On August 12, the White House issued a Presidential Memorandum establishing a new “Program to authorize Participating Companies…to conduct Cyber Surveillance and Cyber Effects Operations” against certain transnational criminal organizations under federal direction, authorization, and oversight. The program will be led by the Department of Homeland Security (DHS) and Department of Justice (DOJ). It follows from Executive Order 14390 of March 6, 2026, which directed the government to develop an action plan for preventing, disrupting, investigating, and dismantling transnational criminal organizations engaged in cybercrime. 

The memorandum also builds on the March 2026 Cyber Strategy, which explicitly called for the United States to “unleash the private sector” to help identify and disrupt adversary networks, while using the full suite of defensive and offensive capabilities to impose costs on cybercriminals and other threat actors. The fact sheet, which accompanied the August 12 memorandum, further explains that the key targets are the “sophisticated” transnational criminal organizations that engage in ransomware attacks, phishing campaigns, financial frauds, sextortion schemes and impersonation scams to “exploit Americans in cyberspace.”

The new memorandum sets a framework for authorizing vetted U.S. companies to support government cyber surveillance and effects operations against transnational criminal organizations. More broadly, the memorandum reflects the Administration’s continued emphasis on using private-sector capabilities to expand the scale and speed of federal cyber operations, including disruption operations.

Key details that will shape how the program operates remain to be developed. The memorandum directs the government to establish implementing procedures within 60 days of its August 12 publication, which should provide further clarity regarding the program’s legal, operational, and practical framework. 

The Program Details

Per the Presidential memorandum, the program will be overseen by two Executive Directors, one designated by the Attorney General and one by the Secretary of Homeland Security, in order to authorize two broad categories of activity:

  • Cyber Surveillance Operations, which include unauthorized access to foreign information systems for intelligence collection and preparation for potential future operations, with the intent to remain undetected; and
  • Cyber Effects Operations, which includes manipulation, disruption, denial, degradation, or destruction of information systems, networks, infrastructure, or information.

The Executive Directors are not permitted to approve operations that are expected to involve Critical Outcomes, defined as those actions likely to result in the loss of life or serious injury, or that rise to the level of use of force or armed attack under international law. 

Targets of possible operations are “cyber-enabled transnational criminal organizations,” defined as any foreign group that conducts cyber-enabled crime against the U.S. government, a U.S. person, or U.S. interests, and is not an institutional part of a foreign government or wholly operated under a foreign government’s direction. This definition is broad enough to encompass foreign criminal groups that receive state support, so long as there is no “clear intelligence” establishing that they are part of, or wholly directed by, a foreign government. 

The Timeline and Procedures

The memorandum gives the Executive Directors 60 days to develop the program’s operating procedures in coordination with the Homeland Security Council. Per the memorandum, these procedures will:

  • set standards for what companies can participate;
  • ensure both large and small companies can participate; 
  • set forth the operational workflow, to include operational deconfliction procedures and standardized rubrics and templates for target identification and approval of specific operations; 
  • establish reporting obligations and review procedures; and 
  • address compliance issues. 

If a participating company discovers an imminent cyberattack against critical infrastructure, or develops a reasonable belief that an approved operation may yield a Critical Outcome as defined above, the participant is required to immediately notify the National Coordination Center (NCC), which in turn must notify the Attorney General. 

The memorandum also requires procedures to ensure that any program activity directed at a United States person, or otherwise implicating the U.S. government’s obligations under the Constitution, federal law, or international law, receives any necessary authorization, judicial or otherwise, before the operation is approved.

Participating companies will be required to enter into contractual agreements with either DHS or DOJ and will, according to the memorandum, be conducting activities on behalf of the federal government pursuant to the government’s “lawful authorities.” Participating companies must also maintain a bond or escrow in an amount of $1 million or more, to be forfeited in the event of non-compliance. The memorandum further states that participating companies will be permitted to enter into commercial agreements with other non-participating companies, obtain threat information from those entities or in the ordinary course of business and use it to develop proposed operations. 

The memorandum is accompanied by a classified annex. Those details are not publicly known.

Key Considerations as the Program Moves Forward

The memorandum establishes the program’s broad structure while leaving many of the legal and operational details to the forthcoming implementing procedures, to be issued jointly by the Departments of Justice and Homeland Security. We have outlined key questions that these procedures should address.

Legal Authorities and Protections

The memorandum expressly provides that participating companies will act under federal control and oversight and pursuant to the government’s lawful authorities, creating an important framework for government direction of private-sector activity. Among the key questions:

  • What existing statutory or other authorities will DOJ and DHS rely on to support surveillance and effects operations under the program? Will those authorities apply outside the context of a traditional criminal case or investigation, and if so, on what grounds?
  • Will participating companies be treated as agents of the government? If so, will they be bound by the Fourth Amendment and other constitutional requirements applicable to government actors?
  • How will participating companies be protected from civil, criminal, regulatory, contractual, and other forms of potential liability, including when an approved operation produces unintended effects on third-party systems, infrastructure, data, or services?
  • What protections are in place for non-participating companies whose information is shared with and used by participating companies in carrying out an effects or surveillance operation?

