executive-ordertrade-pressNewsThe Broadside2 min read

Trump memo authorizes private-sector offensive cyber operations

Contractors get a federal safe harbor for hacking criminal networks abroad, but the government gets veto power over every target and method.


TL;DR

A new national security memorandum from President Trump establishes the National Coordination Center under joint DOJ/DHS oversight, creating the first formal U.S. framework for authorizing private-sector offensive cyber operations against transnational criminal organizations. Vetted companies must sign contracts with DOJ or DHS, operate under federal supervision, and comply with 18 U.S.C. 1030 and international law. The memo doesn't define who must sign off on "Critical Outcomes" (operations risking loss of life or rising to armed attack under international law) and is silent on indemnification and insurance requirements for participating firms.

Trump memo authorizes private-sector offensive cyber operations
Editorial illustration · drawn by The Broadside

The August 12 memorandum is the first time the U.S. government has built an explicit on-ramp for private companies to conduct offensive cyber operations under federal authority. That's a big deal, and it changes the liability calculus for any contractor who's been sitting on capability they couldn't legally use.

Under the new structure, the National Coordination Center (with co-executive directors from DOJ and DHS) will review, authorize, and oversee operations proposed by participating companies. Those companies must survive "rigorous vetting," sign contracts with one of the two departments, and follow operational procedures the memo leaves to subsequent implementation guidance. The legal architecture is straightforward: companies that operate inside the NCC framework get the shelter of acting "under the control and oversight of the United States Government," with the memo specifically invoking 18 U.S.C. 1030 (the Computer Fraud and Abuse Act) to signal that authorized operations aren't prosecutable hacking.

That safe harbor is the point. Without it, a U.S. company breaching a foreign server to disrupt a ransomware group is arguably violating multiple statutes and international norms, and no general counsel would sign off. With it, the risk shifts from the contractor to the sovereign.

But the shift isn't total, and the gaps matter.

The memo draws a line at "Critical Outcomes", operations that would likely cause loss of life, serious injury, or "rise to the level of use of force or armed attack under international law." Co-executive directors can approve routine operations after coordinating with each other. Critical Outcomes require something higher. The memo doesn't say what. A cabinet officer? An interagency panel? The President personally? Until that's spelled out in implementation guidance, every operation that approaches the line sits in a procedural vacuum.

What the memo doesn't say

Three omissions will shape how fast contractors sign up. First, indemnification: the memo says companies act under federal supervision, but it doesn't say the government will cover their legal bills if something goes sideways, say, a foreign state treats a company's operation as a hostile act and retaliates. Second, insurance: cyber insurers already struggle to price offensive-cyber exposure, and a federal contract doesn't automatically make the risk insurable. Third, the vetting bar: "rigorous vetting" could mean anything from a background check to a full counterintelligence review, and the depth of that process determines whether mid-tier firms clear it.

The memo builds on the March 6 cybercrime executive order, which directed a review of frameworks for combating transnational criminal organizations engaged in cyber-enabled crime. That EO led to the national cyber strategy; this memo is the operational annex.

For contractors who've watched DOJ's Civil Cyber-Fraud Initiative expand False Claims Act exposure for cybersecurity failures, the memo offers a rare countercurrent: a structure where the government explicitly wants private offensive capability, under government control, with government legal cover. The question is whether the implementation guidance (due on an unspecified timeline) answers the indemnification and approval-threshold questions before companies start bidding.


Published ·Deep Fathom