Skip to Main Content
08/19/2026|8 minute read

Key Takeaways

  • The Trump administration has created a framework permitting vetted private companies to participate in government-directed cyber operations against foreign cybercriminal organizations, representing a significant departure from the long-standing prohibition on private-sector offensive cyber activity.
  • The program does not authorize independent “hack back” activity. Participating companies must operate pursuant to federal contracts, written approvals and ongoing Department of Justice and Department of Homeland Security oversight.
  • Potential opportunities may emerge for cybersecurity and incident response firms, threat intelligence providers, government contractors, and sophisticated entities interested in pursing offensive cyber operations on their own behalf, but participation will likely require significant compliance, vetting, reporting, and operational safeguards, including potential escrow or bonding obligations of at least $1 million.  
  • Companies evaluating participation should carefully assess retaliation risks, government-contracting obligations, insurance coverage, cross-border legal exposure, governance requirements, and potential False Claims Act liability.

Background and the Aug. 12 Presidential Memorandum

Private offensive cyber activity has traditionally remained the province of U.S. military, intelligence, and law-enforcement agencies. The Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030, prohibits unauthorized computer access and does not provide a general exemption for private companies acting independently.

Although the CFAA’s prohibition on independent activity remains in place, the White House, on Aug. 12, issued a National Security Presidential Memorandum (NSPM),  “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” that creates a framework for vetted U.S. companies to support government-directed cyber operations against foreign cyber-enabled transnational criminal organizations (CE-TCOs). The policy could allow organizations with sophisticated internal cyber operations, cybersecurity service providers, and government contractors to expand their operations and service offerings — but also creates substantial operational, legal, and business risk.

The NSPM moves beyond traditional private-sector information sharing by creating a narrow, formal channel for approved companies to propose targets and participate directly in specified surveillance and disruption activities under federal contracts, written authorization and continuing government control. 

Narrow or not, this new structure raises real questions for private-sector clients. Some may consider participating, and many more may be asked to share threat data, contract with other participating companies or simply adapt to a new landscape reflecting what their competitors and vendors are now allowed to do.

A New Horizon: Future Opportunities (and Challenges) for the Private Sector

Specifically, the NSPM directs the National Coordination Center (NCC), with Department of Justice (DOJ) and Department of Homeland Security (DHS) oversight, to establish a program for approved companies to conduct cyber operations against approved CE-TCOs. Participating companies must contract with DOJ or DHS, pass a vetting process, and operate under federal direction, control, and legal authority. Operating procedures are to be established within 60 days (approximately mid-October).

The program contemplates two categories of activity:

  • Cyber Surveillance Operations: Accessing foreign CE-TCOs to collect intelligence, identify threats, and support disruption.
  • Cyber Effects Operations: Manipulating, disrupting, denying, degrading, or destroying systems and infrastructure used by foreign CE-TCOs.

The Administration describes the initiative as engaging private-sector speed, scale, data, and technical expertise in the fight against ransomware, fraud, and other foreign cyber-enabled crime. Each operation, however, remains subject to government approval, deconfliction, and legal limits.

Program Requirements and Safeguards

Participation will be tightly controlled. Participating Companies may only target foreign, non-state, CE-TCO.  Further, companies must immediately cease and report any operation that affects U.S. persons, systems they control or U.S.-based systems. Participating Companies must also cease operations that they determine may result in a “Critical Outcome” — an operation likely to cause loss of life, serious injury or conduct rising to the use of force under international law. Companies should further anticipate obligations addressing:

  • Annual eligibility and vetting. DOJ and DHS are expected to assess technical capability, operational experience, personnel reliability, security controls, and continuing eligibility. Cleared personnel or facilities may become a competitive advantage, although the NSPM does not expressly require them.
  • Contracting and authorization. Companies must enter into agreements with DOJ or DHS. Each operation requires written government approval, a defined scope, and government direction and deconfliction.
  • Reporting and review. Participants should expect detailed operational reporting, recordkeeping, audits, performance measures, and annual eligibility reviews.
  • Financial assurance. DOJ and DHS may require a bond or escrow account of at least $1 million, potentially subject to forfeiture for noncompliance.
  • Operational safeguards. The framework calls for minimization procedures, protection of U.S. persons and domestic systems, and mandatory cessation and notice if activity exceeds authorization.
  • Legal compliance. Operations must comply with the Constitution, U.S. law, and applicable international obligations. The framework does not insulate companies from contractual, regulatory, or foreign-law exposure.

