Suzu Labs | Blog

Trump's Hack-Back Memo: Building the Civilian Component

Written by Mike Bell | Aug 13, 2026, 6:04:03 PM

The short version

On August 12, 2026, President Trump signed a National Security Presidential Memorandum (NSPM), “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” authorizing vetted private U.S. companies to conduct offensive cyber operations, hacking back, against foreign cyber-enabled transnational criminal organizations (CE-TCOs) under federal direction and oversight, run through the National Coordination Center (NCC). I have been publicly arguing for this model for the better part of a year, so I am not going to spend this piece debating whether the concept is sound. I believe it is.

What I am going to do instead is the harder thing: lay out how the civilian component of this program should actually be built. The memo gives the two Executive Directors 60 days to write the operating procedures that will govern vetting, targeting, approvals, and the protection of Americans. Those procedures do not exist yet. Every hard question about this program lives in that unwritten document, and the country gets exactly one first draft. Having spent two decades running offensive operations, first in uniform and now leading authorized offensive engagements for enterprise and government clients, I want to put a working blueprint on the table while the drafting window is open.

The offensive talent already exists in the private sector. What does not exist yet is the civilian machinery to direct it accountably. That machinery is what the next 60 days will decide.

The headline shorthand is already settled meaning that people are viewing these as cyber letters of marque, the digital descendant of the commissions that let privateers hunt enemy shipping under a government’s flag. Critics will reach for the other word — cyber mercenaries. Both labels miss what the document builds. A letter of marque was a standing license which allowed privateers to take the commission, go hunting, keep the prize. This program grants no standing license and pays no prize and every operation requires fresh written approval from two federal executive directors, the target set is restricted to criminal organizations rather than foreign states, and an operation that drifts out of scope must stop and report itself. Congress spent a decade flirting with looser versions of this idea under the banner of active cyber defense, the hack-back bills that never passed, and this memo is tighter than any of them. The privateering analogy is the door people will walk in through. The per-operation control is what should actually be paid attention to.

This did not appear out of nowhere. It is the end of an eighteen-month chain, and the clock that matters now started with the August 12 signature. One link in that chain has gone almost entirely unremarked in today’s coverage: NSPM-11, the June directive on artificial intelligence in the national security enterprise. I will come back to it, because read next to today’s memo it says something bigger than “companies can hack back”, and the bigger picture is what I think has the most opportunity to turn the tide.

What “the civilian component” actually means here

The program is co-led by the Department of Justice and the Department of Homeland Security, each designating an Executive Director, operating through the NCC. That places this squarely on the civilian side of American cyber power, distinct from what Cyber Command and the intelligence community do under their own authorities. The distinction matters more than most coverage will acknowledge, because the civilian side carries a different set of obligations:

  • Protecting U.S. persons and constitutional rights at every step of an operation, not as an afterthought.
  • Defending critical infrastructure while working with the private sector as a partner rather than treating it as a victim pool or a vendor list.
  • Keeping every operation below the threshold of armed conflict, deconflicted with the military and intelligence agencies who own the space above it.
  • Being accountable in ways covert programs are not: contracts, audits, written approvals.

Whoever runs the civilian component is not being hired to hack. They are being hired to make sure a powerful new capability operates inside American law and American values while still moving fast enough to hurt the criminal organizations it was built to hurt. That is a different job than offensive operations, and it is a different job than compliance. It requires someone who has lived on both sides.

Where I stand, and why that history matters

In November 2025, talking to TechNewsWorld about China’s espionage machine, I argued the U.S. was fighting the wrong way: adversaries run whole-of-society programs, and the U.S. needed to mirror that by “deepening partnerships between federal agencies and private sector cybersecurity firms that can serve as force multipliers in the cyber fight.” My closing line was that we need to treat companies in strategic sectors as partners, not just victims to be protected. Days later, commenting on Operation Endgame 3.0, I made the operational version of the same point: sustained disruption of the cybercrime ecosystem only works through a public-private collaboration model, because impact is measured in disruption cost and defender advantage, not permanence. And in December 2025, when the National Cyber Strategy first signaled a private-sector turn on offense, my stated concern was execution speed, whether the government could engage private talent fast enough to matter.

