Inside the Presidential Memorandum on Transnational Cyber-Enabled Crime

August 27, 2026

IST friends and experts hosted a pop-up webinar to examine the recent presidential memorandum on combating transnational cyber-enabled crime. Featuring Jen Ellis, Jason Kikta, Leonard Bailey, Nicholas Leiserson, and Megan Stifel, the discussion covered the ethical, strategic, and legal implications of deputizing private companies to carry out these operations.

The National Security Presidential Memorandum (NSPM) on “Expanding Capabilities To Combat Transnational Cyber-Enabled Crime,” issued on August 12, addresses how the government intends to increase the role of the private sector in U.S. offensive cyber operations. Clarity on this has been much anticipated since the early days of the second Trump Administration, when the government started hinting at a desire to see the private sector play a larger role. IST’s August 24 webinar brought together our cybersecurity and legal experts as they discussed the implications of the NSPM and debated the ethical, strategic, and legal implications of deputizing private companies to carry out these operations. 

The panelists included Jen Ellis (NextJenSecurity), Leonard Bailey (Former Head of Cybersecurity Unit, U.S. Department of Justice, Ret.), Jason Kikta (Automox & IST), Nick Leiserson (IST), and Megan Stifel (IST).

No New Authorities 

This NSPM establishes the infrastructure to allow vetted private companies to carry out offensive cyber operations on behalf of and under the supervision of the U.S. government, following through on the intent outlined in President Trump’s Cyber Strategy for America in March 2026. It specifically aims the operations at cyber-enabled transnational criminal organizations (CE-TCOs), meaning the private sector can target criminal groups, not nation-state actors. 

The program requires the DOJ and DHS to create a framework for three different types of activities: cyber effects operations, cyber surveillance operations, and information sharing between participating companies. Operations that would produce critical outcomes (defined as any action that is likely to result in the loss of life or serious injury or rise to the level of use of force or armed attack under international law) are not authorized. 

On Monday, Leonard Bailey began by emphasizing that the NSPM creates no new authorities, since all activities are pursuant to federal government laws and to the Constitution: “The NSPM can’t provide authorities that override things like the Computer Fraud and Abuse Act or statutes that are electronic surveillance laws, and that’s underscored at various points in the NSPM,” he said. 

What it does do is establish a new structure. The National Coordination Center, supervised by two co-executive directors (one appointed by the Attorney General and the other by the Secretary of DHS), is responsible for issuing implementing guidance within 60 days. That guidance matters, Bailey explained, because of what he identified as definitional ambiguities in the NSPM itself, which, for instance, calls out fraud, predatory schemes, and cybercrime but provides no clear limits on “crimes.” 

All Flash, No Bang?

For Jason Kikta, the NSPM is “all flash, no bang” with its “perverse” incentives and contradictions. “The whole attribution angle is backwards,” said Kikta, “that these private companies would have better attribution capabilities than someone [at] NSA is just farcical.” 

Looking at how U.S. defense operations have previously harnessed private sector innovation and technology raises a different question of whether the shift of the private sector’s role enumerated in the NSPM is the right way to do it, Nick Leiserson explained. Historically, the private sector provides resources and materiel that U.S. forces employ, and that involvement is “not new,” he said. The departure is the instruction to go “do the operations yourself.” If the point is to increase speed by giving the private sector more leeway, those actors become more likely to step on U.S. government operations. The NSPM’s deconfliction process guards against that, but it also spends the time the leeway was supposed to save. For Leiserson, the design can offer speed or deconfliction, not both: “I don’t want some random private sector company going and blowing up DOJ’s spot when they are about to make an indictment…But I also want to increase the volume. I think those are two worthy goals. I’m not sure how this NSPM is going to square that circle.”

Buying Risk Without Much Protection

For private companies to have protections, they must act in accordance with the directions they were given by the U.S. government, with no discretion. Combined with the government’s inability to extend protections under foreign civil and criminal laws, “they’re buying a lot of risk without much protection,” Bailey said.

Companies may lose power that they already hold, since some authorities currently available to them are written for non-federal entities: “You lose some of those authorities when you’re acting as a proxy for the government because they are intended to allow providers acting as providers to protect themselves, not to circumvent the Fourth Amendment or other protections,” continued Bailey.

Jen Ellis explained how the risk-averse nature of large companies could lead them to subcontract non-multinational companies, rather than participating directly. Though she noted: “it’s unclear at the moment, based on the level of detail that’s in the NSPM, whether that would be doable.”

Given that private companies’ aim is to make a profit, doing business with the U.S. federal government “is not different,” said Kikta, who believes that the contracts will likely incur high costs on the government. That is not necessarily a bad thing, Leiserson noted, since the program could exchange dollars for speed and, assuming oversight is extensive, would give the government a way to “quickly put dollars against stuff.” 

The problem is that the money has not been visible: “If our strategy is that we’re going to put billions of dollars against this particular problem, and the only way to do it in an operationally relevant timeline of the next 12 months is to do it with contractors,” said Leiserson, “I’m not sure I’d agree with that, but at least I could see where you were going with something like this, and we haven’t seen [the budget for that] out of the administration yet.”

What Counts as Cyber-Enabled Crime? 

Cyber-enabled crime likely covers expected categories, such as business email compromise, ransomware, and data extortion. But, as the panel noted, there are risks that the definition of “cyber-enabled crime” could be stretched to fit other operations.

Asked whether surveilling foreign groups attempting to influence U.S. politics could be legally permitted, Bailey said he could not rule it out, but hopes that existing law would forbid it. 

Kikta read the protections for Americans narrowly, noting that the NSPM guards against inadvertent targeting, and not against intentional targeting. Megan Stifel flagged the institutional dimension: “It almost suggests that the president is directing [the] DOJ’s activities again.”

The implementing guidance due within 60 days is where some of these answers may come from. For the full discussion, watch the full recording:

Related Content

Topics

Share

Facebook
Twitter
LinkedIn
Print
MENU

GET IN TOUCH

Email: [email protected]
Send us a message: Contact

JOIN THE CATALINK MAILING LIST