White House Launches Private Cyber Ops Program With “Cyber Effects” Powers

hackback-usa-lassen-private-firmen-f0cb

The White House has ordered a new US program that would let selected private companies carry out offensive cyber operations under government control as part of the fight against international cybercrime. The plan, formalized by a National Security Presidential Memorandum signed on August 12, expands beyond traditional public-private defense by authorizing “Cyber Surveillance” and “Cyber Effects” missions that can include manipulating or even destroying systems.

Private contractors get state-controlled offensive cyber missions

Under the memorandum, the National Coordination Center (NCC) within the Homeland Security Task Force is tasked with building the program. The US Department of Justice (DOJ) and the Department of Homeland Security (DHS) are also involved in setting it up.

The program does not create a general right for companies to “hack back” on their own after being attacked. Instead, participating organizations are appointed as government contractors and must conduct only pre-approved operations under official oversight. The memorandum explicitly requires that each operation is carried out in the name of, and under the supervision of, the US government.

From covert intrusion to disruption or destruction

The memorandum defines two categories of activity. A “Cyber Surveillance Operation” allows participants to enter foreign computer systems without the owner’s consent in order to collect information covertly. The data gathered can also be used to support later actions.

“Cyber Effects Operations” go further: they cover interventions intended to manipulate, disrupt, block, degrade, or destroy computers, networks, or digitally controlled physical infrastructure. Stored data may also be targeted.

While the model brings capabilities that have previously been limited mainly to law enforcement, intelligence services, and military cyber units into a contractor framework, it is still not a blanket authorization. Planned missions must be submitted to the program’s responsible directors and receive written approval before execution.

Operational details are not finalized yet. DOJ and DHS must deliver joint rules within 60 days covering technical requirements for companies, personnel security checks, and how targets are selected.

  • Memo signed: August 12
  • Rules deadline: within 60 days
  • Possible activities: surveillance, effects (disrupt/manipulate/destroy)
  • Authorization: written approval by program directors

Limits, security deposits, and what kinds of targets are covered

Participation is open to large companies and smaller specialized cybersecurity firms, but it requires demonstrated experience with cyber operations, relevant technical capability, and vetted personnel. DOJ and DHS can also require companies to post at least US$1 million as a security deposit. If a company breaches the contract rules, that amount can be seized.

The memorandum also sets constraints during operations. If a contractor discovers that a US person—or a computer system located in the United States—has been affected, it must stop the operation and notify the NCC.

Operations with “Critical Outcomes” are treated separately and cannot be authorized through the standard approval process. The memorandum highlights cases where fatalities or serious injuries are likely, or where the action could be considered a “armed attack” under international law.

The target set is described as “Cyber-Enabled Transnational Criminal Organizations,” meaning foreign groups conducting cybercrime against US citizens, businesses, or government institutions. Examples named include ransomware, phishing, financial fraud, extortion, and identity fraud.

Organizations that are part of a foreign government or fully controlled by one are excluded. For situations without clear intelligence establishing a government link, the program initially assumes the group is acting independently.

Which companies ultimately join and when the first missions begin remain unclear, since key details will be established once the 60-day rulemaking is completed.