U.S. Opens the Door for Private Cybersecurity Firms to Participate in National Cyber Operations

Notice

This article is based on the U.S. White House National Security Presidential Memorandum, “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” U.S. government materials, and the FBI’s “2025 IC3 Annual Report,” publicly available as of August 14, 2026. DANA NOTES analysis is also included.

On August 12, 2026, U.S. President Trump signed a National Security Presidential Memorandum directing the creation of a program to involve private companies in government cyber operations. It is an official presidential document published by the White House under Presidential Memoranda, and in this memorandum, the Department of Justice, the Department of Homeland Security, and other relevant agencies were directed to establish the program and develop operating procedures.

The work participating companies may perform is not limited to providing security advice or tracking attackers.

Within a government-approved scope, they may conduct Cyber Surveillance Operations, which involve accessing an adversary’s systems to collect information, and Cyber Effects Operations, which may involve manipulating or disrupting systems and networks, denying access, degrading performance, and, in some cases, destruction.

However, this should not be understood as allowing ordinary companies to freely conduct retaliatory attacks, commonly known as Hack Back.

The more important change in this policy is not that private companies are being given unrestricted authority to attack, but that the U.S. government is creating a structure in which cyber technology and personnel held by the private sector can be used for national missions within the government’s chain of command.


Private Companies Have Not Been Given the Freedom to ‘Hack Back’ on Their Own

Hack Back refers to an active response in which an organization that has suffered a cyberattack goes beyond blocking the attack and accesses the attacker’s systems or infrastructure to track or disrupt them.

This program may use similar techniques, but its operational structure is different.

Participating companies must contract with the U.S. Department of Justice (DOJ) or Department of Homeland Security (DHS), and all operations must be carried out on behalf of the U.S. federal government, under government supervision and legal authority.

The program is managed by joint officials designated by the Department of Justice and the Department of Homeland Security. Every cyber operation package must be reviewed by government officials, and participating companies may carry out an operation only after receiving written authorization and instructions.

Therefore, the structure is not

Private company identifies an attacker → retaliates independently

but rather

Government determines the target and scope of the operation → private company carries out the approved mission.

Nor does this mean that the existing role of private cybersecurity firms will disappear or that the entire cybersecurity industry will turn into an offensive industry. The presidential memorandum explicitly states that participating companies may continue their existing lawful defensive cyber activities outside the program.

What changes under this policy is not the role of private companies itself, but the scope within which the U.S. government can use private-sector cyber capabilities.


Why Does the U.S. Government Want to Bring in Private-Sector Cyber Capabilities?

The United States is creating this structure against the backdrop of growing cybercrime losses and specialized capabilities that have already accumulated in the private sector.

According to the FBI’s “2025 IC3 Annual Report,” the Internet Crime Complaint Center (IC3) received 1,008,597 complaints in 2025, with reported losses totaling approximately $20.877 billion. Reported losses increased by 26% from 2024.

However, these figures should not be interpreted as meaning that the total number of cyberattacks targeting the United States increased.

IC3 compiles information on internet crime and cybercrime reported by victims and others, so it is not a comprehensive count of all attacks. Even so, the fact that reported economic losses alone exceeded $20 billion helps explain why the U.S. government is treating cybercrime not simply as a corporate security issue, but as an economic and national security issue.

The direction of the U.S. government’s response had already been changing.

Executive Order 14390, signed by President Trump in March 2026 to address cybercrime by foreign transnational criminal organizations, directed the government to use the technical capabilities, threat intelligence, and operational experience of commercial cybersecurity companies and other non-federal entities to strengthen the ability to identify, track, and disrupt attackers.

The U.S. “Cyber Strategy for America,” released in the same month, also set out a direction of expanding cooperation between the government and the private sector and using U.S. cyber capabilities for both defensive and offensive missions.

The August presidential memorandum makes that direction more concrete by establishing a program in which private companies can actually participate.

In the memorandum, the White House stated that the scale, speed, and capacity of the U.S. private sector are important resources for America’s offensive cyber advantage, but that private-sector capabilities have not been sufficiently used to identify and disrupt criminal networks.

In other words, the U.S. government is not choosing only to build every offensive capability and specialized workforce inside the government itself.

It is creating a structure that can identify capabilities that already exist in the private sector and, when needed, deploy them on national missions under government command and control.

