Overview
On August 12, President Trump issued a National Security Presidential Memorandum (NSPM), titled Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, that directs the federal government to establish a program through which private US companies will be vetted and authorized to conduct cyber surveillance and cyber effects operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs).1
Issued pursuant to Executive Order 14390 issued March 6, Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens, and in support of President Trump's Cyber Strategy for America, the new program aims to shape adversary behavior by incentivizing private companies to identify and disrupt criminal cyber networks under the direction of the US government.
While the government's partnership with cybersecurity firms—for both defensive and offensive strategies—is nothing new, this announcement signals an increased interest in these tools and resources by the administration and the likelihood of additional regulation and controls to come.
Program Overview
The NSPM establishes the National Coordination Center (NCC) to develop, manage, and oversee a program authorizing participating companies to conduct cyber surveillance and effect operations against foreign CE-TCOs at the direction of the US government. The program will be co-led by executive directors from the Departments of Justice and Homeland Security who will administer the program and coordinate cyber operations among members of the intelligence community and across federal law enforcement agencies and relevant departments, including the Departments of State, Treasury, and Defense.
The NCC may authorize cyber operations by private companies on behalf of and under the supervision of the US government. However, the NCC is not authorized to approve cyber operations that may result in the loss of life or cause serious injury, or that may rise to the level of the use of force or armed attack under international law.
Once established, the program will authorize participating US to conduct two types of offensive cyber operations against CE-TCOs:
- Cyber Surveillance Operations: Intelligence-collection activities conducted through information technology infrastructure with the intent to remain undetected, involving unauthorized access to information systems.
- Cyber Effects Operations: Actions that manipulate, disrupt, deny, degrade, or destroy targeted information systems, networks, infrastructure controlled by those systems, or data residing on them.
The NSPM does not purport to create a general authorization for private companies to conduct independent hacking activity. Participating companies must be vetted and accepted into the program before they are authorized to conduct operations under the direction, control, and oversight of the US government. The NSPM frames the program "as part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement," which closely mirrors the Computer Fraud and Abuse Act's exemption at 18 U.S.C. § 1030(f). The NSPM further directs the NCC to ensure all operations are conducted in accordance with the Constitution, applicable law, and US international obligations, expressly including 18 U.S.C. § 1030.
The NCC may authorize operations that could affect US persons or otherwise implicate constitutional, federal statutory, or international-law obligations. As part of the review and approval process, DOJ will be required to ensure that all necessary authorizations, such as judicial warrants, were obtained prior to the operation.
If an operation exceeds approved parameters, including inadvertently targeting a US person, a US-based information system, or a system controlled by a US person, participating companies will be required to immediately stop the operation, implement minimization procedures, and notify the NCC, which will then notify DOJ. Companies must also immediately report to the NCC any imminent cyberattack against US critical infrastructure or any reasonable belief that an approved operation could result in the loss of life, serious injury, or other critical outcomes.
Who May Participate
The NCC must implement rigorous vetting requirements for participating companies, including demonstrated technical proficiency, a proven record of cyber-operations performance, adequate facility security, and personnel background checks. Approved companies will enter into a contract with either DOJ or DHS and may be required to maintain a bond or escrow of at least $1 million, subject to forfeiture for non-compliance with contractual obligations. The NSPM also directs the program to establish eligibility criteria that encourage participation by both large and small companies.
Participating companies may enter into commercial agreements with other private entities, as well as with state and local governments, to receive cyber threat intelligence to help identify CE-TCO targets. This intelligence-sharing framework may inadvertently implicate companies that share or receive cyber threat intelligence, even if they do not intend to participate in the program.
What Comes Next
More information about the program should be available by mid-October, when the operating procedures are due to be finalized. The program's executive directors, in coordination with the Homeland Security Council, must develop procedures to facilitate the review and authorization of cyber operations, including safeguards to ensure legal compliance and federal control and oversight.
Companies providing cybersecurity, threat intelligence, incident response, and technology services should monitor this guidance closely. Companies that possess or provide cyber threat information relevant to foreign criminal organizations should also take note, as the NSPM's commercial agreement provisions create avenues for sharing their threat data to participating companies.
Key Takeaways
The memorandum marks a notable increase in the federal government's efforts to use private-sector cyber capabilities against foreign cyber-enabled criminal organizations. For now, however, the memorandum creates a framework rather than a fully detailed operating regime. Some key workflow and implementation details may be absent from the public NSPM because they are addressed in the accompanying classified annex.
Because the NSPM contemplates commercial agreements through which private entities may provide threat intelligence to participating companies for target identification, companies should assess whether their sharing practices permit disclosure and downstream use of regulated data, customer telemetry, proprietary research, or information subject to contractual, regulatory, or cross-border transfer restrictions.
Until the mid-October deadline, companies should watch for forthcoming DOJ and DHS procedures that are expected to provide greater clarity on eligibility, the nature of the activities that may be authorized, and applicable legal and compliance obligations.
1 The NSPM defines a CE-TCO as "any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests, and that is not an institutional part of a foreign government or wholly operated under a foreign government's direction." A foreign group is presumed not to be government-controlled unless clear intelligence establishes otherwise — a presumption that theoretically broadens the universe of potential targets.