1. Home
  2. |Insights
  3. |License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations

License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations

What You Need to Know

  • Key takeaway #1

    A recently signed National Security Presidential Memorandum (NSPM) establishes a highly regulated program under joint Department of Justice and Department of Homeland Security oversight, allowing vetted private companies to conduct some cyber operations against cybercriminal syndicates.

  • Key takeaway #2

    This program, to encourage certain U.S. companies to conduct offensive cyberattacks, marks a major shift in U.S. government cyber policy, which has previously emphasized private-sector defenses in the face of cybercrime.

  • Key takeaway #3

    The NSPM provides federal prosecution immunity but leaves significant gaps: no civil liability shield for collateral damages, unresolved criminal discovery obligations that could expose proprietary tools and personnel in federal court, and the risk of asymmetric retaliation from threat actors against companies operating in an “active” capacity.

Client Alert | 4 min read | 08.14.26

What You Need to Know

On August 12, 2026, the White House released a National Security Presidential Memorandum (NSPM) making a seismic shift in U.S. cybersecurity policy and establishing a framework to authorize private-sector companies to conduct offensive cyber operations — historically strictly prohibited by federal law — against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCO). It builds on an executive order issued in March 2026 that directed federal agencies to develop plans to combat cybercrimes against Americans.

Historically, the Computer Fraud and Abuse Act (CFAA) and the Cybersecurity Information Sharing Act of 2015 (CISA 2015) drew a hard line against offensive operations by private sector entities — such as executing distributed denial-of-service (DDoS) attacks against attacker infrastructure, deploying retaliatory malware, or conducting surreptitious access against threat actors. The new NSPM creates a federally sanctioned framework designed to bridge the gap between private-sector technical capabilities and public-sector authorities. Jointly overseen by the U.S. Department of Justice (DOJ) and the U.S. Department of Homeland Security (DHS) through the National Coordination Center (NCC), the program allows vetted “Participating Companies” to carry out authorized offensive cyber operations against foreign cybercriminals.  By entering into formal contracts with federal agencies, participating private entities can legally engage in activities that were previously strictly off-limits under federal anti-hacking statutes like the CFAA.

The New Framework: What the NSPM Does

The NSPM establishes a formal program to deputize the private sector. Key features include:

  • Vetted “Participating Companies: The government will enter into contractual agreements with vetted entities, ranging from large corporations providing scale to agile, specialized firms.
  • Strict Oversight: Every cyber operations package requires written approval from Program Executive Directors at the DOJ and DHS.
  • Financial Assurance: Participating Companies may be required to maintain a bond or escrow of no less than $1 million, subject to forfeiture for noncompliance.
  • Minimization and U.S. Person Protections: The program mandates immediate cessation and DOJ notification if an operation inadvertently targets a U.S. person or U.S. infrastructure or exceeds the approved parameters.

The program authorizes “Participating Companies” to conduct “Cyber Surveillance Operations” and “Cyber Effects Operations” under the control and oversight of the federal government. The NSPM defines “Cyber Effect Operations” as activity intended to manipulate, disrupt, deny, degrade, or destroy threat actor infrastructure. “Cyber Surveillance Operations” entail accessing information systems without authorization from the owner or operator and with the intent to remain undetected.

The NSPM directs the DOJ and DHS to establish, within 60 days, operating procedures for the program that “ensure the Federal Government’s complete oversight and control of Participating Companies’ performance.” These procedures include:

  • Setting minimum technical, operational, and security benchmarks that companies must meet to participate in the program.
  • Mandating disclosure of all relevant contractual relationships to the NCC.
  • Providing a framework to ensure surveillance and effects operations only target CE-TCOs.
  • Setting reporting requirements and requiring written pre-approval prior to any actions.
  • Subjecting companies to at least annual performance reviews, requiring prompt reporting of imminent threats to U.S. critical infrastructure, and requiring DOJ review and appropriate judicial authorization for operations implicating U.S. persons or constitutional, federal law, or international law obligations.

Significant Questions Remain

While the NSPM states that the NCC and the participating companies are to conduct all activities in accordance with applicable laws, including the CFAA, it leaves numerous questions unanswered:

  • Collateral Damage — No Civil Shield: The NSPM provides federal criminal immunity but does not appear to offer safe harbor against civil liability. Because threat actors routinely route operations through third-party systems, a participating company that inadvertently disrupts an innocent party's infrastructure remains exposed to civil CFAA claims, common law tort, and intellectual property suits.
  • The Criminal Discovery Trap: Successful cyber operations are only one part of the government’s disruption strategy. When successful operations lead to an indictment, it’s unclear what criminal discovery obligations are triggered for participating companies. Such discovery may force disclosure of proprietary code, zero-day exploits, and intelligence methodologies in open court, with personnel subject to cross-examination.
  • Asymmetric Retaliation Risk: Private companies lack the institutional protection of federal agencies. The Flax Typhoon disruption illustrates the point: China-based actors launched a retaliatory DDoS attack that stopped only upon learning they were targeting the FBI. Private firms operating offensively should expect escalated responses from adversaries who may now view them as combatants, not victims.
  • The AI Accelerant: AI-driven autonomous cyber tools will quickly outpace human oversight. While the NSPM encourages automation, deploying agentic AI in offensive operations raises the likelihood of actions exceeding approved parameters — triggering bond forfeiture or civil exposure at machine speed.

For a further discussion of the potential implications of offensive cyber operations conducted by industry, see our article, “Cyber Offense: How Far Can Private Organizations Go?” published in May 2026 in Lawfare.

What You Should Do Next

As previously discussed, DOJ and DHS are tasked with establishing operating procedures for the program within 60 days. In the interim, corporate leaders, general counsels, and CISOs should:

  • Audit Current “Active Defense” Measures: Ensure your current incident response protocols (e.g., canary tokens, honeypots) do not inadvertently cross the line into unauthorized offense. The CFAA is still the law and actions reaching beyond your own network perimeter still incur legal risk.
  • Evaluate Vendor Capabilities: If you rely on managed security service providers (MSSP), inquire whether they intend to apply as Participating Companies. Evaluate how their potential offensive operations might alter your organization’s risk profile or invite third-party retaliation.
  • Weigh the Risks: Before applying to the program, companies should carefully weigh the strategic and commercial value of participation against the unresolved legal risks. Crowell will continue to monitor the implementation of the NCC Program, and our team stands ready to advise clients on navigating participation in this novel framework.

Insights

Client Alert | 4 min read | 08.13.26

Supreme Court Confirms Contractual Loss of Bargain Without Repudiatory Breach

English law has long treated the choice between terminating for repudiatory breach and exercising a contractual termination right as consequential. Under the Financings[1] causation principle, a party exercising a contractual right for a non-repudiatory breach could recover losses accrued to the date of termination — but nothing more. Loss of bargain was out of reach unless the breach went to the root of the contract. A practical workaround, confirmed in Lombard,[2] was to designate the relevant obligation as a condition, elevating any breach to repudiatory status, but that device carries significant strategic risk if the termination is later found to have been wrongful....