The White House Authorized Private Hack-Back. I Spent 11 Years Arguing Against It.
Table of Contents
On August 12, 2026, President Trump signed a National Security Presidential Memorandum directing the creation of a federal program under which vetted American companies may conduct covert access and destructive cyber operations against foreign criminal groups. It is titled Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.
Having read it several times, my view is that the United States has shot itself in the foot, and that most of the damage is not what the debate is about.
The argument so far is whether private firms should be allowed to hack back, and whether foreigners will get hurt. Go through the memorandum clause by clause, though, and the party that keeps getting hit is American. American security vendors lose foreign markets they cannot defend, because they cannot answer the only question a foreign buyer now has to ask. American prosecutors lose the distinction that made the indictments of Chinese contractor hackers land. American defenders lose the foreign CERT cooperation that produces most of the takedowns anyone celebrates. American operators pick up criminal exposure in allied countries that their own government cannot indemnify. And the argument that kept other governments from building programs exactly like this one was American policy, which no longer exists for anybody to use.
None of that is a case against acting. It is a list of costs that I do not believe anyone counted, and I would know, because for eleven years talking governments out of this was a large part of my job.
The administration answers most criticism by pointing at what this is not, and that answer is a good one. This is not hack-back in the form our industry has argued about since the late 1990s, and a breached company still cannot retaliate on its own account. Participating Companies act on behalf of, under the direction of, and under the supervision of the federal government, and every operations package needs written approval before anything runs. What the memorandum creates is a public framework for putting private firms inside a standing federal offensive pipeline.
That distinction answers the vigilantism charge, and it is also, as I will show, precisely what makes the resulting operations acts of the United States under the law of state responsibility.
Washington cannot have both.
About 25 of my 30+ years have been directly or indirectly in cybersecurity. For roughly 11 of them I ran CyberAgency, which did red teaming and penetration testing for NATO and NATO-aligned governments, defense, and the critical infrastructure operators inside them. Engagements ran 12-24 months and cost a million or two. We found our own zero-days, wrote the exploits, and I don’t remember a target we didn’t get into or a flag we didn’t capture. This was not the automated checkbox exercise that passes for penetration testing today.
The asks came from that. When you show a government what an attacker can do to its power grid or its classified networks, the people watching draw the next conclusion on their own. Why not point that capability outward – at the country’s adversaries, at criminal networks, at whoever is causing problems. Sometimes the request was narrower, tied to a specific breach with three-day-old forensics and a partial IP range. But the larger version, the one that kept coming back, was a standing national offensive capability built on what we could do, which we would then teach their own people to run.
We refused every time. More than just refused, we would sit with their lawyers and policy staff and explain why this was a bad idea, and they agreed. Not instantly, and sometimes not for a year, but eventually and without exception. This memorandum grants what we spent a decade talking governments out of, and it grants that without having the argument.
The memorandum builds on Executive Order 14390 of March 6, 2026, and routes everything through the National Coordination Center created by Executive Order 14159, an immigration enforcement order. It defines two categories of operation, requires vetting, deconfliction, reporting, and annual review, and authorizes Justice and Homeland Security to demand a bond or escrow of at least $1 million as a contract condition. As an exercise in institutional design it is careful work, which is why the places where it says nothing stand out.
Three things in the text produce effects the document never addresses. Its definition of a criminal organization is drawn so that groups working part-time for a foreign state fall inside the target class rather than outside it. Its control language supplies foreign governments with the exact legal test for attributing these operations to the United States. And every harm-mitigation example it gives is American, with no notification, remediation, or compensation standard anywhere for a foreign third party.
The Argument That Always Won
Everything started with attribution, and it was never a philosophical point. Three days into an incident you have an IP address, and an IP address is a lease on a machine that somebody else is very often renting, borrowing, or has stolen outright. Our attribution was better than most, because we had the budget and the months to spend on it, and it still wasn’t good enough to shoot on.
What persuaded people was the next step rather than the humility. If nobody can reliably say whose machine this is, then across enough operations somebody eventually hits a friendly nation. Say that in a room in a NATO capital and the temperature changes. Take one more step, to the case where the machine turns out to serve American interests, and the conversation is over. Nobody in those rooms wanted to explain that call afterwards.
The closer, when one was needed, was the United States itself. American policy ran the other way, and said so publicly. Washington argued in every multilateral forum that states should not use private proxies for offensive operations, that civilian infrastructure was off limits, and that responsible states exercised restraint. If nothing else in the meeting had worked, that did. However enthusiastic a minister was about the capability, no government wanted to build a private offensive program and then defend it to the Americans.
That argument no longer exists.
I could make it in 2006 and I cannot make it in 2026, because the country that supplied it has now written down the opposite. Anyone sitting in front of a policy committee in Ankara or Delhi or Riyadh next month has lost the strongest card in the deck, and the United States is who took it away.
The last of the three reasons has aged best. Offensive operations produce second-order effects that the people launching them do not model, cannot model, and generally don’t learn about until someone else reports them. NotPetya was aimed at Ukrainian tax software and did around ten billion dollars of damage worldwide; Maersk alone put its loss at $250–300 million and Merck at $870 million. Stuxnet was built to hit specific Siemens controllers at Natanz and its payload stayed dormant everywhere else, but the tool escaped anyway, was pulled apart by researchers, and its techniques passed into general circulation. Those were state programs with intelligence support and years of preparation behind them.
The memorandum does not simply hand companies a licence. It builds vetting, federal direction, package-by-package written approval, deconfliction, reporting, and annual review around them, and those controls are more than the debate usually credits. The question is whether they can compensate for effects the controls never touch.
