Infosecurity

White House Opens Door for Private Firms to Join Offensive Cyber Strikes

Published

on

A New Era for US Cyber Policy

The White House has quietly changed the rules of engagement in cyberspace. A new National Security Presidential Memorandum (NSPM), signed by President Donald Trump on August 12, now allows federal law enforcement to team up with private companies for offensive cyber strikes against foreign threat actors targeting the US.

This isn’t a small tweak. It’s a structural shift that brings Silicon Valley and other private firms directly into the business of hacking back — something the US government has long avoided.

The memorandum builds on an Executive Order from March that told agencies to take “rigorous actions” against cyber-enabled crime. Now, the private sector gets a formal seat at the table.

Why the Private Sector? The Rationale Behind the NSPM

The White House argues that American companies are the most innovative in the world, but their capabilities have been “historically underutilized” in the fight against cybercriminals. That’s a fair point. Many private firms already possess world-class threat intelligence and offensive capabilities — they just haven’t been allowed to use them against adversaries.

The numbers make the case compelling. American consumers reported losing more than $20.8 billion to cyber-enabled crime in 2025. Nearly three-quarters of US adults (73%) have experienced some form of online scam or attack. The status quo isn’t working.

So the NSPM creates a framework where private companies can enter into agreements with other firms and government bodies — federal, state, and local — to gather threat intelligence and propose cyber operations designed to disrupt transnational crime groups.

How the Program Will Work

The Homeland Security Task Force’s National Coordination Center (NCC) will run the show. Two Executive Directors — one from the Department of Justice, one from the Department of Homeland Security — will oversee operations.

The memorandum promises “rigorous procedures” for reviewing and conducting “limited” cyber operations. These won’t be free-for-alls. All operations will be directed by the US government, and the program must comply with the Constitution, US laws, and international agreements.

Still, the language is deliberately broad. “Every available tool” should be deployed against transnational cyber threats, the White House insists.

Industry Reactions: Welcome, Caution, and Fear

The cybersecurity community is split. Some see this as a long-overdue evolution. Others see a recipe for disaster.

Chris Wysopal, co-founder of Veracode, called the policy a “big shift” on X. His take: “Not exactly ‘hack back,’ but definitely a major expansion of the private sector’s role in offensive cyber operations.”

That’s the optimistic read. The pessimistic one comes from people who’ve actually done this work.

The Attribution Problem

Nick Carr, technical director for the Microsoft Threat Intelligence Center (MSTIC) and a former chief technical analyst at CISA, knows the terrain better than most. He ran the global cybercrime and ransomware intelligence team for almost four years.

His warning is blunt: attribution in criminal operations is extremely difficult. “Few organizations can repeatably do it right (including certain gov agencies),” he wrote on X. “People are regularly and willingly wrong on pretty important incidents.”

That’s a chilling thought when private firms are about to get a license to strike.

Escalation Risks

Dr. Lukasz Olejnik, an independent cybersecurity and privacy researcher, raised another red flag. He warned that authorizing private firms to destroy cyber-controlled infrastructure could hit state-linked systems. That raises the risk of interstate escalation — a cyber skirmish turning into a diplomatic crisis or worse.

The line between criminal groups and state actors is blurry. Ransomware gangs often operate with tacit state approval. A private company aiming at a criminal server might accidentally take down something connected to a foreign government. Then what?

Global Context: The UK’s Playbook

The US isn’t alone in this direction. The UK created its National Cyber Force (NCF) in 2020, and in 2023 published principles on how it uses offensive capabilities. The UK’s stance: these tools are rarely deployed, and only when other responses aren’t better suited.

That’s a more cautious approach than what the NSPM describes. The American version leans harder into private sector involvement, which is a distinctly US twist on the model.

What This Means for Businesses and Individuals

For everyday Americans, the practical impact is unclear — for now. The program is still being set up. The NCC has to establish procedures, and companies need to opt in.

But the direction is unmistakable. The US government is signaling that cybercrime is a national security threat worthy of offensive action, and that private companies will be part of the solution.

If you’re a business owner, this could mean new opportunities to collaborate with federal agencies on threat intel. It could also mean new risks if your company gets drawn into operations with unclear legal boundaries.

For the broader cybersecurity landscape, this is a paradigm shift. The question isn’t whether private sector offensive action will happen — it’s whether the guardrails will hold.

Related: how to protect yourself from cybercrime and the latest ransomware trends.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version