Trump's private cyber offensive wins support — and plenty of alarm
The cybersecurity community largely agrees that the US needs to hit cybercriminals harder. But Trump's plan to enlist private companies to do it has opened a thicket of questions about attribution, liability, escalation and who pays when an operation goes wrong.
Donald Trump’s plan to enlist private companies in government-directed offensive cyber operations is drawing both enthusiasm and alarm from cybersecurity experts, who see the initiative as potentially giving the United States powerful new weapons against cybercrime while opening a thicket of unresolved questions about attribution, liability, collateral damage and escalation.
The National Security Presidential Memorandum signed Wednesday creates a program under which vetted US companies could conduct surveillance and disruptive cyber operations against foreign transnational criminal organizations under the direction of the Justice and Homeland Security Departments.
The operations could go considerably further than the threat intelligence sharing and technical assistance that have traditionally characterized public-private cybersecurity partnerships. The memo defines permissible “cyber effects” as potentially including the manipulation, disruption, denial, degradation or destruction of information systems, networks, data and physical or virtual infrastructure controlled by information systems.
The case for bringing in private firepower
Supporters say the approach recognizes a basic reality, namely that much of the talent, intelligence, infrastructure visibility and technical capability needed to fight cybercrime resides outside the federal government.
“The new National Security Presidential Memorandum on combating transnational cyber-enabled crime represents an important shift in how the United States approaches cyber threats originating overseas,” Michael Centrella, head of public policy at SecurityScorecard, told Metacurity.
“Strengthening defenses remains critical, but the memorandum recognizes that addressing cybercrime also requires identifying and disrupting the infrastructure and networks that allow criminal organizations to operate.”
Centrella said the expanded role for private companies is particularly significant because much of the threat intelligence, telemetry and technical expertise needed to understand malicious activity exists outside government.
“Creating a framework for vetted US companies to support government-directed operations could significantly improve the government's ability to identify malicious infrastructure, understand interconnected digital ecosystems, and act against transnational cybercriminal organizations,” he said.
“Effective disruption, however, starts with visibility. Understanding the infrastructure, third parties, and digital relationships surrounding malicious actors can help government agencies move from reacting to individual attacks toward identifying the broader ecosystems enabling them.”
The policy, Centrella said, represents an evolution in public-private cybersecurity collaboration “from primarily sharing information about threats toward combining government authorities with private-sector intelligence and capabilities to more actively disrupt them.”
Mieke Eoyang, who oversaw military cyberweapon use as a senior Pentagon official during the Biden administration, offered another argument for expanding the pool of cyber operators.
“The current pace of cyberoperations is unsustainable for just the military,” Eoyang said.
But Eoyang also said the program’s success would depend heavily on the still-classified procedures governing company vetting and target approval. The existing process for authorizing military cyber operations, developed during the first Trump administration, was “onerous,” she said, but took collateral consequences and deconfliction into account.
Aiden Buzzetti, president of the Bull Moose Project, which has advocated restoring the American privateer tradition in cyberspace, called the memo “seismic,” arguing that rapidly expanding non-state capabilities make private-sector participation increasingly important.
“The capabilities of non-state actors are rapidly expanding,” Buzzetti said, adding that private actors “often have more capabilities and interesting tools than the government does.”
Others argue that failing to use offensive capabilities carries risks of its own.
Duncan Greatwood, CEO of Xage Security, told Metacurity that leveraging the American private sector for offensive operations “can absolutely make us more formidable,” although greater offensive capability does not lessen the need for strong domestic defenses.
“Offensively, while the US and its allies will want to be careful to avoid runaway geopolitical escalation, if the US never responds to cyberattacks it risks the opposite problem of enabling attackers, and their supporters, to operate with impunity,” Greatwood said. “In other words, there is a real role for offensive cyber in disrupting and deterring attacks.”
Rob T. Lee, chief of research at SANS Institute, pointed to recent disruption operations by Sandra Joyce’s Google Threat Intelligence Group as evidence that private-sector disruption can work. But he stressed that Google stayed within a legal boundary the new program explicitly crosses, acting on infrastructure it controlled or using court orders when it did not.
“This memo is uncharted waters, and licenses a lane Google deliberately refused to enter,” Lee wrote.
