The Legal, Strategic, and Operational Risks of Privatized Offensive Cyber Operations
Why a CISO Should Care
On August 12, 2026, the White House published a Presidential Memorandum titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.” The document authorizes a program under which vetted private U.S. companies will conduct offensive cyber operations against foreign criminal organizations, under contract to the Department of Justice and the Department of Homeland Security. The program runs through the National Coordination Center established by Executive Order 14159, an immigration enforcement order from January 2025.
Most CISOs will read a headline about fighting cybercrime and move on. That would be a mistake. This memorandum changes the threat model for every company in the U.S. defense industrial base, every critical infrastructure operator, and every organization whose supply chain touches American cybersecurity vendors. It creates a class of supply chain risk that existing frameworks cannot assess, cannot measure, and cannot mitigate through contractual controls. Your vendor might be a Participating Company. Your vendor’s vendor might be. You will not know, because the program’s design forbids disclosure. And if one of those vendors conducts an operation that provokes retaliatory action from a foreign state or state-tolerated criminal organization, the blast radius extends through shared infrastructure, shared cloud tenants, and shared network adjacency into your environment.
A Legal Construction That Stops at the Border
The memorandum frames the entire program as law enforcement. The operations are described as “part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement.” The oversight runs through DOJ and DHS. The legal hook is 18 U.S.C. 1030, the Computer Fraud and Abuse Act. Every structural choice routes the program through law enforcement authorities rather than military (Title 10) or intelligence (Title 50) channels.
That framing does real work domestically. It keeps the program out of the congressional notification requirements that govern military cyber operations and covert action. It avoids the oversight architecture that Congress built into Title 10 and Title 50 specifically to provide accountability for the use of force abroad. It lets the executive branch run offensive operations against foreign targets through contracts rather than commands, through NCC approvals rather than CYBERCOM targeting cycles, and through DOJ review rather than JAG legal opinions.
The framing stops working the moment it crosses the border. Foreign governments do not distinguish between a U.S. law enforcement cyber operation and a U.S. military cyber operation. If an American private company degrades, disrupts, or destroys information systems inside Russia, China, Iran, or any other sovereign state, that state will respond based on the effect, not the legal theory behind it. The label “law enforcement” is an American domestic legal construction. It carries no weight in Moscow, Beijing, or Tehran. It carries limited weight in London, Berlin, or Tokyo.
The United States has spent years at the United Nations Group of Governmental Experts and the Open-Ended Working Group arguing that civilian infrastructure should be protected from state cyber operations. The U.S. position rests on the distinction between military and civilian, between state and non-state, between legitimate targets and protected infrastructure. This memorandum converts American civilian companies into instruments of state coercive power. It does not merely undermine the U.S. negotiating position on norms. It invalidates it.
Allied nations face their own legal complications. The EU’s NIS2 Directive, the UK’s Computer Misuse Act, and comparable frameworks in allied states all criminalize unauthorized access to information systems. A U.S. company operating under this program that conducts operations transiting allied infrastructure has potentially committed criminal offenses in those jurisdictions. The U.S. government’s domestic authorization provides no shield against foreign prosecution. It does not provide sovereign immunity to the company. The classified annex may address deconfliction with allies, but the public document is silent.
The Memorandum: Structure and Legal Fault Lines
The memorandum builds on Executive Order 14390 of March 6, 2026, which directed the federal government to combat cyber-enabled crime and created an operational cell within the NCC. The memorandum extends that framework by authorizing Participating Companies to conduct two categories of operations: Cyber Surveillance Operations (persistent covert access to foreign systems for intelligence collection) and Cyber Effects Operations (manipulation, disruption, denial, degradation, or destruction of foreign information systems and infrastructure).
The program is overseen by co-Executive Directors, one from DOJ and one from DHS, who must jointly approve each operation in writing. Operations likely to produce “Critical Outcomes,” defined as loss of life, serious injury, or use of force under international law, cannot be approved at the Executive Director level and presumably escalate through channels defined in a classified annex. Participating Companies must meet vetting standards, maintain at least a $1 million bond, and disclose their commercial relationships to the NCC.
