What the White House's New Private-Sector Cyber Operations Memo Actually Says (and What It Doesn't)
The August 12 memorandum authorizes vetted private companies to conduct cyber operations under federal control. What it says, what it doesn't, and why authorization is the hinge.
On August 12, 2026, the White House published a presidential memorandum titled "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime". In plain terms: it directs the creation of a federal program under which vetted private US companies can be authorized to hack foreign criminal organizations, both to gather intelligence and to disrupt their infrastructure, under the direction and oversight of the federal government.
That is a significant moment for anyone who cares about the legal architecture around security work. This post walks through what the memo actually says, what it does not say, and why it matters for the vulnerability disclosure ecosystem. We are keeping this factual: every claim below traces to the memo text or a linked primary source.
What the memo sets up
The memo directs the National Coordination Center (NCC) to "create, manage, and maintain a Program to authorize Participating Companies... to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), under the control and oversight of the Federal Government" (Sec. 2(a)).
The structural pieces, all from the memo text:
- Two co-Executive Directors, one designated by the Attorney General and one by the Secretary of Homeland Security, oversee the Program. Every cyber operations package requires their review and written approval before action may be taken (Sec. 2(a)(i), Sec. 3(a)(xiv)).
- Participating Companies are private US companies accepted into the Program after "rigorous vetting", operating under contractual agreements with the Department of Justice or the Department of Homeland Security (Sec. 2(a)(ii), Sec. 4(f)).
- Companies may take in threat information from other private-sector entities and from federal, state, local, tribal, and territorial agencies, and use it to propose operations to the NCC (Sec. 2(a)(iii)).
- The memo builds on Executive Order 14390 of March 6, 2026 ("Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens"), which it cites as the predicate for the broader federal push against cyber-enabled fraud (Sec. 1).
A provenance note, because readers will reasonably ask what the NCC is: the memo describes it as "established pursuant to section 6(d) of Executive Order 14159 of January 20, 2025 (Protecting the American People Against Invasion)". EO 14159 is an immigration-enforcement order, and its section 6(d) directs the Attorney General and the Secretary of Homeland Security to "provide an operational command center" to coordinate Homeland Security Task Forces; the EO's text does not itself use the name "National Coordination Center". That name appears in later executive actions, including EO 14390, which treat the NCC as the instantiation of that provision.
The targets are "Cyber-Enabled Transnational Criminal Organizations": foreign groups conducting cyber-enabled crime against the US government, US persons, or US interests, that are "not an institutional part of a foreign government or wholly operated under a foreign government's direction" (Sec. 4(c)). More on that definition below.
Two kinds of operations
The memo defines two operation classes (Sec. 4):
Cyber Surveillance Operations collect information or intelligence from a target's systems "with the intent to remain undetected." The definition is explicit about what this means legally: these operations "entail accessing such information systems without authorization from the owner or operator or by exceeding authorized access" (Sec. 4(d)).
Cyber Effects Operations are activities that result in "the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon" (Sec. 4(a)).
If the surveillance definition sounds familiar, it should. "Without authorization" and "exceeds authorized access" are the operative concepts of the Computer Fraud and Abuse Act, 18 U.S.C. § 1030, the statute that has shaped the legal risk calculus of security research for four decades. The memo's definition tracks the statute's phrasing almost word for word, and then adds a qualifier the CFAA itself does not carry: "without authorization from the owner or operator". Specifying whose authorization is absent leaves room for authorization from somewhere else. That four-word addition is, in miniature, the entire design of the Program.
The legal mechanism: authorization, not amendment
This is the part worth reading slowly. The memo does not amend the CFAA, and it does not claim to. Instead, Sec. 2(b) provides:
"The NCC shall conduct all Program activities in accordance with the Constitution and all other applicable laws and international obligations of the United States, including section 1030 of title 18, United States Code, thereby ensuring that Participating Companies are acting under the control and oversight of the United States Government."
And Sec. 2(a) frames the entire Program as operating "[a]s part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement," with any operational action "exclusively conducted on behalf of and under the supervision of the Federal Government pursuant to the Federal Government's lawful authorities."
The CFAA itself contains a carve-out at § 1030(f): "This section does not prohibit any lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency of the United States, a State, or a political subdivision of a State, or of an intelligence agency of the United States." The memo's "lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement" framing tracks that carve-out nearly clause for clause.
Two precision points matter here. First, the § 2(b) compliance duty attaches to the NCC's conduct of Program activities; the memo never spells out the exact legal theory under which a Participating Company's own access becomes lawful. Second, § 1030(f) speaks of activity of a law enforcement agency; whether contractor conduct performed under agency direction and supervision inherits that status is precisely the question the public text does not resolve. What the memo does, structurally, is direct CFAA compliance and position every operation as government-directed activity, leaving the agency-relationship theory implicit. A memorandum directs the executive branch; it cannot exempt private parties from a criminal statute. Whatever legal effect the Program has on its companies runs through the CFAA's own architecture.