Foreign-Law and International Considerations

Actions taken against cyber-enabled transnational criminal organizations will almost inevitably involve foreign persons, systems, or infrastructure. The memorandum requires program activities to comply with applicable international obligations of the United States, but this still leaves key questions unresolved:

  • How will foreign law implications be considered and addressed?
  • Will participating companies be protected from potential criminal and civil liability if their actions are deemed to violate national or local criminal, privacy, data-protection, cybersecurity, telecommunications, or other applicable law in a foreign country?
  • How will the program account for and protect participating companies from potential diplomatic, sanctions, travel, trade, or cyber consequences arising from operations that affect foreign persons or infrastructure?

Operational Risk Evaluation

The memorandum establishes an important outer boundary on permissible activity by prohibiting operations expected to result in a Critical Outcome as outlined above. However, it is silent as to how the government will assess other risks that fall below this threshold, including potential cascading effects on shared cloud services, compromised infrastructure, third-party accounts, or systems belonging to otherwise uninvolved organizations. 

Key questions include whether and how the program will evaluate the risk of:

  • significant service disruptions;
  • loss, corruption, or exposure of data;
  • effects on civilian or third-party infrastructure;
  • impacts on networks or systems not controlled by the intended target;
  • privacy or supply-chain consequences; or
  • substantial economic or operational harm.

Targeting and Approvals

The memorandum leaves open important questions about the nature and scope of approved targets. Among the key questions:

  • Who are the primary targets? How will the program assess whether foreign criminal organizations that have ties to, or receive support from, foreign governments are ‘wholly directed’ by those governments and therefore outside the program’s scope?
  • Will operations focus on known and identified actors, accounts, infrastructure, or systems? 
  • How will ‘unknowns’ be assessed and handled, including unknown locations, actors, or infrastructure?
  • What level of confidence that a target is what it appears to be and meets the requisite criteria will be required before an operation is approved? 
  • How will the government address situations in which targeted infrastructure is shared with legitimate users or operated by third-party providers?

Information Sharing

The memorandum allows participating companies to enter into commercial arrangements with non-participating entities and obtain threat information from them or through the ordinary course of business for use in developing proposed operations. That raises questions about the legal framework surrounding information sharing between participating and non- participating companies, including the following:

  • Will participating companies be treated as federal or non-federal entities, and how does that impact liability protections under the Cybersecurity Information Sharing Act of 2015 (CISA 2015)?
  • Will non-participating companies be protected if they provide threat information for program purposes? What if that information is used in a way that causes unintended damage or destruction?

Eligibility for Participation

The memorandum specifically directs the program to accommodate companies of different sizes and capabilities, which requires implementing procedures to translate that direction into practical eligibility standards. Key questions include:

  • How will key considerations, such as technical proficiency, operational experience, personnel vetting, facility and information security, reliability, compliance capabilities, and the ability to operate under government direction, be weighed and evaluated?
  • How will the contracting and onboarding process address the needs of smaller and specialized companies?

Interagency Governance and Deconfliction

The memorandum establishes the Executive Directors as the central approval authorities, but many questions remain about the broader government process surrounding individual operations: which agencies will participate in target development, intelligence support, legal review, and operational deconfliction. The memorandum does not explicitly mention cyber defense or explain how the program will connect to defensive cyber responsibilities. Key areas for clarification include: 

  • What coordination role will the Cybersecurity and Infrastructure Security Agency (CISA) and Office of the National Cyber Director (ONCD) play when an operation implicates defensive cyber activities, critical infrastructure, or broader national cyber policy?
  • Who will serve as the day-to-day interface with participating companies? Who will make key operational decisions in the face of rapidly changing circumstances on the ground?
  • What role will the Secretary of Homeland Security and the Attorney General have in decision-making? 
  • How will target development, legal review, interagency deconfliction, and written approvals be structured? How will this process balance the need to move quickly for time-sensitive operations with the need for oversight and review? 

Government and Participating Company Roles

The memorandum also raises questions about where government decision-making ends and contractor execution begins. Federal policy places limits on contractors performing inherently governmental functions, making the degree of government direction, oversight, and retained decision-making authority particularly relevant to the program’s design. Key areas for clarification include:

  • How much operational discretion may participating companies exercise within an approved operation?
  • How will the government retain oversight and control if conditions change quickly and immediate operational judgment is required?

Looking Ahead

The forthcoming operating procedures will provide an important opportunity to clarify how authority, responsibility, risk, and accountability are allocated among the government, participating companies, and other entities whose infrastructure or information may be affected by an operation. 

The Center looks forward to working constructively with the Administration, DOJ, DHS, and other relevant agencies as they work through these important questions and move from policy to implementation. 

Read Next

The EU’s e-Evidence Package Takes Effect Today. Now Comes the Hard Work.

The European Union's new e-Evidence framework promises to dramatically transform the way law enforcement can access data for criminal investigations and prosecutions across borders.

European Commission Publishes Final Cyber Resilience Act Implementation Guidance, Addresses Concerns Raised by Cybersecurity Coalition

The Cybersecurity Coalition welcomes final guidance on the Cyber Resilience Act that provides covered entities with clearer guidance on the landmark product security regulation.

Building Texas Cyber Resilience: From Awareness to Action

Texas is building a new model for cyber resilience. A recent convening of state, local, academic, and private sector leaders identified practical steps to strengthen coordination, expand shared capabilities, and improve cybersecurity readiness.