrokes can become unauthorised access. The technical action may look continuous while the authority changes completely.
The US Computer Fraud and Abuse Act sits near that boundary. The Justice Department’s current prosecution policy explains how federal prosecutors apply the law against unauthorised access and damage. The new memorandum repeatedly says programme activity must comply with the Constitution, federal law, international obligations, and 18 U.S.C. § 1030. It relies on government authority, written direction, and supervision rather than creating an open exception for private action.
That arrangement gives every approval document unusual importance. A contractor needs to know the named target, permitted methods, time window, collection rules, stop conditions, and person who can change the order. “Disrupt this group” is a policy aim. It is far too loose for an operator at a keyboard. The safe version identifies what may be touched and what must remain untouched, then makes exceeding that scope detectable.
Lawyers at Wiley made the same practical point in their 14 August analysis of the memorandum. Companies considering participation will need to examine liability allocation, indemnification, litigation support, operational authority, bonding, subcontracting, and compliance. They also recommend retaining adequate documentation of government approval for each activity. A classified instruction that cannot later be explained to a court, customer, or foreign partner may protect a source while leaving the contractor exposed.
The memorandum’s language about “complete oversight and control” sets a demanding standard. Control means the government can prevent an unsafe action before it happens, see what a contractor is doing while it happens, and stop it quickly when facts change. A review after the target has disappeared does not meet that standard. Neither does a dashboard that records commands without showing whether the operator reached an unapproved tenant behind the same address.
Written authority is therefore necessary, but the operational system around it matters more. The programme will need narrow credentials, live telemetry, independent approval for high-impact steps, and a reliable kill switch. It will also need people with enough time and technical context to say no. If approval becomes a rubber stamp because criminal infrastructure moves fast, federal supervision will exist on paper while the contractor makes the real decision alone.
Attribution becomes an operational safety control
Investigators rarely discover a tidy server labelled with a gang’s name. They assemble a case from infrastructure patterns, malware behaviour, financial movement, access records, reused accounts, victim reports, and intelligence that may be incomplete. Each clue can be persuasive. None makes every machine in the chain safe to enter or disable.
The new programme defines a covered group as a foreign organisation conducting cyber-enabled crime against US people or interests, provided it is not part of a foreign government or wholly directed by one. The definition then adds a striking presumption: a foreign group is assumed not to be part of a government unless clear intelligence establishes that connection. That may help the programme move, but it places heavy pressure on the quality of the intelligence search.
Consider a compromised hosting account used by both a criminal operator and an intelligence service. The visible ransomware activity may fit the programme. A surveillance foothold placed there could still cross into state infrastructure or reveal a separate American operation. The error would not necessarily come from poor hacking. It could come from a correct observation paired with an incomplete map.
Shared infrastructure creates a second problem. An internet address can point to a reverse proxy serving thousands of domains, a content delivery node, a virtual server host, or a router carrying traffic for unrelated customers. Destroying the wrong virtual machine can erase victim evidence. Disabling the right domain at the wrong layer can interrupt innocent services. A clean target name does not guarantee a clean technical boundary.
The memorandum acknowledges this through “deconfliction,” the process of checking whether an operation interferes with another agency’s work or another national interest. Former FBI intelligence official Tonya Ugoretz told Federal News Network that deconfliction remains difficult even after decades of government experience because agencies have different equities and adversaries shift infrastructure quickly. Adding private participants creates another layer of communication and timing.
Deconfliction should extend beyond a list of government operations. The target package needs a current dependency map: who owns the address, what tenants share the host, what upstream provider can act lawfully, what evidence sits on the machine, and what happens to adjacent services if a disruptive step succeeds. The map will decay. A target verified on Monday may have moved by Tuesday morning.
At that point, speed must bend to verification. A contractor may be able to act in minutes, but its authorisation should expire as the infrastructure changes. High-confidence identity at noon cannot be carried forward indefinitely. The approval system needs short validity windows and a forced recheck immediately before any action that alters or destroys data.
