What the memorandum actually does
On August 12, 2026, President Trump signed the National Security Presidential Memorandum Expanding Capabilities to Combat Transnational Cyber-Enabled Crime. It directs the National Coordination Center — co-run by Executive Directors from the Department of Justice and the Department of Homeland Security — to build a program letting vetted US companies conduct two categories of operations against foreign Cyber-Enabled Transnational Criminal Organizations: Cyber Surveillance Operations (covert intelligence collection) and Cyber Effects Operations, defined as activity that manipulates, disrupts, denies, degrades, or destroys a target's information systems.
Participation is not casual. Companies must pass "rigorous vetting," sign a contract with DOJ or DHS, post a bond or escrow of at least $1 million forfeitable for non-compliance, and get written approval before each individual operation. Anything touching a US person or domestic system requires separate, prior legal authorization. The two Program Executive Directors have 60 days — until roughly October 11 — to publish the operating procedures that will actually define vetting standards, approval workflows, and target-identification rules, as CyberScoop's reporting on the memo's rollout confirms.
The case for deputizing the private sector
The strongest argument for this program is scale. The FBI's Internet Crime Complaint Center reported $20.8 billion in cyber-enabled crime losses for 2025 — a roughly 26% jump over 2024, and the highest figure IC3 has recorded in its 25-year history. Federal cyber units cannot hire or scale at anything close to that growth rate, while private threat-intelligence and incident-response firms already sit closer to the criminal infrastructure than most government analysts do, mapping ransomware infrastructure and botnet command-and-control as a matter of daily business. Formalizing that expertise under contract, rather than leaving it in a legal gray zone, is a defensible response to a genuine capacity gap. It also has precedent in miniature: the government has long relied on cleared contractors for signals-intelligence and defense work; extending a comparable model to cybercrime disruption is an incremental, not radical, move — and the memo is notably narrower than the "letters of marque" hack-back proposals some conservative cyber hawks have floated for years, since it withholds carte-blanche retaliation and keeps every operation under federal sign-off.
Where the design gets shaky
But the memo asks companies to absorb risks the government has not clearly agreed to share. A Wiley legal alert on the program notes that Computer Fraud and Abuse Act exposure is only conditionally addressed — protection applies while a company operates within its approved scope, not as a blanket exemption — and that the memorandum commits to no automatic indemnification or legal defense if an operation goes sideways or a foreign government objects. Firms are told to negotiate liability protection into their own contracts, against a federal counterparty that also controls whether their $1 million bond gets forfeited for "non-compliance" that the memo does not tightly define.
The oversight gap compounds this. As CyberScoop reported, a former US Cyber Command official warned there is "no clear oversight or review process on the determinations that will be made by unnamed political appointees," and separately dismissed the structure as risking becoming "a perpetual motion machine for billable" work — a real concern when the same firms identifying targets may profit from being approved to act against them. That is a governance problem distinct from the underlying policy goal, and one Congress or DOJ's Inspector General should be watching closely once operating procedures land in October.
There's a foreign-policy cost too. Washington has spent a decade at the UN Group of Governmental Experts and Open-Ended Working Group building an international norm that only states conduct offensive cyber operations — precisely to contain the escalation and misattribution risk that comes from letting non-state actors act with a state's blessing. A licensing program for private cyber effects operations, however tightly supervised domestically, sits awkwardly next to that diplomatic position, and other governments will notice the inconsistency.
The proportionate fix
None of this argues for scrapping the program — transnational cybercrime at $20.8 billion a year is a real and growing harm, and mobilizing private capability against it is a legitimate policy instinct. But the October operating-procedures deadline is the actual test. DOJ and DHS should use it to commit to real indemnification terms, a narrow and specific definition of what "non-compliance" forfeits a bond, and a public reporting requirement — even in aggregate, unclassified form — on how many operations are approved and against whom. Absent that, the program's practical effect may be to attract only the risk-tolerant fringe of the cybersecurity industry rather than the most capable firms, which is the opposite of what the policy is trying to achieve.