The White House’s latest cybersecurity initiative has generated both interest and concern across the cyber community. On August 12, 2026, President Donald Trump signed a National Security Presidential Memorandum titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” establishing a framework that allows vetted private-sector companies to participate in government-directed cyber operations against foreign transnational criminal organizations (TCOs).
The administration argues that cybercrime has become so pervasive and costly that the United States needs to leverage the innovation, expertise, and speed of the private sector alongside traditional government capabilities. Critics, however, warn that the initiative raises difficult questions about oversight, accountability, international law, and the potential consequences for cybersecurity professionals operating globally. Among those expressing scepticism is Jake Williams, Faculty Member at IANS Research, former National Security Agency (NSA) operator, and a well-known cybersecurity expert with extensive experience in incident response, cyber threat intelligence, malware analysis, and offensive operations.
A new model for cyber operations
According to the White House, the memorandum is designed to strengthen efforts against cyber-enabled criminal organizations responsible for ransomware attacks, phishing campaigns, financial fraud, sextortion schemes, and impersonation scams targeting Americans. The framework directs the Homeland Security Task Force’s National Coordination Center (NCC) to establish a program through which approved private-sector companies can support cyber operations under government direction and oversight.
Administration officials argue that this approach acknowledges an important reality: many of the most advanced cyber capabilities today reside within the private sector rather than government agencies. The memorandum explicitly states that American businesses possess innovative capabilities that have historically been underutilised in combating cybercrime. Supporters see the initiative as a practical response to increasingly sophisticated criminal enterprises operating across multiple jurisdictions. Cybercrime losses reported by Americans exceeded $20.8 billion in 2025, according to figures cited by the White House. Yet the proposal has immediately prompted questions about where the boundaries lie between public and private cyber operations.
Williams is among those unconvinced that sufficient safeguards exist. His concern is not whether cybercrime should be challenged aggressively. Rather, it is whether involving private actors in offensive cyber operations creates legal and operational risks that have not been fully considered. One issue involves the potential status of cybersecurity personnel operating internationally.
Williams argues that Americans participating in such programs could face allegations of acting as non-uniformed combatants while travelling abroad. Even if accusations are unfounded, he notes that merely creating such a program could provide adversarial governments with a convenient basis for making those claims. This concern is particularly relevant because attribution in cyberspace is notoriously difficult. Cyber operations often occur across multiple jurisdictions, through compromised infrastructure, and under conditions where evidence may be incomplete or disputed. Critics fear that cybersecurity professionals conducting legitimate work abroad could find themselves exposed to geopolitical complications far beyond their control.
Another question concerns how targets will be identified and selected. The memorandum establishes a framework for government-approved cyber operations but leaves many operational details to implementation procedures and a classified annex. Williams argues that if intelligence agencies already possess sufficient confidence that a target is a transnational criminal organization, existing legal authorities and government cyber operators may already be capable of taking action.
This raises a practical question: what gap is the new programme actually intended to fill? Legal analysts have similarly noted that many implementation details remain undefined, including operational approval processes, participant vetting standards, oversight mechanisms, liability allocation, and compliance requirements. Supporters contend that these details will emerge through subsequent guidance. Critics worry that the absence of publicly available information makes it difficult to evaluate the proposal’s safeguards.
The initiative reflects a larger shift occurring across cybersecurity. Governments worldwide increasingly recognize that defending critical infrastructure and responding to cyber threats requires close collaboration with industry. Private-sector firms often possess threat intelligence, incident response capabilities, and technical expertise that rivals or exceeds those available within some governmental agencies. The distinction between public and private cybersecurity has therefore become increasingly blurred.
What makes the new White House memorandum unusual is the apparent expansion beyond defensive collaboration toward active operational participation under government supervision. This has prompted some commentators to draw comparisons with historical “privateering,” where governments authorized private ships to act against enemy vessels. While supporters argue the analogy reflects pragmatic innovation, critics warn that cyber operations carry unique legal and geopolitical complexities.
Questions regarding accountability, operational transparency, legal authority, target selection, and international implications will need convincing answers if the programme is to gain broad support within the cybersecurity community.
What does this mean for Canada?
Although the programme is American, its implications extend well beyond U.S. borders. Canada maintains deep cybersecurity, intelligence, defence, and law enforcement partnerships with the United States through arrangements including the Five Eyes intelligence alliance. Canadian businesses, infrastructure operators, financial institutions, and government agencies also face many of the same cyber threats cited in the memorandum.
For Canadian cybersecurity companies, the initiative may create new opportunities to participate in cross-border threat intelligence and operational collaborations. It could also accelerate discussion about the appropriate role of private companies in national cyber defence. However, it also raises regulatory and legal questions.
Canada has traditionally approached cybersecurity through a combination of government leadership, public-private cooperation, and legal oversight. Any move toward private-sector participation in offensive cyber activities would likely generate substantial debate regarding accountability, jurisdiction, privacy protections, and international law. Canadian organizations operating internationally may also need to pay close attention to how evolving American cyber policies affect attribution, risk assessments, and international business activities.