The CFAA tension is immediate. Section 2(b) states the program must comply with 18 U.S.C. 1030. But the definition of Cyber Surveillance Operations in Section 4(d) explicitly describes accessing systems “without authorization from the owner or operator or by exceeding authorized access.” That is the statutory language CFAA uses to define criminal conduct. The legal theory is that government authorization under lawful investigatory authorities provides the basis, but that theory has never been tested at this scale, and any federal court could reject it.
The targeting presumption in Section 4(c) inverts the expected burden. A foreign group is presumed not to be part of a foreign government “unless clear intelligence exists establishing such connection.” Given the blurred lines between state-tolerated and state-directed cyber actors in Russia, China, and Iran, this presumption increases the probability that operations will engage state-connected targets without anyone realizing it until after the effects are delivered.
The most important controls are not in the public document. Sections 3(a)(v) and 3(a)(vi) defer the operational workflow and the adjudicatory framework for target validation to a classified annex. No congressional notification requirement appears in the memorandum. No Inspector General review is mandated. The 180-day status report goes to the Homeland Security Advisor and the National Cyber Director, both executive branch officials. The oversight loop closes inside the branch that created the program.
The Fourth Amendment provision in Section 3(a)(ix) requires DOJ review for operations involving U.S. persons. But cyber operations frequently touch U.S. person data or U.S. systems without advance knowledge. Section 3(a)(x) addresses this with a cleanup procedure: cease, minimize, notify. The sequence is act, discover the problem, stop. That is not prior authorization. It is incident response.
A drafting note: the memorandum addresses the “Secretary of War,” reflecting the administration’s rebranding of the Department of Defense. Whether that renaming was accomplished by statute or only by executive action matters. If the underlying U.S. Code still says “Secretary of Defense,” these documents are addressed to a position that may not legally exist under the name used. The fact sheet describes the document as an “NSPM” but the text carries no NSPM number, which complicates citation.
The Privateer Debate: Tanji and Those Who Followed
Michael Tanji wrote the foundational piece in this debate. Buccaneer.Com: Infosec Privateering as a Solution to Cyberspace Threats appeared in the Journal of Cyber Conflict Studies, Volume 1, Number 1, in 2007. Tanji, a former DIA division chief who had worked information warfare and computer network operations, drew a direct analogy between the ungoverned cyberspace of the early 2000s and the loosely governed seas of the 17th century. He argued that the private sector possessed offensive capabilities the government could leverage, much as maritime powers had leveraged privateers to extend their reach beyond the capacity of standing navies.
Tanji’s argument was grounded in institutional experience. He had served in Army Intelligence, worked signals intelligence and information warfare at DIA, managed the DoD’s cyber threat intelligence warning system, and contributed to projects for the National Intelligence Council, National Security Council, and NATO. When he proposed privateering as a cyber policy option, he did so from inside the framework that governs the use of force: LOAC training, targeting discipline, rules of engagement, command authority. His analogy carried implicit conditions that his career had taught him were non-negotiable.
The idea gathered academic attention over the following decade. Florian Egloff published Cybersecurity and the Age of Privateering in the Carnegie Endowment’s Understanding Cyber Conflict volume in 2017. Egloff’s analysis was cautionary. Writing on Lawfare in 2016, he identified three risks: unnecessary escalation, the potential for reprisal, and the establishment of an international norm strategically undesirable for the United States. He noted that historical letters of marque authorized attacks against broad categories of targets based on nationality, not the surgical targeting modern advocates imagined. Dave Aitel advocated the opposite position on Lawfare that same year, arguing for resurrecting privateering in cyberspace. In 2019, the U.S. Naval Institute’s Proceedings published an argument for cyber letters of marque tied to the Active Cyber Defense Certainty Act, noting that War of 1812 privateers operated under letters that imposed specific operational restrictions and that violation meant reparations.
