That definition — written into a presidential memo signed on Wednesday — sets the target for a new United States program that will allow government agencies to contract private cybersecurity firms to carry out operations against what the memo calls cyber-enabled transnational criminal organizations, or CE-TCOs. The document lays out permissions for both covert surveillance and what it calls "Cyber Effects Operations," marking a substantial change in who may be authorised to touch adversary networks on behalf of the U.S. government.
President Trump's memo and the target: CE-TCOs, not nation-states
The memo authorises participating companies to "support national operations against criminals," explicitly naming cyber surveillance and technical disruptions as potential tasks. It defines CE-TCOs as "any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests," and expressly excludes "entities directly associated with, or operating wholly on behalf of, foreign governments." The policy therefore distinguishes private criminal groups from actors acting as instruments of states.
What "Cyber Effects Operations" and surveillance look like in the memo
The memo defines "Cyber Effects Operations" as activities that cause "the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon." It also draws a distinction between those effects operations and cyber surveillance missions, while acknowledging that surveillance will "inevitably involve some disruption or manipulation of systems" in order to collect intelligence. Surveillance, the document says, is intended for intelligence-gathering — either to support further snooping or for later use in cyber effects operations — and is to be carried out with the intent of remaining undetected.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleOperational guardrails: vetting, procedures, bonds, and prohibitions
The memo requires that participating companies undergo "rigorous vetting" and operate under "strict operational procedures." Those procedures are to be written within 60 days and codified by program executive directors working with the Homeland Security Council. Companies must show they have the technical capabilities needed for assigned work and must re-prove that capability each year through annual evaluations. Program managers are ordered to design procedures that allow both "highly resourced, large organizations" and "smaller, more agile companies" to participate.
There are concrete limits. Participating companies are barred from executing operations that could lead to "critical outcomes" — described in the memo as attacks that result in loss of life or serious injury, or those that could be characterised as an armed attack under international law. The Justice Department will have a role in authorising operations that target U.S. residents or raise domestic legal issues. Firms must also maintain a bond or escrow of at least $1 million, which the memo states "shall be forfeited" if they violate contract terms.
Legal issues: CFAA, exemptions, and competing analyses from law firms and think tanks
The policy has prompted a sharp legal debate. Earlier coverage and analyses cited in the memo's rollout noted concerns that the Computer Fraud and Abuse Act (CFAA) could impede private-sector participation unless the law or enforcement practice changed. Gareth Mott, writing for the Royal United Services Institute (RUSI), suggested the CFAA "might need to be amended" for U.S. companies to offer such services. Lawyers at Skadden, Arps, Slate, Meagher & Flom wrote that "any attempt to more directly involve the private sector in offensive cyber actions will likely require further legal and regulatory changes before it can be meaningfully implemented," and warned that civil penalties under the CFAA and its five-year statute of limitations could blunt executive incentives.
By contrast, Jenner & Block pointed to Title 18, § 1030(f) of the U.S. Code, which says the CFAA "does not prohibit lawfully authorized investigative, protective, or intelligence activity by a US government agency or intelligence agency." Jenner & Block’s analysis cautioned that "No court has addressed whether this exception provides any protection for private-sector entities engaged to perform these activities on behalf of the US government and, if so, under what circumstances," and concluded: "At the very least, it is unlikely that a court would interpret this provision to extend to private companies engaged in independent offensive operations, without government direction or involvement." The memo’s emphasis on government-drawn procedures and direction is presented in the source as the hinge that might bring contractor activity within that statutory exemption.
How technologists, policymakers, and participating companies will respond
- Technologists and security teams will watch the operational procedures that must be produced within 60 days for details about permitted techniques, the threshold for "disruption," and the boundaries between surveillance and effects operations.
- Policymakers and regulators — including the Justice Department, which has an explicit authorisation role for U.S. resident-targeted activity — will focus on the legal framing, whether enforcement guidance or statutory changes are necessary, and how the CFAA's exemptions will be applied.
- Companies that seek to be called up must demonstrate technical capability annually and post a minimum $1 million bond or escrow; they will need to weigh business and legal risk in light of divergent law-firm analyses cited in the rollout.
The administration framed the wider intent in March when it published "President Trump's Cyber Strategy for America," promising to "unleash the private sector by creating incentives to identify and disrupt adversary networks and scale our national capabilities." The strategy added: "We will leverage the immense talents and ingenuity of our private sector research base" and "We will establish a new level of relationship between the public and private sectors to defend America in peace and war." For now, the next concrete steps are the drafting of operational procedures within 60 days and the practical tests of whether the DOJ authorisations and the CFAA exemption, as interpreted by courts, will permit the program to operate as described.
Source: The Register — Trump wants to grant private cyber firms a license to hack back