This memo is that argument written into national policy. I am glad it exists. But advocating for a capability obligates you to hold it to the standard you set when you asked for it. The rest of this piece is me doing that work: not a critique from the sidelines, but the operating model I would build if I were holding the pen.

How the hack-back program’s operating procedures should be written

Section 3 of the memo lists fourteen things the procedures must accomplish. Here is how I would build the load-bearing pieces. None of this is theoretical for me; it is the discipline any serious offensive firm already runs on every authorized engagement, scaled up to a national program.

Vetting: qualify operators, not just companies

The memo’s minimum standards (Sec. 3(a)(i)) name technical proficiency, proven performance, facility security, personnel vetting, and reliability. The mistake to avoid is vetting at the corporate logo level. Offensive capability lives in specific people and specific methodology, and a company’s marketing deck tells you nothing about either. The vetting rubric should require a demonstrated-operations portfolio reviewed by cleared assessors, named and cleared operators on every package rather than interchangeable staff, and an examination of the firm’s internal authorization discipline: how it scopes, how it documents, how it stops when something drifts. A firm that cannot show you its own rules of engagement in writing should not be trusted with the government’s.

The small-firm provision (Sec. 3(a)(ii)) is the sleeper clause of the whole memo, and it needs to be real rather than decorative. The last decade of offensive talent leaving government did not flow to three primes; it dispersed into small specialist shops. If the on-ramp requires prime-scale infrastructure just to apply, the program will have locked out the exact operators it was created to reach. Build a tiered entry: full participants for firms that clear every bar, and a sponsored track where a specialist operates on discrete tasks under the facility and contract umbrella of a full participant or the government itself, with the same per-operation approval discipline. Capability should gate participation. Overhead should not. The same tiering logic should govern the memo’s financial gate, a bond or escrow of at least $1 million, forfeited if a company violates its contract (Sec. 3(a)(iv)). Skin in the game is the right instinct, but let a sponsored specialist’s bond sit at the umbrella level so the gate screens for seriousness rather than balance-sheet size.

Per-operation approval: make the package do the work

The memo’s best feature is that both Executive Directors must give written approval before every single operation (Sec. 3(a)(xiv)). No standing licenses. To make that real at operational tempo, the standardized package (Sec. 3(a)(vii)) has to carry the entire decision: attribution evidence graded against a published confidence standard, blast-radius analysis covering every system the operation could plausibly touch in transit, a U.S.-person exposure assessment reviewed by DOJ before the directors ever see it, defined abort criteria, and the specific effect requested — nothing broader. If the package is rigorous, approval can be fast. If approval is slow, firms will quietly push for broader authorizations to compensate, and broad authorizations are precisely how a disciplined program becomes an undisciplined one. Speed and safety are not in tension here; they are both products of the same paperwork discipline.

Deconfliction: an intake, not a meeting

The classified annex on deconfliction (Sec. 3(a)(v)) has to function as standing infrastructure: a real-time intake where every proposed target is checked against DOJ, DHS, State, Treasury, War Department, and intelligence community equities before a package advances, with a hard hold anytime an equity flags. The oldest and most legitimate objection to private-sector operations is a company blundering into a live government operation. A quarterly coordination meeting does not answer that objection. A queryable, always-on process does.

Protecting Americans: minimization as muscle memory

The stop-and-report rule (Sec. 3(a)(x)) — halt, minimize, and notify the moment an operation touches a U.S. person or drifts out of scope — is the single provision that will make or break public trust in this program. The procedures should require every participating firm to demonstrate its minimization workflow live, during vetting, before its first operation is ever approved. Not a policy PDF. A demonstration: here is the trigger, here is who calls it, here is what gets preserved for the record, here is the notification hitting the NCC. In the military we never treated rules of engagement as a document; they were drilled until they were reflex. Civilian offensive operations deserve the same standard, because the first firm that hides an overreach instead of reporting it will hand opponents of this program everything they need to kill it.

