Cybersecurity & Tech Executive Branch Surveillance & Privacy

White House Unveils Program to Authorize Private-Sector Cyber Surveillance and Disruption Operations

Aaron R. Cooper, Philip Chertoff
Tuesday, September 1, 2026, 10:02 AM
The Aug. 12 presidential memorandum directing the creation of a private-sector hacking program raises novel questions for participants.
The White House (Carol M. Highsmith Archive - Library of Congress, https://tinyurl.com/4dnk7d55, https://guides.loc.gov/p-and-p-rights-and-restrictions/rights#482_high.html)

On Aug. 12, President Trump signed a national security presidential memorandum titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” which directs the departments of Justice and Homeland Security to create a program to vet private U.S. companies to conduct cyber surveillance and cyber disruption operations against foreign cyber-enabled transnational criminal organizations (CE-TCOs).

The presidential memorandum follows on the heels of the administration’s March National Cybersecurity Strategy. As discussed in our prior analysis, the strategy asserted that the U.S. government will use its full suite of cyber capabilities—including offensive capabilities—against cyber adversaries and that it would enlist private-sector support by creating incentives to identify and disrupt adversary networks. Yet the strategy stopped short of expressly authorizing private companies to conduct cyber operations, and it offered limited detail on how the private sector would be engaged.

The new memorandum now establishes the framework for how the administration plans to bring the private sector into offensive cyber operations, outlining a conceptual structure and establishing authorities and limits for the new program. The framework suggests an approach closer to traditional defense contracting arrangements than prior proposals for free-wheeling private-sector “hack back.”

The procedural details of the program will not be known for another 60 days from the date of the memorandum, when the implementation plan is due to be released. However, entities considering participating will likely have to navigate a suite of important legal issues, including U.S. and foreign anti-hacking and surveillance laws, the nuances of defense contracting, government vetting and auditing, and the business and operational considerations of participating in these activities, even under the direction of the U.S. government.

Authorizing Private-Sector Cyber Surveillance and Disruption—Under Government Supervision

Under the new memorandum, the Department of Homeland Security’s National Coordination Center (NCC) is directed to create, manage, and maintain a program authorizing private companies to conduct “cyber surveillance operations” and “cyber effects operations” against foreign CE-TCOs, while under federal control and oversight.

The memorandum defines a “cyber surveillance operation” as activity conducted on network infrastructure for the primary purpose of collecting information or intelligence, including information usable for future cyber effects operations, with the intent to remain undetected—in effect, cyber espionage. The definition makes clear that this activity includes not only investigating around the network perimeter but also “accessing [an] information system[] without authorization from the owner or operator or by exceeding authorized access”—actions that would trigger most (if not all) anti-hacking laws. It also covers actions essential and inherent to enabling surveillance, “such as manipulation or temporary disruption that is not intended to cause physical effects or impact the usability of physical or virtual infrastructure.”

Meanwhile, the memorandum describes a “cyber effects operation” as an activity conducted in or through network infrastructure “that results in the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon.” In effect, cyberattacks or network disruptions that affect the confidentiality, availability, or integrity of targeted systems and networks. Again, these are actions that would trigger anti-hacking laws.

A critical element is how the memorandum defines potential targets. Under the memorandum, a CE-TCO is defined as “any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests, and that is not an institutional part of a foreign government or wholly operated under a foreign government’s direction.” To this definition, the memorandum adds an important presumption: A foreign group is assumed not to be state-connected unless clear intelligence establishes such a connection. The addition of this presumption is likely in recognition of a practice in which foreign adversaries have used non-state actors as proxies to execute cyberattacks against the U.S., where the link is difficult to prove. This specific callout may suggest a priority in disrupting such nation-state proxies.

Scope of Authorized Private-Sector Operations and Guardrails

While the NCC will manage the program, the attorney general and the secretary of homeland security will each select one of the two co-executive directors to oversee and direct its operations. The delegation of authorities to leaders from these specific agencies illustrates a clear focus for the program on law enforcement investigation, disruptions, and intelligence gathering.

