A presidential memorandum issued on Wednesday expands federal capabilities against foreign cybercrime by establishing a program that allows vetted private US companies to conduct offensive and intelligence-gathering cyber operations under federal control.
Managed by the National Coordination Center (NCC), the program authorizes participating companies to execute ‘cyber surveillance operations’ and ‘cyber effects operations’ targeting foreign cyber-enabled transnational criminal organizations (TCOs).
The initiative operates under co-executive directors designated by the Attorney General and the Secretary of Homeland Security, ensuring all operational actions remain under direct federal supervision.
To participate, US companies must undergo rigorous vetting and sign formal contracts with the Department of Justice (DOJ) or the Department of Homeland Security (DHS). These contracts may require a bond or escrow of at least $1 million, which will be forfeited if a company fails to comply with operational requirements.
Participating firms may enter commercial agreements with other private entities to receive threat intelligence, as well as with federal, state, and other agencies to identify specific foreign threats.
The directive establishes clear boundaries for authorized activity. Cyber surveillance operations focus on covertly accessing systems to collect intelligence, while cyber effects operations cover actions that disrupt, degrade, or destroy adversary information systems and infrastructure.
However, the program explicitly bars operations that result in ‘critical outcomes’, which are defined as actions likely to cause loss of life, serious injury, or rise to the level of a use of force or armed attack under international law.
Operational controls require written approval from the executive directors before any company takes action on a cyber package. Proposed operations must undergo multi-agency deconfliction involving law enforcement, the Department of State, the Department of the Treasury, the Department of War, the DOJ, and the Intelligence Community.
The White House noted that target selection is restricted to non-state criminal groups, though foreign entities are assumed to be independent of foreign governments unless clear intelligence proves otherwise.
The memorandum enforces strict safeguards regarding domestic targets and US persons. If a contractor discovers an operation has accidentally breached a US person or a domestic system, it must immediately cease operations and notify the government.
Related: US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
Related: White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative
Related: White House Issues Memo to Bolster NSS Cybersecurity