New Presidential Memorandum Expands Private Sector Role in Fighting Cybercrime
On August 12, 2026, the White House released a National Security Presidential Memorandum titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.” The memorandum marks a deliberate shift in how the United States approaches foreign cyber-enabled transnational criminal organizations (CE-TCOs) — the ransomware crews, scam networks, fraud rings, and other predatory groups that target American citizens, businesses, and interests from overseas.
For years, the private sector’s technical depth, speed, and scale have been recognized as a unique national advantage in cyberspace. This memorandum creates a formal, government-controlled pathway to put those capabilities to work against criminal networks that have historically operated with relative freedom beyond traditional law-enforcement reach.
What the Memorandum Actually Does
Building on Executive Order 14390 (March 6, 2026) on combating cybercrime and fraud, the memorandum directs the National Coordination Center (NCC) — part of the Homeland Security Task Force — to establish and manage a new Program. Under this Program, rigorously vetted U.S. private-sector companies (“Participating Companies”) may be authorized to conduct two categories of activity against foreign CE-TCOs:
Cyber Surveillance Operations — accessing systems without authorization (or exceeding authorized access) primarily to collect intelligence, with the intent to remain undetected.
Cyber Effects Operations — actions that manipulate, disrupt, deny, degrade, or destroy information systems, networks, or data.
These operations occur exclusively under the control, supervision, and legal authorities of the federal government. Oversight is shared by co-Executive Directors from the Department of Justice and the Department of Homeland Security. They must coordinate before approving most operations; any activity that could produce “Critical Outcomes” (loss of life or serious injury, or rising to the level of use of force or armed attack under international law) faces additional restrictions.
Participating Companies must enter contractual agreements with DOJ or DHS, undergo rigorous vetting (technical proficiency, proven operational performance, facility security, personnel screening, and more), and maintain a bond or escrow of at least $1 million. The memorandum explicitly encourages both large firms (for capacity) and smaller, more agile companies (for specialized tasks). Companies may also form commercial agreements to receive threat information from other private entities or government agencies and use that intelligence to propose responsive operations to the NCC.
Detailed operating procedures — covering eligibility, deconfliction, reporting, minimization if U.S. persons or systems are implicated, annual reviews, and more — are required within 60 days. All activity must comply with the Constitution, federal law, and applicable international obligations.
Why This Matters
Transnational criminal organizations continue to inflict significant harm through ransomware, large-scale fraud, phishing, and other cyber-enabled schemes. The private sector has long possessed advanced tools and talent that could help disrupt these networks at the source. Until now, legal, liability, and policy barriers limited how far most companies could go in an offensive capacity on behalf of the government.
This memorandum changes the equation. It creates a structured, overseen channel for vetted firms to contribute directly to government-directed operations against foreign CE-TCOs while remaining under federal control and legal cover. It also reinforces that companies retain the ability to conduct their own lawful defensive operations outside the Program.
For cybersecurity companies that already invest heavily in threat intelligence, operational capability, and defensive excellence, the memorandum opens a new avenue to support national efforts against the criminal groups that prey on American organizations and individuals.
Cyber Misfits’ Perspective
At Cyber Misfits, we have always believed that defending against sophisticated adversaries requires more than reactive tools — it requires deep understanding, technical excellence, and a willingness to innovate within clear legal and ethical boundaries. We welcome the recognition that private-sector capability is a strategic asset in the fight against transnational cybercrime.
We are carefully reviewing the memorandum and will closely follow the forthcoming operating procedures. Our team is prepared to evaluate how Cyber Misfits can responsibly contribute should the opportunity arise under this new framework. Any participation would, of course, be conducted strictly under the oversight and authority of the U.S. Government and in full compliance with all applicable laws.
In the meantime, our core mission remains unchanged: helping organizations stay ahead of evolving threats through high-quality defensive capabilities, threat intelligence, and practical security outcomes.
We encourage industry peers, partners, and clients to read the full memorandum for themselves: Expanding Capabilities to Combat Transnational Cyber-Enabled Crime
If you have questions about how this development may affect your organization or would like to discuss Cyber Misfits’ approach to the evolving threat landscape, we are always open to conversation.
— The Cyber Misfits Team