Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

White House Releases National Security Presidential Memorandum on Expanding Capabilities to Combat Transnational Cyber-Enabled Crime

By Jim Garland, Caleb Skeath, Ashden Fein, Micaela McMurrough, Ali Cooper-Ponte, Shayan Karbassi & Bryan Ramirez on August 17, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

On August 12, 2026, the Administration published a National Security Presidential Memorandum (“NSPM”) (“Expanding Capabilities to Combat Transnational Cyber-Enabled Crime”) that signals the Administration’s focus on private-sector participation in offensive cyber operations by establishing a federally supervised program to enable private sector participants to conduct offensive cyber operations against “Cyber-Enabled Transnational Criminal Organizations” (“CE-TCOs”).  

The NSPM follows Executive Order 14390, which, together with the U.S. National Cybersecurity Strategy, demonstrated the U.S. government’s continued focus on disrupting foreign cyber-enabled criminal organizations that engage in fraud, scams, and related cyber-enabled schemes.  The NSPM, which states that “it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime,” signals a potential shift in the U.S. government’s approach to offensive cyber operations by non-government actors.  At the same time, the NSPM makes clear that any such operations would be conducted only after U.S. government vetting and authorization, under federal coordination and oversight, and consistent with U.S. law.   This post summarizes the NSPM and identifies practical takeaways for private-sector entities that may be considering whether to participate in the program.  Additional implementation guidance is expected by mid-October 2026 (60 days after the NSPM publication).

Offensive Cyber Program

The NSPM, which includes certain classified annexes that have not been publicly disclosed, creates a National Coordination Center (“NCC”) and directs it to establish a Program through which vetted private companies (“Participating Companies”) may conduct certain operations against foreign CE-TCOs under the control and oversight of the federal government.  The NCC is itself established pursuant to Executive Order 14159 (“Protecting the American People Against Invasion”), which authorized the Departments of Justice and Homeland Security to create “Homeland Security Task Forces” to “end the presence of criminal cartels, foreign gangs, and transnational criminal organizations.” The broad framework includes the following:

  • Federal Oversight and Supervision: The Program is led by appointed Program Executives from the U.S. Departments of Justice and Homeland Security and will require that any private sector offensive cyber operations be coordinated across the U.S. national security apparatus, including the Department of War and the U.S. Intelligence Community.  The NSPM requires that “any resulting operational action” be “exclusively conducted on behalf of and under the supervision of the Federal Government pursuant to the Federal Government’s lawful authorities.”  Notably, the framework expressly contemplates that Program Executives may approve certain “covered cyber operations” that may result in “Critical Outcomes,” defined in the NSPM as actions that will likely “result in the loss of life or serious injury” or “rise to the level of use of force or armed attack under international law.”
  • Contract Requirement: Participating Companies must enter into contractual agreements with the U.S. government, undergo “rigorous vetting,” and adhere to “strict operational procedures.”  The NSPM also authorizes the Departments of Justice and Homeland Security to require that Participating Companies maintain a bond or escrow of at least $1 million that would be forfeited should the Participating Company fail to comply with its contractual obligations.
  • Peer-to-Peer Information Sharing: Participating Companies are permitted to enter into commercial agreements with:
    • Other private entities to receive threat information collected in the course of those entities’ normal business activities “for the purpose of proposing responsive cyber operations to the NCC”; and
    • Federal, state, local, tribal, and territorial agencies, “which will identify CE-TCO threats” to the Participating Companies “in a manner that enables them to propose cyber operations to the NCC that address those threats.”
  • Compliance with Constitution and Applicable Law: Program activities are to be conducted “in accordance with” the Constitution and other applicable laws, including the Computer Fraud and Abuse Act (“CFAA”) and other international obligations of the United States.

Forthcoming Implementing Guidance

The NSPM sets out a 60-day timeline for Program Executives to provide implementation guidance, which falls on October 11, 2026.  Among other requirements, the guidance must address:

  • Participant Eligibility: Establish minimum standards for Participating Companies—including technical proficiency, prior cyber operations performance, facility security, personnel vetting, competence, and reliability—and require disclosure to the NCC of all commercial agreements entered into under the Program.  The criteria should “enable participation by both large companies, which provide critical capacity, and smaller, more agile companies, which may be better suited for specialized or discrete tasks.”
  • Operational Workflows: In conformance with a classified annex, the Departments of State, Treasury, War, Justice, and the Intelligence Community are instructed to establish an operational workflow for the Program, including inter-agency deconfliction procedures and:
    • An adjudicatory framework to ensure approved operations target only CE-TCOs and account for other U.S. government equities;
    • Standardized rubrics and templates for target identification and surveillance and operational packages; and
    • Certain reporting requirements for Participating Companies.
  • Escalation, Minimization, and Incident Notification: Set out procedures to minimize risk to U.S. persons, U.S.-based information systems, or information systems controlled by U.S. persons, and to immediately notify the Program Executives of operational activity that exceeds the approved parameters.  Additionally, Participating Companies must immediately notify the NCC of imminent cyber-attacks against United States critical infrastructure or if an approved operation may result in Critical Outcomes (as defined above).