The Idea Has a Literature, and It Lost Every Time
Michael Tanji wrote the foundational argument in “Buccaneer.Com: Infosec Privateering as a Solution to Cyberspace Threats,” in the Journal of Cyber Conflict Studies, volume 1, number 1, 2007. Tanji had been a division chief at DIA and came to the analogy from inside the framework that governs force: rules of engagement, targeting discipline, command authority. He drew the parallel to seventeenth-century privateering because the seas then were ungoverned and the crown’s navy was too small for the ocean it claimed.
The parallel is better than its modern users realize, and worse for them. Letters of marque authorized attacks on entire categories of shipping defined by flag, not on individually adjudicated targets. Privateers routinely took neutral vessels, and the resulting claims consumed decades of admiralty litigation.
Britain and France abolished privateering among the parties to the Declaration of Paris in 1856, and the reasons were mixed – naval supremacy, neutral trade, the politics of the moment. But the reading I find most persuasive is the least romantic one. The maritime powers had worked out that policing their own privateers cost more than the reach those privateers bought them. On that reading the institution died of accounting.
Florian Egloff made the modern case against it on Lawfare in November 2016, naming three risks: unnecessary escalation, reprisal against the privateers themselves, and the establishment of an international norm that works against American interests. He was answering Dave Aitel, who had argued the other way on the same site that year, so the debate has always had two competent sides and I would rather say so. Ronald Deibert published the most complete opposing analysis, The Perils of Privatized Cyberwarfare, on April 1, 2026. Deibert was writing against the March cyberstrategy and noted that it had stopped short of authorizing anything. Four months later the administration authorized it.
Sam Liles published his analysis of the memorandum on August 13, and he is right about the routing. Every structural choice sends this through law enforcement authorities rather than Title 10 or Title 50, which keeps it clear of the congressional notification architecture built to provide accountability for the use of force abroad.
He also notes that Section 2(b) commits the Program to comply with 18 U.S.C. 1030 while Section 4(d) defines Cyber Surveillance Operations as accessing systems “without authorization from the owner or operator or by exceeding authorized access,” which is the statute’s own definition of the crime. That reads as a contradiction and I do not think it is one. Section 1030(f) provides that the statute “does not prohibit any lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency of the United States.” Section 2(a) of the memorandum describes the Program as “part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement.” That is the exemption, quoted back almost word for word.
The drafters saw the CFAA coming. The harder question is what the exemption is doing. Justice’s own guidance on the parallel exemption in the identity-fraud statute says “lawfully authorized” means functions approved in accordance with an agency’s rules, and does not excuse an officer who has “gone on a lark of his own.” Two questions follow. What existing authority makes a destructive effects operation against a foreign system lawfully authorized? And how far does an agency exemption reach a private contractor executing one? The memorandum asserts compliance without publishing the theory that would make the assertion true.
And he found the fact that should have ended the debate. Representative David Schweikert introduced the Scam Farms Marque and Reprisal Authorization Act in August 2025, invoking Article I, Section 8, Clause 11, which is the clause that actually grants this power and grants it to Congress. The bill went to House Foreign Affairs and sat there. The constitutional route was open, someone had already walked partway down it, and the administration took a different one.
The Case For It Is Better Than Its Critics Admit
Americans lost more than $20.8 billion to cyber-enabled fraud in 2025 by the administration’s count. Mutual legal assistance doesn’t function against the jurisdictions where this activity concentrates, and it isn’t close to functioning. Requests to some capitals go unanswered for years, and requests to others are answered by warning the target.
The pig-butchering compounds in Myanmar, Cambodia, and Laos operate at industrial scale with the tolerance or participation of local authorities, and the people running them are not deterred by an indictment they will never be served. Takedown operations that do work, like the seizures Microsoft’s Digital Crimes Unit has run through civil process, reach infrastructure rather than organizations – and the organizations rebuild in weeks.
A decade of doing it the polite way has produced a $20 billion annual transfer from American consumers to organized crime. Serious people who once opposed private offensive action have changed their minds looking at that number, and dismissing them as vigilantes is both lazy and false.
So my disagreement isn’t with acting. It’s with a mechanism whose own text guarantees that the bill goes to people who never chose it, and which damages the cooperative machinery that currently produces most of the wins we actually get.
Two Definitions and a Non Sequitur
Section 4(c) defines a Cyber-Enabled Transnational Criminal Organization as a foreign group conducting cyber-enabled crime against American interests “that is not an institutional part of a foreign government or wholly operated under a foreign government’s direction.”
The word doing the work is “wholly.” A group that takes state tasking part of the time and freelances the rest isn’t wholly operated under government direction, so it doesn’t fall outside the definition – which places it inside the program’s target class. That is a definitional finding, not a claim that any particular operation would be lawful.
None of that is hypothetical. In March 2025 the Justice Department indicted employees of i-Soon, the Chinese contractor that hacked at the direction of the Ministry of State Security and the Ministry of Public Security and also on its own initiative, selling access to compromised inboxes on a price list.
i-Soon is the archetype of the modern threat, and under Section 4(c) i-Soon is eligible. Not by mistake, not in the fog, but by definition, with perfect intelligence about exactly what it is. The same reading could encompass Russian or Iranian groups that combine state tasking with private criminal work, which is a large and growing category.