As discussed in our prior analysis, the Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030, has always been the principal legal obstacle to private-sector offensive cyber operations. The CFAA criminalizes accessing a computer without authorization or exceeding authorized access, and § 1030(a)(5)(A) separately prohibits knowingly transmitting a program, information, code, or command that intentionally causes damage without authorization to a protected computer.

However, the memorandum appears to take advantage of an exemption under the CFAA that would enable participating companies to undertake activities the CFAA would otherwise prohibit. Specifically, § 1030(f) provides that the statute “does not prohibit any lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency of the United States, a State, or a political subdivision of a State, or of an intelligence agency of the United States.” The memorandum looks to take advantage of this exemption by requiring all operations to be taken under the direct supervision and direction of a law enforcement agency.

Specifically, the memorandum specifies that all operations must occur under the authorizing agency’s direct and close supervision, and requires the director’s review and written approval of an operation before a participating company can take an action. It further orders that any operational action the departments of Justice and Homeland Security direct will be “exclusively conducted on behalf of and under the supervision of the Federal Government pursuant to the Federal Government’s lawful authorities.”

The program will also require participating companies to enter into contracting agreements with the Justice Department or the Department of Homeland Security. The memorandum alludes that this contractual arrangement will ensure “rigorous vetting” of the participating companies and will likely incorporate requirements to adhere to strict operational procedures described in forthcoming implementing guidance. Altogether, these guardrails bring the program much closer to private contracting on cyber threat operations than proposals for private actors to hack back independently.

However, the memorandum pushes the 1030(f) exemption into new territory, as no court has squarely addressed whether it protects private entities engaged to perform such activities on behalf of the U.S. government, or under what circumstances. And the contours of a “lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency of the United States ... or of an intelligence agency of the United States” remain largely undefined.

Non-law enforcement agencies, such as the Department of Defense and the National Security Agency, have conducted many overseas offensive cyber operations and intelligence activities—but for non-law enforcement purposes. And, when law enforcement engages in disruptive activity such as botnet takedowns and malware remediation, it has usually done so under court authorization and/or in coordination with foreign partners, who are themselves conducting cyber operations within their jurisdiction. Courts therefore have not been asked to address the scope of the exemption head-on, let alone how private-sector activity fits in.

Given that all operations undertaken are to be pursuant to the Justice and Homeland Security departments’ “lawful authorities,” potential operations under the program could support criminal investigations, national security investigations (including electronic surveillance abroad), and botnet takedowns and malware remediation. Whether any form of judicial authorization would be required here—with a private entity acting under law enforcement direction—remains an open question, likely depending on the specific operational and geographic details.

The memorandum also places certain guardrails on the types of operations that can be authorized under the program—specifically, the program directors may not approve operations resulting in “critical outcomes.” According to the memorandum, an operation may generate a critical outcome “if it is likely that it will result in the loss of life or serious injury; or rise to the level of use of force or armed attack under international law.” But the memorandum does not state whether anyone may approve operations above that threshold, or if critical outcomes are simply off-limits. This guardrail is likely an attempt to avoid the risk that private-sector operations contribute to an escalation dynamic with foreign adversaries that could lead to more significant cyber conflicts.

Upcoming Implementing Guidance and Contractual Requirements

While the memorandum outlines the program’s general structure and purpose, it leaves the program’s mechanics of how it will work in practice to the departments of Justice and Homeland Security. Specifically, within 60 days of Aug. 12 (which falls on Oct. 11), the program executive directors—in coordination with the Homeland Security Council—must establish operating procedures that “ensure the Federal Government’s complete oversight and control of Participating Companies’ performance.”

The guidance must also establish standardized rubrics and templates for target identification, for the creation and processing of “operations packages” (which, while undefined in the executive order, likely refers to proposals for cyber operations, including identified targets and operational procedures), and reporting requirements covering both CE-TCO activity and the participating companies’ own operational activity. All of this may be easier said than done, given the complex and often overlapping equities across the national security community that typically present themselves when assessing potential cyber operations.

