President Trump has announced a plan to engage private companies in cyber operations against foreign cybercriminals. This initiative, outlined in a presidential memorandum, proposes that U.S. businesses could pursue cybercriminals selected by the government. Historically, such tasks have been managed by government agencies.
The memorandum does not provide detailed guidance on how private companies would undertake roles traditionally reserved for government entities, such as spying or conducting disruptive cyber operations. While U.S. anti-hacking laws generally prohibit unauthorized access to digital infrastructure, they do allow law enforcement to perform such tasks. Despite this, the memo mandates that any involved company must have a contract with the federal government.
Potential Impact and Concerns
If implemented, this directive would mark a significant shift in how the private sector interacts with cyberspace. It would enable businesses to take disruptive actions against organizations deemed by the government as cybercriminals or gather intelligence on them. Joshua Steinman, former senior director for cyber policy on the National Security Council, noted that potential targets could include entities involved in organized crime or money laundering.
While this move has garnered praise from some advocates, it does not extend legal authority to companies to act as ‘privateers,’ a concept likened to naval engagements of the 16th century. Instead, this memorandum outlines a framework where companies could undertake additional work for the government.
Implementation Details
The memo doesn’t specify which companies might pursue this opportunity. Traditionally, private corporations have collaborated with the government but mainly as supportive contractors rather than independent digital operatives. Arthur Tellis, a former Department of Defense staffer, believes smaller firms or startups might view this as a lucrative chance to secure government contracts.
Private companies that participate must undergo a rigorous vetting process, enter contracts with specific government departments, and set aside a financial guarantee. They could then attempt to access and manipulate the information systems of foreign cyber groups, though details on vetting and target selection are not explicit in the memo.
Industry Skepticism and Legal Challenges
Some cybersecurity experts, like Paul Rosenzweig, express concerns about the memorandum’s implications for digital security. He points out the practical and legal challenges that could arise if private actors engage in foreign cyber activities, as these could conflict with international laws.
Chris Wysopal, co-founder of Veracode, also worries about the risks entailed, such as targeting the wrong group or causing unintended damage. He emphasizes the dangers of large-scale cyberattacks, where unintended targets, like critical infrastructure, could suffer.
The Growing Threat of Cyberattacks
Cyberattacks pose a significant threat, costing Americans billions annually. Such attacks compromise both private business entities and public utilities, often resulting in data theft or ransom demands. A recent attack linked to Iran targeted numerous water systems in Minnesota.
While Steinman advocates for private sector involvement to bolster U.S. cyber capabilities, there is skepticism about its effectiveness in solving the escalating cybercrime threat. Wysopal doubts that offensive measures alone can ensure security, suggesting that a focus on constant vigilance against emerging threats is necessary.

Understanding the Risks of Cyberattacks on Critical Infrastructure
Understanding the Digital Upgrade of Driver’s Licenses
Understanding Shared vs. Dedicated VPN IPs
Brinks Home Security Breach Sparks Concern and Urgency
Beware of Apple Pay Scam Texts: Protect Your Finances
AI Autonomy Raises Concerns as Meta’s Model Goes Rogue