There is a second cost buried in that, though it is diplomatic rather than legal. American indictments of contractor hackers rest on substantive offences – unauthorized access, wire fraud, identity theft – and this memorandum does not legalize any of that. What it does is blur a distinction Washington depends on when it explains those cases: contractor intrusions under an asserted public-law mandate on one side, contractor intrusions for an intelligence service or private profit on the other. The distinction remains legally real, but it has become much harder to explain from a podium, and naming and shaming was one of the few instruments here that produced any behavioural change.
The second sentence of 4(c) then adds a presumption: a group is assumed not to be governmental “unless clear intelligence exists establishing such connection.” Liles reads this as raising the odds of hitting a state-connected target by accident, and it does. But the accident is the smaller problem, because the definition has already put most state proxies inside the target set on purpose.
The way I used to win this argument was to describe attribution failure as a risk that accumulates until it produces a state-to-state incident. Section 4(c) converts that risk into a design decision. The part-time proxy is not something an operator might hit in the fog. It is a category the memorandum has declared open.
The memorandum then describes its own controls in language that cuts against it. Operations are “exclusively conducted on behalf of and under the supervision of the Federal Government.” Participating Companies act “under the control and oversight of the Federal Government.” They are “authorized to conduct cyber operations under the direction of the United States Government.” That language appears four separate times. It is doing political work, and the work is answering the charge of vigilantism.
It is also, almost word for word, the test in Article 8 of the International Law Commission’s Articles on State Responsibility. Conduct by persons acting on the instructions of, or under the direction or control of, a State is attributable to that State. Article 5 covers entities empowered by domestic law to exercise elements of governmental authority, and Tallinn Manual 2.0 applies both to cyber operations by non-state actors.
The harder the administration insists on control, the more cleanly these acts become acts of the United States. There is no version of this program where Washington gets the reassurance and the deniability both.
It has bought the first by writing the second away, in public, in a document its adversaries’ lawyers have already printed.
Section 2(b) then produces a sentence I have read a dozen times and still find remarkable. The NCC shall conduct Program activities in accordance with the Constitution and all other applicable laws “and international obligations of the United States, including section 1030 of title 18, United States Code, thereby ensuring that Participating Companies are acting under the control and oversight of the United States Government.”
Complying with the Computer Fraud and Abuse Act does not ensure anything about federal control. The two halves of that sentence have no logical relationship, and a clause carrying this much weight should not need to be read twice to find out that it argues nothing.
The commitment to international obligations creates a harder problem for the Program than the CFAA does. Whether unauthorized access to a foreign computer breaches sovereignty is genuinely unsettled – states divide on it, and the published American position rejects the idea that customary law prohibits every non-consensual cyber operation. Effects are the harder case: damage, loss of function, coercive interference with governmental functions. The memorandum promises compliance and publishes none of the consent, countermeasure, or threshold analysis the promise depends on. The program is also built around non-state criminal groups, while the clearest countermeasure doctrine responds to wrongful acts attributable to states. Nothing in the public text says which justification is being relied on.
What Breaks
The effects reach much further than the operations that cause them. These are structural, meaning they arrive whether or not a single operation goes wrong. Ten are developed in the sections that follow, five more get a paragraph each, and five are handed to another writer who covers them better.
| Consequence | Mechanism |
|---|---|
| Threat-intel sharing contracts | Section 2(a)(iii)(A) makes commercial threat intel a named input to the operations pipeline. Foreign CERTs that assume their indicators may feed a billable operation will share less, later, with fewer people. |
| US security vendors become unverifiable | Any “private United States company” may be a Participating Company, and EDR agents with kernel access are indistinguishable from implants by design. Foreign buyers who cannot verify will assume the worst. |
| Crypto inventories become target lists | Regulators compel cryptographic discovery, and the output ranks an organization’s weakest cryptography by exploitability. Section 2(a)(iii)(A) covers “threat information” and never defines it. |
| Vulnerabilities stay unpatched | The memorandum never mentions disclosure. Some likely participants both sell security software and run operations, giving them customers who need a flaw fixed and a contract that values it unfixed. |
| The sector reprices, then consolidates | Non-US buyers accelerate replacement, international revenue falls, dependence on government contracts rises, and joining the program becomes more attractive. The exclusion produces the participation that justifies it. |
| Foreign third parties face a coverage fight | Every harm-mitigation example in Section 3(a)(x) is American. Lloyd’s state-backed exclusions give an insurer its strongest argument once the victim’s own government attributes the damage to a state, which here is the United States. |
| No de-escalation channel exists | The memorandum creates no incident-notification route to an affected state and names no counterpart for a foreign ministry that wants an answer quickly. |
| Trafficked people absorb the effects | UN estimates put roughly 220,000 people in the compounds as of 2023. Degrading a compound’s connectivity reaches the people at the terminals before it reaches anyone who owns it. |
| Operators carry personal criminal exposure abroad | A US indemnity does not reach foreign jurisdictions. National laws implementing Directive 2013/40/EU, the UK Computer Misuse Act, and equivalents criminalize unauthorized access whatever government authorized it. |
| Approval capacity lags proposal volume | Section 3(a)(xiv) puts two people on every package while Section 3(b) instructs the NCC to automate. The procedures must say which judgments are non-delegable. |
| Attribution gets noisier for everyone | Defenders cannot separate vendor telemetry from operations. Adversary campaigns get misattributed to privateers and the reverse. |
| The scope widens | Cyber-enabled crime is elastic, and the contract structure creates a paid constituency whose revenue grows with the definition. |
| Evidence may not survive court | Unauthorized access by a contractor invites suppression fights and can taint parallel prosecutions. |
| Security research gets caught in it | Foreign governments lose any reliable way to tell a researcher examining a C2 from a privateer preparing an operation. |
| Allied services restrict what they share | A Participating Company can burn a partner’s access. No allied service appears in the Section 3(a)(v) deconfliction list. |
The Sharing Stops
Commercial threat intelligence is now a named input to an offensive operations pipeline. Section 2(a)(iii)(A) permits Participating Companies to enter commercial agreements with other private entities and to receive from them “any threat information collected in the course of those entities’ normal business activities.” The stated purpose is in the same sentence: “for the purpose of proposing responsive cyber operations to the NCC.”
