White House Outsources Cyber Offence to Private Firms in Unprecedented Anti-Crime Push
The White House has signed a presidential memorandum giving vetted private US companies the authority to run offensive cyber operations against foreign criminal organisations. Not advisory roles. Not threat feeds. Actual offensive and intelligence-gathering operations, carried out under federal supervision.
The programme is managed by a newly designated National Coordination Center, co-led by appointees from the Attorney General and the Secretary of Homeland Security. The idea is that private firms do the technical heavy lifting while the government keeps its hand firmly on the controls.
To get a seat at the table, companies must pass rigorous vetting and sign formal contracts with either the DOJ or DHS. There's a financial commitment too: participants may be required to post a bond or escrow of at least one million dollars, which they forfeit if they breach operational terms. That's a meaningful deterrent, though arguably modest given the scale of activity being authorised.
Once in, firms can run two categories of operations. Cyber surveillance operations involve covertly accessing foreign systems to gather intelligence. Cyber effects operations go further, covering actions that disrupt, degrade, or outright destroy adversary infrastructure. The targets are foreign cyber-enabled transnational criminal organisations, not state actors, at least in theory.
The memorandum is careful to set limits. Operations cannot produce what it calls 'critical outcomes', defined as actions likely to cause loss of life, serious injury, or anything that would constitute a use of force under international law. So no kinetic knock-on effects, please.
Before any operation goes ahead, companies need written sign-off from the executive directors. Proposed actions also have to clear a multi-agency deconfliction process involving law enforcement, State, Treasury, the DOJ, and the Intelligence Community. It's a long list of stakeholders, which will either prevent recklessness or create enough bureaucratic drag to make the whole thing unworkable. Possibly both.
On the question of who counts as a legitimate target, the programme restricts operations to non-state criminal groups. Foreign entities are assumed to be independent of their governments unless solid intelligence says otherwise. That assumption will do a lot of work in practice.
There are also rules around accidental domestic exposure. If a contractor stumbles onto a US person or a domestic system during an operation, they must immediately stop and report it. Whether that's sufficient protection is a reasonable question.
The broader picture here is that the US government is effectively deputising private cybersecurity firms to carry out what would traditionally be considered intelligence or military activity. That's a significant shift. Whether the oversight architecture is robust enough to match the risk is something we'll find out the hard way.