There is also a privacy consequence. A surveillance operation is designed to remain undetected and collect information for possible later action. Criminal systems contain conversations with victims, stolen databases, reporter contacts, employee records, and data copied from unrelated organisations. Entering the criminal’s machine can expose more innocent people, not fewer. The programme’s minimisation rules must cover that material even when no US person was the intended target.
The Anonymity Playbook returns often to the same practical question: where does observation cross a trust boundary, and who can join what they see to a real person? This programme creates a new observer with powerful access. Its collection limits should be treated as part of the operational design, rather than a legal appendix read after the data arrives.
The hardest failures happen at the seams
A carefully approved operation can still fail between organisations. The government writes the target package. A prime contractor interprets it. A smaller specialist may supply a tool. A threat-intelligence company provides indicators gathered from customers. A cloud provider hosts the system. Each party sees a different slice, and nobody automatically sees the whole risk.
The memorandum permits participating companies to make commercial agreements with private entities that hold threat information from normal business activity. It also requires disclosure of those contractual relationships to the NCC. That is sensible because the information supply chain affects targeting. It does not yet tell us whether the source company can audit how its customer data was used or correct an indicator after an operation begins.
A stale indicator is an ordinary intelligence problem until it enters an effects package. Then it becomes a command pointed at the wrong machine. The programme should record the source, collection time, confidence, known alternatives, and expiry for every material indicator. If a source retracts a claim, that change should reach the operator before the next action, not during the annual review.
Tooling creates another seam. An operator may receive approval to collect a defined set of files, while an automated scanner discovers and indexes far more. A disruption tool may follow redirects or move laterally because its default behaviour was written for a test lab. The person who approved the package can believe the scope is narrow while the software interprets it broadly.
The memorandum says the NCC should use automation to streamline programme elements where appropriate. Automation can help compare target packages, enforce expiry, and block commands outside an allowlist. It can also accelerate a bad assumption across many systems. Any automated step that chooses, expands, or changes a target needs the same review as a human proposal and a hard ceiling on what it can cause.
Financial incentives sit at the same seam. A contractor is paid to provide capability and complete a mission. The government wants useful results. Both can start to treat caution as delay, especially after an operation has consumed weeks of intelligence work. A $1 million bond may deter obvious non-compliance, but it may be small next to a large contract and says little about harm to a third party.
The bond’s trigger is not defined in the public memorandum. The phrase “enter non-compliance” leaves open whether forfeiture follows a technical overshoot, a late report, an unapproved subcontractor, or only a serious breach. A useful control needs predictable consequences. If the penalty depends on a private contract interpretation after an incident, it will shape behaviour less than the headline figure suggests.
Customer trust is part of this calculation too. A security provider may know how its telemetry could identify criminal infrastructure. Customers may have supplied that telemetry for defence, support, or fraud prevention without expecting it to feed an offensive package. Ugoretz told Federal News Network that companies adjacent to the programme will need to weigh customer trust, whether they operate directly or provide data. That concern deserves a direct answer in contracts and privacy notices.
The seam test is simple: can every participant explain what authority it has, what data it may use, what action it may cause, and who stops it? If any answer relies on “the other party handles that,” the boundary is open. The programme will be judged by those handoffs because that is where technically capable systems usually become unaccountable ones.
What this means for defenders outside the programme
Most security teams will never conduct an approved federal cyber operation. The memorandum still changes their environment because many will hold the intelligence, logs, infrastructure, or customer relationships that participating companies need. A provider may approach them for data. Law enforcement may ask them to preserve a system. An outage may later turn out to have been an authorised disruption.
The first lesson is wonderfully boring: do not hack back. A presidential memorandum creating a supervised programme does not extend federal authority to a company defending its own network. Help Net Security’s account of the order confirms that both surveillance and effects operations require written government approval and direction. A consultant’s confidence, a victim’s consent, or a clear-looking indicator does not substitute for that process.
The second lesson concerns evidence. When you find a command server, stolen data store, or attacker account, preserve what your own systems can lawfully show. Record times in Coordinated Universal Time, retain original logs, hash exported files, note how the evidence was collected, and keep the chain of custody. Send it through counsel and the established law-enforcement contact instead of exploring the remote system yourself.