The annual re-evaluation: keep the bar honest

Continued participation is reviewed at least yearly (Sec. 3(a)(xiii)). Use it. Firms that cut corners, pad attribution confidence, or treat disclosure obligations casually should exit the program before they generate the incident that discredits it. A program that never removes anyone has no bar. Treat it as continuous validation at the end of every engagement. Annual checks on the over compliance of each engagement.

AI in offensive cyber operations: kept on a human leash

There is a capability running through all of this that the memo mentions only in passing and the procedures cannot afford to treat as an afterthought — artificial intelligence. AI has already changed what a small team can do offensively. It enumerates infrastructure, correlates scattered intelligence into a coherent target picture, drafts and adapts tooling, and works through a target’s environment at a tempo a human crew cannot sustain. Any honest design of this program has to account for that, because the criminal organizations on the other end already do. Leaving AI out of the equation is not caution. It is preparing for the last war.

Here is where I expect Washington to take the wrong turn. The reflex will be to treat AI as something to procure from the foundational model providers — hand the hard problems to the big labs and let them bolt an offensive capability onto a general-purpose model. That is a mistake, and the evidence is sitting in public. Those same providers cannot reliably keep their own models inside the guardrails they built for a chat window. We watch the models get jailbroken, prompt-injected, and talked into behavior their makers swore was contained; we watch agentic versions take actions no one authorized. When OpenAI’s models hacked HuggingFace it was a clear sign that the correct precautions where not taken. A company that cannot keep its model in its lane inside a customer-support widget is not the company to trust with autonomous operations against a foreign target under color of federal authority.

The answer is not to keep AI out. It is to keep AI controlled. The right model is an agentic harness with a skilled operator in the loop on every consequential decision, the doctrine my firm has built our AI Offensive Security practice around, and what the trademark we hold, Hacker in the Loop, means in actual operation. The machine does the heavy, fast, tireless work: enumerate, correlate, propose, draft. A cleared human decides. The AI never earns the authority to cross a boundary on its own, not to escalate from surveillance to effect, not to reach into a system that was not in the approved package, not to act inside the United States. The memo already encodes this principle in Section 3(a)(xiv): a human authorizes every operation, in writing, before anyone acts. An autonomous agent proposing and executing its own operations is fundamentally incompatible with that rule. AI belongs inside the harness accelerating the operator. It does not belong holding the trigger. The human (read hacker) in the loop holds the responsibility at the end of the day.

And here is the part of today’s coverage that is missing entirely: the government has already committed itself to this model, in writing, twice. NSPM-11, signed June 5, requires that every AI system adopted across the national security enterprise be “reliable, robust, steerable, and controllable,” and its Accountability pillar keeps commanders, directors, and agency heads personally responsible for what AI does at every level of command. It even bars any commercial entity from retaining the power to disable, degrade, or materially modify a mission system without the government’s knowledge and approval. Nine weeks later, today’s memo requires written human approval before every operation — while its own Section 3(b) directs the NCC to “utilize automation to streamline Program elements wherever appropriate.” Put the two directives side by side: a controllable machine, an accountable human, authorization in writing before anything consequential happens. That is one doctrine, stated in two documents five months apart, and it is the same architecture I just described. The June memorandum puts the machine on a leash. The August memo hands the leash to a person. The drafters of the operating procedures should keep both documents on the table, because the government has now told us twice what it expects the relationship between the AI and the human to be.

That points straight at who should be building this. Not the model labs, who understand training runs but not rules of engagement, not deconfliction, and not what it means to be wrong about a target in a foreign country. The people who can build a controlled offensive AI harness and sit across the table from the intelligence community to make targeting and authorization calls are a narrow group: operators fluent in both the AI and the tradecraft, cleared to be in the room where those decisions happen, and disciplined enough to keep the machine on the leash. That is exactly the specialized depth the small-firm provision was written to reach, and exactly where the government has the thinnest bench of its own.

The hard problems, and what the civilian program office does about each

My analytical read of this memo flagged real risks. A leader’s obligation is to pair every risk with the control that manages it, so here is that pairing, summarized first and argued below.

