The memorandum’s core directive: a federal‑run program for Participating Companies
The memorandum orders a federal coordination center to “create, manage, and maintain a Program to authorize Participating Companies … to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber‑Enabled Transnational Criminal Organizations (CE‑TCOs), under the control and oversight of the Federal Government.” The document frames those private operations as components “part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement.”
Participating companies will be expected to propose cyber operations to the coordination center after working with federal, state and local governments to identify threats. The program, the memo says, will be run under federal control and oversight and will include requirements for regular reporting to federal officials.
Contracts, vetting, and threat sharing: how the private sector plugs in
Under the memorandum, companies must sign contracts with either the Department of Justice or the Department of Homeland Security and “undergo rigorous vetting” before they can join the program. The memo also allows participating companies to enter commercial agreements with other private‑sector entities to receive threat information — creating a formal path for information flows between government partners and private cyber vendors.
The program language explicitly calls for technical proficiency reviews and includes provisions to ensure both small and large companies can participate, according to the text.

Your town's IT department is one person. Maybe.
Ransomware crews target small municipalities because nobody's watching. Nubivance gives Maine and New Hampshire towns a security program sized to a town budget.
Protect the town officeLegal constraints: the Computer Fraud and Abuse Act remains in force
The memorandum instructs that the program must adhere to existing laws, explicitly including the Computer Fraud and Abuse Act. That adherence contrasts with earlier proposals that would have amended that statute to clear or expand private sector offensive activity; the memo keeps the current legal framework in place while authorizing a government‑controlled program.
The White House justified the memo by citing “sustained fraud and other cyber‑enabled campaigns from transnational criminal organizations,” and described a fraud‑focused executive order from March as “only the first step.”
Responses from cyber professionals: cheer, caution, and criticism
Reaction among former officials and security pioneers was mixed. Jason Kitka, a former Cyber Command official, posted on social media that the memorandum amounted to “a perpetual motion machine for billable threats.” By contrast, Josh Steinman, described in the memo’s coverage as a former top White House cyber official during Trump’s first term and a Galvanick co‑founder, “cheered the development.”
Cyber pioneer Chris Wysopal, now co‑founder of Veracode, called the memo “a pretty big shift in US cyber policy” while noting it stopped short of some other “hack back” proposals. The coverage also notes longstanding industry condemnation of “hack back” legislative proposals and broader concern in cyber circles that broad private participation in offensive operations could set dangerous precedents.
Political and historical echoes: letters of marque and a policy pivot
The memorandum arrives amid conversations — “in recent years” according to the White House account — in some conservative circles about authorizing “letters of marque” for private‑sector cyber firms, an analogy drawn to early U.S. sea privateers. The memo represents a different path: not unregulated privateering, but a government‑managed program that explicitly ties private offensive action to federal investigatory, protective, or intelligence goals.
What this means for private cyber firms, federal law enforcement, and CE‑TCOs
- Private cyber firms: Companies seeking to participate will need to secure contracts with DOJ or DHS, pass rigorous vetting and technical proficiency evaluations, and agree to regular federal reporting — creating both commercial opportunity and compliance obligations.
- Federal law enforcement and the coordination center: Agencies will inherit responsibility for designing and operating the Program, vetting participants, and ensuring activities remain within existing laws; the memorandum makes the coordination center the central manager of private‑sector offensive work.
- Cyber‑Enabled Transnational Criminal Organizations (CE‑TCOs): The government frames the program as an expansion of the fight against sustained fraud and other cyber‑enabled campaigns by CE‑TCOs, signaling an intent to use private expertise under federal control to disrupt those operations.
The memorandum is explicit about intent and process: use private ingenuity, but do it under federal contracts, vetting, and legal constraints. The immediate, concrete task ahead is implementation — the federal coordination center must now build the Program, evaluate technical standards, and set oversight and reporting mechanisms. How those rules are written, how rigorously vendors are vetted, and how reporting and oversight are enforced will determine whether the memo becomes a tightly controlled extension of law enforcement capability or a flashpoint in the debate over private offensive cyber operations.
https://cyberscoop.com/trump-memo-private-sector-offensive-hacking/