Your evidence should also carry uncertainty. Separate what you observed from what you inferred. “Address 203.0.113.18 connected to our gateway at 04:12 UTC using this certificate” is an observation. “That address belongs to the gang” is an assessment that needs supporting context. Keeping those layers apart helps an approving official see where a target package can break.
A request for data deserves its own authority check. Ask who is requesting it, under what legal or contractual basis, for which operation, and with what retention and onward-sharing rules. If the request comes from a private company, establish whether it is a programme participant and whether your agreement is one the NCC requires it to disclose. A logo and a federal-sounding project name prove very little.
Cloud and network providers need a response path for suspected programme activity. Their abuse teams may otherwise see government-directed access as ordinary intrusion and block it, while their operations staff could later comply with a request that lacks proper authority. A small, cleared contact group can verify requests without spreading sensitive details across the company. Everyone else should keep following the normal incident process.
Boards should resist a different misunderstanding. The existence of an offensive programme does not reduce the need to patch, segment, back up, rehearse recovery, and remove exposed services. Disruptions buy time. Criminal groups rebuild, change providers, or split into new names. Federal News Network’s sources made that resilience explicit: even well-organised government action rarely ends the underlying business permanently.
The programme may produce valuable intelligence for defenders, but the sharing direction matters. A contractor that learns a gang is exploiting a product should have a defined route to warn the vendor and likely victims without exposing the operation. If secrecy prevents timely defence, the government should record that trade-off and revisit it. Silence can protect a mission while leaving another organisation open.
A practical preparation sequence
You do not need an offensive-cyber policy unless your organisation plans to seek a programme contract. You do need a policy for the moment someone asks you to supply threat information, preserve infrastructure, or support an operation. Write it before the request arrives, when nobody is leaning on the urgency of an active case.
-
Draw the legal boundary around your current response work. Document which systems your team owns, which customer actions its contracts permit, and where remote investigation must stop. Include managed-service and cloud environments because ownership and permission often diverge there.
-
Name the people who can receive a government-linked request. Route it to a small group spanning incident response, legal counsel, privacy, and an accountable executive. Give the security operations centre a simple escalation path rather than asking an analyst on night shift to interpret federal authority.
-
Separate evidence from attribution. Use an incident record with distinct fields for observed facts, source reliability, assessment, competing explanations, confidence, and expiry. Preserve the raw material that another investigator would need to challenge your conclusion.
-
Set rules for sharing customer-derived intelligence. Identify which contracts, notices, and laws permit each class of data to be shared. Require a written purpose, minimisation plan, retention period, onward-sharing limit, and deletion or review date.
-
Verify the request and its scope. Confirm the programme participant, government contact, operation identifier, legal instrument, approved data fields, and secure delivery route through independently obtained contact details. Treat a request to “send everything” as a scope failure.
-
Keep a decision log. Record what was requested, what you supplied, who approved it, what uncertainty you disclosed, and when the recipient must review or delete it. This protects the people whose data appears in the case and gives your own investigators a record when staff change.
-
Create an emergency stop path. If you discover that shared intelligence points to a US person, an innocent tenant, a journalist’s source, or unrelated victim data, know exactly whom to call. The programme’s own stop-and-notify rule should be mirrored by organisations feeding it information.
-
Rehearse one awkward case. Use a scenario where the suspected criminal server shares infrastructure with an innocent customer and the indicator changes halfway through the exercise. The rehearsal should test who can halt disclosure, correct the record, and notify affected parties.
This sequence does more than prepare for one federal initiative. It improves ordinary breach work because it forces your team to mark the point where a log becomes an allegation and where an allegation might cause action. That point deserves a person, a record, and a stop button.
The tests the programme should have to pass
The White House has set a 60-day deadline for operating procedures and a 180-day deadline for the first status report. Those milestones measure whether documents were produced. The public also needs evidence that the controls can catch the failures the documents describe.
A useful test begins with a target that moves. Give reviewers a valid criminal server, then move the domain to shared hosting before execution. Does the approval expire? Does the operator re-resolve and re-map the dependency? Can the system prevent an effects command when the current host falls outside the package?