The legal foundation is a theory. The program rides on the Computer Fraud and Abuse Act (CFAA) carve-out for “lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency” stretching to cover supervised private companies. That is untested, and an executive memo cannot override a statute. The civilian program office should do two things from day one: build a documented authorization chain of custody for every operation, written direction, named supervising officials, and contemporaneous records. If the theory is ever tested in court, the government’s supervision is a provable fact rather than a characterization; and push openly for Congress to codify the authority and liability protection. A program built on durable statute survives administrations. A program built on a memo is one signature from erasure, and every participating firm knows it. No one wants to be burned.

The state-actor presumption invites escalation. The memo assumes a criminal group is not state-operated “unless clear intelligence exists establishing such connection.” In the real world that line is deliberately blurry, and plenty of the worst crews operate with their government looking the other way or taking a cut. The targeting adjudication framework (Sec. 3(a)(vi)) is where this gets managed: require an affirmative state-nexus assessment on every package, not just a check for disqualifying intelligence, and route anything with an ambiguous nexus to the interagency rather than letting the presumption default it into the approval queue. The presumption as written leans toward action. Adjudication discipline is what leans it back.

Surveillance and effects blur in live operations. The memo’s surveillance definition includes breaking in and limited manipulation to stay hidden, which means “surveillance” here is a real intrusion, and the line between watching and acting is one of intent and degree. The procedures should treat any manipulation beyond the approved surveillance scope as a new operation requiring new written approval, full stop. Ambiguity in that seam is where operators freelance, and freelancing is what this entire architecture exists to prevent.

The intelligence funnel is wide. Participating companies can ingest threat data that other firms collected in their normal course of business. That is a powerful engine for proposing well-scoped operations, and it is also how a security vendor’s customer telemetry quietly becomes targeting input. The disclosure requirement (Sec. 3(a)(iii)) should be enforced with teeth, and the program should publish guidance on what participating firms owe the upstream customers whose data feeds the pipeline. Trust in the funnel is trust in the program.

Offense cannot outrun defense. My CTO, Denis Calderone, made this point in March 2026 and it still stands: if we lean into offensive cyber, defensive investment has to keep pace, and standing up this program in the same year the administration proposed cutting CISA’s budget by more than $700 million sends a mixed signal. The civilian component sits inside the Homeland Security apparatus. Its leadership should be a voice for resourcing the whole fight, not just the exciting half.

What leading the civilian component actually requires

By roughly October 11, 2026, the procedures will exist, and shortly after that, so will the first cohort of participating companies. Then the question becomes who runs this day to day — who the directors, the firms, and eventually Congress trust to hold the line. Based on everything above, the profile is fairly clear.

Start with someone who has actually conducted offensive operations under rules of engagement and a chain of command, because you cannot supervise work you have never done, and operators can tell within minutes whether the person across the table has been on the keyboard. They need to have run the accountability side too which means scoping, written authorization, documentation, and the discipline of stopping at the right time. The civilian component’s product is not access, it is trust. They have to understand how to put AI to work on offense and, more importantly, how to keep it on a human leash, because that capability is arriving whether the program plans for it or not. A clearance is non-negotiable; the deconfliction and targeting frameworks live in classified annexes, and the person running this has to live there with them. The private sector should regard them as one of its own rather than a regulator, because this program only works if the best firms want in. And they need a public record of straight talk about the program’s weaknesses as well as its promise, because the first time something goes wrong (and in operations, something always goes wrong) the person explaining it to the public needs credibility they banked before the incident, not after.

People matching that profile exist. There are not many of them, and most of the ones I know left government service in the past decade and are running the private-sector teams this memo was written to reach. That is not a problem for the program. It is the point of the program.

What the memo gets right

Credit where due, because the document is more carefully built than the failed hack-back bills that preceded it. Per-operation written approval with two independent sign-offs. A hard ceiling excluding anything lethal or war-triggering. Interagency deconfliction as a requirement rather than a courtesy. A mandatory stop-and-report obligation when operations drift. A target set restricted to criminal organizations precisely so the program stays below the threshold of armed conflict. And explicit room for smaller specialist firms, the provision I pushed for specifically, because the offensive talent that left government over the last decade is a national asset sitting in exactly those shops.

