National Security & Defense
What is the Presidential Action, explain the Purpose in layman’s terms in 10 lines.
This presidential memorandum aims to strengthen the United States’ fight against international cybercriminal groups that threaten American citizens and businesses. It recognizes that these criminal organizations use the internet to commit fraud and other crimes that hurt the economy and national security. To better combat these threats, the government will partner with trusted U.S. private companies that have advanced cyber capabilities. These companies will be authorized to conduct cyber surveillance and offensive cyber operations under strict federal government control. This collaboration leverages the private sector’s innovation and speed to detect and disrupt cybercriminal networks more effectively. The program ensures all actions comply with U.S. laws and constitutional protections. Ultimately, it expands the government’s cyber defense tools by including private sector expertise to protect Americans from cyber-enabled crimes.
What are the Actions Directed to Agencies (Also identify which agencies) by this executive order. Explain in 10-15 lines
The memorandum directs the National Coordination Center (NCC), established under a prior executive order, to create and manage a program authorizing vetted private companies to conduct cyber operations against foreign cybercriminal groups. The Department of Justice (DOJ) and Department of Homeland Security (DHS) will jointly oversee the program through designated co-Executive Directors responsible for approving cyber operations. Participating companies must enter into contracts with DOJ or DHS, undergo rigorous vetting, and comply with strict operational procedures. The NCC will coordinate with federal, state, local, tribal, and territorial agencies to share threat information with these companies. The program requires comprehensive oversight, including legal review to protect U.S. persons’ rights and ensure compliance with constitutional and international law. Other agencies involved in operational coordination include the Department of State, Treasury, War, Intelligence Community, and the Office of Management and Budget. The NCC will also handle reporting, operational deconfliction, and continuous program evaluation.
Are there any deadlines written in this executive order, and if so, what they are in 5 lines.
Yes, the Program Executive Directors must establish consensus operating procedures within 60 days of the memorandum’s date. They are also required to produce a detailed report on the program’s status within 180 days and annually thereafter. Additionally, Participating Companies will be evaluated at least annually for continued participation. These deadlines ensure timely implementation and ongoing oversight.
What will be the impact on citizens, states, federal agencies, businesses for this executive order. Explain in detail in 20 lines
For citizens, this memorandum aims to enhance protection against cyber-enabled fraud and criminal activities that threaten personal and financial security. By disrupting transnational cybercriminal networks, it reduces the risk of identity theft, financial scams, and other cybercrimes that directly affect individuals. States and local governments will benefit from improved intelligence sharing and coordination with the federal government and private sector, strengthening regional cybersecurity defenses. Federal agencies, particularly DOJ, DHS, intelligence, and defense-related entities, will gain a powerful new tool by integrating private sector cyber capabilities under federal oversight, improving responsiveness and operational reach. Businesses, especially those in the cybersecurity and technology sectors, will have opportunities to participate in the program, fostering innovation and collaboration with the government. However, businesses involved must meet stringent vetting and operational standards, including maintaining bonds to ensure compliance. The program’s oversight mechanisms aim to prevent misuse and protect civil liberties, but it will require careful balancing of security and privacy concerns. Overall, the memorandum promotes a public-private partnership model that leverages private innovation to enhance national cyber defense, potentially reducing the impact and frequency of cyberattacks on American infrastructure and economy.
Are there any budget or funding directions through this executive order.
The memorandum states that implementation is subject to the availability of appropriations but does not specify new funding or budget allocations. It acknowledges that the Director of the Office of Management and Budget retains authority over budgetary proposals related to the program.
What is the political context of this executive order in 5-10 lines.
This memorandum follows increasing concerns over the growing threat posed by transnational cybercriminal organizations exploiting technological advancements to target the U.S. economy and national security. It builds on a prior executive order aimed at combating cybercrime and reflects a broader bipartisan recognition of the need to strengthen cybersecurity defenses. The initiative aligns with efforts to modernize national security approaches by incorporating private sector capabilities while maintaining strict government oversight. It also responds to calls for more proactive and offensive cyber measures against foreign cyber threats. The memorandum may face scrutiny from civil liberties advocates concerned about privacy and government overreach, highlighting the political balancing act between security and individual rights.
