President Donald Trump has implemented a new policy that permits private companies to engage in government-led cyber operations aimed at foreign cybercriminals. This memorandum targets cyber-enabled transnational criminal organizations (CE-TCOs) responsible for illicit online activities affecting American individuals and businesses.
Role of the National Coordination Center
The National Coordination Center (NCC) has been tasked with establishing and overseeing this initiative. Companies participating in the program will conduct cyber surveillance and effects operations, but these actions will be strictly regulated and supervised by the federal government.
The joint oversight by the Department of Justice and the Department of Homeland Security ensures that these operations are thoroughly monitored. Cyber surveillance operations, defined as covert intelligence collection activities, are intended to gather crucial data from various digital systems without detection.
Cyber Effects and Legal Boundaries
Cyber effects operations, which are more proactive, involve manipulating or disrupting systems and networks. However, the memorandum mandates that operations causing severe harm or resembling acts of war must not be approved by executive directors. The initiative does not endorse unauthorized hack-back activities by private companies.
All operations require thorough review and written consent from the government before execution. Companies will operate under the legal authority of the government and must coordinate with federal and international agencies involved in foreign policy and defense.
Participation Requirements and Oversight
Companies interested in participating must secure contracts with either the Justice Department or Homeland Security. They will undergo comprehensive vetting processes, including technical, security, and personnel assessments. Both large and small firms can engage in specialized tasks under this program.
Participants must disclose any commercial affiliations and may need to post a bond or escrow, potentially forfeited for non-compliance. If a U.S. entity is inadvertently targeted, operations must cease immediately, and data collection minimized, with the NCC notified promptly.
The memorandum requires the program’s executive directors to develop operating procedures within 60 days and report on the program’s progress within 180 days, continuing annually. This initiative might streamline the exchange of threat intelligence and facilitate government-supervised countermeasures against criminal infrastructures.
For cybersecurity teams, this policy could pave the way for a structured collaboration with the government in addressing cyber threats. However, its effectiveness will largely depend on the classified protocols, legal assessments, and the selection of participating companies.
