← All posts

Somebody Is Going to Ask Your Board About Hacking Back

On August 12, the President signed a memorandum with a classified annex that could change how an entire class of security vendor does business. Most boards have not read it. Most boards do not need to read it. But somebody in your organization is going to raise it in the next ninety days, and that conversation will go badly if the directors at the table think it is a technology question.

It is a liability question.

The document is called Expanding Capabilities to Combat Transnational Cyber-Enabled Crime. It directs the National Coordination Center to build a program authorizing vetted American firms — the memo calls them Participating Companies — to conduct cyber surveillance and cyber effects operations against foreign criminal groups, under federal control and oversight. Two co-executive directors, one designated by the Attorney General and one by the Secretary of Homeland Security, run the program. Participating Companies must contract directly with DOJ or DHS. And the operating procedures, once written, must authorize those agencies to require a bond or escrow of not less than a million dollars, forfeited if a company falls out of compliance with its contract.

Small detail worth noticing: the National Coordination Center was not created for any of this. It was established under an immigration executive order signed in January 2025.

The press called it hacking back. In my experience that phrase does real damage in a boardroom, because it makes people picture a revenge fantasy instead of a procurement decision with a ten-year tail.

What the memo actually does

Read the definitions section and the picture sharpens. Cyber Surveillance Operations, per the memo, "entail accessing such information systems without authorization from the owner or operator or by exceeding authorized access." That is the conduct the Computer Fraud and Abuse Act makes a federal crime, and a presidential memorandum cannot amend a criminal statute — only Congress can do that. So the memo threads a needle. Program activity is framed as occurring "as part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement," language that Mayer Brown's national security team reads as drawn from 18 U.S.C. § 1030(f), the CFAA's savings clause for lawfully authorized law enforcement and intelligence activity.

A company never owns that protection. It borrows it, and the loan lasts exactly as long as the government's direction and control holds up.

Two more passages deserve a second read. The memo defines its targets as foreign groups that are "not an institutional part of a foreign government or wholly operated under a foreign government's direction," then adds that a group "will be assumed" to meet that test "unless clear intelligence exists establishing such connection." The default assumption runs toward permission. Gary Corn, a former staff judge advocate at U.S. Cyber Command, put the practical problem to Cybersecurity Dive plainly: "A lot of the proxy actors don't operate wholly under a foreign government's direction. Foreign governments tap into these different non-state entities as they want."

The memo does draw one hard boundary. The program's executive directors may not approve any operation likely to cause loss of life or serious injury, or to rise to the level of a use of force or armed attack under international law. That is the floor. The memo says nothing about what happens if an approved operation produces one of those outcomes anyway. It requires only that a company notify the government the moment it develops a reasonable belief that one might.

There is also a question the memo leaves genuinely open, and it matters more than the headlines suggested. Section 2 delegates to those directors the authority to approve operations conducted "by personnel of their respective departments." Mayer Brown flagged the ambiguity: the companies may end up proposing targets and building capability while federal employees execute. Whether a vendor pulls the trigger or merely loads the weapon changes its liability exposure completely, and nobody will know until the operating procedures are published.

The part that reaches companies who never sign up

Here is the section nobody forwarded to your board. Participating Companies may enter commercial agreements with other private entities and receive from them "any threat information collected in the course of those entities' normal business activities" for the purpose of proposing operations to the government.

Your managed detection vendor collects threat information in the course of its normal business activities. So does your endpoint platform, your email gateway, your incident response retainer firm, and the forensics shop that imaged forty laptops for you last spring. Mayer Brown saw the same door from the other side, writing that these provisions "create potential pathways for selling such data to Participating Companies."

Nobody is alleging misconduct here. The memo is twelve days old, the operating procedures do not exist yet, no vendor has announced anything, and Mayer Brown's own read is skeptical that the program will increase the volume of operations much, since the government already contracts for cyber capability development and operational support. But the pathway is now written into federal policy, and your contracts were negotiated before it existed. If telemetry from your environment ends up inside a targeting package, and that operation touches a server in a third country whose government objects, you become a footnote in someone else's diplomatic incident. You would find out from a reporter.

What to ask this week

Four things, in this order.

Ask your CISO whether any of your security vendors have signaled intent to seek Participating Company status. Skip the legal memo. This is a phone call to your account team, made this week, before the sixty-day operating procedures land on or about October 11.

Ask your general counsel to pull the threat-intelligence and data-sharing clauses out of your five largest security contracts and read them against this memo. The question is narrow. Can our vendor route telemetry from our environment to a third party for a purpose that has nothing to do with defending us, and do we get notice when it happens?

Ask your risk officer what your cyber policy and your D&O tower say about intentional acts and government-directed operations. Insurers priced those policies for defense. Offense is a different actuarial animal, and the exclusions were drafted for a world in which this program did not exist.

Then, if anyone inside your own company floats participating — because the margins look attractive, or because a customer asked — treat it as a board-level decision on the order of entering a sanctioned market. The memo states plainly that it creates no right or benefit enforceable at law or in equity against the United States, and that it is subject to the availability of appropriations. The million-dollar bond is forfeiture money; it buys you nothing when a plaintiff arrives. And a foreign criminal organization that decides to retaliate against a private company will not be met with a military response on that company's behalf.

I spent years sitting with executives after the fact, walking back through decisions that looked reasonable in the moment and indefensible in a deposition. The pattern almost never changes. Nobody asked the boring question early, while asking was still cheap.

The operating procedures are due on or about October 11. Put the vendor call on the calendar before then.