The White House is creating a contractual route for private U.S. companies to conduct cyber surveillance and disruptive operations against foreign criminal groups, alongside federal law enforcement and national security agencies.
A presidential memorandum directs the National Coordination Center (NCC) to establish the program and requires participating companies to contract with either the Department of Justice (DOJ) or Department of Homeland Security (DHS). The companies keen to be involved will undergo vetting and follow procedures that are still being written.
Targeting and scope of authorized operations
Other than defensive monitoring, the cyber surveillance includes covert access to target systems without the owner’s authorization, while cyber effects operations can manipulate, disrupt, deny, degrade or destroy systems, networks, infrastructure or data, the memorandum reads.
Eligible targets are foreign cyber-enabled transnational criminal organizations committing cyber-enabled crime against the U.S. government, a U.S. person or U.S. interests.
The memorandum presumes a foreign group is not part of or wholly directed by a foreign government unless clear intelligence establishes that connection.
Federal oversight and legal boundaries
Participating companies cannot act independently under the program. The program will be overseen by two co-Executive Directors, one from DOJ designated by the Attorney General and one from DHS designated by the Homeland Security Secretary.
The Program Executive Directors must review every cyber-operations package and provide written approval and direction before action. Program activity must comply with the Constitution, applicable law and U.S. international obligations, including the Computer Fraud and Abuse Act.
The procedures must require DOJ review and any necessary judicial or other authorization before activity directed at a U.S. person or otherwise implicating constitutional, federal-law or international-law obligations.
The program builds on a March 6 executive order that told DOJ and DHS to use commercial cybersecurity capabilities and threat intelligence to improve attribution, tracking and disruption. The August memorandum goes further by defining participating companies as private U.S. businesses authorized to conduct cyber operations under federal direction.
Vetting standards and financial requirements
The memorandum tells officials to make eligibility possible for large companies and “smaller, more agile companies” that may be better suited to specialized or discrete tasks. Minimum standards must cover technical proficiency, proven performance in cyber operations, facility security, personnel vetting, competence and reliability.
DOJ and DHS may also require a participating company to maintain a bond or escrow of at least $1 million, forfeitable for contractual noncompliance. The condition is discretionary, and the memorandum does not say which contracts would trigger it.
Proposing operations and emergency safeguards
Accepted companies may receive threat information from other businesses under commercial agreements and use it to propose cyber operations to the NCC. Those relationships must be disclosed, and companies must be reviewed for continued eligibility at least annually.
Companies must stop an operation, apply required minimization procedures and immediately notify the NCC when activity exceeds approved parameters, including unintended targeting of a U.S. person or U.S.-based information system. Program directors cannot approve operations likely to cause death or serious injury or rise to a use of force or armed attack under international law.
Future procedures and implementation timeline
The memorandum establishes a contractor role but leaves the operational workflow, interagency deconfliction and cyber-operations package processing to procedures due within 60 days. The workflow and deconfliction provisions must conform to a classified annex. The first status report is due within 180 days, and implementation remains subject to available appropriations.