The U.S. government is taking new steps to fight cybercrime. Recently, President Donald Trump approved a policy allowing vetted private U.S. companies to engage in cyber operations against certain foreign criminal groups. This policy aims to counter cyber-enabled crimes such as ransomware and phishing targeting Americans and U.S. interests.
Understanding the Memorandum
The National Security Presidential Memorandum introduces a framework for U.S. companies to conduct cyber operations. These operations are categorized into two main types:
- Cyber Surveillance Operations: Companies can collect secret intelligence from targeted computer systems, discreetly accessing these systems without the owner’s consent.
- Cyber Effects Operations: With federal approval, operations could manipulate or disrupt systems, deny access, degrade infrastructure, or destroy information controlled by targeted organizations.
Both types of operations require government acceptance and contractual agreements with either the Department of Justice (DOJ) or the Department of Homeland Security (DHS).
Government Direction and Oversight
Operations under this program must be supervised by federal authorities. Before a company can initiate an operation, it must receive written approval after executive directors from DOJ and DHS review the plans. Companies are subject to vetting based on technical skills and past operations. Large and small companies can participate if they meet proficiency standards.
Participating entities might be required to maintain escrow accounts, with penalties up to $1 million for contractual violations. However, the names of participating companies are yet to be announced.
Targeting Criteria
Targets are defined as Cyber-Enabled Transnational Criminal Organizations (CE-TCOs). These are foreign entities conducting cyber-enabled crimes against U.S. interests. The definition excludes organizations affiliated with any foreign government.
If operations unintentionally affect U.S. persons or systems, participating companies must halt immediately and alert the National Coordination Center, which in turn notifies the Justice Department. Legal review by DOJ is mandatory when constitutional, federal, or international law concerns are involved.
Implications for the Public
There’s no need for individual involvement or settings change with this program. It provides the government with a tool to address foreign cyber threats. Private companies will conduct these operations under strict government supervision.
As final operating rules are still under development, the focus remains on improving oversight. Personal cybersecurity practices continue to be crucial for protecting individual devices.
Key Takeaway: This initiative seeks to apply pressure on foreign criminal organizations by disrupting infrastructure or gathering intelligence with government oversight.
For further insights on cyber protection, visit CyberGuy.com, a trusted resource for tech tips and scams detection.

Data Centers Stir Controversy in Texas Amid Growth Boom
The Technology Rivalry: Trump’s Meeting with Xi and the AI Ecosystem Clash
Ways to Protect Your Finances from Cyber Threats
Interview with Nvidia CEO Jensen Huang: AI Outlook and Business Strategy
Concerns Rise Over Addictive Design of Sports Betting Apps
Seton Hall National Security Graduate Fellowship Provides Hands-On Experience