Ronald Deibert of the Citizen Lab published the most comprehensive opposing analysis in April 2026 on Lawfare, titled The Perils of Privatized Cyberwarfare. Deibert argued that privatized offensive cyber would complicate oversight, empower the mercenary spyware industry, create counterintelligence risks, fuel an arms race, and put civilians at risk. He drew on fifteen years of Citizen Lab research tracking the mercenary spyware industry and its abuses, and raised a point that deserves its own treatment here: the zero-day problem. Participating Companies conducting offensive operations will discover vulnerabilities in widely used systems. Their incentive is to hoard those vulnerabilities for future operations rather than disclose them through the Vulnerabilities Equities Process. Every hoarded zero-day is an unpatched flaw in systems used by billions of people, including the defense industrial base companies this essay is written for. The program designed to fight cybercrime makes everyone’s attack surface worse.
The Aspen Digital program weighed in with Old Tools, New Problems in May 2026, tracing the privateer analogy from the War of 1812 through the post-9/11 period to the present and concluding that privatized cyber retaliation undermines U.S. sovereignty, stability, and national security.
Representative David Schweikert of Arizona introduced H.R. 4988, the Scam Farms Marque and Reprisal Authorization Act of 2025, in August 2025. The bill explicitly invoked Article I, Section 8, Clause 11 of the Constitution and routed the authority through the constitutionally designated branch. It required a security bond and defined scope. That bill was referred to the House Foreign Affairs Committee and has not advanced. The NSPM arrives at the same functional destination but through the executive branch alone. The constitutional path was available. A bill was pending. The administration chose a different route.
Low-Intensity Conflict by Contract
My doctoral dissertation at Purdue examined cyberwarfare as a form of low-intensity conflict. The core argument was that cyber operations occupy a gray zone between peace and war, that they are conducted below the threshold of armed conflict, and that the existing legal and institutional frameworks designed for conventional warfare do not map cleanly onto them. The intervening years have confirmed that thesis more thoroughly than I would have preferred.
I have an entire unpublished book on cyberwarfare doctrine from this perspective if anybody is interested.
This memorandum is a case study in the gray zone problem. The program targets criminal organizations, not state militaries. It authorizes effects below the threshold of armed conflict as defined by international law. It operates in the space between law enforcement and warfare where neither framework applies cleanly and both claim jurisdiction. The law enforcement label keeps LOAC out. The offensive effects keep ordinary criminal procedure out. What remains is a gap, and the program lives inside it.
The operators who conduct these operations will not train on LOAC because the framework tells them it does not apply. They will not think about distinction, proportionality, military necessity, or humanity because nobody in the law enforcement contracting chain told them to. But the effects they produce, degradation, disruption, destruction of foreign information systems and the physical infrastructure those systems control, are military effects by any functional definition. When CYBERCOM produces those effects, a JAG is in the room. When a Participating Company produces them, a contract manager is in the room. The effects at the other end are identical. The discipline behind them is not.
Tanji understood this. His career spanned the line between intelligence and operations, and he knew that the capability cannot be separated from the discipline that governs its use. The NSPM takes the capability and discards the discipline by routing it through a framework, law enforcement contracting, that was never designed to govern the use of coercive force against foreign targets.
The Chartered Company Problem
The privateer analogy captures part of the historical pattern but not all of it. The closer analog may be the chartered trading company. The British East India Company began as a commercial venture with a royal charter granting monopoly trade rights. Over two centuries it acquired its own army, navy, and diplomatic corps, and the authority to wage war, collect taxes, and administer justice across a subcontinent. It operated under nominal Crown oversight, but the distance between London and Calcutta, combined with the company’s profit motive and the Crown’s dependence on the revenue the company generated, meant that oversight was theoretical more often than actual. When the company’s conduct provoked the Indian Rebellion of 1857, the Crown dissolved it and assumed direct control. By then, two centuries of delegated violence had reshaped the map.
