
On August 12, 2026, President Donald Trump signed a National Security Presidential Memorandum directing the creation of a federal program that can authorize vetted U.S. companies to participate in cyber operations against foreign cyber-enabled transnational criminal organizations. (The White House)
This goes considerably further than asking technology companies to share information or improve their defenses.
The memorandum specifically authorizes two categories of activity.
Cyber Surveillance Operations can involve accessing targeted computer systems without the owner’s authorization to collect intelligence.
Cyber Effects Operations can include manipulating, disrupting, denying, degrading or destroying information systems, networks, data and certain infrastructure controlled by those systems. (The White House)
The private companies will not be independent cyber operators.
Every operation must remain under federal control and supervision, participating companies must be vetted and contracted by the Department of Justice or Department of Homeland Security, and every proposed cyber-operation package requires written government approval before action can begin. (The White House)
That distinction matters.
This is not a government authorization for companies to go hunting hackers on their own.
It is the creation of a framework through which private companies can become operational participants in federally directed cyber missions.
And that represents the deeper signal.
The headline is easy to reduce to:
America is letting private companies hack cybercriminals.
That misses what is actually changing.
For decades, much of the cybersecurity industry’s commercial role has been defensive: detect intrusions, patch vulnerabilities, protect networks, investigate breaches, recover systems and share threat intelligence.
The new framework potentially adds another category:
Private cyber operator working directly inside a government-authorized offensive mission.
The White House explicitly argues that private companies possess scale, speed, technical capacity and specialized expertise that have historically been underused in efforts to disrupt criminal networks. (The White House)
There have already been signs of deeper public-private cooperation. In June 2026, the Justice Department’s Scam Center Strike Force described coordinated government and private-industry actions that disrupted millions of accounts connected with transnational scam operations. (Department of Justice)
The August memorandum pushes that relationship another step.
Information sharing can now potentially become operational participation.
That could eventually create an entirely new government-facing segment of the cybersecurity industry.
Government contracting in cybersecurity is nothing new.
What changes is the work being authorized.
Companies accepted into the program could participate directly in surveillance and effects operations rather than simply supplying software, intelligence or defensive services.
The memorandum specifically instructs officials to create eligibility standards that allow both large companies with significant capacity and smaller firms capable of specialized missions to participate. (The White House)
That could create opportunities for cybersecurity companies specializing in threat intelligence, malware analysis, infrastructure mapping, intrusion operations and other highly technical areas.
Getting into this program will not simply require good software.
The government must evaluate technical proficiency, previous cyber-operation performance, facility security, personnel vetting, competence and reliability. Companies must also undergo at least annual reviews to remain eligible. (The White House)
That means security clearances, operational history, trusted personnel and compliance systems could become increasingly valuable corporate assets.
Offensive cyber operations carry very different risks from defensive cybersecurity.
A defensive company protects a client’s network.
An offensive operator may be interacting with infrastructure located in another jurisdiction, potentially involving systems owned or used by parties other than the intended target.
The memorandum recognizes this risk.
Companies must stop operations and notify the government if activity unexpectedly reaches a U.S. person, a U.S.-based information system or a system controlled by a U.S. person. (The White House)
DOJ and DHS may also require participating companies to maintain a bond or escrow of at least $1 million, which can be forfeited for contractual noncompliance. (The White House)
This is where the Deep Signal becomes larger than the memorandum itself.
Today, many cybersecurity companies sell protection.
Tomorrow, some may also compete for permission to conduct government-authorized disruption.
Those are very different businesses.
One protects infrastructure.
The other potentially enters adversarial infrastructure.
If the program expands, investors, insurers, customers and employees may eventually distinguish between companies that remain strictly defensive and companies willing to participate in offensive government operations.
Advanced offensive cybersecurity requires people who understand vulnerabilities, malware, networks, identity systems, cloud infrastructure and adversarial behavior at an unusually deep level.
Government agencies already compete with private companies for that talent.
This framework changes the equation.
Instead of government always having to hire those people directly, it can potentially contract organizations where that expertise already exists.
That could make specialized cyber teams increasingly valuable.
One reason for bringing private companies into the framework is capacity.
Private cybersecurity firms investigate attacks around the world every day and often see malicious infrastructure before governments do.