What are the short term and long term effects of this executive order and what should be monitored in terms of impact in 20-25 lines.
In the short term, the establishment of the program will enhance coordination between federal agencies and private companies, enabling faster identification and disruption of cyber-enabled criminal activities. The vetting and operational procedures will set standards for private sector participation, improving the quality and reliability of cyber operations. Early reports will provide insight into the effectiveness of these partnerships and identify areas for improvement. In the long term, the program could significantly shift the U.S. cybersecurity landscape by institutionalizing public-private collaboration in offensive cyber operations, potentially deterring cybercriminal groups through increased risks and disruption capabilities. However, continuous monitoring is essential to ensure compliance with legal and ethical standards, particularly concerning the protection of U.S. persons and civil liberties. The impact on the private sector’s role in national security should be assessed to avoid over-dependence or conflicts of interest. Additionally, the program’s effect on international norms and relations must be observed, as offensive cyber operations can have diplomatic repercussions. Metrics such as reduction in cybercrime incidents, successful disruption of criminal networks, and transparency in reporting will be critical to evaluate program success. Monitoring for unintended consequences, such as escalation of cyber conflicts or misuse of authority, is also necessary.
What are the criticisms or risks that need to be monitored in 15-20 lines.
Key criticisms and risks include potential privacy violations and civil liberties concerns, especially regarding cyber surveillance operations that may inadvertently target U.S. persons or domestic information systems. The involvement of private companies in offensive cyber operations raises questions about accountability, transparency, and the potential for abuse or errors without adequate oversight. There is a risk of mission creep, where operations could extend beyond intended targets or legal boundaries. The requirement for companies to maintain bonds and rigorous vetting may limit participation to larger firms, potentially excluding innovative smaller companies. Coordination among multiple agencies and private entities could lead to operational conflicts or inefficiencies. The classified nature of parts of the program may reduce public and congressional oversight, increasing concerns about unchecked executive power. Internationally, offensive cyber operations risk escalating tensions with foreign governments or violating international law. The program must also guard against over-reliance on private sector capabilities, which could create vulnerabilities if companies face conflicts of interest or operational failures. Continuous evaluation and transparency will be essential to mitigate these risks.
Are there any past precedents of this executive order by previous presidents or by the judicial court, which could support or not support the validity in 10-15 lines.
Previous presidents have issued executive orders to combat cybercrime and enhance cybersecurity, such as Executive Order 13636 under President Obama, which focused on critical infrastructure cybersecurity and public-private collaboration. President Trump’s own Executive Order 14159 established the National Coordination Center and addressed cyber threats more broadly. The use of private sector partnerships in national security is well-established, though the authorization of offensive cyber operations by private companies under federal oversight is relatively novel. Judicial precedents generally uphold executive authority in national security matters, provided constitutional and statutory safeguards are followed. However, courts have also emphasized the need for oversight to protect civil liberties, particularly in surveillance and intelligence activities. This memorandum’s emphasis on legal compliance, vetting, and oversight aligns with these precedents, though its novel scope may invite future legal challenges regarding the limits of executive power and private sector involvement in offensive cyber operations. MEMORANDUM FOR THE VICE PRESIDENT THE SECRETARY OF STATE THE SECRETARY OF THE TREASURY THE SECRETARY OF WAR THE ATTORNEY GENERAL THE SECRETARY OF COMMERCE THE SECRETARY OF ENERGY THE SECRETARY OF HOMELAND SECURITY THE ASSISTANT TO THE PRESIDENT AND CHIEF OF STAFF THE DIRECTOR OF NATIONAL INTELLIGENCE THE ASSISTANT TO THE PRESIDENT FOR SCIENCE AND TECHNOLOGY THE DIRECTOR OF THE CENTRAL INTELLIGENCE AGENCY THE DIRECTOR OF THE OFFICE OF MANAGEMENT AND BUDGET THE ASSISTANT TO THE PRESIDENT FOR NATIONAL SECURITY AFFAIRS THE ASSISTANT TO THE PRESIDENT AND DEPUTY CHIEF OF STAFF FOR POLICY AND HOMELAND SECURITY ADVISOR THE NATIONAL CYBER DIRECTOR THE CHAIRMAN OF THE JOINT CHIEFS OF STAFF THE DIRECTOR OF THE NATIONAL SECURITY AGENCY By the authority vested in me as President by the Constitution and the laws of the United States of America, I hereby direct the