Lee also zeroed in on the same attribution problem raised by other experts: “The program assumes a target is criminal rather than state-run unless clear intelligence says otherwise, and in the Russian ecosystem that distinction is one phone call. Attribution is the load-bearing wall. Almost right is the expensive kind.”
Attribution may be the policy’s Achilles’ heel
The memo’s targeting standard is drawing particular scrutiny.
Section 4(c) of the memorandum defines eligible targets as foreign cybercriminal organizations that aren’t institutional components of foreign governments or wholly operating at their direction. But it then establishes a striking presumption: An organization is assumed not to have such a government connection unless “clear intelligence” establishes otherwise.
Security researcher Davi Ottenheimer argues that the provision places the evidentiary burden in the wrong place.
“They set an evidentiary standard for protecting a target and none for striking one,” Ottenheimer told Metacurity. “Force is most available where its consequences are least assessable.”
Ottenheimer said the problem echoes concerns he raised about active cyber defense as far back as 2012, when he argued that any such operation needed to confront three questions: legality, effects on innocent bystanders, and the consequences of failure. His 2012 CyberFall presentation on active defense specifically addressed the legal ramifications, potential harm to innocent bystanders, and risk of failure surrounding active defense.
“This answers none of them: shoot first, ask questions never,” Ottenheimer told Metacurity.
The attribution problem is particularly difficult because the boundary separating ordinary cybercriminals from state-linked operators is often anything but clear.
A Russian ransomware group, for example, might operate with government tolerance, maintain relationships with intelligence officers or occasionally perform work benefiting the state without being wholly directed by Moscow.
Nick Carr, Microsoft’s threat intelligence lead and a former US cybersecurity official, said his biggest concern was “just how difficult attribution in criminal operations is, and how few organizations can repeatably do it right,” including government agencies.
Carr added that the order could ultimately improve those efforts. But the difficulty is particularly significant because an attribution mistake would no longer merely produce an erroneous government accusation. It could help determine whether the United States authorizes an operation that disrupts or destroys somebody else’s infrastructure.
Michael Garcia, who served as associate chief of policy at CISA until departing in June, made a related point: Attribution has improved, but “obfuscation is still a hell of a tactic.”
And the problem becomes still more complicated if adversaries deliberately manipulate attribution — planting another group’s tools or routing operations through compromised third-party infrastructure in an effort to make someone else appear responsible.
Who takes the fall when an operation goes wrong?
The memo contains safeguards. Companies must be vetted, operations require written government authorization, and procedures are supposed to deconflict private operations with federal law-enforcement, diplomatic, military, and intelligence activities.
But the memorandum leaves major questions about what legal protection participating companies and their employees receive when they follow government instructions and something nevertheless goes wrong.
“From the lawyer perspective, it’s, ‘Are you okay with engaging in this kind of legal risk? And who knows what protections the government will provide?’” Garcia said. “I’d be very curious to see what the foreign governments’ reactions are — ‘We’re going to cut ties with any participating company that engages in this.’
Participating companies may also be required to maintain a bond or escrow of at least $1 million that could be forfeited for violating their contracts.
But the White House memorandum leaves major questions about what legal protection participating companies and their employees receive when they follow government instructions, and something nevertheless goes wrong.
The problem becomes particularly acute because cyber effects are difficult to contain. Infrastructure used by criminals may belong to innocent third parties, reside in another country, or share services with unrelated organizations. An operation aimed at one target can therefore produce consequences somewhere else.
The policy also creates an unusual question about the relationship between private actors and government authority: What happens if a company performs an operation Washington has approved but that violates the law of the country where the targeted infrastructure resides?
Eoyang’s warning about the importance of the classified approval and deconfliction procedures takes on particular significance here. The public memo establishes the outer boundaries of the program, but some of the procedures most likely to determine whether an operation is safe are hidden from public view.
Private cyber warriors could become targets themselves
Gary Barlet, public sector CTO at Illumio, supports using private-sector capabilities, noting that US adversaries have long relied on third parties to conduct cyber operations while preserving plausible deniability.
“The reality is that the private sector has access to more talent and resources and not necessarily the same constraints,” Barlet told Metacurity.
