Overview
- The National Security Presidential Memorandum was signed on Aug. 12 and directs the Homeland Security Task Force’s National Coordination Center to build a program run jointly by co‑executive directors from the Department of Justice and the Department of Homeland Security who must give written approval before any operation proceeds.
- The program authorizes two types of activity — Cyber Surveillance Operations to covertly collect intelligence and Cyber Effects Operations to manipulate, disrupt, degrade, deny or destroy target systems — while forbidding actions likely to cause loss of life or rise to the level of armed force.
- Companies must enter contracts with DOJ or DHS, undergo rigorous vetting, post at least $1 million in bond or escrow, submit to annual reviews, and operate only under federal direction and oversight.
- Agencies have 60 days to publish detailed implementation rules and no participating firms or active operations have been publicly named; legal questions about liability under the Computer Fraud and Abuse Act, problems of reliable attribution, and risks of diplomatic escalation and harm to personnel remain unresolved.
- The memorandum builds on a March executive order and mirrors foreign precedents for state‑sanctioned private cyber work while aiming to counter billions in annual US losses to cybercrime, but experts warn the plan could create new legal, operational and international risks if procedures and safeguards are not tightly defined.