President Trump has signed a presidential memorandum authorizing US federal law enforcement agencies to collaborate with vetted private cybersecurity firms in conducting offensive cyber operations against foreign threat actors targeting the United States. The move represents the first formal US program to deputize the private sector for hack-back and cyber disruption operations under government oversight.

What does the Trump cyber memorandum authorize?

The memorandum, titled Expanding Capabilities to Combat Transnational Cyber-Enabled Crime and published on August 12, 2026, authorizes private US companies to conduct cyber surveillance and cyber effects operations against foreign cyber-enabled transnational criminal organizations (CE-TCOs). These are defined in the memorandum as "any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests."

The White House framed the initiative as a necessary escalation: "Transnational Criminal Organizations (TCOs) pose a growing threat to American citizens, businesses, and national security. These organizations conduct sustained cyber campaigns to perpetrate frauds that undermine American prosperity, security, and freedom… By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens."

Which cybersecurity companies can participate?

The opportunity is not limited to large, established players. The memorandum explicitly opens the door to both highly resourced organizations and "smaller, more agile companies" that may prove useful for "specialized or discrete tasks." Foreign-government-affiliated entities — those directly associated with, or operating wholly on behalf of, a foreign government — are excluded from participation.

Companies wishing to participate will undergo what the memorandum describes as "rigorous vetting" and will be required to sign contracts with the Department of Justice or the Department of Homeland Security. Participating firms must demonstrate the technical capabilities to carry out required operations, and those capabilities will be reassessed on an annual basis.

What oversight and restrictions apply?

Operational procedures are being drawn up and are to be published within 60 days of the memorandum's signing. The program will be codified by Program Executive Directors working with the Homeland Security Council. The Justice Department will play a specific authorization role for operations targeting US residents or raising domestic legal issues.

Participating companies are prohibited from executing operations that could lead to what the memorandum terms "critical outcomes" — understood to mean attacks that result in loss of life or serious injury, or actions that could be construed as an armed attack under international law.

Why is this significant for the cybersecurity industry?

The memorandum marks a significant policy shift, moving the US toward a model where the government actively contracts and coordinates private-sector offensive cyber capability rather than relying solely on military and intelligence agencies. For smaller cybersecurity firms with specialized technical skills, the program represents a new avenue for government engagement — provided they can meet the vetting and operational standards that will be set out in the coming weeks.

The program is not yet operational. No operations will be authorized until Program Executive Directors establish full consensus operating procedures, a process the memorandum gives 60 days to complete. Analysts at Lawfare and CyberScoop have noted that the initiative, while unprecedented in its formal structure, builds on an existing tradition of government-private sector collaboration in cyber defense.