Trump Greenlights Private Tech Firms To Join The Fight Against Cybercriminals

A new presidential memorandum lets vetted private companies work alongside federal agencies on offensive cyber operations, but industry voices are split on whether it will work in practice.

President Trump has signed a national security presidential memorandum allowing federal law enforcement agencies to partner with private technology companies to execute offensive cyber operations against foreign criminal groups and international adversaries. In practice, this means vetted private sector tech firms will be permitted to work under direct federal supervision to propose, coordinate, and execute targeted cyber actions.

It’s a notable step for a government that has historically kept offensive cyber capabilities tightly within agencies like the NSA, FBI and CISA.

 

Industry Welcomes The Collaboration

 

Kyle Hanslovan, CEO and co-founder of cybersecurity company Huntress, welcomed the news, telling us, “Considering the rapidly accelerated sophistication of organised cybercrime and nation-state actors, close public and private collaboration is no longer an option. When you add the reality of AI-powered autonomous threats, the only viable solution is a stronger coalition of the willing, which we are eager to support.

One key pillar to the success of this programme will be the appropriate use of hyperscalers for their breadth of intelligence data and die-hard security research labs like Huntress for their agility and operational depth to truly disrupt adversaries. Another key pillar will be the deconfliction process to ensure private industry doesn’t interfere with the value of long term persistent access operations which often lead to public arrests and geo-political negotiations.

All-in-all, I’m proud to see the US Government push the boundaries when it comes to denying, degrading, and disrupting these measurable threats to democracy. If done correctly, I believe it will ultimately slow the illegal transfer of wealth and knowledge from Western civilisation.”

But Is It Realistic?

 

Not everyone is convinced the plan will run smoothly. Ben Bernstein, cybersecurity advisor at Huntress, offered a more cautious take, saying, “I’m all for expanding public-private cooperation because the government clearly can’t fight transnational cybercrime on its own, but I have concerns about how this actually plays out in the wild. When you look at the operational reality of green-lighting private offensive ops, you hit two massive roadblocks: collateral damage and bureaucratic lag.

Threat actors don’t launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network. That makes it practically impossible to “strike back” without taking out innocent bystanders. Plus, adversary infrastructure is incredibly ephemeral, often burning down in a matter of hours. By the time a vetted firm submits a target, sits through the DOJ and DHS deconfliction reviews, and finally gets a green light, they’ll be shooting at ghosts. Expecting government bureaucracy to move at the speed of modern ransomware operators is wildly optimistic.”

 

Risk Of Misuse

 

Tim Mackey, head of software supply chain risk strategy at Black Duck, went further, warning the policy could backfire entirely. He concluded, “Ignoring the reality that it’s difficult to identify the source of cybercriminal activity, endorsing private companies to conduct offensive cyberactivity is far more likely to increase criminal, and potentially nation-state, activity than deter it. Without careful governance and control, individuals with access to sophisticated surveillance technologies could easily abuse that access and engage in surveillance efforts for personal gain. Unfortunately, one message this memo does send to adversaries is, the US government needs private companies and their capabilities to defend against cyberattacks.”

Whether the initiative strengthens America’s cyber defences or opens the door to new risks will likely depend on how tightly the government controls which firms get involved and how quickly it can move once they do.