On August 12, the White House signed a presidential memorandum formally authorizing vetted private US cybersecurity companies to conduct offensive cyber operations against foreign criminal organizations under direct government oversight. The memorandum establishes what it calls a Program — managed by the National Coordination Center under DOJ and DHS co-direction — that licenses participating companies to run both cyber surveillance operations and cyber effects operations against Cyber-Enabled Transnational Criminal Organizations, or CE-TCOs, targeting American citizens and interests.
This is not a hypothetical policy proposal. It is an operational directive with a 60-day implementation timeline, specific vetting requirements, a $1 million bond structure, and a classified annex governing targeting and deconfliction. The legal framework it creates — government-authorized, privately executed offensive cyber operations against criminal networks — is new in scope and structure, and it has direct implications for healthcare security programs that procure cybersecurity services from the firms most likely to become Participating Companies.
What the Memorandum Actually Establishes
The Program has two operational categories. Cyber Surveillance Operations cover intelligence gathering through unauthorized access to foreign criminal infrastructure — accessing systems without permission for the primary purpose of collecting information, including information that can be used to enable future effects operations. Cyber Effects Operations cover the active disruption, degradation, or destruction of those systems and the infrastructure they control.Both categories require written approval from Program Executive Directors — one designated by the Attorney General, one by the Secretary of Homeland Security — before any action is taken. The approval requirement applies to every operation package. The one explicit carve-out from Executive Director authority is "Critical Outcomes" — actions likely to result in loss of life, serious injury, or actions rising to the level of armed attack under international law. Those require a higher authorization level not specified in the public text of the memorandum.
The target definition is precisely bounded. A CE-TCO must be a foreign group conducting cyber-enabled crime against US government, US persons, or US interests, and must not be an institutional part of a foreign government or wholly operated under foreign government direction. The memorandum includes a telling presumption: a foreign group is assumed not to be state-directed unless clear intelligence establishes otherwise. That presumption has operational consequences for ransomware groups with known but deniable state ties — a category that includes several of the organizations that have conducted the most damaging attacks on healthcare infrastructure in recent years.
The Private Sector Structure and What It Means
The Participating Company framework is the most operationally significant structural element of the memo. Private cybersecurity firms that pass vetting enter contractual agreements with DOJ or DHS. Those agreements govern their performance, require disclosure of all commercial relationships that feed threat intelligence into the Program, and mandate a $1 million bond or escrow forfeited on non-compliance. Firms can receive threat intelligence from private sector clients in the course of normal business operations and use that intelligence to propose responsive cyber operations to the NCC — but the NCC approves and directs all resulting action.The explicit inclusion of both large companies with scale capacity and smaller, more agile firms for specialized tasks signals that the Program is not designed around a single prime contractor model. The cybersecurity industry ecosystem — large managed security service providers, specialized threat intelligence firms, incident response boutiques — maps directly onto the large/small segmentation the memo describes.
The commercial intelligence pathway — where Participating Companies receive threat data from private clients and propose operations based on it — creates a channel through which a healthcare organization's threat intelligence could, in principle, flow into a government-authorized offensive operation against a criminal network targeting that organization. That is not a theoretical future state. It is the operational design of the Program as written.
The Ransomware Groups Targeting Healthcare
The CE-TCO definition is written to cover the organizations that have caused the most significant damage to US healthcare infrastructure. ALPHV/BlackCat, which shut down Change Healthcare's claims processing for weeks in early 2024 and exposed data on more than 100 million Americans, qualifies. LockBit, responsible for attacks on hospital systems across the country before its 2024 disruption operation, qualifies. Rhysida, which attacked Lurie Children's Hospital and several regional health systems in 2024 and 2025, qualifies. The Scattered Spider affiliates responsible for MGM and Caesars, who have since expanded targeting to healthcare, qualify.Each of these groups operates from foreign infrastructure, targets US persons and US interests, and lacks the kind of clear, documentable state direction that would move them out of the CE-TCO category under the memo's presumption. The Program is not written with healthcare in mind specifically — it is written for the full landscape of transnational cybercriminal organizations — but the organizations that have inflicted the most severe damage on US healthcare are exactly the type of target the Program is designed to reach.
The Classified Annex
The public memorandum explicitly references a classified annex governing two elements: the operational workflow of the Program, including deconfliction across federal law enforcement, State, Treasury, DOJ, and the intelligence community; and the adjudicatory framework for ensuring operations target only CE-TCOs while accounting for other US government equities.The classified annex is where the most operationally sensitive questions are answered — how targeting packages are built, what intelligence thresholds trigger approval, how the Program handles a situation where a CE-TCO infrastructure overlaps with legitimate infrastructure, and how the government deconflicts Program operations with ongoing law enforcement investigations, intelligence collection, or diplomatic equities. Healthcare security professionals reading the public memorandum should understand that the governance structure it describes is deliberately incomplete. The procedural safeguards that matter most — how targeting errors are prevented and corrected — are not in the public text.