The memorandum tacitly acknowledges the targeting and civil liberties risks associated with this new program and issues several requirements to limit activities potentially affecting U.S. persons. Specifically, the implementing guidance must include targeting procedures to ensure that any targeting of a U.S. person, or a person that raises comparable due process concerns, receives any necessary authorization—judicial or otherwise—before the operation is approved. This will likely be similar to comparable targeting requirements for electronic surveillance of U.S. persons abroad pursuant to authorities provided by the Foreign Intelligence Surveillance Act of 1978 (FISA).

Separate procedures must also address operations that exceed approved parameters, including unintentional targeting of a U.S. person, an information system residing in the United States, or an information system under the control of a U.S. person. In those circumstances, the memorandum directs that the participating company must cease the operation, conduct minimization procedures, and immediately notify the NCC, which notifies the Department of Justice. What steps the Justice Department might take at that point, and any remedies available to affected U.S. persons, are unclear.

Participating companies also must adhere to information sharing requirements—namely, to immediately notify the NCC, which will in turn notify the Justice Department, if they discover an imminent cyberattack against U.S. critical infrastructure, or if they form a reasonable belief that an approved cyber effects operation or cyber surveillance operation may result in critical outcomes.

The implementing guidance will also set certain standards for participating companies, including:

  • Establishing minimum standards to participate, including technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence, and reliability.
  • Setting eligibility criteria that enable participation by both large companies providing capacity and smaller, more agile companies suited to specialized or discrete tasks.
  • Authorizing the departments of Justice and Homeland Security to require, as a condition of contract, that a company maintains a bond or escrow of no less than $1 million, forfeitable upon the company’s noncompliance with its contractual agreement.
  • Providing for evaluation of each participating company for continued participation at least annually.

Notably, the memorandum does not address how the program will navigate situations in which proposed operations run afoul of state computer crime statutes, the laws of foreign jurisdictions targeting where targeted infrastructure may reside, civil suits by third parties, indemnification of participating companies, or the effect of participation on insurance coverage.

While government contractors have received sovereign immunity from state tort claims arising from conduct at the direction of the government, the Supreme Court’s recent decision in Fluor v. Hencely clarified that contractors may not invoke sovereign immunity for conduct not specifically ordered or authorized by the federal government. This precedent suggests significant potential tort liability risks when a participating company acts beyond the scope of an operation authorized by the government agency.

Meanwhile, although certain Supremacy Clause immunity jurisprudence, such as In Re Neagle, shields federal law enforcement from state criminal liability for actions taken while performing federal duties, it is unclear whether that immunity stretches to private actors. And there is no immunity doctrine for federal criminal liability, meaning the government would need to address immunity by contract or side-letter. Participating companies leveraging agentic capabilities should focus on the scope of potential immunity or other available protections, as agents that bypass operational parameters, guardrails, or human oversight would, by definition, operate outside government supervision and the resulting conduct could create significant liability. Developing appropriate processes to address immunity and liability protections will be critical to participating companies and the federal government alike.

The memorandum also does not indicate whether or how private-sector actors will be compensated for these efforts. Arrangements might take shape similar to the well-established coordinated public-private efforts to take down botnets and similar criminal infrastructure. However, because the memorandum requires contractual arrangements with participants, and the Antideficiency Act generally prohibits federal employees from accepting voluntary services for the government, except in limited circumstances, compensation arrangements will likely be addressed in future solicitations.

Expanded Intelligence Gathering

The memorandum also lays the groundwork for enhanced threat information gathering to support private-sector operations. In furtherance of that objective, the memorandum purports to permit participating companies to enter into commercial agreements with two categories of counterparties.

First, the memorandum allows agreements with other private-sector entities, from which the participating company may receive threat information collected in the course of those entities’ normal business activities, in order to propose responsive cyber operations to the NCC. This provision seems to suggest an interest in allowing private-sector entities targeted by foreign cyber actors to share threat information with participating companies.

