On August 12, 2026, the White House issued a National Security Presidential Memorandum, Expanding Capabilities to Combat Transnational Cyber-Enabled Crime (“Memorandum”), directing the creation of a Program to marshal private-sector capabilities against Cyber-Enabled Transnational Criminal Organizations (CE-TCOs),1 i.e., any foreign, non-government groups that engage in cyber-enabled crime to attack US interests, companies, individuals, or the US government itself. Common examples of current cyber-enabled criminal activity include ransomware, phishing or vishing, fraud, business email compromise, sextortion, economic espionage and/or profiling, and impersonation scams. The Memorandum builds on Executive Order 14390 and reflects a policy judgment that the private sector’s “scale, speed, and capacity” give the United States an offensive cyber advantage that has been “historically . . . underutilized.”
The Memorandum tasks the National Coordination Center (NCC) with creating, managing, and maintaining the Program, under which authorized “Participating Companies” may conduct “Cyber Surveillance Operations”2 and “Cyber Effects Operations”3 against CE-TCO's. The Program grants participants no authority of their own: each operation is undertaken solely for the Federal Government and under its supervision, relying entirely on the government’s own legal authorities. Oversight rests with two co-Executive Directors, one drawn from the Department of Justice (DOJ) and one from the Department of Homeland Security (DHS).
Key takeawaysThe Memorandum reflects the administration's policy of using “all instruments of national power, including the innovative capabilities of the private sector,” to combat cyber-enabled crime. It contemplates a framework in which authorized private companies may conduct surveillance and disruptive cyber operations against foreign criminal networks, subject to federal direction and oversight. Participation is voluntary and limited to companies that are vetted and authorized under the Program.
Technology, cybersecurity, cloud, healthcare, financial-services, transportation, energy, manufacturing, and telecommunications companies are the most likely candidates to be invited to participate or to be asked to share threat information. The operative details of the Program—including eligibility and vetting criteria, the scope of permitted operations, and the procedures governing them—are to be developed by the Program Executive Directors and the Homeland Security Council, and are not fully set out in the public documents. Companies that may engage with the Program should monitor for the forthcoming implementing procedures.
In more detailCreation of the Cyber Disruption ProgramThe Program is housed in the NCC, which was created under section 6(d) of Executive Order 14159 (January 20, 2025) and sits within the Homeland Security Task Force. The Memorandum tasks the NCC with building and running a Program that authorizes Participating Companies to conduct Cyber Surveillance Operations and Cyber Effects Operations against CE-TCOs. Participants receive no freestanding authority of their own; every operation is carried out for the government and under its supervision, drawing on the government’s own legal authorities. The two co-Executive Directors—one designated by the Attorney General, the other by the Secretary of Homeland Security—must approve each operation in writing beforehand, and neither may greenlight one likely to cause a “Critical Outcome.”4
Entry into the Program has conditions. A prospective participant must enter a contract with DOJ and DHS, post a forfeitable bond or escrow of no less than USD 1 million, pass a searching vetting review, and be reassessed annually. Every operation, per the memorandum, must square with the Constitution, the Computer Fraud and Abuse Act (18 USC. § 1030), and US obligations under international law, and any inadvertent targeting of a US person or US-based system triggers mandatory minimization and notice. The Program Executive Directors and the Homeland Security Council have 60 days to issue implementing procedures and must deliver an initial status report within 180 days. Notably, the Memorandum leaves existing statutory information-sharing regimes intact—neither expanding nor overriding the Electronic Communications Privacy Act (ECPA), the Stored Communications Act (SCA), or the Cybersecurity Information Sharing Act of 2015.
Two aspects of the Program are handled through a classified annex instead of the public text. The first is operational: precisely how missions are carried out and how they are coordinated among the various agencies that have an interest in them. The second is adjudicative: the process for deciding which targets are legitimate, structured to confine operations to genuine CE-TCOs and to avoid interfering with other government equities.
Safeguards
The Memorandum contemplates some safeguards:
The Program overall contemplates that whatever is done through it remains subject to the government’s control, oversight, and legal authority.
Many outstanding questions remain regarding the Program, including:
Baker McKenzie can help clients evaluate potential risks and legal issues around Program participation as the implementing guidance takes shape.
1 § 4(c). The Memorandum defines a CE-TCO as a foreign criminal group engaged in cyber-enabled offenses targeting the United States, US persons, or US interests, excluding entities that are part of, or entirely controlled by, a foreign government.
2 § 4(d). The Memorandum defines a Cyber Surveillance Operation as covert, unauthorized access to an information system for intelligence-gathering purposes. The definition also encompasses limited manipulation or temporary interference necessary to facilitate information collection, so long as the activity is not intended to cause physical consequences or materially impair system functionality.
3 § 4(a). The Memorandum defines a Cyber Effects Operation as cyber activity designed to alter, disrupt, deny access to, degrade, or destroy information systems, networks, data, or infrastructure that depends on such systems.
4 § 4(b): A “Critical Outcome” is defined as anything resulting in the loss of life or serious injury; or be considered a use of force or armed attack under international law.
Explore More Insight
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | United States: DOJ Renews Expedited Merger Review | 0 | 10 | 29-07-2026 |
| 2 | United States: FCC Adds Inverters and Robotics to Covered List | 0 | 10 | 12-08-2026 |
| 3 | United States: FTC Proposes Enforcement Framework for Personalized Pricing | 0 | 10 | 26-08-2026 |
| 4 | United States: SEC Proposes Proxy Framework Overhaul | 0 | 10 | 25-09-2026 |
| 5 | United States: SEC Proposes Optional Semiannual Reporting | 0 | 10 | 14-05-2026 |
| 6 | United States: SEC Proposes Public Offering and Reporting Reforms | 0 | 10 | 27-05-2026 |
| 7 | United States: Early Court Approval for AI Document Review | 0 | 10 | 10-08-2026 |
| 8 | United States: Court Reinforces Duty to Respond to Congressional Subpoenas | 0 | 8.1 | 21-08-2026 |
| 9 | United States: Non-Compliance with Client Agreements Risks SEC Attention | 0 | 21.11 | 03-09-2026 |
| 10 | United States: Third Circuit Revives Algorithmic Pricing Case | 0 | 10 | 03-08-2026 |