The pattern is consistent across centuries and domains. When a state delegates coercive power to a commercial entity, the commercial entity’s interests gradually supplant the state’s interests as the operational driver. The company that starts as an instrument of state policy becomes an autonomous actor pursuing its own objectives under the cover of state authority. The oversight mechanisms described as rigorous at the outset always prove inadequate over time, because the entity being overseen has stronger incentives and better information than the entity doing the oversight. The NSPM’s $1 million bond is a licensing fee. The annual review in Section 3(a)(xiii) is a checkbox. The real question is what happens when a Participating Company conducts an operation that provokes an international incident, and the answer in this memorandum is that the NCC gets notified, DOJ gets notified, and the classified annex takes over.
This Is Not Blackwater
PMCs operated in recognized conflict zones, under at least nominal military command structures, within the framework of the law of armed conflict. They still produced Nisour Square. They still created escalation the government could not control and accountability gaps the legal system struggled to close for years. The UCMJ did not apply to them. Iraqi law was unenforceable against them. The Military Extraterritorial Jurisdiction Act of 2000 provided theoretical criminal jurisdiction that was rarely exercised.
Cyber privatization is worse on every dimension that made PMCs problematic. PMCs operated in defined geographic spaces with some physical accountability. Their personnel were present in country, visible to military chain of command. Cyber operators sit in offices in Virginia or Colorado. They are physically unreachable by the states they are targeting, which reduces the personal risk that acts as a natural constraint on behavior while creating a false sense of safety. The operator may be unreachable, but the company is not. Its corporate infrastructure, its employees’ personal data, its executives’ travel patterns and financial accounts are all accessible to any competent intelligence service.
PMCs operated under rules of engagement, even when violated. This program operates under law enforcement authorities that explicitly disclaim the applicability of LOAC. PMCs operated in zones where armed conflict was already occurring; the retaliatory violence they provoked was absorbed within an existing conflict. Cyber operations under this program target organizations in states where the United States is not at war. The retaliation they provoke will be directed at American private infrastructure, not at military assets in a conflict zone, and it will arrive without respect for the law enforcement framing that authorized the operation.
The Revolving Door and the Talent Drain
The officials at DOJ and DHS who approve NCC contracts today will be executives at Participating Companies in two years. The Program Executive Directors will leave government and join the companies they oversaw. This is the revolving door that already turns between the Pentagon and the defense industry, accelerated by the secrecy and specialized knowledge this program requires. An official who spent three years approving operations for a Participating Company walks out of government with knowledge that no competitor possesses and relationships that no outsider can replicate. That official’s next employer does not need to lobby for contracts. It needs to hire the person who wrote them.
The talent drain runs in parallel. CYBERCOM and NSA already struggle to retain offensive cyber operators against private sector compensation. This program creates a new category of private employer offering the same work, similar mission framing, and significantly higher pay with fewer restrictions. Every operator who leaves military or IC service for a Participating Company weakens the government’s organic offensive capability, the capability it built over two decades and now outsources to the companies poaching its people. The government is paying to train operators who will leave to work for the contractors the government pays to do what the operators used to do in uniform. The circular economics of that arrangement benefit the companies, not the country.
Shareholder Value, Securities Law, and the Billionaire Target Set
The Securities Law Trap
A publicly traded company that becomes a Participating Company faces an immediate conflict between two legal obligations that cannot both be satisfied. SEC Regulation S-K, Item 105, requires disclosure of material risk factors. The SEC’s cybersecurity disclosure rules adopted in July 2023 make clear that material cybersecurity risks must be disclosed. Participation in a program that invites state-level retaliation is material by any reasonable definition.
But the NCC program depends on secrecy. The contractual agreements under Section 2(a)(ii) will almost certainly prohibit disclosure. A company that files a 10-K risk factor describing its participation has compromised the program and breached its contract. A company that omits the risk factor has withheld material information from investors. There is no clean path. The company either complies with securities law and breaches its government contract, or complies with its government contract and breaches securities law.
For PE-owned firms, the securities law pressure is lower but the fiduciary obligations to limited partners remain. The fund manager who fails to ask whether a portfolio company is conducting government-directed offensive operations, or who knows the answer and fails to disclose it, has a fiduciary problem of their own.
