Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Government

White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs

Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements.

White House cybersecurity

A presidential memorandum issued on Wednesday expands federal capabilities against foreign cybercrime by establishing a program that allows vetted private US companies to conduct offensive and intelligence-gathering cyber operations under federal control.

Managed by the National Coordination Center (NCC), the program authorizes participating companies to execute ‘cyber surveillance operations’ and ‘cyber effects operations’ targeting foreign cyber-enabled transnational criminal organizations (TCOs). 

The initiative operates under co-executive directors designated by the Attorney General and the Secretary of Homeland Security, ensuring all operational actions remain under direct federal supervision.

To participate, US companies must undergo rigorous vetting and sign formal contracts with the Department of Justice (DOJ) or the Department of Homeland Security (DHS). These contracts may require a bond or escrow of at least $1 million, which will be forfeited if a company fails to comply with operational requirements. 

Participating firms may enter commercial agreements with other private entities to receive threat intelligence, as well as with federal, state, and other agencies to identify specific foreign threats.

The directive establishes clear boundaries for authorized activity. Cyber surveillance operations focus on covertly accessing systems to collect intelligence, while cyber effects operations cover actions that disrupt, degrade, or destroy adversary information systems and infrastructure. 

Advertisement. Scroll to continue reading.

However, the program explicitly bars operations that result in ‘critical outcomes’, which are defined as actions likely to cause loss of life, serious injury, or rise to the level of a use of force or armed attack under international law.

Operational controls require written approval from the executive directors before any company takes action on a cyber package. Proposed operations must undergo multi-agency deconfliction involving law enforcement, the Department of State, the Department of the Treasury, the Department of War, the DOJ, and the Intelligence Community. 

The White House noted that target selection is restricted to non-state criminal groups, though foreign entities are assumed to be independent of foreign governments unless clear intelligence proves otherwise.

The memorandum enforces strict safeguards regarding domestic targets and US persons. If a contractor discovers an operation has accidentally breached a US person or a domestic system, it must immediately cease operations and notify the government.

Related: US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’

Related: White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative

Related: White House Issues Memo to Bolster NSS Cybersecurity

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

John Opala has joined Ralph Lauren as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.