A new presidential memorandum attributed to President Donald J. Trump would expand the federal government’s fight against transnational cybercrime by bringing vetted private U.S. companies into government-directed cyber operations.
The memo frames foreign cyber-enabled criminal organizations as a growing threat to American citizens, businesses and national security. It says those groups run sustained online campaigns involving fraud and other predatory schemes that harm the U.S. economy and public safety.
The central change is significant: the National Coordination Center, or NCC, is directed to create and manage a program that can authorize participating U.S. companies to conduct cyber surveillance operations and cyber effects operations against foreign cyber-enabled transnational criminal organizations.
According to the memorandum, those operations would not be free-lance private action. They would be carried out under federal control and oversight as part of lawful law enforcement, protective or intelligence activity.
## Private firms, but under federal supervision
The program would be led by two executive directors: one designated by the attorney general from the Department of Justice and one designated by the secretary of homeland security from the Department of Homeland Security.
Those officials would be able to approve cyber operations within the program after coordination with one another. However, the memo says they may not approve operations that would result in “Critical Outcomes,” a term the document defines as actions likely to cause loss of life, serious injury, or rise to the level of use of force or armed attack under international law.
Participating companies would have to enter contracts with either DOJ or DHS. Those agreements would require vetting and compliance with operating procedures that are still to be written.
The memorandum also allows participating companies to enter commercial agreements with private entities and with federal, state, local, tribal and territorial agencies. Private entities could provide threat information gathered during normal business activity, while government agencies could identify cyber-enabled criminal threats for potential action through the NCC.
## What the companies could be allowed to do
The memo distinguishes between two major types of operations.
A “Cyber Surveillance Operation” is described as activity conducted through information systems primarily to collect information or intelligence, including information that could be used in future cyber effects operations. The definition says such activity may involve accessing systems without authorization from the owner or operator, or exceeding authorized access, with an intent to remain undetected.
A “Cyber Effects Operation” is defined more aggressively. It includes cyber activity that results in manipulation, disruption, denial, degradation or destruction of information systems, networks, infrastructure controlled by information systems, or information stored on them.
The memo states that program activities must comply with the Constitution, applicable laws and U.S. international obligations, including 18 U.S.C. § 1030, the federal computer crime statute.
## New rules due within 60 days
The memorandum gives the program’s executive directors 60 days to establish operating procedures in coordination with the Homeland Security Council.
Those procedures must set minimum standards for companies, including technical proficiency, proven cyber operations performance, facility security, personnel vetting, competence and reliability.
The memo says eligibility rules should allow both large companies and smaller firms to participate. Larger companies are described as providing capacity, while smaller companies may be better suited for specialized or discrete tasks.
The rules must also require participating companies to disclose relevant contractual relationships to the NCC.
DOJ and DHS would be allowed to require participating companies to maintain a bond or escrow of at least $1 million, which could be forfeited if a company fails to comply with its contract.
## Safeguards aimed at U.S. persons and critical infrastructure
The memorandum includes several limits and reporting requirements.
Any program activity directed at a U.S. person, or otherwise implicating constitutional, federal law or international law obligations, must receive necessary authorization before approval. The memo specifically calls for Justice Department review in those circumstances.
If a participating company discovers that an operation has exceeded its approved limits — including unintentionally targeting a U.S. person, an information system in the United States, or a system controlled by a U.S. person — it must stop the operation, carry out minimization procedures and immediately notify the NCC. The NCC must then notify DOJ.
Companies must also immediately notify the NCC if they discover an imminent cyberattack against U.S. critical infrastructure or develop a reasonable belief that an approved operation may produce a Critical Outcome.
Every cyber operations package must receive written approval and direction from the program executive directors before action is taken.
## Annual reports and continuing review
The memo requires the program executive directors to produce a status report within 180 days and then annually. Those reports must be submitted to the Assistant to the President and Deputy Chief of Staff for Policy and Homeland Security Advisor and to the National Cyber Director.
Participating companies would be reviewed at least once a year for continued eligibility.
The document also says the NCC should use automation to streamline program elements where appropriate and legal.
## A major shift in public-private cyber operations
The memo casts the private sector as an underused asset in the fight against cybercrime. It argues that American companies possess scale, speed and technical capacity that can give the United States an offensive advantage against criminal networks operating online.
At the same time, the document repeatedly states that authorized activity must occur under government supervision and legal authority, not as independent private retaliation.
If implemented as written, the program would mark a more formal role for vetted U.S. companies in offensive and intelligence-gathering cyber operations against foreign criminal organizations — while placing major responsibility on DOJ, DHS and the NCC to prevent overreach, accidental domestic targeting and operations with potentially grave consequences.