Directors and Officers Exposure
The board that approves participation assumes personal liability exposure beyond ordinary business risk. The business judgment rule protects directors who make informed decisions in good faith with a rational belief the decision serves the company. Approving entry into a program that by design invites retaliation from foreign intelligence services, that could destroy the international client base, and that carries the possibility of existential reputational damage is a decision a court could find was not rational in the business sense. The upside is contract revenue. The downside is the company itself.
D&O insurance carriers will want to know about this. Standard policies exclude claims arising from criminal conduct, fraud, and sometimes government-ordered activities. If an insurer learns a company was conducting government-directed offensive operations and failed to disclose that fact, the policy may be voided. The directors are then personally exposed with no coverage behind them.
Stock Price Contagion
Once the program is publicly known, every publicly traded U.S. cybersecurity company trades under a question mark. Analysts will ask on quarterly earnings calls whether the company participates. The company cannot confirm or deny. That refusal becomes a standing risk factor priced into models, and the uncertainty itself becomes a discount across the sector. CrowdStrike, Palo Alto Networks, Fortinet, and their peers carry combined market capitalizations in the hundreds of billions. A sector-wide multiple compression driven by unquantifiable program participation risk translates to billions in destroyed shareholder value falling on retirement accounts, pension funds, and index fund holders who never heard of the NCC.
Short sellers will find opportunity in the ambiguity. A credible rumor attributing a specific company as a Participating Company sends that stock down fast. The company cannot issue a clear denial if it is participating, and cannot issue a clear denial if it is not participating but is bound by a general NDA. The information asymmetry runs in the wrong direction for investors.
Institutional Investors and Foreign Capital Flight
Sovereign wealth funds and pension systems operate under mandates that include risk screening, ESG governance criteria, and prohibitions on investing in companies involved in weapons production or military operations. Norwegian Government Pension Fund Global, Dutch pension giant ABP, Japan’s Government Pension Investment Fund, and comparable institutions apply ethics screens to their holdings. A U.S. cybersecurity company conducting offensive operations under government contract may trip those screens, even if specific participation cannot be confirmed. The safer institutional response is to underweight the entire U.S. cybersecurity sector.
Allied governments may go further. This is the Huawei dynamic in reverse. The United States spent years arguing that Huawei’s ties to the Chinese state made its equipment a national security risk for any country that deployed it. This memorandum validates the identical argument against U.S. cybersecurity vendors. The EU’s NIS2 Directive gives member states authority to impose supply chain security requirements that could exclude vendors deemed to pose unacceptable risk. The market access consequences for U.S. cybersecurity firms in Europe alone could exceed the total contract value the NCC program will ever generate.
Personal Targeting
When a Participating Company disrupts a foreign criminal organization with state connections, the executives of that company become persons of interest to foreign intelligence services. Russian, Chinese, Iranian, and North Korean services have all demonstrated capability and willingness to target individuals. Financial accounts can be attacked. Personal communications intercepted. Travel tracked. Family members surveilled. Business interests outside the United States sanctioned or seized. Iran has used criminal organizations, including the Jalisco New Generation Cartel, to conduct operations against individuals abroad.
The targeting logic extends beyond C-suite executives to major shareholders, PE fund general partners, and board members with public profiles. A billionaire who sits on the board of a Participating Company has personal wealth held in commercial financial instruments, commercial real estate, and commercial bank accounts, all accessible to a determined state-level adversary. The PE firm’s general partners who approved the portfolio company’s strategic direction could be named in foreign sanctions, placed on travel watch lists, or targeted personally. The GP who approved entry into the NCC program has accepted a risk on behalf of limited partners that most LP agreements do not contemplate.
The Blast Radius
Participating Companies use AWS, Azure, or GCP for infrastructure. They bank at commercial institutions. They depend on the same power grid, ISPs, and DNS infrastructure as every other American business. Retaliatory operations do not have to hit the Participating Company precisely. They can hit the infrastructure around it, and everyone sharing that infrastructure absorbs the cost.
