On August 12th, 2026, a presidential memorandum was published authorizing Participating Companies—vetted private contractors—to conduct government-directed cyber operations. The new program covers both Cyber Surveillance Operations and Cyber Effects Operations. While Surveillance Operations include intelligence and data collection, Effects Operations explicitly include the manipulation, disruption, degradation, and destruction of information systems. This announcement marks the formal entry of private industry into offensive cyber activity, rather than just defense and tooling.
Why the Private Sector is Being Brought In
This memorandum, titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” builds on a previous executive order issued in March 2026 targeting cyber-enabled fraud against Americans. The memorandum frames transnational criminal organizations as a growing, sustained threat to citizens and businesses, emphasizing the importance of taking steps to mitigate the risks.
Citing the U.S. private sector’s speed, scale, and technical edge, the memorandum makes the point that private companies’ cyber capabilities are underutilized as a strategic asset for national security. This signals federal acknowledgment that the dominant government-only system of cyber enforcement has fallen behind the pace of adversarial development.
The Workings of Government-Directed Private Offense
As outlined in the memorandum, the National Coordination Center (NCC)—established by a January 2025 executive order—will manage the Program under the joint supervision of the Executive Directors of the Department of Justice (DOJ) and Department of Homeland Security (DHS). Participating Companies are required to pass rounds of vetting, sign federal contracts, and meet a minimum $1 million bond or escrow in order to be authorized.
These companies may receive threat intelligence from private partners and government agencies to propose operations. Every operations package requires the written approval of a Program Executive Director before any company is permitted to take action.
The Guardrails and Where They May Fall Short
The memorandum also lays out certain safeguards to curb the potential damage of private sector companies being overly privileged in cyber operations. Actions resulting in “Critical Outcomes,” meaning any operations that may result in loss of life or acts rising to the use of force, are required to be escalated beyond the approval of the Program Executive Directors. It is also mandatory that organizations stop operations, take minimization efforts, and immediately notify the NCC if their actions unintentionally impact any U.S. person or domestic system.
Activity that concerns or affects U.S. persons or constitutional obligations is required to be reviewed by the DOJ before it can be carried out. The establishment of annual reevaluations and required reporting aims to maintain continuous oversight rather than relying on a one-time vetting gate to keep these activities and operations secure.
Even with these safeguards in place, some experts remain uneasy about the potential security fallout of this decision. The vetting and operational requirements set up a foundation for keeping these activities safe, but they do not guarantee anything. “My primary concern is the security of these contractors,” says Corey Ham, Director of Continuous Pentesting at Black Hills Information Security, Inc. “Giving more entities access to sensitive information increases the likelihood that it can be compromised.”
What Comes Next for Participating Companies
It remains to be seen how the implementation of the memorandum’s terms will play out in practice. There is a 60-day deadline for the Program Executive Directors to establish operating procedures for the Program, which will define who realistically qualifies to participate. The framework is deliberately built to include both large-capacity firms and smaller, specialized operators. The success of the Program will hinge on how deconfliction works across the Departments of Justice, State, Treasury, and War, as well as the intelligence community. This memorandum raises the industry-defining question of accountability when a private company’s authorized operation eventually causes unintended harm.