Start your day with intelligence. Get The OODA Daily Pulse.

Home > Analysis > OODA Original > Security and Resiliency > Opinion: Deputizing Private Cybersecurity Firms Comes With Hidden Risks

Editor’s note: We recognize opinions vary on this topic, and would welcome responses from other informed experts on this critically important subject.

The August 12, 2026 National Security Presidential Memorandum (NSPM) Expanding Capabilities to Combat Transnational Cyber-Enabled Crime established a federal framework to authorize vetted private cybersecurity firms to conduct offensive cyber operations. Many view it as a significant breakthrough given the historic challenges of federal intelligence/law enforcement agencies countering the volume and speed of transnational cyber crime. By leveraging the “scale, speed, and capacity” of the private sector, this new policy looks to turn the tables on organizations like ransomware cartels and cyber extortion gangs under the supervision of the Department of Justice (DOJ) and Department of Homeland Security (DHS) via the National Coordination Center (NCC).

While a seemingly promising endeavor, it potentially represents a dangerous erosion of the boundaries between sovereign state authority, commercial incentives, and international law. While the NSPM attempts to create strict guardrails, it also introduces structural vulnerabilities that could aggravate geopolitical instability, undermine legal responsibility, and fail to achieve its primary objective of curbing global cybercrime.

The Myth of Precision Attribution in Cyberspace

One of the weaknesses of the NSPM rests on the assumption that cyber criminal gangs exist as neatly isolated, purely private entities. The reality is that the line that once separated cyber crime from state cyber activity is steadily blurring. China, Iran, and North Korea groups have demonstrated this evolution.

The first and most obvious problem is attribution. Cyber attackers routinely hide behind compromised and sometimes shared infrastructure, bulletproof hosting providers, proxies, botnets, stolen credentials, cryptocurrency services, and layers of intermediaries. A server used by a ransomware group may not actually belong to the group. A compromised computer used to launch an attack may belong to an innocent organization, and a criminal-linked infrastructure provider may itself have been compromised.

This means that determining where an attack originated is not the same as determining who is responsible. That distinction becomes critical when the response involves disrupting or destroying another organization’s systems. Private threat intelligence teams excel at tracking infrastructure, mapping campaigns, and profiling threat actors. But high analytic confidence isn’t the same as the legal or factual certainty that should be required before attacking an adversary’s systems.

The consequences of getting attribution wrong are much greater when the response is offensive.

As I have previously argued, cyberspace is complicated by “layers” of attribution, jurisdiction, proxies, and proportionality. Misattribution and collateral damage can transform what begins as a corporate security incident into something much larger. The new policy may put government oversight around private-sector operations, but oversight does not eliminate the fundamental problem of determining who is actually behind an attack.

Legal Vulnerabilities and Civil Liability

From a legal standpoint, the NSPM attempts to bridge a gap by relying on statutory exemptions within the Computer Fraud and Abuse Act (CFAA) for activities conducted on behalf of federal law enforcement, according to one source. However, offering a shield against domestic criminal prosecution does not protect these vetted entities from civil litigation or international law.

  • Third Party Infrastructure. Modern threat actors typically route their traffic through compromised third-party infrastructure (e.g., residential networks, cloud service providers, university servers, etc.). If a vetted company deploys a payload that inadvertently impacts a third party’s legitimate infrastructure, there is the potential for civil suits and property damage claims.
  • Criminal Discovery. If a successful indictment should result from one of these operations, criminal discovery obligations could compel those involved to disclose proprietary tools and operational methodologies thereby calling into question the cost-benefit of that effort.

Retaliation and Corporate Risk

When nation-states or government-backed intelligence agencies conduct offensive operations, they operate behind such justifications of national defense, deterrence, or national security interests. Once a participating vetted firm executes a disruptive attack against a hostile cyber entity, that firm potentially becomes a high-priority target for retaliation. The threat actors may not restrict their counter attack to the firm’s environment, and could extend it to its supply chain as well as any affiliate and client systems as well. Moreover, while vetted firm’s must abide by the legal restrictions set forth in the document, the NSPM does not expressly say that vetted companies are immune from criminal or civil liability for their conduct, only that they cease operations should unintentional targeting occur.

An Example That Others Will Follow

Perhaps the most damaging long-term consequence of this policy is the precedent it establishes for other state cyber actors. For at least two decades, U.S. cyber diplomacy has advocated for responsible state behavior in cyberspace. With the formalization of NSPM permitting vetted private sector organizations to conduct offensive operations with strict government oversight, Washington in essence is okaying the practice to be replicated globally. Adversarial regimes such as Russia, China, Iran, and North Korea will inevitably follow suit officially permitting similar private sector groups under their purview to target under the pretext of conducting “counter-crime” or “defensive disruption” operations, and perhaps without as much oversight. The result will not be a safer Internet, but one that threatens eroding accountability.

Outlook

After years of being victimized by hostile threat actors, the desire to mount an aggressive counter-offensive against transnational cybercrime networks is entirely understandable. Cyber-extortion gangs inflict severe financial damages, disrupt critical healthcare delivery, and compromise essential national infrastructure. Yet, delegating sovereign offensive responsibilities to even a handful of commercial entities introduces a fundamentally flawed approach in dealing with this threat. If vetted private contractors must obtain explicit federal authorization prior to executing a strike, and if the government assumes ultimate accountability by approving that mission, it raises a critical question: why insert a commercial intermediary into the kill chain at all? Multiplying the number of offensive actors in cyberspace does not establish strategic deterrence; it merely amplifies potential volatility and contributes to geopolitical instability. Ultimately, when an operation inevitably strays off-target, it won’t be just the company that falls into the crosshairs of accountability – but the state who signed off on the strike as well.

Tagged: Cybersecurity
Emilio Iasiello

About the Author

Emilio Iasiello

Emilio Iasiello has nearly 20 years’ experience as a strategic cyber intelligence analyst, supporting US government civilian and military intelligence organizations, as well as the private sector. He has delivered cyber threat presentations to domestic and international audiences and has published extensively in such peer-reviewed journals as Parameters, Journal of Strategic Security, the Georgetown Journal of International Affairs, and the Cyber Defense Review, among others. All comments and opinions expressed are solely his own.