But he also raised one of the fundamental questions created by putting private companies directly into offensive operations.
“Does empowering private companies turn them into legitimate targets or combatants in the eyes of foreign states?” he asked.
“Some would argue they are already in the crosshairs, so giving them a path to fight back makes sense. The potential benefits outweigh the risks, but we need to go into this eyes wide open – there will be friction, grey areas, and unintended consequences we can't fully predict yet.”
Vanessa Le, a partner at Latham & Watkins who advises companies on geopolitical risk, raised a related issue: What does becoming an offensive cyber contractor mean for a publicly traded cybersecurity company?
“This approach from the government presents novel questions for publicly traded companies in the sector: Even if they engage in ‘hack back’ activities under US government cover or direction, how will they manage the increased operational risk to their business and customers, and how and when will they disclose it?” Le said.
The consequences could extend well beyond securities disclosures. A company known to conduct offensive operations for Washington could become a higher-value target for foreign intelligence services or criminal groups. Its employees could face risks while traveling abroad, and adversaries could seek to compromise the contractor itself to obtain intelligence about US operations and targets.
Barlet’s question about whether participating companies could be viewed as combatants therefore isn’t merely theoretical.
Who guards against a market for offensive cyber operations?
The program also creates potential financial incentives that some former officials find troubling.
Jason Kikta, a former US Cyber Command official, characterized the program as a “perpetual motion machine for billable threats.”
The White House memo permits participating companies to receive threat intelligence from other private organizations and use that information to propose cyber operations to the government. If approved, private contractors could then participate in executing those operations.
That raises the possibility that companies could play roles in identifying a threat, proposing the government response, and carrying out the resulting operation.
Chris Wysopal, cofounder of Veracode, similarly described the memo as a “pretty big shift in US cyber policy” while distinguishing the government-controlled program from unrestricted private-sector hack-back.
The concern isn’t necessarily that companies will manufacture threats. Rather, the structure creates a question familiar to other areas of government contracting: How do officials ensure that the party with a financial interest in operating isn’t exerting disproportionate influence over the determination that an operation is necessary?
The US may be borrowing from its adversaries
The policy also creates an unusual reversal in the relationship between US and adversary cyber models.
China and Russia have long benefited from relationships with nominally private hackers and contractors that provide governments with technical capacity while sometimes blurring responsibility for their operations.
Dakota Cary, an expert on China’s hacking ecosystem and an adviser at SentinelOne, noted that Beijing has historically borrowed from US approaches to cybersecurity.
“Now it seems the US is interested in copying China’s system for deputizing private-sector hackers,” Cary said.
The analogy has limits. The White House program calls for formal government contracts, vetting, written authorization, and interagency deconfliction rather than the deliberately murky relationships that can exist between foreign intelligence services and ostensibly independent hackers.
But the memo nevertheless changes the traditional division of labor between private cybersecurity companies and the government.
A new offensive landscape for everyone
Even organizations that never participate in the program could feel its effects.
Brian Anderson, global field CTO at Cato Networks, told Metacurity that a more active and contested cyber environment could make life harder for ordinary defenders.
“Disruption rarely stays neatly contained, often affecting sectors, vendors, and supply chains far beyond the original participants,” Anderson said.
“Attribution remains difficult—particularly where criminal networks and state interests may overlap. That uncertainty can complicate risk decisions for everyone.”
Anderson also warns that the operational environment may become noisier as activity increases in cyber’s gray areas, making meaningful signals harder for defenders to distinguish from background activity.
“This is not a call for alarm,” Anderson said. “It is a reminder to invest in the fundamentals: strong visibility, continuous validation, Zero Trust principles, resilient vendor relationships, and incident-response plans practiced for uncertain conditions.”
One voice has been conspicuously absent from the extensive public debate over the memo: the Trump administration itself.
While dozens of current and former officials, cybersecurity executives, researchers and policy experts have debated the plan’s merits and risks, administration officials have offered no public explanation of how the program will work or answers to the questions it has generated about attribution, liability, oversight and escalation.
Metacurity is the cybersecurity news you'd need hours to assemble yourself.
Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.
A paid subscription to Metacurity delivers
- Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
- Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
- Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.
Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.
Please consider supporting us. And thank you!