Another test should inject a US person into collected data. The memorandum requires the company to stop, minimise, and report when operational activity unintentionally targets a US person or US-controlled system. Reviewers should measure how long discovery takes, whether collection truly stops, what data remains in backups, and who verifies the minimisation. “The operator notified the NCC” leaves most of the control untested.
A third test should create an intelligence conflict. One agency wants to watch the server, another wants to seize it, and a contractor proposes disruption because victims are still being hit. The deconfliction process must produce an accountable decision quickly enough to matter. It should also record who accepted the cost to victims if observation continues.
The programme needs an independent route for reporting mistakes. Operators and subcontractors should be able to raise a scope or safety concern outside their immediate chain without losing evidence or facing retaliation. Providers and foreign partners need a way to report suspected collateral damage and receive a case number. Secret operations still require a door through which errors can enter.
Public reporting can protect operational details while answering basic questions. How many companies participate? How many operations were approved, changed, halted, or found to exceed scope? How often did US-person minimisation occur? How many third-party systems were affected? How many bonds were forfeited, and for what class of failure? Aggregate counts will not expose a target, but their absence will make “complete oversight” impossible to assess.
Congress has a role even if the programme begins under executive authority. Funding, reporting, liability, privacy, and international consequences all benefit from a durable public framework. The memorandum’s general provisions say it creates no enforceable right or benefit against the government or its agents. That language makes external oversight more important when someone outside the programme bears the cost of an error.
Foreign partners will judge the programme by conduct rather than its American contract language. A server in another country remains subject to that country’s law and sovereignty concerns, even if a US official approves access. The Council of Europe’s Budapest Convention framework exists to support cooperation and evidence work across borders. A fast effects operation and a slower cooperative process solve different problems, but speed should not quietly erase the second country’s interest.
The strongest version of this programme would be difficult to join, tedious to approve, narrow to execute, and quick to stop. That sounds inefficient until you remember what the contractor is being allowed to do. Friction is useful when a mistaken command can destroy evidence, interrupt an innocent service, or cross a national boundary.
The line worth defending
The new memorandum recognises a real asymmetry. Criminal groups rent global infrastructure, reuse compromised machines, and abandon them quickly. Private companies often have the telemetry and people to follow that movement faster than a conventional government process. Bringing some of that capability into supervised federal operations could help victims.
The plan also moves state power through commercial hands. That is the part worth watching. A contract can define a mission, but it cannot make attribution certain. A bond can punish a breach, but it cannot restore erased data. A classified annex can protect methods, but it cannot replace public evidence that the programme stays inside its limits.
The argument should therefore move past the slogan of “hack back.” Private retaliation remains outside the programme described on 12 August 2026. What is being built is a government operation that uses private operators, private intelligence relationships, and private tools. Its legitimacy will depend on whether government control is real at the exact moment a target changes or an operator reaches the wrong system.
For defenders, the immediate action is clear. Keep your own response work on systems you are authorised to touch. Preserve evidence. Mark uncertainty. Verify any request for data through an independent route. If your company considers joining, demand precise written scope, live government supervision, liability terms, and a stop mechanism before anyone opens a terminal.
The programme’s first public success should not be a dramatic takedown. It should be an operating procedure that makes restraint visible and failure measurable. That is how useful capability earns trust when the work itself must stay mostly out of sight.
If you want security and privacy guidance without a daily alarm bell, the newsletter sends one email per month. The signup is on this site.
Sources
- The White House: Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, accessed 2026-08-17
- Federal News Network: Trump’s move to ‘unleash’ private sector hackers raises novel oversight, liability questions, accessed 2026-08-17
- Help Net Security: White House authorizes private US companies to hack foreign criminal networks, accessed 2026-08-17
- Wiley: Analysis of the New Presidential Memorandum on Transnational Cyber-Enabled Crime, accessed 2026-08-17
- US Department of Justice: Justice Manual, Computer Fraud and Abuse Act, accessed 2026-08-17
- Council of Europe: About the Convention on Cybercrime, accessed 2026-08-17