"The United States has had enough in cyberspace."
The White House has created a new program that authorises some American companies to conduct offensive cyber operations against ransomware gangs and other "cyber-enabled transnational criminal organizations." The plan is explicit: government policymakers will not simply outsource vigilantism, they will create an institutional framework that vets firms, retains operational control, and expects reporting and accountability.
White House program: authorised private offensive cyber operations
The program authorises a small number of vetted companies to carry out disruptive activities aimed at criminal groups. The source emphasises these actions are not intended as quick "hacking back" strikes but as "longer term surveillance and disruption to frustrate their operations." Companies chosen for the program will be contracted and overseen by co-executive directors drawn from the departments of Justice and Homeland Security, who "will vet and contract with companies and approve and retain operational control of their activities." Participating firms must report their activities and can be removed from the program if they fail to meet standards.
Operational design and the centrality of oversight
The design deliberately binds private action to public control. That institutional layer — contracts, vetting, retained operational control and reporting — is presented as the White House's attempt to avoid simple privateering. But the article warns the devil is "truly in the details," echoing the observation attributed to the author's colleague Erica Lonergan: implementation will determine whether the experiment delivers relief or chaos.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleImplementation risks: staffing, compliance, and a weakened bureaucracy
Implementation is not just technical; it is bureaucratic. The piece foregrounds three government weaknesses: "the Department of Justice is removing staff seen as enemies of the president; the Department of Homeland Security (DHS) is obsessed with border security; while DHS’s Cybersecurity and Infrastructure Security Agency has been drained of talent." It also cautions against capture by the authorised companies themselves: "the US Congress must commit to reporting and oversight to ensure these authorised cyber companies — many of which will be staffed with veterans of the same organisations meant to oversee them — cannot capture their ostensible regulators." The author further warns the program will be hard for "any government, much less one so thoroughly DOGEd and short of quality staff."
Adversaries, legal exposure, and sanctuary
The argument for moving to offensive disruption is grounded in how criminal groups operate: they "operate with near impunity, often given sanctuary by Russia, Iran and China, and are unafraid of prosecution," and they target "the most vulnerable among us, attacking schools and hospitals during a pandemic." The author rejects escalation fears as a primary objection but highlights personal legal risk for operators. As Jake Williams and others have pointed out, "anyone conducting these operations is doing so at substantial personal legal risk." The United States may choose not to prosecute participants, but that would not prevent "Russia or China issuing an Interpol Red Notice or an EU prosecutor issuing arrest warrants when some mission impinges on EU sovereignty."
What this means for Britain, Australia, and the US Congress
- Britain and Australia: The piece suggests other Five Eyes members "may actually be better positioned to conduct these experiments in authorised private offensive cyber operations than the US is," implying allies should observe, prepare, and possibly test similar frameworks.
- The US Congress: Lawmakers are urged to "commit to reporting and oversight" so that the authorised companies cannot "capture their ostensible regulators" and to insist on clear criteria to measure success and failure.
- Policymakers broadly: The White House must "set out criteria to measure both success and failure" and be prepared to cancel the program if it "gets out of control or is not clearly succeeding." Without such metrics, supporters could continually extend the program on the claim of near-victory — a pattern the author compares to failed long wars and an earlier Pentagon plan.
The author is candid about limits. Relying on offence is "not a long-term plan" because defenders cannot "counterattack their way to a more secure cyberspace." Still, the judgment rendered is conditional: "offence might meaningfully reduce depredations in the short term" — and therefore a "controlled, well-overseen plan to disrupt cybercriminals' attacks is an experiment worth trying." The test will turn on whether the White House can translate institutional intent into strict oversight, clear metrics, and the willingness to stop the experiment if it fails.



