BakerHostetler·CYBERSECURITY

Trump NSPM Opens Door for Vetted Companies to Join Federal Cyber Ops

An Aug. 12 presidential memorandum creates a framework letting vetted U.S. companies participate in government-directed offensive cyber operations against foreign criminal groups under DOJ/DHS contracts and oversight.

The National Security Presidential Memorandum, titled Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, departs from the longstanding prohibition on private-sector offensive cyber activity under the Computer Fraud and Abuse Act, 18 U.S.C. § 1030. Rather than legalizing independent hack-back, the policy creates a narrow channel for vetted U.S. companies to propose targets and conduct cyber surveillance and disruption operations against approved foreign cyber-enabled transnational criminal organizations under federal contracts, written authorization, and continuing DOJ and DHS control. The National Coordination Center is directed to stand up the program within roughly 60 days. Participants must pass vetting, contract with DOJ or DHS, and meet significant compliance, reporting, and operational safeguards, including potential escrow or bonding obligations of at least $1 million. Companies considering involvement should weigh retaliation risk, contracting obligations, cross-border exposure, insurance coverage, governance demands, and possible False Claims Act liability. Sophisticated counsel should also advise clients on downstream effects: vendor selection, threat-intelligence sharing, and incident-response scopes may shift as competitors and service providers enter the program. Watch for the NCC implementing procedures and any proposed CFAA amendments or new regulations.

cyber-privateersnspmoffensive-cybercfaadojdhsgovernment-contractingincident-response
Read the original firm alert →Friday, August 21, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.