Security.io Intelligence DeskThursday, 3 September 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
Regulatory · Executive briefing

US sets framework for supervised private-sector cyber operations

A presidential memorandum directs the US government to create a programme under which vetted private companies may conduct federally supervised cyber-surveillance and cyber-effects operations against defined foreign criminal organisations.

RegulatorySecurity LeadershipEnterprise Risk
Why it is in today’s brief

The memorandum was signed on August 12; accountable reporting on August 13 brought its contractual and governance implications into the current decision window. Unlike earlier policy statements favouring disruption, this creates a defined route for vetted private firms to perform federally supervised operations. It warrants inclusion because security leaders must now examine telemetry rights, participation boundaries and board authority before implementation guidance appears.

Read first

The White House has ordered creation of a federally controlled programme allowing vetted US companies to conduct cyber-surveillance and cyber-effects operations against defined foreign cyber-enabled criminal organisations.

Act now

Ask counsel to review contracts governing threat-data use and onward disclosure.

Accountable owner

General Counsel with the CISO and Chief Risk Officer

Decision horizon

Near term: assess contractual and governance exposure before implementation guidance is issued.

AssessmentHigh confidence
Emerging riskThe operating procedures, contract templates, target-approval rules, liability allocation and handling requirements for private-sector threat information will determine the programme’s practical enterprise impact.

What happened

On August 12, 2026, the White House issued a memorandum directing the National Coordination Center to create and manage the programme. The programme would authorise vetted private US companies to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations under federal control and oversight. The programme is to be overseen by co-Executive Directors designated by the Attorney General and the Secretary of Homeland Security. Participating Companies must enter contractual agreements with the Department of Justice or the Department of Homeland Security.

The memorandum requires consensus operating procedures within 60 days of its date. No operation may be approved until the required operating procedures are established. The procedures must address eligibility, target identification, review, reporting, deconfliction and action that exceeds approved parameters. The implementation guidance may require a participating company to maintain a bond or escrow of at least $1 million, subject to forfeiture for contractual non-compliance. A Critical Outcome includes activity likely to cause death or serious injury, or to reach the level of a use of force or armed attack under international law.

Participating Companies may enter commercial agreements to receive threat information collected by private entities during normal business activities. The Record reported on August 13, 2026 that the programme would pair private firms with the Justice and Homeland Security departments for offensive and surveillance operations. Attribution posture: The memorandum establishes a process for operations against defined foreign cyber-enabled transnational criminal organisations; it does not attribute any specific campaign or actor. The published memorandum establishes the framework, but the detailed operating model remains dependent on forthcoming procedures and a classified annex.

Why this matters now

This is not a general authorisation for companies to retaliate independently. It creates a federal contracting and oversight structure through which selected US firms could perform operations on behalf of the government. The distinction matters for boards, insurers, counsel and security providers because the relevant decision is whether to participate, supply threat information or contract with a participating company under a tightly governed federal programme.

Enterprises that share telemetry with managed-security, infrastructure, telecommunications or intelligence providers should determine whether existing terms permit that information to support proposed operations. Questions include ownership, permitted use, customer notification, cross-border data handling, legal privilege, minimisation, evidence preservation and restrictions attached to regulated or confidential information. A normal threat-intelligence clause may not have been drafted with government-supervised surveillance or disruptive operations in mind.

For potential participants, technical capability is only one eligibility dimension. The memorandum anticipates personnel vetting, facility security, performance standards, contractual disclosure, reporting and continuing evaluation. Leadership should avoid creating a capability, marketing commitment or customer expectation before the government publishes the operating procedures and the company establishes independent legal, ethical and operational approval gates.

The decision for security leaders

Treat participation and data provision as separate decisions. A company may decline to conduct operations yet still discover that its telemetry can be supplied through a participating provider. Legal, privacy, security, procurement and customer owners should map those paths before guidance and contract opportunities arrive.

Potential participants should establish a board-approved operating boundary covering authorisation, personnel separation, target validation, minimisation, evidence handling, insurance and cessation authority. The programme’s federal supervision does not eliminate enterprise exposure arising from contractual non-compliance, mistaken targeting, customer trust or operational spillover.

Security leaders should resist labelling the programme as ordinary defensive threat intelligence or unrestricted private hack-back. The memorandum creates a distinct government-controlled activity. Internal policy, sales language and customer communications should preserve that distinction and remain conditional until the implementation procedures are available.

Evidence of closure

  • A contract map identifies every provider permitted to reuse or onward-share threat telemetry.
  • A board-approved policy defines participation, data-sharing and operational approval boundaries.
  • Legal analysis documents applicable authorisation, privacy, liability and insurance assumptions.
  • Procurement language requires notice before enterprise information supports programme proposals.

The Security.io assessment

The memorandum materially changes US cyber policy by creating a route for private operational capacity to be used under federal authority. It does not automatically authorise any company, approve a specific operation or replace existing restrictions on independent access to systems. Companies should therefore plan governance without representing participation as established.

The most consequential enterprise issue may be information flow rather than offensive tooling. Commercial agreements could make privately collected threat information an input to government-directed operations. Existing contracts may be technically permissive yet insufficiently explicit for customers, regulators or boards, creating a need for transparent terms and documented approval.

Implementation quality remains unresolved. The required procedures, classified deconfliction mechanisms, judicial authorisations and contractual allocation of responsibility will determine whether the programme has narrow, auditable boundaries. Until those controls are published, leadership should prepare decision criteria rather than commit personnel, capabilities or customer data.

Questions for the morning meeting

  • Could existing customer or intelligence contracts permit threat data to enter the new programme?
  • Which executive owns decisions about participating in government-directed offensive cyber operations?
  • Are legal, insurance and board-risk frameworks prepared for operational activity outside enterprise-owned systems?

Related intelligence

Shared decision context