Under Section 3(a)(iii) those relationships get disclosed to the NCC. Nothing requires that a source entity be told whether its indicators supported an operations proposal, and there is no consent or provenance rule for information passing through two or three commercial intermediaries before it arrives.
Nearly everything that works in this field depends on informal cooperation between people who assume the intelligence goes to defense. Shadowserver sinkholes and notifies, FIRST mediates between national CSIRTs that have no diplomatic relationship, and vendors trade indicators across borders on a handshake. Foreign hosting providers pull criminal infrastructure voluntarily, in hours, because the researcher asking is understood to be nobody’s instrument – which is the backbone of most takedowns, and entirely a function of trust.
The 2015 UN Group of Governmental Experts wrote a norm about exactly this. States should not use authorized emergency response teams for malicious international activity. Several likely Participating Companies run or contract national CSIRT functions outside the United States. Once a European or Asian CERT has to assume that indicators shared with an American vendor may be converted into a billable operations proposal, the rational move is to share less, later, and with fewer people. None of us will watch that happen in real time. We’ll see the takedown numbers fall a year or two later and attribute it to something else.
The Agents Come Out
An enterprise endpoint agent exposes most of the primitives an implant would want. Kernel-level driver, continuous telemetry to vendor-controlled infrastructure, remote script execution by design, and an update channel the vendor pushes unilaterally. None of that is a criticism – it is what EDR is, and it is why EDR works. Signed code, attestation, documented control planes, and audit logging do distinguish a well-run agent from an implant, which is exactly why the assurance question is answerable in principle.
It also means that for a CISO in Frankfurt or Riyadh or Singapore, the question “could my endpoint vendor be a Participating Company” is the same as asking whether there is a US-government-directed implant with kernel privileges on every machine they own. Under this memorandum that question has no answer.
In principle, but not yet in practice. The program requires vetting, contracts, and disclosure to the NCC. It imposes no public secrecy obligation and does not bar a participant from telling its customers anything – but neither does it create a customer-facing disclosure duty, an attestation mechanism, or any way for a buyer to verify an answer. Whether the contracts and the operating procedures require silence, permit disclosure, or support customer assurance is unknown, because none of those documents exist publicly.
For a risk manager, unanswerable plus catastrophic resolves to assume yes.
The memorandum also hands foreign procurement offices a criterion they did not have before. Eligibility runs to “private United States companies” – not companies with poor security practices, not companies with unclear ownership, but American ones. Nationality is now a defensible line to draw in a tender, where previously drawing it invited the charge of protectionism.
How clean that line turns out to be is an open question, because the memorandum never defines the term. Incorporation, principal place of business, ownership, ultimate control, and which subsidiary signs the contract could all give different answers, and the operating procedures may settle it. Section 3(a)(ii) does require eligibility criteria that admit smaller firms alongside large ones, so no buyer can reason that this is confined to a handful of household names.
I have written before about why I moved my own firm’s center of gravity to Europe, and the sovereignty argument I was making then was about supply chains and control of the stack. This is the sharper version of it.
The hard case isn’t the standalone EDR contract that comes up for renewal in eighteen months. It’s Defender, which arrives bundled inside E5 and entangled with identity and device management, so a European CISO who follows this logic to its conclusion isn’t swapping a security vendor – they’re unwinding Microsoft. Some will start, and the ones who do will find that ownership screens and headquarters screens diverge, since Sophos is British and owned by Thoma Bravo, an American private equity firm. The first wave of sovereignty clauses will get this wrong in both directions before it gets it right. This is a third-party risk problem that existing vendor governance cannot assess, because the disclosure it depends on is unavailable by design.
The Inventory Is the Target List
Cryptographic discovery hands over something worse than access. An endpoint agent gives an operator a way into the estate. A cryptographic inventory gives them a ranked map of what is weak once they are inside, built by the defender, at the defender’s expense, and kept current on a compliance schedule.
Consider what these tools actually produce. They crawl the estate and enumerate every place cryptography is used: which algorithms, which key lengths, which certificates expire when, which protocol versions are still negotiated, which systems cannot be upgraded without replacing hardware, and which business processes depend on each one. The output is a cryptographic bill of materials, and its entire purpose is to rank exposure so that migration can be sequenced.
Rank exposure for defense and you have ranked it for offense. The same document that tells a bank which payment path to fix first tells anyone else which payment path to attack first, and it arrives with the dependency map explaining why that path cannot simply be switched off.
None of this is discretionary. NIS2, DORA, CNSA 2.0, the American federal memoranda, and the European roadmap all require organizations to know where their cryptography lives and to plan its replacement against published deadlines. A cryptographic inventory is not a product a CISO chooses to buy. It is a deliverable a regulator demands, on a clock, and the tooling market for it is heavily American.
The shelf life is what makes it different from telemetry. Endpoint data ages in weeks. A cryptographic inventory describes what an organization will still be running in five years, because the systems hardest to migrate are precisely the ones that stay. That makes it the natural companion to harvest-now-decrypt-later collection, because it tells a collector which traffic to store today and which key material to wait for.