Whoever drafted this studied why every previous attempt died and answered the objections one by one. The design intent is genuinely good. The execution is a 60-day promissory note, which is why the drafting window matters more than the signing ceremony.

Bottom line

The United States just formally declared the private sector an offensive instrument of national power against cyber-enabled crime. I asked for that, publicly and repeatedly, and I stand by it. But the version I argued for treats private firms as cleared, disciplined, accountable partners operating inside real machinery and vetted operator by operator, approved operation by operation, deconflicted in real time, and drilled to stop and report the moment something drifts. That machinery is the civilian component, and it gets built in the next 60 days or it gets improvised afterward at much higher cost.

Building it well takes people who understand the whole problem covering the offensive craft, because the criminal organizations on the other end are genuinely good at this; AI as a force multiplier that has to stay under human command, because it is already on the field; and the civilian guardrails, because the program answers to American law and American citizens. I have spent almost twenty years working that exact seam, in uniform and out, and my firm and I intend to be useful to the people writing these procedures in whatever way serves the mission. The country finally built the on-ramp. Now it has to be worth driving onto.

Frequently asked questions

Is hacking back legal now in the U.S.?

Only inside this program. For everyone else, reaching into someone else’s systems remains a federal crime under the Computer Fraud and Abuse Act (CFAA, 18 U.S.C. 1030). The memo’s legal theory is that vetted companies operating “on behalf of and under the supervision of” DOJ or DHS fit the CFAA’s carve-out for lawfully authorized law-enforcement activity. That theory is untested in court, and state and foreign computer-crime laws still apply.

What is the National Coordination Center (NCC)?

The NCC is the body created inside the Department of Homeland Security apparatus by Executive Order 14159 in January 2025. Under the August 12, 2026 memo, it runs the private-sector offensive cyber program, overseen by two Executive Directors, one designated by the Attorney General and one by the Secretary of Homeland Security, who must jointly approve every operation in writing.

Can private companies conduct cyber attacks for the U.S. government?

As of August 12, 2026, yes, within strict limits. Vetted Participating Companies under contract with DOJ or DHS can conduct cyber surveillance and cyber effects operations against foreign criminal organizations, but only with per-operation written approval from both Executive Directors, and never anything likely to cause loss of life or rise to a use of force under international law. DO NOT JUST START HACKING BACK!

What is a CE-TCO?

A Cyber-Enabled Transnational Criminal Organization: a foreign criminal group that commits cyber-enabled crimes against the United States and is not an institutional part of a foreign government or wholly operated under a government’s direction. The memo presumes a group is not state-operated unless clear intelligence establishes the connection — a presumption that, as I argue above, needs an affirmative state-nexus check in practice.

What is the $1 million bond requirement for participating companies?

Section 3(a)(iv) of the memo lets DOJ and DHS require participating companies to post a bond or escrow of at least $1,000,000, forfeited if the company violates its contract. It is the program’s financial stake and unless the operating procedures tier it, a hard floor on which firms can afford to participate.

Are these cyber letters of marque?

It is the closest historical analogy, but the program is more controlled than privateering ever was. A letter of marque was a standing license with a prize at the end. This program grants no standing licenses and pays no prizes: every operation requires fresh written approval from two federal directors, targets are restricted to criminal organizations, and an operation that drifts out of scope must stop and report itself.

How does NSPM-11 relate to the hack-back memo?

NSPM-11 (June 5, 2026) governs artificial intelligence across the national security enterprise. It requires AI systems to be reliable, robust, steerable, and controllable, and it holds commanders, directors, and agency heads accountable for AI’s conduct through the chain of command. The August 12 memo requires written human approval before every private-sector cyber operation. Read together, the two directives describe one operating doctrine: machines provide speed and scale, and a named, accountable human authorizes every consequential action.

Primary source: Presidential Memorandum, “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime” (Aug 12, 2026)
Companion: White House Fact Sheet · EO 14390 (Mar 6, 2026) · NSPM-11, “Artificial Intelligence in the National Security Enterprise” (Jun 5, 2026)
Prior coverage: TechNewsWorld, Nov 2025 · Operation Endgame 3.0, Nov 2025 · SC Media, Mar 2026 · The National Interest, Jul 2026