Private contractors cleared for offensive cyber missions
A national security memorandum lets vetted firms join offensive cyber operations targeting foreign transnational criminal groups under DHS and DOJ oversight.
Atlas Newsdesk ·

A national security memorandum has created a new route for private companies to participate in offensive cyber operations directed at foreign transnational criminal organizations, officials said. Under the policy, any activity must be conducted under federal oversight and direct authority, with the Department of Homeland Security and the Department of Justice positioned as the central agencies for operational control.
Officials said participating firms could be authorized to conduct cyber surveillance and “effects” missions. Those missions can include actions intended to disrupt or destroy information systems, provided the work is carried out under DHS and DOJ authority rather than as independent private activity.
Federal oversight rules and eligibility requirements
Homeland Security
The memorandum sets conditions that companies must meet before taking part in any operation. Officials said firms seeking to participate must complete a government vetting process in advance, establishing eligibility before any cyber activity is proposed or executed. The framework also includes a financial requirement. Participating companies must maintain at least a $1 million bond or escrow, according to the memorandum’s terms described by officials. Officials framed the structure as a way to keep offensive operations firmly tied to federal direction. The memo’s language, as described, places DHS and DOJ at the center of both authority and oversight, aiming to prevent private entities from conducting offensive cyber action outside government control.
Coordination center created for planning and information flow Coordination center created for planning and information flow Homeland Security The memorandum establishes a coordination center intended to support information sharing and to route proposed cyber operations between private participants and government agencies, officials said. The center is designed to provide an organized mechanism for proposals and coordination when multiple agencies and outside operators are involved. Officials said the framework is intended to connect private entities with agencies at all levels of government. In practice, the coordination center is expected to help manage joint planning and information flow during time-sensitive cyber activity, where overlapping responsibilities and rapid decision-making can complicate execution. Expanded role beyond defensive cybersecurity, with defined limits Officials portrayed the memorandum as an expansion of the private sector’s role in national security beyond defensive cybersecurity services. They described the authorization as a meaningful change in how offensive cyber capabilities could be applied against foreign transnational criminal organizations, while emphasizing that the government would retain direct authority. The memo’s scope remains limited in two key ways described in the framework: its focus is restricted to foreign transnational criminal organizations, and operations must proceed under federal supervision. Officials said the extent of private participation will depend on the vetting process and on how proposed actions are approved through the new coordination mechanism. Legal and operational questions remain open Legal experts have raised concerns about the potential consequences of bringing private firms into offensive cyber activity, even with federal oversight. Risks cited include escalation in international digital conflict and unintended collateral effects when disruptive or destructive actions affect interconnected systems.
Experts also pointed to the practical difficulty of maintaining tight coordination across multiple agencies and private actors during live operations. How the coordination center will function in fast-moving incidents, and how oversight will be enforced in practice, were highlighted as uncertainties.
Officials have not detailed how frequently the authority will be used or how operational decisions will be documented, reviewed, and audited. Those implementation questions remain unresolved even as the memorandum outlines the basic permission structure and guardrails for private participation.