The core distinction is straightforward: The NSPM creates a highly regulated federal program in which select companies may support the government, not a private-sector license for offensive cyber activity.

Business Opportunity — and Strategic Tradeoffs

The program may create new federal work for incident response firms, threat intelligence providers, managed security service providers, digital forensics firms, cyber threat-hunting companies and national-security contractors. Potential assignments could include intelligence collection, infrastructure analysis, operational support, cyber surveillance, technical reporting and program compliance.

Those opportunities come with uncommon strategic tradeoffs. Participation could change a company’s threat profile, customer relationships, insurance position, disclosure analysis or exposure in foreign jurisdictions. Companies also may need to consider costs associated with personnel screening, secure facilities, compliance systems, and continuous government reporting in their cost-benefit analysis.

The threshold question is therefore not simply whether a company can perform the work, but whether the opportunity fits its strategy, controls, risk tolerance, and commercial relationships.

Key Risks for Participants

Retaliation and operational security. Participants—and potentially their suppliers, customers, executives, and business partners—could face cyberattacks, extortion, disinformation, doxing, physical threats, or other retaliation. Companies should assess whether existing incident response, business continuity, executive protection, and crisis communications plans address a sophisticated and persistent adversary.

Contractor liability and derivative sovereign immunity. Although program-authorized conduct ordinarily could expose a private company to liability under the CFAA and comparable foreign laws, participants acting under federal control and oversight may invoke derivative sovereign immunity under Yearsley v. W.A. Ross Construction Co. for conduct performed pursuant to validly conferred and properly executed government authority. That protection, however, may not provide an early exit from litigation: in GEO Group, Inc. v. Menocal, decided Feb. 25, the Supreme Court held that denial of a Yearsley defense is not immediately appealable under the collateral-order doctrine, meaning a contractor may have to litigate through final judgment before seeking appellate review.

Attribution, collateral effects, and deconfliction. The memorandum limits targets to TCOs that aren’t “an institutional part of a foreign government.” But threat actors use compromised infrastructure, intermediaries, and deceptive tradecraft. Even strong intelligence may lead to operations that inadvertently target a nation-state actor or neutral third parties, or interfere with other U.S. operations. Written authorization, verification standards, technical guardrails, stop-work triggers, and real-time government coordination will be central.

Liability, indemnification and insurance. The NSPM does not resolve who bears losses arising from misattribution, collateral damage, data exposure or retaliation. Participants should scrutinize government indemnification, limitations of liability, defense and cooperation obligations, cyber and professional liability coverage, directors and officers liability insurance (D&O) implications, potentially applicable exclusions and aggregation risk.

Governance and disclosure. Boards should treat participation as an enterprise risk decision, not merely a technical engagement. Public companies should assess whether the operational and retaliation risks are material and require Security and Exchange Commission disclosures, whether disclosures require updating and whether approval, documentation and escalation protocols are adequate.

Cross-border exposure. U.S.-authorized activity may still draw scrutiny under foreign privacy, cybersecurity, sanctions, national-security, data-localization, or criminal laws. Companies should map affected jurisdictions, involve local counsel, segment sensitive operations and data, and plan for regulatory inquiries, inspections, access demands, or restrictions on local personnel and assets.

Government-contracting enforcement. Participation may require certifications concerning eligibility, technical capability, personnel, controls, and compliance. Inaccurate certifications, deficient reporting, or failures to follow operational restrictions could trigger suspension, termination, forfeiture, contractual remedies, or False Claims Act (FCA) scrutiny.

Data governance. If your company will share threat intelligence with a Participating Company, assess the arrangement against applicable privacy notices, data processing agreements, and legal or regulatory data-sharing requirements. While many privacy and cybersecurity frameworks contain exceptions or safe harbors for cybersecurity, fraud prevention, law enforcement cooperation, or threat-intelligence sharing, companies should confirm that any contemplated sharing falls within those authorities before routing customer or network data to support a government-directed operation.

Compliance with other legal regimes. For example, offensive tooling — exploits, intrusion frameworks — can be export-controlled. A company conducting Cyber Effects Operations may be functionally deploying that kind of technology into a foreign jurisdiction. The memorandum’s government-authorization framework doesn’t explicitly address export-control and other regulatory obligations, and risk could arise particularly if an operation strays outside its authorized scope.

