President Trump has signed a memorandum that could fundamentally reshape how the United States conducts cyber operations against transnational criminal organizations, potentially handing private companies a leading role in offensive cyber activities.
The memo, signed Wednesday, directs the National Coordination Center to establish a program under which private sector firms, after rigorous vetting and contractual agreements with the Departments of Justice (DOJ) and Homeland Security (DHS), would be authorized to conduct cyber surveillance and effects operations against criminal groups operating online. The program would be overseen by senior officials from both agencies.
This marks a significant departure from longstanding U.S. cyber policy, which has traditionally reserved offensive cyber operations for intelligence and military agencies. Previous efforts to increase private sector involvement have sparked controversy and faced resistance from privacy advocates and legal experts concerned about accountability and the potential for unintended escalation.
The memo argues that American businesses have been underutilized in the fight against cybercrime. "Yet, American businesses' innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace," it states. "Thus, it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime."
The move is part of a broader administration push to crack down on transnational crime, which the White House says cost Americans more than $20.8 billion last year through phishing, ransomware, impersonation, and sextortion schemes. The memo's language suggests a desire to leverage the agility and technological expertise of the private sector, which often outpaces government agencies in cyber capabilities.
The program's details remain unclear, including how companies will be selected, what specific authorities they will receive, and how oversight will be enforced. Critics worry that granting private firms offensive cyber powers could lead to abuses, violate privacy laws, or trigger retaliatory attacks against U.S. companies. Supporters, however, argue that the current approach is too slow and bureaucratic to counter agile criminal networks.
This policy shift comes amid other controversial administration actions, such as the recent court ruling on the Alien Enemies Act, and signals a broader willingness to push legal boundaries in national security matters. The administration's economic pressure campaigns have also drawn attention, though this cyber initiative is distinct in its focus on private sector involvement.
Legal scholars note that the memo's reliance on contractual agreements between companies and federal agencies may be designed to provide a legal framework for operations that would otherwise be restricted to government actors. Still, the scope of permissible actions—and the potential for collateral damage—remains a key concern.
The White House has not yet released a timeline for implementing the program, but the memo directs the National Coordination Center to begin development immediately. As the administration accelerates its cyber strategy, the private sector's role in national security is poised to expand dramatically, with implications for both cybersecurity policy and civil liberties.
