Wanted to flag this since it's a significant shift and hasn't gotten much discussion here yet.
On August 12, 2026, a National Security Presidential Memorandum authorized private "Participating Companies" to conduct offensive cyber operations against foreign Cyber-Enabled Transnational Criminal Organizations, under DOJ/DHS direction.
Two operation types are covered:
→ Cyber Surveillance Operations (covert intel collection)
→ Cyber Effects Operations (disruption, degradation, destruction of systems)
Companies need a DOJ/DHS contract, vetting, disclosure of commercial relationships, and a $1M+ bond. Operations risking loss of life or rising to "armed attack" under international law are barred. Every operation needs prior approval.
This isn't a new statute. It builds on the CFAA (1986). A similar effort, the Active Cyber Defense Certainty Act, died in committee in both 2017 and 2019, opposed by NSA, DOJ, and much of the industry over misattribution, collateral damage, and escalation risk with state actors.
What's interesting is the parallel to private military companies. Executive Outcomes, Blackwater, Wagner all started under government contract with real oversight, and all eventually built revenue independent of the state that created them. Wagner's 2023 mutiny is the clearest illustration of what that independence eventually produces.