The escalation path to kinetic action is not theoretical. In 2019, the Israel Defense Forces responded to a Hamas cyberattack by bombing the building that housed those responsible. Russia’s 2024 nuclear doctrine lowered the threshold for attacks warranting a nuclear response, and some analysts have noted that threshold could hypothetically include cyberattacks. When a private company operating under this program degrades infrastructure a foreign state considers critical, the response may not stay in cyberspace. The foreign state does not distinguish between a law enforcement action and an act of war. It responds based on the damage, not the label. The people who absorb that response are the power utility, the hospital system, the water authority, and the defense contractor sitting in the retaliatory blast radius, none of whom were parties to the contract or had a voice in its approval.
If This Is the Public Version
Intelligence services do not read a document like this NSPM and take it at face value. They read it as an indicator. The question every foreign intelligence analyst is asking is not what this memorandum says. It is what the document implies about what they cannot see.
The memorandum references a classified annex containing the operational workflow and the targeting framework. That annex exists. Its contents are unknown outside a small circle. But its existence tells foreign services that the public document is the sanitized version. Every foreign service will now dedicate analytical resources to modeling what that annex contains, what authorities it grants, and what constraints it does or does not include. That modeling will not be generous. Foreign intelligence analysts plan against worst case. If the public document authorizes effects operations against criminal organizations, the classified annex may authorize broader target sets. If the public document limits Critical Outcomes to loss of life and use of force, the classified annex may define those thresholds narrowly enough to permit significant destruction below the line.
The deeper inference concerns programs that were never published at all. Governments do not reveal their most sensitive offensive capabilities voluntarily. If this administration was comfortable publishing a memorandum authorizing private offensive cyber on the White House website, foreign analysts will conclude that this program is either the least sensitive in the portfolio or it was published to normalize a practice already underway in classified channels. Neither conclusion is reassuring.
Allied governments will be unsettled in particular. The Five Eyes partners, NATO allies, and close security partners maintain intelligence-sharing relationships with the United States that depend on trust and predictability. A public memorandum authorizing private offensive cyber, without any apparent allied consultation in the public text, raises the question of what other offensive programs exist that allies have not been briefed on. If the United States privatizes offensive cyber without telling Congress, the inference that it would do so without telling Ottawa, Canberra, or London is straightforward. Allied services may restrict what they share, impose caveats, or demand assurances about downstream use that the United States cannot provide without revealing program details it wants to keep classified.
Escalation Signal, Declared Intent
Will this memorandum be read by adversaries and allies as significant escalation, or as a declaration of intent? The answer is both, and the reading is the minimum competent assessment any foreign intelligence service will produce.
Capability plus publicly declared intent equals threat assessment. That equation is universal. This memorandum declares both: the capability (private companies conducting offensive cyber operations) and the intent (to use them against foreign targets under a standing program with defined workflows and timelines). Publishing it on the White House website is the declaration. A foreign analyst does not need to speculate. The President signed a document saying it will happen.
The United States already possesses offensive cyber capability through CYBERCOM and NSA. Foreign governments know this and have planned against it for years. The decision to build a parallel private capability signals a desire to scale operations beyond what the existing apparatus can or will do, or to conduct operations it would refuse or flag through its oversight mechanisms, or to create deniability it cannot provide. All three interpretations are escalatory from the receiving end.
The privatization element carries specific meaning in international security signaling. When a state keeps offensive operations inside its military, it maintains a clear chain of command, a known interlocutor for crisis communication, and an implicit commitment to the discipline that military operations carry. When a state delegates offensive capability to private companies, it loosens all three. The foreign government on the other end faces an adversary whose offensive operations run through entities outside military command, outside established communication channels, and outside the frameworks that provide predictability in crisis. That is a less stable posture than what existed before.