Considerations for Private Sector Participants

Consistent with the Administration’s other recent actions, the Program demonstrates the continued interest on leveraging U.S. private sector capabilities to address new and emerging cybersecurity threats—and in particular, on countering the threats posed by TCOs.  At the same time, although the Program signals a potential shift in the Administration’s approach to private-sector participation in offensive cyber operations, it underscores that any such activity will remain subject to careful federal review and approval to ensure alignment with U.S. foreign policy and national security interests and to mitigate unintended consequences.  While public-private partnerships to combat cybercrime are not new, the NSPM creates a new framework for such collaboration, with additional guidance that the NSPM anticipates will be forthcoming this fall.  Potential participants may wish to consider the following:

  • Review Participant Obligations and Protections.  As the NSPM contemplates a framework where private sector participants would enter into contracts with U.S. government entities and be subject to close supervision by U.S. government stakeholders, entities considering participation might want to carefully evaluate the obligations that would attach and potential protections that participants would receive under this framework—including under relevant contracts, as well as the “rigorous vetting” and “strict operational procedures” contemplated by the NSPM. 
  • Assess U.S. Enforcement and other Legal Risks.  While private sector participants might receive certain protections when they undertake activities pursuant to U.S. government supervision, oversight, and approval, the publicly-accessible portions of the NSPM do not specifically direct the Department of Justice and other agencies as to enforcement of potentially applicable federal laws, including the CFAA.  Note, however, that language in the NSPM closely mirrors the CFAA’s language excepting “lawfully authorized investigative, protective, or intelligence activity of” law enforcement and intelligence agencies.  See 18 U.S.C. § 1030(f).
  • Assess Cross-border Risks. Even where activities are conducted under U.S. government supervision and approval, Participating Companies may wish to assess potential additional risks arising from offensive cyber operations, including the possibility of retaliatory targeting by cyber threat actors and the potential application or enforcement of foreign laws against U.S. companies involved in offensive cyber operations that impact foreign jurisdictions.
  • Secondary Effects for Non-Participants.  As the NSPM explicitly permits peer-to-peer information sharing among private entities for purposes of proposing responsive cyber operations, non-participants who are engaged in information sharing activities should consider whether these information flows counsel in favor of any changes to their existing information sharing practices.
  • Monitor Implementation Guidance.  With Program Executives required to issue implementation guidance by October 11, 2026, entities interested in participation should monitor forthcoming guidance on participant eligibility criteria, operational workflows, and compliance requirements.
Photo of Jim Garland Jim Garland

Jim Garland’s practice focuses on government investigations and enforcement matters, litigation, and cybersecurity. Recognized by Chambers USA as a leading practitioner in both the white collar and cybersecurity categories, Jim draws upon his experience as a former senior Justice Department official to advise…

Jim Garland’s practice focuses on government investigations and enforcement matters, litigation, and cybersecurity. Recognized by Chambers USA as a leading practitioner in both the white collar and cybersecurity categories, Jim draws upon his experience as a former senior Justice Department official to advise clients on sensitive, multidimensional disputes and investigations, often with national security implications. He previously served as co-chair of Covington’s “Band 1”-ranked White Collar and Investigations Practice Group and currently is a member of the firm’s Management and Executive Committees.

Jim regularly represents corporate and individual clients in government investigations and enforcement actions. He has successfully handled matters involving allegations of economic espionage, theft of trade secrets, terrorism-financing, sanctions and export control violations, money laundering, foreign bribery, public corruption, fraud, and obstruction of justice. He has particular expertise advising clients in connection with investigations and disputes involving electronic surveillance and law enforcement access to digital evidence.

Jim has substantial experience litigating high-stakes, multidimensional disputes for clients across a range of industries, including companies in the high-tech, financial services, defense, transportation, media and entertainment, and life sciences sectors. Many of his civil representations have substantial cross-border dimensions or involve parallel government enforcement proceedings in multiple forums.