From this perspective, the technology held by private companies can also become a national cyber resource.

What matters is not simply whether the government directly owns the technology, but whether it can identify which companies possess the capabilities it needs at a given moment and safely connect those capabilities to national operations.


Even Companies That Are Not Large Can Participate in National Missions If They Have the Capability

When private companies participate in national cyber operations, large defense contractors or major government contractors may come to mind first.

However, the presidential memorandum explicitly states that the participation criteria should consider both large and small companies.

Large companies have the capacity to provide substantial personnel and resources, while smaller and more agile companies may be better suited to particular specialized missions or limited tasks.

This means more than simply allowing small and medium-sized companies to apply.

If a company has a particular capability that the country needs, whether it can actually perform the mission may become a more important criterion than the size of the company.

A company that has spent years analyzing a specific type of malware or attack technique, a specialized cybersecurity firm that has tracked the infrastructure of a particular criminal organization, or a small company with deep expertise in a narrow technical field may also have an opportunity to participate in national missions.

Of course, it has not yet been disclosed which companies will actually receive contracts or how large those contracts will be.

However, the fact that small specialized companies are explicitly included from the program design stage shows that the pool of suppliers in the government cyber contracting market may not be limited to large companies.


What Kind of Private Companies Does the U.S. Government Want to Bring into Cyber Operations?

Having technical expertise alone does not mean a company can immediately take on national cyber operations.

The presidential memorandum requires the minimum criteria for participating companies to include the following:

  1. Technical proficiency
  2. Proven cyber operational performance
  3. Facility security
  4. Personnel vetting
  5. Operational capability
  6. Reliability

These criteria are intended to determine whether the government can have a high degree of confidence that the company can successfully carry out the program’s missions. Even after joining, companies must be reassessed at least once a year to determine whether they remain qualified to participate.

What is particularly notable here is facility security, personnel vetting, and reliability.

National cyber operations do not involve sharing attack techniques alone.

Sensitive information may be provided to private companies, including which organizations are being investigated, which systems will be accessed, and when particular operations will be carried out. Some operating procedures must also be established through a classified annex rather than through publicly available documents.

Therefore, the company a government wants cannot simply be described as “the company that hacks best.”

It must possess technical capability while also being able to manage its personnel and information, remain within the scope of operations defined by the government, and report accurately when problems arise.

In cyber operations, capability and trust can together become competitive advantages in government contracting.


How Far Can Private Companies Actually Go?

The presidential memorandum defines two broad types of operations in which private companies may participate.

Cyber Surveillance Operation

This is an operation in which a company accesses an adversary’s information systems or networks to collect information and intelligence.

It may include obtaining information needed for a future Cyber Effects Operation, and the definition includes accessing systems without the permission of the owner or operator or going beyond authorized access. Limited manipulation or temporary disruption necessary to carry out the operation may also be included within a certain scope.

Cyber Effects Operation

This is a more active operation that affects information systems or networks.

The presidential memorandum defines it as activity that causes manipulation, disruption, denial, degradation, or destruction.

Therefore, participating companies would not merely locate attackers and report the information to the government.

If authorized by the government, private companies may participate in actions that actually affect the operation of an adversary’s systems.

However, outcomes that could cause death or serious bodily injury or potentially rise to the level of a use of force or armed attack under international law are classified separately as Critical Outcomes. The program is not structured to allow ordinary program officials to authorize operations that would cause such outcomes.

Offensive operations are permitted, but their scope is not unlimited.


The Government Determines the Actual Targets and Scope of Operations

Even if private companies execute the technical work, the authority to choose targets is not transferred to them.

The program targets foreign organizations defined as Cyber-Enabled Transnational Criminal Organizations, or CE-TCOs.

Foreign organizations that engage in cybercrime targeting the U.S. government, U.S. persons, or U.S. interests may qualify, while organizations that are part of a foreign government or are wholly operated under the direction of a foreign government are excluded from this definition.

Every operation must pass through a government-developed target adjudication framework, and each individual operation package must also be reviewed and approved in writing by government officials. Procedures must also be established to ensure that operations do not conflict with the activities of other federal law-enforcement, diplomatic, intelligence, and related government agencies.

In other words, private companies do not decide,

“This organization attacked the United States, so we will attack it.”