following: Section 1. Purpose. Transnational Criminal Organizations (TCOs) pose a growing threat to American citizens, businesses, and national security. These organizations conduct sustained cyber campaigns to perpetrate frauds that undermine American prosperity, security, and freedom. Through Executive Order 14390 of March 6, 2026 (Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens), I directed the Federal Government to take various actions to combat cyber‑enabled crime harming American citizens. This memorandum expands the fight against TCO-perpetrated cybercrime by incorporating the ingenuity of the private sector. The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States. Yet, American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace. Thus, it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime. By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens. Sec. 2. Establishing the Program. (a) The National Coordination Center (NCC), established pursuant to section 6(d) of Executive Order 14159 of January 20, 2025 (Protecting the American People Against Invasion), shall create, manage, and maintain a Program to authorize Participating Companies, as defined in section 4(f) of this memorandum, to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), under the control and oversight of the Federal Government. As part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement, this Program shall: (i) be overseen by co-Executive Directors, one from the Department of Justice, designated by the Attorney General, and one from the Department of Homeland Security, designated by the Secretary of Homeland Security (Program Executive Directors). The Program Executive Directors shall be delegated authority to approve, after coordination with each other, cyber operations conducted within the Program by personnel of their respective departments, except that they may not approve operations resulting in Critical Outcomes, as defined in section 4(b) of this memorandum. Cyber operations shall only be approved after coordination between the Program Executive Directors, and any resulting operational action will be exclusively conducted on behalf of and under the supervision of the Federal Government pursuant to the Federal Government’s lawful authorities; (ii) require Participating Companies to enter into contractual agreements with the Department of Justice or the Department of Homeland Security, which shall ensure that Participating Companies undergo rigorous vetting and that their performance adheres to the strict operational procedures outlined in the implementation guidance directed in section 3 of this memorandum; and (iii) permit Participating Companies to enter into commercial agreements with: (A) private sector entities, from which the Participating Companies may receive for the purpose of proposing responsive cyber operations to the NCC any threat information collected in the course of those entities’ normal business activities; and (B) Federal, State, local, tribal, and territorial agencies, which will identify CE-TCO threats to the Participating Companies in a manner that enables them to propose cyber operations to the NCC that address those threats. (b) The NCC shall conduct all Program activities in accordance with the Constitution and all other applicable laws and international obligations of the United States, including section 1030 of title 18, United States Code, thereby ensuring that Participating Companies are acting under the control and oversight of the United States Government. Sec. 3. Implementing Guidance. (a) Within 60 days of the date of this memorandum, the Program Executive Directors shall, in coordination with the Homeland Security Council, establish consensus operating procedures for the Program that ensure the Federal Government’s complete oversight and control of Participating Companies’ performance. No operation may be approved unless it complies with these operating procedures. The procedures shall: (i) establish minimum standards that Participating Companies must meet in order to take part in the Program, which shall include appropriate levels of technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence, reliability, and other factors that the Program Executive Directors, in coordination with the Homeland Security Council, determine are relevant or necessary for guaranteeing high confidence in a Participating Company’s ability to perform successfully in the Program; (ii) ensure that the Program’s eligibility criteria enable participation by both large companies, which provide critical capacity, and smaller, more agile companies, which may be better suited for specialized or discrete tasks; (iii) mandate that Participating Companies disclose to the NCC all contractual relationships entered into pursuant to section 2(a)(iii) of this memorandum; (iv) authorize the Department of Justice and the Department of Homeland Security to mandate as a condition of their contractual agreements with Participating Companies under section 2(a)(ii) of this memorandum that such companies maintain a bond or escrow in an amount not less than $1 million, to be forfeited