The goal is to let private companies take on foreign cyber criminals, but the unprecedented approach raises plenty of questions about oversight and liability.
President Donald Trump’s order to “unleash” the private sector to conduct offensive cyber operations against foreign criminal hackers is raising novel questions about government oversight, as well as legal liability and other risks for private companies that enlist in the program.
The national security presidential memorandum signed by Trump this week does not enable private sector companies to “hack back” when they face a cyber intrusion. Instead, it establishes a government-run program that will contract with private sector companies and approve any offensive cyber operations conducted by industry participants.
The new directive follows the White House’s national cyber strategy, released in March, which says the Trump administration will “unleash the private sector by creating incentives to identify and disrupt adversary networks and scale our national capabilities.”
Trump’s memo directs the National Coordination Center to create and manage a program that authorizes companies to take offensive cyber action against “cyber-enabled transnational criminal organizations.” The Department of Homeland Security and the Justice Department will each designate a program executive director to co-lead the program.
“Cyber operations shall only be approved after coordination between the program executive directors, and any resulting operational action will be exclusively conducted on behalf of and under the supervision of the federal government pursuant to the federal government’s lawful authorities,” the memo states.
Tonya Ugoretz, former assistant director of intelligence at the FBI’s directorate of intelligence, said the directive is “a novel approach to what’s proved to be an intractable problem of cyber-enabled crime that we know affects every U.S. citizen to the tune of billions of dollars per year.” Ugoretz is currently the leader of PwC’s Cyber & Risk Innovation Institute.
“These cybercriminal groups have proven to be resilient, and they bounce back inevitably after even the best, most sophisticated, well-organized disruptions that the government brings to bear,” Ugoretz told Federal News Network. “I think this memo is a step towards taking an out-of-the-box approach to say, how can the government add additional capabilities to its arsenal?”
Lyn Brown, a former senior attorney at the FBI and partner at Wiley Rein, says the memo is “kind of a natural extension” of Trump’s 2018 policy that streamlined approval for military cyber operations.
“This is recognizing some of the unique capabilities and access that the private sector has, and trying to leverage that and expand the fight against transnational organized crime to a broader degree,” Brown said in an interview.
Gary Barlet, a former federal chief information officer and public sector chief technology officer at Illumio, said the new approach recognizes that other nations have relied on criminal groups and other third parties to execute cyber attacks.
“The reality is that the private sector has access to more talent and resources and not necessarily the same constraints,” Barlet said. “We’ve already seen successful examples of this, like a big tech enterprise going after cyber domains that were involved in ransomware attacks.”
Government oversight and deconflictionThe landmark program, however, faces plenty of questions surrounding its implementation.
Ugoretz said a key area to watch will be the resourcing of the National Coordination Center, a relatively new entity that was established to coordinate the activities of Federal Homeland Security Task Forces created by an immigration-focused Jan. 20, 2025, executive order.
“Is it 24/7? Is it staffed with people with enough cyber and cyber operations expertise? That’s where having an integrated entity like that can be challenging,” said Ugoretz, who served as the first director of the Cyber Threat Intelligence Integration Center.
“When you’re standing up entities like that in the government, you’re often not adding net new personnel and expertise,” Ugoretz continued. “You’re borrowing and pulling from the limited resources and expertise that already exists in various government agencies, which then has an impact on those agencies you’re pulling from.”
The center’s resourcing and other issues may be addressed by a classified annex to Trump’s memo.
The new approach also raises questions about how government agencies with classified intelligence will coordinate with the new private sector participants.
“I imagine from a security standpoint, that the disclosures of sensitive intelligence to the private sector will be relatively narrow in scope for security reasons,” Brown said. “But there’s going to have to be some level of sharing for the government to be able to supervise and direct, and the private sector to be able to effectively carry out these kinds of operations against the targets that are selected.”
The memo also directs officials to establish “operational deconfliction” across federal law enforcement, the State Department, the Treasury Department, the Defense Department, DoJ and the intelligence community.
The effort to deconflict operations is a “good signal,” Ugoretz said, given the potential for private sector hacking to clash with other operations in cyberspace and beyond.
But she added that even after decades of experience, it’s still difficult for government leaders to deconflict cyber operations and keep pace with fast-moving adversaries.
“I don’t know that they’ve cracked it yet,” Ugoretz said. “And that’s through no fault of their own. It’s hard. There are so many agencies with so many different equities. Now you’re adding private companies who need to be coordinated with and deconflicted. That’s an additional level of complexity, but it’s a real opportunity to address a challenge that’s been longstanding, because adversaries are not using static infrastructure. They’re shifting constantly to stay a step or two ahead of any disruption operations.”
Gray areas for the private sectorWhile the public part of the memo goes into detail on government oversight mechanisms, the risks and liabilities for private sector participants are less clear.
Trump’s memo requires companies to enter into contractual agreements with DoJ and DHS to participate in the program. The agreements are aimed at ensuring the companies undergo “rigorous vetting and that their performance adheres to … strict operational procedures,” the memo adds.
The memo also allows those companies directly participating in the program to enter into commercial agreements with other firms that may have access to “threat information.”
Ugoretz pointed out that the memo doesn’t directly address legal liability for private sector companies and the implications of laws that make hacking illegal – such as the Computer Fraud and Abuse Act – even if they’re nominally operating under U.S. government oversight and supervision.
“I think that will be front and center as companies decide whether and how much they want to participate,” Ugoretz said.
Brown said the contractual agreements will be “key” as DHS and DoJ develop the program.
“I would hope there will be robust dialog so that the private sector can articulate to the government what it is that they’re seeking in terms of potential liability protection or indemnification, along with the government’s probable desire to have some kind of standardized template agreements for efficiency’s sake and for uniformity’s sake,” Brown said.
Barlet said the program also raises novel questions, such as whether private sector companies that participate in the program will be considered legitimate targets by foreign countries.
“Some would argue they are already in the crosshairs, so giving them a path to fight back makes sense,” Barlet said. “The potential benefits outweigh the risks, but we need to go into this eyes wide open – there will be friction, gray areas, and unintended consequences we can’t fully predict yet.”
In addition to facing reprisal from foreign hackers, companies that contribute to the program could face “customer trust” issues by participating in or informing offensive cyber operations, Ugoretz said.
“There’s a lot for companies to weigh either when they’re thinking about participating, providing data that enables the participants, or just being adjacent to this whole new ecosystem,” she said.
Copyright © 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Trump restrictions on private AI models turns attention to open source | 0 | 5 | 05-07-2026 |
| 2 | Trump admin reshaping federal employee discipline, firing rules | 0 | 5 | 10-07-2026 |
| 3 | Trump restrictions on private AI models turns attention to open source | 0 | 5 | 05-07-2026 |
| 4 | Trump restrictions on private AI models turns attention to open source | 0 | 5 | 05-07-2026 |
| 5 | Trump restrictions on private AI models turns attention to open source | 0 | 5 | 05-07-2026 |
| 6 | Trump restrictions on private AI models turns attention to open source | 0 | 5 | 05-07-2026 |
| 7 | Trump EOs Pair Quantum Push With Cyber Defense Overhaul | 0 | 7 | 02-07-2026 |
| 8 | Whither Trump’s tariffs? | 0 | 8.46 | 10-08-2026 |
| 9 | Top cyber official wants US open-source AI adopted worldwide | 0 | 13.25 | 05-08-2026 |
| 10 | How will legal challenges fare against CMS rule on gender-affirming care? | 0 | 10.38 | 14-08-2026 |