For the disclosure ecosystem, the takeaway is structural: authorization remains the hinge on which the legality of accessing someone else's systems turns. This program does not blur that line. It formalizes a narrow, government-controlled pathway through it, and in doing so it arguably reinforces the line for everyone outside the Program.
The guardrails
The memo spends most of its length on control mechanisms. From Sec. 3, the Program's operating procedures (due within 60 days) must include:
- Minimum standards for participation: technical proficiency, proven performance, facility security, personnel vetting (Sec. 3(a)(i)), with eligibility designed to include both large companies and smaller specialized ones (Sec. 3(a)(ii))
- A bond DOJ and DHS may require as a contract condition: not less than $1 million in bond or escrow, forfeited on non-compliance with the company's contractual agreement (Sec. 3(a)(iv))
- Contract transparency to the government: companies must disclose to the NCC all commercial threat-information agreements they enter under the Program (Sec. 3(a)(iii))
- Per-operation written approval: the Executive Directors must review every cyber operations package and provide written approval and direction before action (Sec. 3(a)(xiv))
- An approval ceiling on "Critical Outcomes": the Executive Directors may not approve operations likely to result in loss of life, serious injury, or anything rising to the level of use of force or armed attack under international law (Sec. 2(a)(i), Sec. 4(b)). Note the drafting: this removes such operations from the Executive Directors' approval authority; the memo does not say whether anyone else could approve them
- US-person protections: any activity directed at a US person or implicating constitutional obligations requires necessary authorization, "judicial or otherwise", before approval (Sec. 3(a)(ix)); if a company discovers its operation has unintentionally reached a US person, a US-based system, or a US-person-controlled system, it must stop, run minimization procedures, and immediately notify the NCC (Sec. 3(a)(x))
- Escalation duties: companies must immediately notify the NCC if they discover an imminent attack on US critical infrastructure or come to believe an approved operation may cause Critical Outcomes (Sec. 3(a)(xi))
- Annual review of each company's continued participation (Sec. 3(a)(xiii)), plus reporting requirements on operational activity (Sec. 3(a)(viii))
- An automation clause: the NCC is directed to "utilize automation to streamline Program elements wherever appropriate" (Sec. 3(b)), a line worth watching given that written per-operation human approval is the Program's core safeguard
Two elements of the Program's design are explicitly classified: the operational workflow (including deconfliction across federal law enforcement, State, Treasury, the Department of War, DOJ, and the Intelligence Community) and the adjudicatory framework for target selection both conform to a classified annex (Sec. 3(a)(v), 3(a)(vi)).
What the memo does not do
Reading policy documents accurately means being as clear about the absences as the contents:
- It does not amend the CFAA or any statute. A presidential memorandum cannot do that; only Congress can.
- It does not authorize "hack back" generally. Nothing in the memo changes the legal posture of a company, or a researcher, acting outside the Program. For Participating Companies themselves, Sec. 3(a)(xii) clarifies they may still engage in "other lawful defensive cyber operations otherwise permitted to them", a restatement of the status quo, not an expansion of it.
- It says nothing about security research. The memo never mentions it, so researchers operating in good faith without a system owner's authorization are exactly where they were before: protected by the Department of Justice's May 2022 charging policy (which "for the first time directs that good-faith security research should not be charged", per DOJ's announcement) and by whatever safe harbor language organizations voluntarily adopt in their disclosure policies. That policy is prosecutorial discretion, not statute, and it does not touch civil CFAA liability.
- It does not create enforceable rights. The standard general-provisions clause (Sec. 5(c)) states the memo creates no "right or benefit, substantive or procedural, enforceable at law or in equity."
- It does not target foreign governments. The CE-TCO definition explicitly excludes state organs, and operations are aimed at criminal organizations.
Open questions the text leaves open
A factual reading also surfaces the questions the memo does not answer:
Attribution and the state-linkage presumption. Sec. 4(c) provides that a foreign group "will be assumed not to be an institutional part of a foreign government or wholly operated under a foreign government's direction unless clear intelligence exists establishing such connection." Anyone who has worked attribution knows the boundary between criminal ecosystems and state direction is one of the hardest problems in the field. The presumption resolves ambiguity in favor of the target being in scope. What happens when an approved operation touches infrastructure that later proves state-linked is left to the classified adjudicatory framework.
International law and sovereignty. The targets are foreign, and their infrastructure often sits in third countries. The memo requires conformance with "international obligations of the United States" (Sec. 2(b)) and bars operations rising to use of force or armed attack (Sec. 4(b)(ii)), but everything below that threshold, including how partner nations view US-directed private operations on their soil, is unaddressed in the public text.
Transparency. The Program's status reports (first one due within 180 days, then annually) go to the Homeland Security Advisor and the National Cyber Director (Sec. 3(c)). The memo itself provides for no reporting to Congress and no public reporting; whatever oversight obligations may attach under other law are outside its text. Combined with the classified annex that governs both the operational workflow and the targeting-adjudication framework (Sec. 3(a)(v), 3(a)(vi)), the observable surface of this Program, from the outside, will be small.