Instead, the U.S. government determines the target and approves the operation, and the private company performs the mission within the defined scope.


But Can ‘Criminal Organizations’ and ‘States’ Really Be Clearly Separated?

The criteria in the document are relatively clear.

Foreign governments themselves are not targets under this program.

However, in cyberspace, the relationship between states and criminal organizations is not always cleanly separated.

The U.S. government’s March 2026 executive order itself stated that some foreign regimes provide active or tacit support to cybercrime and various fraud activities.

An organization may not formally belong to a government but may receive support from it, or it may make money through criminal activity while also sharing interests with a government.

The presidential memorandum includes one particularly notable standard related to this issue.

Unless clear information exists to the contrary, a foreign organization is presumed not to be part of a foreign government or wholly operated under the direction of a foreign government.

Therefore, although the policy does not authorize attacks on states themselves, in actual operations there may be situations in which the government must determine

whether an organization is an independent criminal organization, an organization controlled by a state, or something in between.

If that distinction is made incorrectly, an operation intended to neutralize a criminal organization could potentially expand into a diplomatic or security issue with another country.

This is why the presidential memorandum does not define only attack techniques, but also requires a target adjudication framework and procedures for coordinating operations among government agencies.

An important national capability in this program is therefore not only offensive technology, but also the intelligence capability to accurately distinguish who should actually be targeted.


Are Operational Failure and Contract Breach the Same Problem?

National cyber operations cannot be assumed to succeed every time.

The adversary may change its systems, use defensive mechanisms that were not anticipated, or newly discovered information during the operation may require the original plan to be stopped.

The presidential memorandum does not state that participating companies will be financially penalized simply because an operation fails to achieve its objective.

Instead, the Department of Justice and the Department of Homeland Security may require participating companies to maintain a bond or escrow of at least $1 million as a contractual condition, and that amount may be forfeited if a participating company fails to comply with its contractual agreement.

Therefore, based on the publicly available document, operational failure and contractual non-compliance must be distinguished.

For example, if a company discovers during an operation that activity has gone beyond the authorized scope, it must stop the operation, mitigate the effects, and immediately report the matter to the government. It must also immediately report if it discovers an imminent attack against U.S. critical infrastructure or determines that an operation could result in a Critical Outcome.

Complying with these control procedures and achieving the operational objective may therefore be separate matters for evaluation.

At the same time, the government must reassess every participating company at least once a year, and the initial evaluation already includes proven cyber operational performance, capability, and reliability.

It is therefore also difficult to assume that repeated operational failures or inadequate performance would have no effect on future program participation or government contracts.

However, because detailed operating procedures and contract terms have not yet been released, it remains to be seen which failures will be treated simply as operational outcomes and which problems may lead to contractual liability.

In DANA NOTES’ view, the government is unlikely to evaluate participating companies solely on their success rate.

Even when an operation fails, whether the company stayed within the authorized scope, accurately identified the reason for failure, properly reported the necessary information to the government, and can improve so that the same problem does not recur may also become factors in determining whether the company can be trusted with another national mission.

The kind of company a government wants may not be one that never fails, but one that combines strong technical capability with the ability to handle failures and unexpected situations in a controllable way.


A New Government Contracting Market Could Also Emerge

Under this program, private companies must enter into contracts with the Department of Justice or the Department of Homeland Security. In other words, using offensive cyber capabilities from the private sector could go beyond simple information sharing or voluntary cooperation and become a structure in which the government procures operational capabilities from private companies through contracts.

The participating companies, contract values, and budget have not yet been disclosed, so it is too early to calculate the size of the market. The presidential memorandum also states that implementation of the program must remain subject to applicable law and the availability of appropriations.

Even so, a new type of government demand may emerge.

Rather than merely purchasing security systems or software, governments could issue contracts to procure the technology and specialized personnel needed to carry out specific cyber missions.

The fact that the U.S. government explicitly considered participation by small specialized companies is particularly important when looking at the competitive structure of this potential market.

A company may lack the ability to build a large government system but still be competitive for a specific national mission if it has deep expertise in a particular attack technique, criminal organization, malware family, or attack infrastructure.

At the same time, the barriers to entry may also differ from those of ordinary security contracts.

Companies must demonstrate not only technical capability, but also facility security, personnel vetting, proven operational performance, reliability, compliance with government control, and reporting systems.