The memorandum never mentions cryptographic data, and it does not need to. Section 2(a)(iii)(A) already permits a Participating Company to receive from other private entities “any threat information collected in the course of those entities’ normal business activities.” Threat information is nowhere defined. A map of which of a foreign organization’s systems are cryptographically weakest, and how long they will stay that way, is difficult to place outside that phrase.
So the vendor question has a sharper version than the one about endpoint agents. It is not whether an American product might one day run an operation against you. It is whether the inventory of your weakest cryptography, which a regulator is compelling you to build anyway, should be produced by a vendor whose government has just reserved the right to conduct operations through American firms.
Vulnerabilities Get Kept
The memorandum never mentions vulnerability disclosure. There is no reference anywhere in it to the Vulnerabilities Equities Process, to coordinated disclosure, to a retention limit, or to any reporting obligation for a flaw a Participating Company discovers. Section 3(a)(iii) requires Participating Companies to disclose their commercial relationships to the NCC. Nothing requires them to disclose a flaw they find in software the rest of the world is running.
Deibert raised the hoarding problem in his April essay. Companies conducting offensive operations discover vulnerabilities, and their operational incentive is to keep them. What this memorandum adds is a conflict inside a single firm rather than between a firm and the government.
Consider what some Participating Companies are likely to be. Not all will sell enterprise software – offensive-security boutiques, cloud providers, and telecoms are all plausible – but some will. A firm in that group sells security software to enterprises, which is how it acquired the telemetry and the reverse engineering talent that make it worth vetting. It now also runs operations. When its researchers find a serious flaw in a widely deployed platform, that company has customers who need the flaw patched and a federal contract that values it unpatched. Both obligations are real, both are commercial, and the memorandum provides no rule for choosing between them – or any acknowledgement that a choice exists.
The VEP was built to weigh exactly this trade-off, and it was built on the assumption that every party holding the vulnerability is part of the government. The public memorandum does not place contractor-discovered vulnerabilities inside the VEP, and does not require the operating procedures to do so either. There is no equities review specified for a private balance sheet – and no obvious place to put one.
Section 3(a)(xi) comes closest to addressing the problem and misses it. It requires immediate notification if a Participating Company discovers an imminent cyber-attack against United States critical infrastructure. That covers an attack already underway, and says nothing about the unpatched flaw that would enable one, and nothing at all about infrastructure outside the United States.
The 2015 GGE norms include one on this too. Norm 13(j) asks states to encourage responsible reporting of ICT vulnerabilities and to share what is known about remedies. A program that pays commercial firms to find vulnerabilities and gives them a reason to sit on the results is the working definition of the opposite.
The Sector Reprices
A US security vendor’s international revenue now depends on something it is not allowed to discuss. Liles works through the equity-market side of this in detail: analysts will ask on earnings calls, no company can answer, and unquantifiable participation risk becomes a discount applied across the listed sector. That mechanism is real and I would not improve on his account of it.
The demand side is larger and slower, and it does not need a single operation to occur.
Buyers outside the United States are not waiting for evidence. A German or Emirati or Singaporean CISO who accepts the argument two sections up has to act on a risk they cannot resolve, and the only available action is replacement. That starts with the deepest integrations, because those are where the exposure is worst, which means endpoint agents, identity, and network inspection rather than peripheral tooling. It will be slow, expensive, and partial – and defensible in front of a board in a way that inaction is not.
The effect then compounds, because falling international revenue increases a vendor’s dependence on domestic and government contracts. Greater dependence on government contracts makes participation in the program more attractive, or at least harder to refuse. More participation confirms the assumption that drove the buyers away. The exclusion manufactures the participation that justifies the exclusion, and nothing in the memorandum’s design interrupts that loop.
The risk also transfers down to the customer, which is what turns this from an investor question into a procurement one. A company that deploys a suspected participant’s agents may be judged by a foreign adversary to be part of the same apparatus, and its infrastructure becomes an acceptable route to the vendor. A CISO does not need to believe their vendor participates. They need to price the possibility that someone else believes it.
Acquisition diligence gets harder at the same time. Until the operating procedures and the model contract are public, a buyer asking whether a target participates cannot know whether a “no” is reliable, whether a refusal to answer is contractual or merely cautious, or what a warranty on the point would actually be worth. A European acquirer of an American security firm could inherit an operational relationship with a foreign government along with the customer list, and auditors face the same uncertainty.
None of this is a prediction. It is the scenario that follows if buyers behave the way risk managers usually behave when a risk is severe and unverifiable.
Nothing in the memorandum’s design interrupts that loop, and nothing in the operating procedures is required to either.
The Insurance Fight Starts
Every harm-mitigation example the memorandum gives is American. Section 3(a)(x) requires a Participating Company that discovers operational activity exceeding an approved operation’s parameters to stop, minimize, and notify the NCC. The trigger is exceeding the approved parameters, and the memorandum introduces its three scenarios with the words “such as” – unintentional targeting of a United States person, of an information system residing in the United States, or of a system under the control of a US person. Those three are examples rather than the whole of the obligation. The narrower reading is the accurate one and it is the one I will argue from.