International law distinguishes between capability and intent, and treats the combination differently than either alone. A state that possesses offensive tools but does not announce a program to use them maintains strategic ambiguity, which preserves decision space on both sides. A state that publishes a memorandum creating an operational program with target categories, approval workflows, and implementation timelines has moved from ambiguity to declared intent. That shift changes how adversaries calibrate their posture, their pre-positioned access, their retaliatory planning, and their thresholds for preemptive action. Russia, China, Iran, and North Korea will treat this as confirmation that the United States intends sustained offensive operations using private proxies. Their rational response is to expand their own programs, pre-position deeper in U.S. infrastructure, and lower their own thresholds. That is an escalation spiral, and this memorandum initiates it.
For allies, the signal is about reliability. The United States led the international effort on norms of responsible state behavior in cyberspace for over a decade, pressing for the UN GGE consensus reports of 2013 and 2015, building the coalition behind the Paris Call. It argued in every multilateral forum that states should not use proxies for offensive cyber, that civilian infrastructure should be protected, and that responsible states exercise restraint. This memorandum contradicts each position in a single document. Allies who aligned with the U.S. on norms, and took political risk at home to do so, now face the question of whether the advocacy was genuine or a constraint the United States intended to apply to others while exempting itself.
The response from allied capitals will not be public, at least not immediately. It will be quiet: a restriction on intelligence sharing here, a new vetting requirement for U.S. vendors there, a revised threat assessment that reclassifies American commercial technology from trusted to monitored. Those adjustments will accumulate. Each one degrades the cooperative frameworks the United States depends on for its own security.
The Template Problem
The essay has so far addressed what this memorandum does to the United States. It should also address what happens when other countries build their own version, because they will.
Once the United States publishes a framework for privatized offensive cyber operations, it becomes a template. India, Turkey, Saudi Arabia, the UAE, Brazil, Indonesia, and every mid-tier power with a growing cyber capability now has a model and a justification. The U.S. did it first. If Washington can contract private companies to attack foreign targets under government oversight, Ankara can too. Riyadh can too. Abu Dhabi, which already ran the Dark Matter program with former NSA contractors and has a documented record of targeting journalists and dissidents, can point to this memorandum as validation. The governments most likely to copy the model are the ones with the weakest rule of law, the least independent oversight, and the fewest restraints on how offensive capabilities are used. The norms damage is not confined to American credibility. It is structural.
The Wassenaar Arrangement adds a complication the memorandum does not address. Offensive cyber tools are dual-use items subject to export controls. Participating Companies building tools for the NCC program will develop capabilities that have commercial value. The interaction between government-funded tool development, the intellectual property rights in those tools, and export control obligations is unaddressed in the memorandum. If a Participating Company develops an offensive capability under NCC contract and then sells a version of that capability to a foreign government, the export control implications are significant and the precedent is dangerous.
Third-Party Risk, Supply Chain, and Executive Protection
For the working CISO, this memorandum breaks the third-party risk assessment model at a foundational level. TPRA processes are built on the assumption that risks are discoverable through diligence. You ask vendors questions. You verify answers against evidence. The process works because the risk categories are knowable and the vendor’s truthful disclosure is enforceable through contract. This program creates a risk category that is structurally undiscoverable. You cannot ask a vendor whether it is a Participating Company and get a truthful answer, because the program’s design prevents disclosure.
Supply chain risk management frameworks, from NIST SP 800-161 through CMMC to ISO 27036, treat supply chain risk as something that can be identified, assessed, mitigated, and monitored. This memorandum creates a class of risk immune to all three. For organizations operating under CMMC, DFARS, NIST 800-171, and ITAR, the implications are concrete. If a vendor serving a defense contractor is a Participating Company, and a retaliatory operation compromises that vendor’s infrastructure, and the compromise cascades into systems processing controlled data, the contractor faces an ITAR spillage problem and a DFARS incident reporting obligation triggered by a program it had no knowledge of. Cyber insurance will not cover it. If the triggering attack is attributable to a foreign state retaliating against a government-directed operation, the insurer invokes the war exclusion clause.
Executive protection must now account for a new threat vector. If your vendors include Participating Companies whose operations provoke retaliation, the targeting may extend to the vendor’s client base. Personal threat assessments for CISOs and executives at DIB companies should now include the possibility that a vendor’s undisclosed participation has placed them in a retaliatory target set they did not choose and cannot see.
