“Every available tool” should be deployed against transnational cyber threats, the White House said as it authorized a new public‑private program to disrupt foreign cyber actors targeting the United States.
What the National Security Presidential Memorandum authorizes
The National Security Presidential Memorandum (NSPM), signed by President Donald Trump on August 12, directs federal law enforcement to collaborate with private firms in conducting offensive cyber strikes on foreign threat actors targeting the U.S. The NSPM builds on an Executive Order released in March that directed government agencies to take “rigorous actions” to combat cyber‑enabled crime targeting Americans.
The memorandum explicitly says private sector capabilities have “historically been underutilized” and establishes a framework to enable companies that wish to participate to enter into agreements with other firms as well as federal, state and local government bodies to gather threat intelligence and propose cyber operations designed to disrupt transnational cybercrime groups.
Operational oversight: the NCC and two executive directors
Operational oversight will be handled by the Homeland Security Task Force’s National Coordination Center (NCC), which the NSPM tasks with setting up a program to oversee these operations. That program will be headed by two Executive Directors from the Department of Justice and the Department of Homeland Security.
The memorandum says “rigorous procedures” will be established for the review and conduct of “limited” cyber operations and emphasizes such operations will only be conducted under the direction of the U.S. government. It adds the program will ensure it complies with the U.S. Constitution and laws, as well as relevant international agreements.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadPrivate‑sector role and the limits the memorandum describes
Under the NSPM, participation by private companies is voluntary and structured through agreements with other private firms and government bodies. Companies can collect threat intelligence and propose operations intended to disrupt criminal networks in cyberspace, but actual offensive actions are to be carried out under government direction and within the “limited” scope the memorandum prescribes.
The White House framed the change as a response to economic harm: it cited figures showing American consumers reported losing more than $20.8bn to cyber‑enabled crime in 2025, and that 73% of U.S. adults have experienced some kind of online scam or attack.
Reactions from cybersecurity professionals and researchers
Responses in the security community were divided. Chris Wysopal, co‑founder at Veracode, described the policy on X as a “big shift” and wrote, “Not exactly ‘hack back,’ but definitely a major expansion of the private sector’s role in offensive cyber operations.”
Nick Carr, technical director for the Microsoft Threat Intelligence Center (MSTIC) team and former chief technical analyst at the Cybersecurity and Infrastructure Security Agency (CISA), warned about attribution challenges. On X he wrote that attribution in criminal operations is difficult and that “few organizations can repeatably do it right (including certain gov agencies). People are regularly and willingly wrong on pretty important incidents,” adding that such issues could be mitigated by the program’s design to ensure improved attribution work.
Independent researcher Dr Lukasz Olejnik cautioned that a “license to destroy cyber‑controlled infrastructure” could impact state‑linked systems and raise the risk of interstate escalation and conflict. The memo’s approach was compared to the U.K. model: the U.K. created the National Cyber Force (NCF) in 2020 and in 2023 published principles stating it would rarely deploy such capabilities where other responses are better suited.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: expect closer coordination opportunities with government authorities to share threat intelligence and to propose operational responses, alongside heightened scrutiny of attribution work, which experts say is hard to do reliably.
- Policymakers and regulators: the NSPM institutionalizes a government‑directed, public‑private offensive program and places explicit responsibility on the NCC and two Executive Directors from DOJ and DHS to establish “rigorous procedures” and ensure compliance with the U.S. Constitution, laws, and international agreements.
- Affected enterprises and procurement leaders: the memorandum frames expanded offensive collaboration as a response to large consumer and corporate losses — $20.8bn reported in 2025 — creating a potential pathway for private firms to participate under government direction while facing concerns over legal exposure and the risk of misattribution or escalation.
The NSPM creates the first clear U.S. framework to let private companies help propose—and in tightly defined circumstances enable—the execution of offensive cyber actions under government direction. The immediate task set by the memorandum is procedural: the NCC must build the program and the two Executive Directors must design the “rigorous procedures” that proponents and critics alike say will determine whether the policy reduces harm or increases risk.