They are, however, the only examples given, and the public text carries no foreign-party notification standard, no remediation rule, no compensation mechanism, and nothing at all about harm caused to a third party while an operation stays comfortably inside its approved parameters. Section 3(a)(ix) puts constitutional review on the same American footing. Section 5(c) is the boilerplate that closes every executive order, and it creates no enforceable right or benefit under this memorandum, which is not the same thing as extinguishing remedies that might exist somewhere else. In practice, a Dutch dental practice whose web server has been used as a command-and-control node will not find one of those easily. It will also find that the party best placed to explain what happened is contractually pointed elsewhere.
The scenario I used to close arguments was an operation that turns out to have hit American interests, and Section 3(a)(x) is that scenario written up as a procedure. Somebody in the drafting took the objection seriously enough to build a control around it. They then wrote every example in one nationality. That is either an accident of drafting or a statement about whose harm generates paperwork, and the memorandum gives no way to tell which.
That isn’t a corner case. Criminal operations run overwhelmingly on mainstream infrastructure, on AWS and Azure and OVH and Hetzner and consumer routers, and a large share of what gets described as criminal infrastructure is stolen. The C2 is a compromised WordPress instance, and the staging server belongs to a Brazilian logistics company that has no idea. In those cases the target of a Cyber Effects Operation isn’t a criminal’s asset sitting near an innocent one – it is the innocent party’s own machine, and the operation victimizes them a second time.
Then the coverage fight starts. Following Lloyd’s Market Bulletin Y5381, standalone cyber policies carry state-backed cyber attack exclusions built on the LMA5564 to LMA5567 model clauses, and in the compliant wordings the primary attribution factor is the determination of the government where the affected system physically sits.
The London market wrote those clauses because of NotPetya. Merck and Mondelez both went to court against insurers who invoked old war exclusions, Merck won, and the industry concluded it could not price a risk whose boundary a judge would draw after the fact. The clauses exist to move that boundary into the contract. Who attributes an attack, and on what evidence, is now a term of the policy rather than an argument to be had afterwards.
I would not claim the exclusion fires automatically. Wordings vary, some turn on war or significant impairment or geography rather than state backing as such, and the LMA is explicit that application depends on the wording, the governing law, and the facts. What explicit American direction changes is the probability distribution. A Dutch or Brazilian government attributing damage to the United States hands an insurer the strongest reservation-of-rights letter available. The victim’s recovery then moves from a claims process into litigation it did not choose and may not be able to afford.
The memorandum does not convert insured loss into uninsured loss by operation of law. It makes uninsured loss substantially more likely for foreign third parties, through a mechanism the London market built to protect itself from Russia.
Nobody designed that. It is what happens when two systems written for different purposes meet in someone else’s server room.
The Memo Builds No De-escalation Channel
A foreign government does have someone to call: Washington. That follows from the attribution argument above, and I would rather concede it than pretend otherwise. Embassies, State, Justice, and Homeland Security do not disappear because a contractor executed the operation.
What the public memorandum never creates is a dedicated route for using any of them. There is no incident-notification channel to an affected state, no rule requiring evidence preservation while governments talk, and no procedure for telling an innocent foreign owner that their infrastructure was touched. Nor is there a named counterpart on the American side for a foreign ministry wanting an answer in six hours rather than six weeks. State-to-state escalation is survivable, when it is survivable, because of machinery built over decades. None of that machinery is wired into this program.
That leaves the injured state with options that all point at the company rather than at the government directing it. It can seize assets in country, charge local staff, revoke operating licences, or exclude the firm from procurement. It can also answer in kind against corporate infrastructure that sits on the same cloud providers and the same networks as everyone else’s. Florian Egloff made the escalation argument in 2016 and identified the mechanism precisely. A capable adversary tracing an intrusion back to American infrastructure cannot distinguish a contractor from the government, so it plans against the worse reading.
Deterrence theory assumes the actor bearing the cost is the actor making the decision. Here the decision belongs to two Executive Directors in Washington and the cost falls first on shareholders, employees, and customers who were not consulted and cannot decline. Whatever that arrangement is, it is not deterrence, and none of the models anyone has built for managing cyber escalation describe it.
The company cannot de-escalate on its own either. It has no standing to negotiate with a foreign ministry and no authority to halt an operation the government approved. Section 3(a)(xi) requires it to notify the NCC when things go wrong, and the notification runs inward. There is no provision anywhere in the public document for anyone talking to the other side.
The People in the Compounds
The targets of this program hold trafficked people under armed guard. The scam operations this program is aimed at are not server racks. They are physical sites, and in August 2023 the UN Human Rights Office reported that at least 120,000 people in Myanmar and around 100,000 in Cambodia were being held in conditions where they were forced to run these scams. Volker Turk’s phrasing was that the phenomenon has two sets of victims. A follow-up report in February 2026 documented torture, arbitrary detention, and sexual violence inside those compounds.
A Cyber Effects Operation that degrades a compound’s connectivity does not reach the people who own it. It could expose the people at the terminals to retaliation for missed quotas, in facilities where quotas are enforced with violence. That is a foreseeable harm an operational planner would have to model, and nothing in the public text requires anyone to. I don’t know how to weigh that against the $20.8 billion, and I distrust anyone who finds the answer obvious in either direction.
What I do know is what the memorandum does with the question. Section 4(b) defines a Critical Outcome as an action likely to cause loss of life or serious injury, or to rise to the level of use of force or armed attack under international law. Section 2(a)(i) forbids the Program Executive Directors from approving anything likely to produce one. And then the document stops. It does not say whether such operations are prohibited within the Program altogether or reserved for some higher authority, and it names nobody who could approve one. Liles reads the classified annex as handling the escalation, which is the generous inference. The public text leaves the question open.