However, it offers no additional protections or liability safeguards for those private-sector entities to share that information with the participating companies. Such information could be protected from further disclosure, privilege waiver, and other risks from sharing if done pursuant to the Cybersecurity Information Sharing Act of 2015. However, that law remains in peril even as it seems poised to receive another short-term extension to Dec. 11. Notably, to the extent participating companies do form these information sharing arrangements, the government wants to know about it: The forthcoming implementing guidance will require participating companies to disclose all such relationships to the NCC.

Second, participating companies may enter into agreements with federal, state, local, tribal, and territorial agencies to obtain information used to identify CE-TCO threats for potential operations. In light of the recent campaign of cyberattacks against U.S. municipal water and waste treatment facilities, likely perpetrated by Iranian proxy actors, this provision suggests an enhanced focus on disrupting cyber threat actors targeting state and local entities as much as those targeting the private sector.

Deconfliction and Valid Targets

The memorandum also acknowledges that, while the departments of Justice and Homeland Security will delegate authorization to bless private-sector cyber operations, they may do so only after robust consultation with peer agencies with cyber equities.

In line with a classified annex to the memorandum, the implementing guidance must set forth an operational workflow that will include procedures for operational deconfliction across federal law enforcement, the departments of State, the Treasury, Defense, and Justice, and the intelligence community. The implementing guidance must also set out an adjudicatory framework ensuring that operational activity targets only CE-TCOs and accounts for other U.S. government equities.

The introduction of a deconfliction process is particularly notable given that the U.S. government previously established a robust cyber operations deconfliction process under Presidential Policy Directive-20 (PPD-20), which the first Trump administration eliminated in 2018. While PPD-20 was revoked in favor of National Security Presidential Memorandum-13 and successor policies for the putative purpose of enabling military commanders to conduct operations more freely, these processes may acknowledge the need to move more slowly as the government tries to expand the scale of its offensive cyber operations with private-sector support.

Considerations for Companies

This new memorandum clarifies the nature of private-sector hacking the Trump administration hopes to launch. While prior statements suggested a desire to allow victim companies to begin to “hack back” against their adversaries, the proposed framework actually suggests that the more likely candidates for participation are standard U.S. defense and intelligence contractors, as well as the new generation of boutique offensive cybersecurity businesses. Companies in the technology, defense, critical infrastructure, and cybersecurity sectors, and other industries frequently targeted by foreign threat actors, may also consider whether to enter into agreements with participating companies to supply the threat information needed to target their attackers rather than participating in operations themselves.

There are still significant open questions about how this program will work in practice. While the forthcoming implementing guidance may answer some questions, such as the selection process, other questions, such as potential liability under state and foreign law, insurance coverage, and indemnification, may be left unresolved.

Given the many legal issues in play—and the substantial risk participating companies could face—those evaluating whether to participate should work with outside counsel to:

  • Conduct a legal risk assessment before engaging, recognizing that the CFAA and state computer crime statutes remain in force notwithstanding executive action, and that foreign laws concerning hacking may also be implicated.
  • Evaluate effects on business relationships, insurance coverage, and securities disclosure obligations, including whether participation in a covert operation is material.
  • Assess reputational, customer, and investor considerations associated with involvement in operations conducted with U.S. law enforcement and intelligence agencies, especially for companies with a global footprint.

Companies interested in shaping the operating procedures have a defined window: The consensus operating procedures are due by Oct. 11.


Aaron R. Cooper is a Partner at Jenner & Block LLP. Mr. Cooper also served as the lead investigative counsel for the Minority in the Senate Select Committee on Intelligence’s bipartisan investigation of Russian interference in the 2016 US elections. Before that, he was a prosecutor in the Department of Justice’s Computer Crimes and Intellectual Property Section, where he investigated and prosecuted high-tech and intellectual property crimes.
Philip Chertoff is an associate at Jenner & Block, where he is a member of the firm's National Security and Crisis and Critical and Emerging Technologies practices. In his role, he advises clients navigating the intersection of technology and national security and represents clients in high-stakes litigation and investigations involving national security concerns. Before that, he served as an Attorney-Advisor in the U.S. Government. He received his J.D. from Harvard Law School.
}

Subscribe to Lawfare