What This Means for Healthcare
Your IR and threat intelligence vendors may become Participating Companies
The firms most likely to qualify for the Program — established managed security service providers, major threat intelligence vendors, specialized incident response firms — overlap significantly with the vendor ecosystem healthcare organizations already use. A healthcare organization's IR retainer, threat intelligence subscription, or MDR provider could be operating under a Program contract. The commercial intelligence pathway in the memo means that threat data those firms collect from healthcare clients could be used to propose offensive operations to the NCC.This is not a disclosure requirement that exists today — the memo does not require Participating Companies to notify their commercial clients that they are operating under the Program. Healthcare vendor risk management programs should be adding questions about Program participation to cybersecurity vendor assessments. The questions are straightforward: Is your firm a Participating Company under the NCC Program established by the August 12 presidential memorandum? If so, what data from our engagement may be used to propose operations to the NCC?
The state-actor presumption creates a gray zone for healthcare's most significant threat actors
The CE-TCO definition presumes groups are not state-directed unless clear intelligence establishes otherwise. Several of the ransomware groups most active against healthcare have documented but deniable relationships with state intelligence services. LockBit affiliates have included individuals with ties to Russian intelligence. ALPHV/BlackCat operated from infrastructure with overlapping indicators to state-adjacent actors. The presumption in the memo means these groups could be targeted under the Program — but it also means the classified annex's adjudicatory framework will be doing significant work in practice to manage the line between criminal and state-directed targeting.Healthcare security programs do not need to resolve that gray zone. They need to understand that the US government is now operating an offensive program against the organizations most likely to be targeting their environments, and that the program's targeting decisions are made through a classified process they will not see.
The SAFE framework and this memo together define the emerging governance architecture
Read alongside the SAFE framework proposal covered in yesterday's post, the August 12 memo describes two complementary halves of an emerging AI-and-cyber governance architecture. SAFE establishes how incidents are reported and shared across the industry. The CE-TCO memo establishes how the government responds offensively, using private sector capability under government direction. The two together suggest a governance model in which critical infrastructure operators — including healthcare — are expected to participate in incident reporting through frameworks like SAFE, while offensive response to the criminal organizations behind those incidents is handled through a government-authorized private sector program.Healthcare security programs should be tracking both frameworks as a pair, not as isolated policy developments.
The $1 million bond structure is a meaningful signal about program seriousness
Requiring Participating Companies to maintain a $1 million bond or escrow forfeited on non-compliance is not standard government contracting language. It signals that the program architects anticipate operational errors, scope violations, and non-compliance events, and have designed a financial deterrent into the structure from the start. For healthcare organizations evaluating vendors who may be Participating Companies, that bond structure is evidence that the government expects these operations to carry real risk of error — and has priced that risk into the program design. It is not a reason to avoid vendors who participate. It is a reason to ask about their compliance history and operational controls.The 60-day implementation window means this becomes operational before the end of October
The operating procedures must be established within 60 days — by approximately October 11, 2026. The first annual report follows within 180 days. Healthcare organizations that want to engage with the framework before it becomes fully operational — whether through industry comment periods, healthcare sector working group participation, or direct engagement with HHS cybersecurity programs — have a narrow window. HC3, the Health-ISAC, and HHS 405(d) are the likely channels for healthcare-specific input into how the Program's operating procedures account for healthcare infrastructure.The Bigger Picture
The August 12 memorandum is the most significant structural change to US offensive cyber authorities in years. The difference from prior frameworks is the private sector element: this memo is about creating a government-authorized, privately-executed offensive cyber capability operating under DOJ and DHS direction against criminal organizations.The legal basis is straightforward — the Computer Fraud and Abuse Act explicitly authorizes government-directed operations, and the Participating Companies are acting on behalf of the government under its lawful authorities. The operational novelty is real — no prior program has formally structured the commercial cybersecurity industry as an authorized offensive instrument of US government cyber policy at this scale.
For healthcare security programs, the near-term actions are practical. Add Program participation questions to vendor assessments. Track HC3 and Health-ISAC communications for healthcare-specific guidance as the 60-day implementation window closes. Understand that the criminal organizations most likely to target your environment are now explicitly within the scope of a government-authorized offensive program — which changes the threat landscape in ways that are net positive for defenders, while creating new vendor due diligence questions that did not exist before August 12.
For related coverage, see The Flight Recorder for AI Agents: What the SAFE Framework Means for Healthcare Security Programs and OpenAI Opens the Door for Defenders: Daybreak Red, GPT-5.6-Cyber, and What the 95% Completion Rate Means for Healthcare Security.
Key Links
- White House: Expanding Capabilities to Combat Transnational Cyber-Enabled Crime (August 12, 2026)
- White House Fact Sheet: President Trump Expands Capabilities to Combat Transnational Cyber-Enabled Crime (August 12, 2026)
- White House: Executive Order 14390 — Combating Cybercrime, Fraud, and Predatory Schemes (March 6, 2026)
- bregg.com: The Flight Recorder for AI Agents: What the SAFE Framework Means for Healthcare Security Programs