Before private companies hack back, the government needs to set the rules
Before private companies hack back, the government needs to set the rules
On Aug. 12, the White House signed a national security presidential memorandum directing the National Coordination Center to use vetted U.S. companies in cyber operations against foreign transnational criminal organizations under federal oversight.
The rationale is understandable. The FBI received more than a million cybercrime complaints in 2025, with reported losses reaching $20.9 billion — a 26 percent increase from the year before.
Some of the most consequential details of the new program have not been written yet. The National Coordination Center’s executive directors have 60 days to establish operating procedures, and no operation can be approved until those procedures are in place.
For years, hacking back has been debated as a question of capability. If we know where cybercriminal infrastructure is, and have the ability to disrupt it, why shouldn’t we? The harder questions begin once offensive cyber operations move from government agencies into private hands.
The appeal is obvious. Cybercriminals move quickly and exploit jurisdictional boundaries, so giving vetted companies more latitude could bring expertise and speed. But speed is only one measure of success. Before the first operation is approved, the National Coordination Center needs clear standards for collateral risk, targeting, intelligence preservation and accountability.
Cyber infrastructure rarely exists in neat, isolated boxes, which makes unintended consequences one of the most immediate issues the center will have to address. If you take down a virtual private server........
