
Donald Trump. Photo by Win McNamee / Getty Images
The program will operate under the National Coordination Center (NCC), and vetted U.S. companies will be eligible to participate. They will be authorized to conduct two types of operations: cyber intelligence and so-called cyber-impact operations. The former involve covert access to information systems to collect data, while the latter involve targeting criminals’ computer systems.
However, private companies will not have the independent right to carry out hacking attacks. All operations will be conducted on behalf of and under the control of the U.S. federal government, within the scope of its legal authority. To participate, companies must enter into an agreement with the Department of Justice or the Department of Homeland Security and undergo a vetting process.
The program will target foreign cybercriminal groups that attack U.S. government agencies, companies, or citizens. However, the program does not apply to organizations that are part of a foreign government or act directly under its direction.
The program has not yet been launched. The Department of Justice and the Department of Homeland Security must develop procedures within 60 days to ensure full government oversight of private companies’ activities. No operation can be approved until these rules are adopted.
The White House stated that it intends to leverage the technological capabilities of the private sector to combat ransomware, financial fraud, phishing, and other forms of transnational cybercrime.

