Under the new program, participating companies may receive threat information from other businesses and government agencies, then propose cyber operations to the National Coordination Center. (The White House)
If the model works as intended, the time between detecting a criminal network and disrupting it could potentially shrink.
That is one of the strongest arguments for the program.
The same speed that creates an advantage also creates risk.
Computer infrastructure crosses borders.
Servers can be rented.
Criminals can compromise legitimate systems and use them as part of their infrastructure.
A cyber operation directed at one target can therefore involve assets belonging to someone else.
The memorandum attempts to address this through government approval, operational deconfliction, DOJ review and rules requiring operations to stop when activity exceeds authorized parameters. (The White House)
Whether those safeguards work effectively in real operations will be one of the program’s most important tests.
This is an inference rather than something promised by the memorandum itself.
If the United States demonstrates that vetted private companies can safely expand government offensive cyber capacity, other countries may consider similar arrangements.
That could eventually create an international policy question:
How much offensive cyber capability should governments delegate to private companies?
The answer could shape cybersecurity regulation far beyond the United States.
Companies capable of meeting federal standards could gain access to a new category of government work.
The biggest opportunities may not necessarily go only to the largest cybersecurity vendors.
The memorandum explicitly calls for eligibility standards that accommodate smaller, agile companies suited to specialized assignments. (The White House)
Federal agencies gain access to a larger pool of cyber capabilities without having to build every capability internally.
If operations successfully disrupt ransomware groups, financial-fraud networks and other foreign criminal organizations before they can attack additional victims, businesses and consumers would be the ultimate beneficiaries.
The administration says Americans reported more than $20.8 billion in losses from cyber-enabled crime during 2025, illustrating the financial scale of the problem the program is intended to address. (The White House)
Highly specialized offensive-security skills could become even more commercially valuable if companies begin competing for government operational contracts.
They become the program’s direct target.
Instead of facing primarily arrests, seizures, sanctions and defensive countermeasures, some networks could now face government-authorized attempts to manipulate, disable or destroy the digital infrastructure supporting their operations. (The White House)
Government cyber work could increasingly reward organizations capable of demonstrating rigorous security, personnel vetting and operational discipline.
The potential upside comes with substantial responsibility.
Operating outside approved parameters can trigger immediate reporting requirements, termination of an operation and potential contractual consequences. (The White House)
A serious operational mistake could also carry reputational consequences far beyond a lost government contract.
The program does not become an unrestricted offensive cyber force overnight.
The memorandum gives the DOJ and DHS program directors 60 days from August 12 to establish operating procedures. (The White House)
Those procedures must establish:
Operations that could result in death, serious injury or rise to the level of a use of force or armed attack under international law are classified by the memorandum as Critical Outcomes and cannot be approved through the ordinary program-director process. (The White House)
The program must also operate consistently with U.S. law and applicable international obligations. (The White House)
The first major milestone will therefore not be a cyberattack.
It will be the rules.
After that, watch three things:
Which companies are selected.
What types of criminal organizations are targeted.
Whether successful operations cause Washington to expand the model.
Those answers will tell us whether this remains a specialized tool against transnational cybercrime or develops into something considerably larger.
The United States has used private cybersecurity expertise for years.
What is changing is the role.
The August 12 memorandum creates a formal pathway for vetted American companies to move beyond providing intelligence and defensive technology and participate directly in government-controlled cyber surveillance and disruption operations against foreign criminal organizations. (The White House)
Supporters can argue that sophisticated cybercriminals operate globally and rapidly, making private-sector speed and technical talent an important force multiplier.
Critics and skeptics can reasonably focus on accountability, mistaken targeting, international implications and the consequences of giving commercial organizations a role in offensive cyber activity.
Both sides point toward the same conclusion:
The boundary between government cyber operations and the private cybersecurity industry just became less rigid.
If the program proves effective and remains controlled, it could establish a new model for fighting global cybercrime.
If it produces serious mistakes or unintended consequences, it could demonstrate why that boundary existed in the first place.
That is why this is more than another cybersecurity announcement.
It is an experiment in who gets to fight back in cyberspace.
Subscribe to follow the Trend newsletter and more.
Pass along insights or story ideas on AI, startups, and business. Focused on signal over noise, impact over headlines. Facts. Trends. Consequences. Always.
Buy Grey Ghost a Coffee