In brief
On August 12, 2026, the White House issued a National Security Presidential Memorandum, Expanding Capabilities to Combat Transnational Cyber-Enabled Crime (“Memorandum”), directing the creation of a Program to marshal private-sector capabilities against Cyber-Enabled Transnational Criminal Organizations (CE-TCOs),1 i.e., any foreign, non-government groups that engage in cyber-enabled crime to attack US interests, companies, individuals, or the US government itself. Common examples of current cyber-enabled criminal activity include ransomware, phishing or vishing, fraud, business email compromise, sextortion, economic espionage and/or profiling, and impersonation scams. The Memorandum builds on Executive Order 14390 and reflects a policy judgment that the private sector’s “scale, speed, and capacity” give the United States an offensive cyber advantage that has been “historically . . . underutilized.”
The Memorandum tasks the National Coordination Center (NCC) with creating, managing, and maintaining the Program, under which authorized “Participating Companies” may conduct “Cyber Surveillance Operations”2 and “Cyber Effects Operations”3 against CE-TCO's. The Program grants participants no authority of their own: each operation is undertaken solely for the Federal Government and under its supervision, relying entirely on the government’s own legal authorities. Oversight rests with two co-Executive Directors, one drawn from the Department of Justice (DOJ) and one from the Department of Homeland Security (DHS).
Key takeaways
The Memorandum reflects the administration's policy of using “all instruments of national power, including the innovative capabilities of the private sector,” to combat cyber-enabled crime. It contemplates a framework in which authorized private companies may conduct surveillance and disruptive cyber operations against foreign criminal networks, subject to federal direction and oversight. Participation is voluntary and limited to companies that are vetted and authorized under the Program.
Technology, cybersecurity, cloud, healthcare, financial-services, transportation, energy, manufacturing, and telecommunications companies are the most likely candidates to be invited to participate or to be asked to share threat information. The operative details of the Program—including eligibility and vetting criteria, the scope of permitted operations, and the procedures governing them—are to be developed by the Program Executive Directors and the Homeland Security Council, and are not fully set out in the public documents. Companies that may engage with the Program should monitor for the forthcoming implementing procedures.
In more detail
Creation of the Cyber Disruption Program
The Program is housed in the NCC, which was created under section 6(d) of Executive Order 14159 (January 20, 2025) and sits within the Homeland Security Task Force. The Memorandum tasks the NCC with building and running a Program that authorizes Participating Companies to conduct Cyber Surveillance Operations and Cyber Effects Operations against CE-TCOs. Participants receive no freestanding authority of their own; every operation is carried out for the government and under its supervision, drawing on the government’s own legal authorities. The two co-Executive Directors—one designated by the Attorney General, the other by the Secretary of Homeland Security—must approve each operation in writing beforehand, and neither may greenlight one likely to cause a “Critical Outcome.”4
Entry into the Program has conditions. A prospective participant must enter a contract with DOJ and DHS, post a forfeitable bond or escrow of no less than USD 1 million, pass a searching vetting review, and be reassessed annually. Every operation, per the memorandum, must square with the Constitution, the Computer Fraud and Abuse Act (18 USC. § 1030), and US obligations under international law, and any inadvertent targeting of a US person or US-based system triggers mandatory minimization and notice. The Program Executive Directors and the Homeland Security Council have 60 days to issue implementing procedures and must deliver an initial status report within 180 days. Notably, the Memorandum leaves existing statutory information-sharing regimes intact—neither expanding nor overriding the Electronic Communications Privacy Act (ECPA), the Stored Communications Act (SCA), or the Cybersecurity Information Sharing Act of 2015.
Two aspects of the Program are handled through a classified annex instead of the public text. The first is operational: precisely how missions are carried out and how they are coordinated among the various agencies that have an interest in them. The second is adjudicative: the process for deciding which targets are legitimate, structured to confine operations to genuine CE-TCOs and to avoid interfering with other government equities.
Safeguards
The Memorandum contemplates some safeguards:
- A “Critical Outcome” threshold rules out any operation that could kill, cause serious injury, or rise to a use of force, with Participants obligated to report proactively any operation approaching the “Critical Outcome” line.
- An operation aimed at a US person—or one that otherwise implicates constitutional, statutory, or international-law obligations—must obtain every required authorization, “judicial or otherwise,” and be vetted by DOJ.
- If a participant recognizes that it has gone beyond what was approved, such as by accidentally affecting a US person, a US-based system, or a system under a US person’s control, it is required to cease operations at once, run minimization procedures, and immediately notify the NCC and DOJ.
The Program overall contemplates that whatever is done through it remains subject to the government’s control, oversight, and legal authority.
Many outstanding questions remain regarding the Program, including:
- What legal protections, if any, are there for Participating Companies. The Memorandum states that Program operations must comport with all applicable legal regimes, including the US Constitution, its laws, and international obligations. However, it does not independently establish any form of civil immunity for Participating Companies in the event a Program activity amounts to a tort or other legal violation.
- What level of information sharing will be expected between Participating Companies and the NCC. Implementing guidance will develop standing reporting requirements meant to broaden the government’s understanding of foreign CE-TCO conduct and to keep the NCC informed of what Program participants are doing.
- What will the NCC expect in terms of standard assistance from Participating Companies. Implementing guidance is expected to create common templates and forms for designating targets and preparing surveillance and effects operation packages.
- Whether the NCC will prioritize certain operations and the criteria for authorization. Because each operation must be authorized and supervised, it remains to be seen how participating companies may be able to balance their interests against NCC's priorities.
- Preserving Privilege Claims. Companies considering participation may wish to consider how existing legal protections, including those applicable to cyber threat information sharing, might be affected if a company participates in the Program.
Baker McKenzie can help clients evaluate potential risks and legal issues around Program participation as the implementing guidance takes shape.
1 § 4(c). The Memorandum defines a CE-TCO as a foreign criminal group engaged in cyber-enabled offenses targeting the United States, US persons, or US interests, excluding entities that are part of, or entirely controlled by, a foreign government.
2 § 4(d). The Memorandum defines a Cyber Surveillance Operation as covert, unauthorized access to an information system for intelligence-gathering purposes. The definition also encompasses limited manipulation or temporary interference necessary to facilitate information collection, so long as the activity is not intended to cause physical consequences or materially impair system functionality.
3 § 4(a). The Memorandum defines a Cyber Effects Operation as cyber activity designed to alter, disrupt, deny access to, degrade, or destroy information systems, networks, data, or infrastructure that depends on such systems.
4 § 4(b): A “Critical Outcome” is defined as anything resulting in the loss of life or serious injury; or be considered a use of force or armed attack under international law.