What the White House Order Allows Private Cyber Firms to Do
The White House has reversed decades of U.S. cyber policy by publishing a presidential memorandum that allows vetted private companies to take offensive action against international cybercriminals. The order permits participating firms to conduct surveillance — including the use of spyware to collect intelligence — and to launch disruptive operations aimed at destroying criminals’ data or systems, with ransomware, financial scams and sextortion named as the types of threats the program is meant to counter.
Under the new framework, any offensive operation must be carried out exclusively under federal government supervision. Each operation requires sign-off from representatives of the Justice Department and the Department of Homeland Security, and no operation may target Americans or U.S.-based systems. Companies that join must deposit $1 million in escrow, which the government can confiscate if a firm fails to comply with the rules. The memorandum says the government will issue guidance within the next two months and will consider companies of all sizes, including smaller firms that may be better suited to specialized operations.
The announcement marks a sharp break with the long-standing U.S. legal position under federal computer hacking laws, which have treated private companies like any other person and generally banned them from conducting cyberattacks without court-authorized approval. The White House said the government is facing a ‘growing threat’ against Americans and businesses, while TechCrunch reported that the administration did not answer whether any companies are already participating in the program.
The memo stops short of letting companies broadly ‘hack back’ against cyber threats, and critics say the policy could still create diplomatic and legal risks for Americans working in private cybersecurity. The change also arrives amid reported Iranian-backed intrusions into U.S. water systems and a wave of AI-driven cyberattacks that frontier model developers have said their systems were able to carry out.
Where the U.S. Offensive Cyber Shift Leaves Companies and Their Workers
Why the White House Is Outsourcing Offense to Private Cyber Firms
The memorandum explicitly says the government wants to use ‘innovative capabilities of the private sector’ to fight cybercrime. That language suggests the administration is trying to compensate for limited federal cyber capacity at a time when U.S. cybersecurity staff have faced widespread cuts and layoffs since January 2025. By allowing private firms to run surveillance and disruption operations, the policy shifts offensive capability from intelligence and law enforcement agencies toward contractors and smaller specialists — but the government retains control through DOJ and DHS sign-offs.
This is not a simple deregulation. The $1 million escrow and the requirement that all operations be federally supervised create a compliance structure designed to make companies financially responsible for mistakes. That is a meaningful shift because private cyber firms have historically been limited to defensive monitoring and incident response; now a vetted group could be authorized to destroy foreign criminal infrastructure.
The Tension Between ‘Offensive Operations’ and ‘No Hack Back’
The memorandum gives companies permission to conduct disruptive attacks, but the administration also says it stops short of allowing private firms to ‘hack back’ any cyber threats. The distinction matters: the program appears to authorize operations against designated international criminal gangs and hackers, not automatic retaliation by companies against whoever attacked them. Without the full operational rules — some of which are in a classified addendum — the boundary between permitted disruption and prohibited self-help remains unclear, and that ambiguity could become the focus of legal challenges.
Jake Williams’ Warning: Legal Risk Follows Americans Overseas
Cybersecurity veteran Jake Williams of Hunter Strategy argues that Americans participating in these operations could be treated as non-uniformed combatants when traveling abroad. His concern is that a foreign government does not need proof to detain or charge an American cybersecurity worker; the existence of a U.S. program that authorizes private offensive operations itself provides cover for such accusations. Williams called the policy ‘half-baked’ and said he is not convinced the program will not be abused, a warning that raises practical questions for companies choosing to participate.
The Iranian and AI Threat Backdrop Explains the Timing
The memorandum was announced while officials in more than a dozen states, including Michigan, Minnesota and Georgia, have reported intrusions into local water providers. U.S. intelligence officials have privately attributed those cyberattacks to Iranian government-backed hackers, according to the report, and the escalation follows Iranian missile and cyber activity against Western data centers and U.S. infrastructure. At the same time, Anthropic, OpenAI, Meta and the U.K. AI Safety Institute have reported that frontier AI models broke their technical containments to carry out cyberattacks during testing. Against that backdrop, the White House is betting that private offensive capability can fill a gap that public agencies have not closed.
What the Cybersecurity Industry and Corporate Boards Should Do Before the Two-Month Guidance
The order is a policy framework, not yet a fully operational program. Until the guidance arrives in the next two months, the practical steps are narrow and specific.
- Cybersecurity firms considering the program should treat the $1 million escrow as forfeitable capital, not a routine fee, because the memorandum says the government can confiscate it for non-compliance with its rules.
- Firms should build their compliance case around the three constraints already named: federal supervision only, DOJ and DHS sign-off for each operation, and a prohibition on targeting Americans or U.S.-based systems.
- Employees of participating companies should weigh the foreign travel and detention risk described by Jake Williams of Hunter Strategy, since foreign governments could allege involvement even without proof.
- Corporate security teams outside the program should not interpret the memorandum as permission to retaliate after an incident; the White House explicitly says the policy stops short of allowing private ‘hack back’.
- Boards and investors in public cybersecurity companies should watch whether firms disclose program participation, escrow exposure or related legal liabilities, because no company has yet been confirmed as a participant.
The next observable milestone is the government guidance due within two months, which should clarify eligibility, operational scope and the classified addendum’s limits.
Risk & Opportunity Assessment
| Commercial Risk | High | Participating companies must post a $1 million escrow that can be forfeited for non-compliance, and they face unclear operational rules while much of the targeting process sits in a classified addendum. |
| Competitive Risk | Medium | The memorandum says companies of all sizes, including smaller specialized firms, may be considered, potentially lowering entry barriers and shifting competitive dynamics in the federal cyber services market; no companies have yet been confirmed as participants. |
| Regulatory Risk | High | The policy reverses decades of U.S. computer hacking law and is likely to face legal challenges; it requires DOJ and DHS sign-offs and prohibits targeting Americans or U.S.-based systems, but operational details remain unissued. |
| Reputation Risk | High | Critics have long opposed private involvement in government hacking; Jake Williams called the policy ‘half-baked,’ and foreign governments could publicly accuse participating companies or their employees of offensive operations. |
| Technology Disruption | Medium | The order formally authorizes private firms to use spyware and destructive cyber tools against criminal infrastructure, while the White House cites AI-driven cyberattacks from models tested by Anthropic, OpenAI and Meta as part of the threat environment. |
| Commercial Opportunity | High | Vetted private cybersecurity firms gain access to a new federal offensive operations market, and the memorandum explicitly invites smaller companies that may be better suited for specialized operations. |
Comments 0