The practical response is limited but necessary. Ask the question in vendor reviews even knowing you will not get a straight answer. Document that you asked. Document that the program’s existence creates a risk your assessment cannot quantify. Make the gap visible. When something goes wrong, the record should show you identified the structural problem and that the government’s own program design prevented you from managing it.
The Memorandum as Precedent
Max Weber defined the state as the entity that successfully claims the monopoly of legitimate violence. This memorandum cedes a piece of that monopoly to commercial entities whose obligations run to shareholders, whose discipline runs to contract compliance, and whose accountability, when an operation goes wrong, runs to a $1 million bond and a classified annex. The constitutional path was available and a bill was pending in committee. The administration chose executive action instead, bypassing the branch the Framers designated for exactly this kind of delegation. The published memorandum is a floor, not a ceiling. Every intelligence service in the world understands that.
Works Cited
Presidential Actions and Legislation
“Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.” Presidential Memorandum. The White House, August 12, 2026.
“Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens.” Executive Order 14390. The White House, March 6, 2026.
“Protecting the American People Against Invasion.” Executive Order 14159. The White House, January 20, 2025.
“Fact Sheet: President Donald J. Trump Expands Capabilities to Combat Transnational Cyber-Enabled Crime.” The White House, August 12, 2026.
H.R. 4988, “Scam Farms Marque and Reprisal Authorization Act of 2025.” 119th Congress. Introduced August 15, 2025, by Rep. David Schweikert (R-AZ). Referred to the House Committee on Foreign Affairs.
Academic and Policy Sources
Tanji, Michael. “Buccaneer.Com: Infosec Privateering as a Solution to Cyberspace Threats.” Journal of Cyber Conflict Studies, Vol. 1, No. 1 (2007): 4-10.
Egloff, Florian. “Cybersecurity and the Age of Privateering.” In Understanding Cyber Conflict: Fourteen Analogies, edited by George Perkovich and Ariel Levite. Carnegie Endowment for International Peace / Georgetown University Press, 2017.
Egloff, Florian. “Cyber Privateering: A Risky Policy Choice for the United States.” Lawfare, November 17, 2016.
Deibert, Ronald J. “The Perils of Privatized Cyberwarfare.” Lawfare, April 1, 2026.
“Old Tools, New Problems.” Aspen Digital, May 12, 2026.
“Grant Cyber Letters of Marque to Manage ‘Hack Backs.'” U.S. Naval Institute Proceedings, Vol. 145, No. 10 (October 2019).
“Cyber Privateers: The Return of the Hack-Back Debate.” GovTech / Lohrmann on Cybersecurity, September 14, 2025.
“Cyber Letters of Marque: Addressing the Geopolitical.” Indiana International and Comparative Law Review, Vol. 36, p. 307.
“Can Cyber Privateers Help Us Combat Cybercrime?” Time, March 11, 2026.
Work, JD. “Private Actors and the Intelligence Contest in Cyber Conflict.” In Cyber Conflict as an Intelligence Contest, edited by Robert Chesney and Max Smeets.
“Hostile State Champion Commercial Cyber Threat Intelligence Services.” International Journal of Intelligence and CounterIntelligence, Vol. 39, No. 1 (2025).
Author Background and Related Writing
Liles, Samuel. Cyberwarfare as Low-Intensity Conflict. Doctoral Dissertation, Purdue University.
Liles, Sam. “Ox Carts of Thunder.” sveoti.net, August 9, 2026.
Liles, Sam. “DoD(w)s Land of Misfit CMMC Toys.” sveoti.net, August 6, 2026.
Liles, Sam. “Fifty Reports Deep and the Strait Is Still Closed.” sveoti.net, July 27, 2026.
Liles, Sam. “The Forensic Terrain Problem: A Decision Framework for the Working Analyst.” sveoti.net, April 7, 2026.
Liles, Sam. “Global Oil Crisis Chaos: A War with Iran.” sveoti.net, March 11, 2026.