The Operators Can’t Travel
A US indemnity does nothing about a criminal file opened in the jurisdiction where the targeted infrastructure sat, or in a third country whose networks the operation transited. National laws implementing EU Directive 2013/40/EU on attacks against information systems, the UK Computer Misuse Act, and comparable statutes across allied states criminalize unauthorized access, and none of them contain an exception for American law enforcement authorization.
The practical consequence is mundane and, for the individuals concerned, severe. Companies will maintain internal lists of countries their operators should not visit. Foreign warrants, arrest on transit, extradition requests, and sanctions listings are all live possibilities for engineers doing a job their employer’s contract described as lawful. None of it is automatic. An Interpol Red Notice is a request built on a national warrant and subject to review, immunities and defences may apply, and extradition is a process rather than a switch. But the exposure is personal, it is not indemnifiable by Washington, and the people carrying it will be the ones with the least say in whether an operation runs at all.
There is a staffing consequence underneath that. Section 3(a)(i) requires personnel vetting, and vetting at this level pushes toward American-citizen-only teams. Our field has a chronic shortage of senior operators and has solved it for twenty years by hiring across borders. This program asks the best firms to build their most sensitive capability out of the narrowest available talent pool, and to do it during a shortage.
Two People, Every Package, and an Instruction to Automate
The memorandum mandates individualized human review in one section and instructs the program to automate in the next. Section 3(a)(xiv) requires the Program Executive Directors to review every cyber operations package and issue written approval and direction before any action is taken. Every package. Two people, one from Justice and one from Homeland Security, individually reviewing each proposed operation against a target set that Section 4(c) has just defined expansively.
Section 3(b) then directs that the NCC “shall likewise utilize automation to streamline Program elements wherever appropriate.”
Those two provisions are not textually incompatible. Automation could handle intake, deduplication, deconfliction lookups, templating, and reporting while the co-directors keep the decision, and “wherever appropriate” leaves room for exactly that reading.
The governance risk survives the charitable reading. The proposing side scales with tooling and with whatever a Participating Company can generate from the commercial threat feeds that Section 2(a)(iii)(A) invites it to buy. The approving side is two people with other duties. Approval regimes I have watched degrade, in banking and in sanctions screening, degraded in this shape: individualized review as the stated control, volume growth as the operating reality, automation introduced to close the gap, and the review surviving in name.
So the operating procedures need to answer three things the memorandum leaves open. Which judgments are non-delegable. What the co-directors must personally read before signing. And how approval quality gets measured as volume grows, by someone who is not the NCC.
Five More, Briefly
Each of these is a consequence of the program’s design rather than of any operation going wrong, and each could carry a section of its own.
Attribution gets noisier for everyone. Defenders worldwide will see activity originating from American commercial infrastructure and have no way to separate vendor telemetry from an operation. Real adversary campaigns get misattributed to privateers, privateer operations get misattributed to criminals, and confidence falls on every side including the American one. Attribution was already the weakest joint in this field – it is the argument I spent a decade making – and this program adds noise to it by design.
The scope widens. Cyber-enabled crime is an elastic category, and the adjacent ones are intellectual property theft, sanctions evasion, and state-tolerated hacktivism. Every widening is a small step from the last. What makes the drift structural rather than merely possible is the contract-and-bond arrangement, which creates a paid constituency whose revenue grows with the definition and who will be the most expert voices in any room where the definition is discussed.
Evidence may not survive court. Material obtained through unauthorized access by a contractor invites suppression motions and can taint parallel prosecutions built on lawful process. Section 3(a)(ix) provides for Department of Justice review where a US person is implicated, which addresses the constitutional question and not the evidentiary one. A program justified by the failure of law enforcement could end up producing fewer convictions than it prevents.
Security research gets caught in it. The takedown community functions because researchers are understood to be nobody’s instrument. Once some American private actors are authorized to conduct unauthorized access against foreign systems, a foreign government examining traffic from an American research group has less reason to accept the benign explanation, and less incentive to look for one. Organizations like Citizen Lab and Shadowserver do this work lawfully and carefully. What changes is the prior a hostile government brings to it, and the researchers with the least to do with any of this are the ones who will absorb that.
Allied services restrict what they share. No allied service appears in the Section 3(a)(v) deconfliction list, which covers federal law enforcement, State, Treasury, Justice, the intelligence community, and what the memorandum calls the Department of War. A Participating Company sitting on a box where GCHQ or the BND already has access can burn that access without knowing it exists. The likelier consequence is quieter. Allied services will now assume American commercial security vendors are potentially operational, and adjust what they tell the vendors as well as what they tell Washington.
What Else Breaks
I was partway through writing this when I found Sam Liles’s Buccaneers at the Keyboard, published on August 13. It is the most thorough public analysis of the memorandum I have seen, and it covers ground I have not. Rather than compress his work into worse versions of it, here is what he does that I do not, with a recommendation to go and read him. I have not independently verified the legal propositions in these five; they are his analysis, summarized, and worth your attention on that basis rather than mine.
- Securities disclosure has no clean path. A listed Participating Company owes investors a material risk factor under Regulation S-K and owes its contracting agency silence. It cannot satisfy both, and Liles walks through why neither choice is survivable.
- Directors carry it personally. Approving entry into a program that invites retaliation from foreign intelligence services is a business judgment a court could find irrational, and D&O carriers may treat the non-disclosure as grounds to void coverage.
- The revolving door turns faster. The officials approving these contracts today will be executives at Participating Companies in two years, while CYBERCOM and NSA lose operators to the firms the government is paying to replace them.