should the Participating Company enter non‑compliance with its contractual agreement described in section 2(a)(ii) of this memorandum; (v) in conformance with the classified annex to this memorandum, set forth the operational workflow of the Program, which shall include operational deconfliction across Federal law enforcement, the Department of State, the Department of the Treasury, the Department of War, the Department of Justice, and the United States Intelligence Community; (vi) in conformance with the classified annex to this memorandum, provide an adjudicatory framework to ensure operational activity targets only CE-TCOs and accounts for other United States Government equities; (vii) set forth standardized rubrics and templates for target identification and the creation and processing of Cyber Surveillance and Cyber Effects Operations packages; (viii) include reporting requirements for Participating Companies that will advance a greater understanding of the activities and impact of foreign CE-TCOs, especially as they relate to the American people and economy, and that will ensure the NCC is fully apprised of the Participating Companies’ operational activities; (ix) include procedures, including a review by the Department of Justice, that ensure any Program activity that is directed at a United States person or otherwise implicates the United States Government’s obligations under the Constitution, Federal law, or international law receives any necessary authorization, judicial or otherwise, prior to approval of the operation; (x) include procedures to ensure that a Participating Company that discovers operational activity exceeding the parameters and restrictions of the cyber operation approved by the Program Executive Directors — such as unintentional targeting of (1) a United States person, (2) an information system residing in the United States, or (3) an information system under the control of a United States person — shall cease such operation, conduct minimization procedures, and immediately notify the NCC, which shall notify the Department of Justice; (xi) include procedures mandating that Participating Companies immediately notify the NCC, which shall notify the Department of Justice, if they discover an imminent cyber-attack against United States critical infrastructure or develop a reasonable belief that an approved Cyber Effects Operation or Cyber Surveillance Operation may result in Critical Outcomes; (xii) clarify that Participating Companies may still engage in other lawful defensive cyber operations otherwise permitted to them, but that any activity authorized by the Program must be conducted subject to the oversight, operational control, and legal authorities of the United States Government; (xiii) include procedures for evaluating each Participating Company for continued participation in the Program on at least an annual basis; and (xiv) mandate that the Program Executive Directors review every cyber operations package and provide written approval and direction to the Participating Company before action may be taken. (b) The Program Executive Directors shall regularly assess and continuously improve the Program’s operational procedures to maintain effective and efficient execution of the objectives outlined in this memorandum. The NCC shall likewise utilize automation to streamline Program elements wherever appropriate, in accordance with applicable law and the requirements of this memorandum. (c) The Program Executive Directors shall, within 180 days of the date of this memorandum and annually thereafter, produce a report detailing the status of the Program and submit it to the Assistant to the President and Deputy Chief of Staff for Policy and Homeland Security Advisor and the National Cyber Director. Sec. 4. Definitions. For purposes of this memorandum: (a) “Cyber Effects Operation” means activity conducted in or through the interdependent network of information technology infrastructure that includes the Internet, telecommunications networks, computers, information systems, industrial control systems, networks, and embedded processors and controllers that results in the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon. (b) “Critical Outcomes.” An action will be considered to generate a Critical Outcome if it is likely that it will: (i) result in the loss of life or serious injury; or (ii) rise to the level of use of force or armed attack under international law. (c) “Cyber-Enabled Transnational Criminal Organization (CE-TCO)” means any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests, and that is not an institutional part of a foreign government or wholly operated under a foreign government’s direction. For the purposes of this memorandum, a foreign group will be assumed not to be an institutional part of a foreign government or wholly operated under a foreign government’s direction unless clear intelligence exists establishing such connection. (d) “Cyber Surveillance Operation” means activities conducted in or through the interdependent network of information systems that includes the Internet, telecommunications networks, computers, information systems