New Program Allows Vetted Firms to Conduct Government-Directed Offensive Cyber Operations
Vetted private companies may now participate in government-directed offensive cyber operations against foreign criminal groups under a new White House framework, creating both significant contracting opportunities and substantial legal and operational risks for participants.
The August 12 National Security Presidential Memorandum establishes a narrow program permitting vetted U.S. companies to conduct cyber surveillance and effects operations against foreign cyber-enabled transnational criminal organizations under DOJ or DHS contracts and oversight. The program does not authorize independent hack-back activity; all operations require written government approval and direction. Participating firms face strict requirements including annual vetting, $1 million minimum bonding, detailed reporting, and operational safeguards to protect U.S. persons and systems. Companies must assess retaliation risks, cross-border legal exposure, insurance coverage, False Claims Act liability, and potential derivative sovereign immunity protections before participating. The framework remains executive-branch policy without congressional authorization, making it vulnerable to reversal by future administrations.