U.S. consumers reported losing more than $20.8 billion to cyber-enabled crime in 2025.
The new authority: a presidential memorandum and the National Coordination Center
A national security presidential memorandum (NSPM) signed on Wednesday by U.S. President Donald Trump directs the National Coordination Center (NCC) — described in the memo as part of the Homeland Security Task Force — to stand up a program that would allow private security companies to apply for approval to conduct cyber operations against foreign transnational criminal organizations. A fact sheet published yesterday says the NSPM “enables the NCC … to leverage the U.S. private sector's capabilities to conduct cyber operations targeting transnational criminal organizations under the control and authority of the U.S. Government.”
Scope and stated targets: ransomware, phishing, fraud and more
The White House framed the program as intended “to disrupt foreign criminal organizations involved in ransomware attacks, phishing campaigns, financial fraud, sextortion schemes and impersonation scams.” The memorandum encourages participating private firms to “enter into agreements with other private entities as well Federal, State, Local, Tribal, and Territorial agencies to gather TCO threat information and propose cyber operations that address those threats.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleOversight, legal constraints, and the next procedural step
Oversight will be administered by executive directors designated by the Justice and Homeland Security departments, according to the fact sheet. The NSPM “directs the Program's Executive Directors and the Homeland Security Council to create rigorous procedures for the review and conduct of these limited cyber operations at the direction of the U.S. Government, ensuring strict compliance with the U.S. Constitution and laws, as well as applicable international agreements.”
The memorandum explicitly requires procedures to ensure operations comply with the U.S. Constitution, federal law, and U.S. international obligations. Participating companies are required to immediately stop operations and notify the National Coordination Center if they discover activity that exceeds approved limits, “including unintended targeting of U.S. citizens or U.S.-based systems.”
Contracting, financial guarantees, and vetting for private firms
Security firms that wish to participate will be vetted before entering into contracts with either the Justice Department or the Department of Homeland Security, the fact sheet says. Companies must maintain a bond or escrow of at least $1 million that “will be forfeited if they don't comply with the contractual agreements.” Those financial and vetting requirements are written into the memorandum as conditions for program participation.
Voices on the policy shift and what defenders see
Industry reaction in the source material was immediate and pointed. Veracode co‑founder Chris Wysopal described the memo as “a pretty big shift in US cyber policy” and “a major expansion of the private sector's role in offensive cyber operations.” Jason Kikta, identified as a former Cyber National Mission Force (CNMF) leader and Automox CTO, characterized it as “a perpetual motion machine for billable threats.”
Separately, a cited assessment called The Blue Report 2026 is referenced in the source material as measuring defenses “technique by technique across 338 million simulations run in customer production environments.” That material includes the observation that “Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply,” a finding defenders will note when weighing both risk and the potential effectiveness of offensive measures.
What this means for technologists, policymakers, and the public
- Technologists and security teams: Private security companies may be able to propose and conduct government‑authorized operations, but any firm that participates must pass vetting, place at least a $1 million bond or escrow, and stop and report immediately if an operation exceeds approved limits, including unintended hits on U.S. persons or U.S. systems.
- Policymakers and regulators: The NSPM assigns oversight to executive directors appointed by the Justice and Homeland Security departments and directs the Program's Executive Directors and the Homeland Security Council to write “rigorous procedures” that must ensure compliance with the Constitution, federal law, and international agreements.
- End users and the general public: The White House presents the program as aimed at disrupting criminals behind ransomware, phishing, financial fraud, sextortion, and impersonation scams — threats the administration linked to the $20.8 billion in consumer losses reported for 2025.
The memorandum lays out a clear architecture — private firms, government vetting and contracts, legal guardrails, and financial penalties — and assigns the practical work to the Program's Executive Directors and the Homeland Security Council to codify procedures. That task is the concrete next step named in the NSPM; how those procedures read, how strictly they are enforced, and how rapidly companies are vetted and contracted will determine whether the program becomes a scaled tool against criminal cyber actors or a debated expansion of private‑sector offensive activity. The record in the fact sheet closes on that administrative handoff and the safeguards the White House says will constrain the effort.
Source: BleepingComputer — White House taps security firms for offensive hack-back operations