- Export control is unaddressed. Tools built under NCC contract have commercial value, intrusion software is dual-use under the Wassenaar Arrangement, and the memorandum says nothing about what happens when a Participating Company sells a variant of a government-funded capability abroad.
- Defence contractors inherit it. CMMC, DFARS, and ITAR obligations can be triggered by an incident originating in a vendor’s participation the contractor had no way to discover, and the insurer’s war exclusion is waiting on the other side of it.
He also develops three things I have deliberately left alone because his versions are better. The East India Company works as a closer analogy than privateering. The comparison to private military contractors shows cyber to be worse on every dimension that made them problematic. And his reading of the classified annex asks what its existence tells foreign intelligence services about everything that was not published.
What the United States Gave Up
For twenty years American diplomats did the unglamorous work of building norms of responsible state behaviour in cyberspace, and they did it well. The 2015 Group of Governmental Experts report produced eleven voluntary norms that remain the high-water mark of multilateral agreement on this subject. Five of them run directly into this memorandum.
Norm 13(c) says states should not knowingly allow their territory to be used for internationally wrongful acts using ICTs. Norm 13(f) says they should not conduct or knowingly support activity contrary to their international obligations that intentionally damages critical infrastructure. Norm 13(i) says they should seek to prevent the proliferation of malicious ICT tools and techniques. Norm 13(j) says they should encourage responsible reporting of vulnerabilities and share what is known about remedies. Norm 13(k) says they should not use authorized emergency response teams for malicious international activity.
A program that funds commercial firms to develop offensive tooling, run effects operations against infrastructure whose co-tenants are unknown, give those firms a paid reason to sit on vulnerabilities, and convert defensive intelligence relationships into targeting inputs isn’t in tension with those five. It does the things they were written to stop states doing.
The timing compounds it. The Open-Ended Working Group closed in July 2025 with a consensus final report creating a permanent UN Global Mechanism, which held its organizational session on 30–31 March 2026 and its first substantive plenary from 20 to 24 July 2026. Getting 193 states to consensus on anything in the First Committee is hard, and this took twenty-one years across six GGEs and two working groups. Nineteen days after that first substantive session closed, Washington published a document that runs against the position it argued inside the room.
Every mid-tier power with a growing cyber capability now has a template and an American precedent, and states across the political spectrum can point at this memorandum while building their own version. What the precedent does not travel with is the American oversight architecture, such as it is. The vetting, the written approvals, the deconfliction and the annual review are not what other governments will be copying.
I have a personal stake in this one. The reason those programs mostly did not get built is that people in my position could always end the meeting with American policy. That worked because it was true and because the consequences were real. It is now false, and the officials who will make this argument in the next few years have to make it without the thing that made it win.
The Sixty-Day Test
Section 3(a) gives the Program Executive Directors 60 days from signature to establish the operating procedures. That lands on October 11, 2026, and no operation may be approved until they exist. Almost everything argued above turns on questions the memorandum leaves to them, which makes that document, not this one, the thing to read when it appears.
Eight questions would tell you most of what you need to know:
- What authority makes each category of operation lawful? Does the CFAA exemption reach a contractor conducting destructive effects?
- What counts as a “private United States company” – incorporation, control, ownership, or the signing subsidiary?
- What may a participant tell its customers? Is there an attestation a buyer could rely on?
- Can customer telemetry, response channels, or update infrastructure be used operationally? What separation controls forbid it?
- How do contractor-discovered vulnerabilities enter an equities process, and on what clock?
- What notification, minimization, remediation, and compensation rules apply to innocent foreign systems and their owners?
- How is allied access deconflicted, and who speaks to an affected government after an incident?
- Which approval judgments are non-delegable? What audit trail survives, and who outside the NCC reviews approval quality?
The memorandum does not require the operating procedures to be published. If they stay classified, every question above becomes a matter of trust in an institution that has just told the world it intends to run offensive operations through commercial firms.
What I Told Them Then
What I told those clients was that they couldn’t name the second target. They knew who they thought they were hitting. They could not tell me who else was on that box, who else depended on it, or what would still be broken in a week. That was true when the requester was a bank with a good forensics team and a real grievance, and it’s true now that the requester is a company with a federal contract.
None of the arithmetic has changed. Attribution three days into an incident is a guess wearing a hostname. Infrastructure is shared and increasingly it is stolen. Second-order effects are discovered rather than predicted. Nobody has solved any of that since 1999, and the memorandum doesn’t claim to have. It routes around the problem by extending its protections to Americans and staying silent about everyone else, which is a decision about who counts rather than a solution to anything.
What did change is that the argument stopped being available. This idea lost on the merits every time it was put in front of people qualified to judge it, and I was in some of those rooms. Schweikert’s bill is the same story in a different building: the constitutional route was open, the argument would have had to be made in public, and the administration took a route where it didn’t. Nobody beat the case against private offensive cyber.
They went around it.
The operating procedures are due on October 11, 2026. The first status report goes to the Homeland Security Advisor and the National Cyber Director on February 8, 2027, both of them inside the executive branch that wrote the program, and the memorandum requires neither document to be public. If you buy security software from an American vendor, you have until roughly then to decide what you are going to assume, and an assurance gap is not the same as proof that any particular vendor participates.
Disclosure: I ran CyberAgency, and Applied Quantum, the firm I run now, moved its center of gravity to the EU in 2026 and advises European and Middle Eastern clients on technology sovereignty. The argument below about foreign buyers replacing American security products runs in the direction of my commercial interest. Read it accordingly.