Vulnerability handling. Surveillance operations are defined to include collecting information "that can be used for future Cyber Effects Operations" (Sec. 4(d)). The memo says nothing about how the vulnerabilities and exploitation techniques that enable these operations are acquired, retained, or ever disclosed: no reference to the Vulnerabilities Equities Process, no disclosure duty anywhere in the text, and no answer to what happens when a Participating Company holds a vulnerability that also affects US systems. Put simply: the government has now formalized who may access systems without the owner's authorization, but not what happens to the vulnerabilities used to do it. Those flaws live in software that everyone else runs too. For a community built on the idea that vulnerability information ultimately serves defense, this is the gap we will be watching most closely.
Why this matters for vulnerability disclosure
disclose.io's core concern is the legal safety of good-faith security research, on both sides of the transaction. Read through that lens, three factual observations:
1. Authorization is now doing even more work. The entire legal theory of this Program runs through government authorization and control. That is the same hinge on which safe harbor language in a disclosure policy turns: the system owner authorizes good-faith access, and conduct that would otherwise be legally risky becomes sanctioned. The memo is a high-stakes demonstration of a principle the disclosure world has been operationalizing for a decade: access without authorization is the line, and authorization is granted by whoever has the standing to grant it.
2. The asymmetry is now sharper. Operations against criminal infrastructure (the memo's purpose section speaks of the private sector securing "a critical offensive cyber advantage" for the United States) now have a formal federal authorization pathway, with vetting, bonds, written approvals, and oversight machinery. Good-faith security research, the defensive input the internet depends on, still has no federal statutory safe harbor: its protections remain a revocable DOJ charging policy, a narrowing judicial construction (Van Buren), and whatever language organizations voluntarily adopt. That contrast is not a criticism of the memo; it is a factual description of where legal-infrastructure investment is going. Closing the research side of that gap is the work disclose.io exists to do.
3. Norms are set by programs like this. The memo's guardrails, per-operation approval, minimization duties, escalation requirements, and annual re-vetting, read like a maturity model for authorized offensive activity. Whatever one thinks of the policy, the document treats "who may access what, under whose authority, with what obligations when something goes wrong" as a first-class design problem. That is the same design problem every vulnerability disclosure policy answers in miniature.
The context: this has been debated before, in three distinct shapes
The idea of authorizing private entities to act against attackers is not new, and it helps to be precise about which version of the idea this is, because three different models have been on the table:
The hack-back model. The Active Cyber Defense Certainty Act (H.R. 4036 in the 115th Congress, H.R. 3270 in the 116th), introduced by Rep. Tom Graves, proposed amending the CFAA itself to give victims a defense for limited measures outside their own networks. It never received a vote in either chamber. This memo is close to that model's inverse: no self-help, no standing authority, and nothing happens without a government-approved operations package.
The privateering model. In July 2026, Senator Mike Lee introduced the Cyber Letters of Marque and Reprisal Act, which would authorize the President to commission private entities against foreign cyber threats, complete with security bonds and asset-recovery sharing. Lee described it as allowing "American digital privateers to raid cartels, cybercriminals, and foreign adversaries, disrupting their operations and seizing their assets." The memo shares some machinery with that model (vetting, bonds) but not its core: there are no commissions to act independently, no prizes, and no profit-sharing in the memo's text, and operations run on government direction rather than a license to act.
The government-directed model is what the memo builds. Notably, it arrives five months after administration officials publicly distanced themselves from the other two. In March 2026, the Office of the National Cyber Director's senior adviser Thomas Lind said of the administration's push to impose costs on attackers: "That does not mean hack back, that does not mean letters of marque. We're not interested in fighting pirates with pirates." National Cyber Director Sean Cairncross said in the same period that "private sector, industry or companies engaging in cyber offensive campaigns" was "not what we're talking about." The memo's answer to how a program of private-sector cyber operations squares with those statements is its control architecture: every operation is "exclusively conducted on behalf of and under the supervision of the Federal Government" (Sec. 2(a)(i)). Whether that distinction holds in practice is one of the things the next year will show.
The bottom line
The memorandum is a significant structural change in how the United States brings private-sector capability into the fight against cybercrime, and it is built with unusual care around the concept that has always governed this space: authorization. It changes nothing, for better or worse, about the legal standing of security researchers acting in good faith without a program behind them. The gap between how thoroughly this memo engineers legal safety for authorized offense and how thin the equivalent infrastructure remains for good-faith research is, for us, the headline.
We will keep tracking the 60-day implementation guidance and what, if anything, becomes publicly visible about the Program's operation.
Primary sources: the memorandum text (whitehouse.gov, August 12, 2026); 18 U.S.C. § 1030; the DOJ CFAA charging policy announcement (May 19, 2022) and Justice Manual § 9-48.000; EO 14159 and EO 14390 (Federal Register). Section citations throughout refer to the memorandum.