Ultimately, companies that are competitive in this market may not simply be technically advanced, but capable of managing both their technology and their organization well enough for the government to entrust them with sensitive missions.


The Boundary Between Government and the Private Sector Is Changing

It would not be accurate to view this policy as an event in which the role of private cybersecurity firms shifts from defense to offense.

Their existing defensive, analytical, and investigative work remains in place.

What changes is the government’s ability to bring those private-sector capabilities into the execution stage of national cyber operations.

Participating companies may also receive threat intelligence from private companies or federal, state, and local government entities and use it to propose new cyber operations to the NCC. The government retains final authority over target determination and operation approval, but a channel is also being created through which threats identified in the private sector can become proposals for government operations.

If this structure becomes established in practice, the criteria for evaluating a country’s cyber capabilities may also change somewhat.

In addition to personnel and technology directly held by government agencies, how effectively a country can connect private-sector technology and specialized personnel that it can use when needed may also become important.


DANA NOTES Commentary

The core of this presidential memorandum is not that private companies have been given the freedom to attack foreign hackers on their own.

It is closer to the opposite.

The U.S. government intends to use private-sector offensive capabilities while keeping target selection, operation approval, and control in government hands.

What is interesting here is the way national cyber capabilities are defined.

A government does not necessarily need to directly maintain every technology and specialist workforce at all times.

If it can identify a company with the capability required for a particular mission, verify that the company is secure and trustworthy enough to handle a national mission, and bring it into the government’s chain of command when needed, that private capability can also become a cyber resource the state can effectively use.

It is particularly important that this policy considers not only large companies but also small companies that are strong in specific missions from the outset.

In cybersecurity, organizational size does not necessarily correspond to expertise in a particular technology. A small company or team that has tracked a narrow area for a long time may be better suited than a large company for a specific mission.

Therefore, once this program begins operating in practice, it will also be necessary to examine which capabilities the U.S. government chooses to retain directly and which capabilities it chooses to procure from the private sector.

At the same time, bringing the private sector more deeply into national operations creates more difficult questions.

How much classified information should be shared with private companies, how should criminal organizations linked to states be distinguished, how should private companies be prevented from exceeding their authorized scope, and how should responsibility for operational failure and contract breaches be separated?

Using private-sector technology as a national capability is not completed simply by borrowing that technology.

A system is also needed to identify the companies that possess it, verify them, trust them, control them, and deploy them to the right missions.

That is the structure this presidential memorandum is seeking to change.


Variables to Watch Going Forward

This policy is not yet at the stage where the actual operational performance of private companies can be evaluated.

The presidential memorandum requires detailed operating procedures to be established within 60 days of its issuance. These procedures must cover participation criteria, target adjudication, preparation and approval of operation packages, reporting, and coordination among government agencies.

The following will need to be monitored:

  1. Which companies actually participate
    It will be important to see whether small specialized firms mentioned in the memorandum are selected in practice, rather than only large defense and cybersecurity companies.
  2. Which technical capabilities the government needs most
    Actual contracts may reveal where demand emerges, including malware analysis, attack infrastructure tracking, intrusion, intelligence collection, and system disruption.
  3. How strict the facility security and personnel vetting standards are
    Because participating companies must be capable of handling classified information and operational intelligence as well as possessing technical capability, these standards may determine the real barriers to entry.
  4. How criminal organizations linked to states are classified
    The information and criteria used to distinguish CE-TCOs from organizations controlled by foreign governments will be central.
  5. How operational failure and contract breaches are distinguished
    It will be necessary to see which contractual violations actually trigger bond or escrow forfeiture and how inadequate performance affects contract renewal and program reassessment.
  6. How far actual Cyber Effects Operations go
    It will be important to determine whether intelligence collection and tracking remain the main activities or whether private companies actually begin carrying out system disruption, degradation, and destruction.
  7. How large the program becomes as a government contracting market
    Once the number of participating companies, contract values, and budgets begin to be disclosed, it will become possible to assess more concretely how far the U.S. government intends to use private-sector cyber capabilities in national operations.

The presidential memorandum requires program officials to submit the first operational status report within 180 days and annual reports thereafter. If participating companies, contracts, and actual operations begin to emerge, these reports may become one of the first indicators of whether the program is moving from a policy plan into an actual national cyber capability.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top