False Claims Act exposure. With any federal contract, once a company signs, it inherits FCA exposure (and qui tam risk) for false certifications about compliance with operating procedures, scope or reporting obligations.

Memorandum status. The program rests on a pending DOJ and DHA memorandum and the operating procedures to be issued under it. It is not based upon Congressional legislation. A future administration, or even a policy shift within this one, could quickly narrow, suspend, or end the program.

Scope creep and protection of sensitive assets. Government requests may expand over time to include telemetry, logs, internal tools, sensors, system changes, or access to sensitive environments. Contracts and operating procedures should require written, mission-specific requests; define access and use limits; protect privilege, confidentiality, and intellectual property; and preserve the company’s ability to decline work outside the approved scope.

What Companies Should Do Now

Organizations evaluating these developments should begin assessing both the opportunities and risks associated with potential participation in future government-directed cyber operations programs and consider the following:

  • Monitor implementation. DOJ/DHS operating procedures due in October and will provide additional detail for vetting standards, reporting templates, and workflows. Companies and counsel should track DOJ, DHS, and NCC guidance on eligibility, approvals, reporting, audits, bonding, suspension, and removal.
  • Assess readiness and fit. Evaluate government-contracting experience, facility and physical security, insider-threat and personnel-screening programs, governance and compliance controls, classified-environment readiness, and demonstrated experience conducting sophisticated cyber operations. Although the NSPM does not expressly require security clearances, cleared personnel and facilities may become meaningful competitive advantages.
  • Define authority and risk allocation. Negotiate mission scope, written approval, deconfliction, stop-work rights, indemnification, liability limits, audit rights, and responsibility for third-party claims.
  • Evaluate insurance. Assess how government-directed operations fit existing cyber, professional liability, errors and omissions and D&O coverage, including potentially applicable exclusions, aggregation, underwriting, and allocation of losses arising from retaliation or collateral effects.
  • Address False Claims Act and government-contracting risk. Establish controls for certifications concerning eligibility, technical capability, personnel qualifications, operational restrictions, reporting, recordkeeping, and program compliance. Inaccurate certifications or failures to satisfy contractual requirements could trigger suspension, forfeiture, contractual remedies, or False Claims Act scrutiny.
  • Protect sensitive systems and information. Establish boundaries for government access, telemetry, logs, tools, intellectual property, privileged material, and downstream use of collected information.
  • Strengthen oversight and compliance. Create board-level reviews, privileged risk assessments, approval protocols, disclosure analysis, and records sufficient to demonstrate compliance.
  • Prepare for potential retaliation and scrutiny. Update incident response, business continuity, crisis communication, executive protection, supply-chain security, and cross-border response plans; test them through tabletop exercises.

How Outside Counsel Can Help

Given the intersection of cybersecurity, government contracting, national security, privacy, insurance, regulatory compliance and corporate governance issues, organizations should consider engaging counsel early in their evaluation process.

Counsel can conduct privileged readiness and risk assessments; evaluate vetting, facility and personnel security requirements; structure and negotiate contracting, indemnification, insurance and other risk allocation provisions; advise boards on governance and disclosure; develop participation playbooks and approval processes; and address procurement, False Claims Act and related compliance risks.

Because participation may involve classified operational details, threat intelligence or government direction, companies should also consider whether their legal team includes counsel who hold – or are eligible to obtain – the security clearances necessary to advise on sensitive aspects of the program. Counsel without the required clearance may be unable to access key information needed to assess authorization, compliance, liability and operational risk.

Counsel can also identify and plan for potential liability and litigation risks. A participating company could inadvertently misidentify a target, disrupt or compromise third-party infrastructure, or provoke retaliation against customers or business partners. The legal protections available in those circumstances remain uncertain. Derivative sovereign immunity and contractual indemnification may provide some protection, but neither has been tested in the context of private companies conducting government-directed offensive cyber operations. Accordingly, outside counsel’s evaluation of liability, indemnification, and related protections in forthcoming operating procedures and contracts may be as important as the operational authority itself.

BakerHostetler attorneys focused on privacy, cybersecurity, government contracting, and national security are available to help organizations evaluate this evolving framework.


Featured Insights