The presidential memorandum issued on August 12, 2026, establishes a formal program to leverage the resources and technical capabilities of the U.S. private sector to combat Cyber-Enabled Transnational Criminal Organizations (CE-TCOs).
### What Happened
The President has directed the National Coordination Center (NCC) to create and manage a program that authorizes vetted U.S. private companies ("Participating Companies") to conduct cyber surveillance and effects operations against foreign criminal organizations. These operations will be carried out under the direct oversight and legal authority of the U.S. Federal Government. The policy aims to utilize private sector speed and innovation to disrupt the cyber campaigns and fraud schemes these organizations perpetrate against American citizens and interests.
### Who Is Affected
* **Participating Companies:** U.S.-based private entities that pass rigorous vetting, meet technical proficiency and security standards, and enter into contracts with the Department of Justice (DOJ) or the Department of Homeland Security (DHS).
* **Foreign CE-TCOs:** Identified foreign groups that are not part of a foreign government and are engaged in cyber-enabled criminal activities against U.S. interests; these organizations are the primary targets of the program.
* **Federal Agencies:** The DOJ, DHS, and other national security/intelligence community entities are involved in oversight, approval, and deconfliction processes.
### Security Implications
* **Offensive Mandate:** The program grants private entities the capability to perform "Cyber Effects Operations" (manipulation, disruption, denial, degradation, or destruction of infrastructure) and "Cyber Surveillance Operations" (covert intelligence collection, including unauthorized system access).
* **Critical Restrictions:** Operations that result in "Critical Outcomes"—defined as loss of life, serious injury, or actions rising to the level of an armed attack under international law—are strictly prohibited.
* **Oversight and Accountability:** All operations require written approval from Program Executive Directors from the DOJ and DHS. Companies may be required to maintain a $1 million bond or escrow as a safeguard against contractual non-compliance.
### Technical Details
* **Cyber Effects Operation:** Activities that interfere with information technology infrastructure (internet, telecommunications, industrial control systems, etc.) to destroy or disrupt data or hardware.
* **Cyber Surveillance Operation:** Covert operations designed to access systems without authorization for intelligence gathering or to enable future effects operations.
* **Operating Procedures:** Within 60 days, consensus procedures must be established covering operational workflow, deconfliction across agencies, standardized target identification rubrics, and strict legal reviews.
### What Defenders Should Know
* **Proactive Coordination:** Companies are encouraged to enter commercial agreements with other private entities to share threat intelligence and with government agencies to identify specific CE-TCO threats.
* **Minimization and Compliance:** If a participating company inadvertently targets a U.S. person or U.S.-controlled system, they are mandated to immediately cease operations, conduct minimization procedures, and notify the NCC.
* **Dual-Nature of Defense:** Participating companies retain the right to engage in their own lawful defensive cyber operations, but any activities conducted under this specific program must adhere to federal oversight and the government’s operational control.
* **Reporting:** Companies must maintain transparency with the NCC regarding their operational activities, relationships, and any discovery of imminent attacks against critical infrastructure.