In conjunction with his investigations and litigation practice, Jim regularly assists clients with cybersecurity preparedness and incident-response matters. He helps clients in assessing security controls and in developing policies and procedures for the protection of sensitive corporate data. He also regularly assists companies in responding to significant cybersecurity incidents, including in connection with criminal and state-sponsored attacks targeting customer and employee data, financial information, and trade secrets.

From 2009 to 2010, Jim served as Deputy Chief of Staff and Counselor to Attorney General Eric Holder at the U.S. Department of Justice. In that role, he advised the Attorney General on a range of enforcement issues, with an emphasis on criminal, cybersecurity, and surveillance matters.

Read more about Jim GarlandEmail
Show more Show less
Photo of Caleb Skeath Caleb Skeath

Caleb Skeath helps companies manage their most complex and high‑stakes cybersecurity and data security challenges, combining deep regulatory insight, technical fluency, and practical judgment informed by leading incident response matters.

Caleb Skeath advises in‑house legal and security teams on the full lifecycle of…

Caleb Skeath helps companies manage their most complex and high‑stakes cybersecurity and data security challenges, combining deep regulatory insight, technical fluency, and practical judgment informed by leading incident response matters.

Caleb Skeath advises in‑house legal and security teams on the full lifecycle of cybersecurity and privacy risk—from governance and preparedness through incident response, regulatory engagement, and follow‑on litigation. A Certified Information Systems Security Professional (CISSP), he is trusted by clients across highly regulated and technology‑driven sectors to provide clear, practical guidance at moments when legal judgment, technical understanding, and business realities must be aligned.

Caleb has deep experience leading and overseeing responses to complex cybersecurity incidents, including ransomware, data theft and extortion, business email compromise, advanced persistent threats and state-sponsored threat actors, insider threats, and inadvertent data loss. He regularly helps in‑house counsel structure and manage investigations under attorney‑client privilege; coordinate with internal IT, information security, and executive stakeholders; and engage with forensic firms, crisis communications providers, insurers, and law enforcement. A central focus of his practice is advising on notification obligations and strategy, including the application of U.S. federal and state data breach notification laws and requirements along with contractual notification obligations, and helping companies make defensible, risk‑informed decisions about timing, scope, and messaging.

In addition to his work responding to cybersecurity incidents, Caleb works closely with clients’ legal, technical, and compliance teams on cybersecurity governance, regulatory compliance, and pre‑incident planning. He has extensive experience drafting and reviewing cybersecurity policies, incident response plans, and vendor contract provisions; supervising cybersecurity assessments under privilege; and advising on training and tabletop exercises designed to prepare organizations for real‑world incidents. His work frequently involves translating evolving regulatory expectations into actionable guidance for in‑house counsel, including in highly-regulated sectors such as the financial sector (including compliance with NYDFS cybersecurity regulations, the Computer Security Incident Notification Rule, and GLBA guidelines and guidance) and the pharmaceutical and healthcare sector (including compliance with GxP standards, FDA medical device guidance, and HIPAA).

Caleb’s practice also addresses evolving and emerging areas of cybersecurity and data security law, including advising clients on compliance with the Department of Justice’s Data Security Program, CISA‑related security requirements for restricted transactions, and preparation for new regulatory regimes such as the CCPA cybersecurity audit requirements and federal incident reporting obligations. He regularly counsels clients on how artificial intelligence and connected devices intersect with cybersecurity, privacy, and consumer protection risk, and how to support innovation while managing regulatory exposure.

Caleb also has extensive experience helping clients navigate high-stakes cybersecurity-related inquiries from the Federal Trade Commission, state Attorneys General, and other sector-specific regulators, including incident-specific inquiries as well as broader inquiries related to an entity’s cybersecurity practices and the security of product or service offerings. For companies that have entered into cybersecurity-related settlement agreements with regulators, Caleb has helped guide them through compliance with settlement agreement obligations, including navigating required third-party assessments and strategically responding to cybersecurity incidents that can arise while a company is subject to a settlement agreement. Caleb also routinely works hand-in-hand with colleagues in Covington’s class action litigation, commercial litigation, and insurance recovery practices to prepare for and successfully navigate incident-related disputes that can devolve into litigation.

Read more about Caleb SkeathEmail
Show more Show less
Photo of Ashden Fein Ashden Fein

Ashden Fein is co-chair of Covington’s Data Privacy and Cybersecurity Practice. He advises clients on cybersecurity and national security matters, including crisis management and incident response, risk management and governance, government and internal investigations, and regulatory compliance. Ashden also serves as lead counsel…

Ashden Fein is co-chair of Covington’s Data Privacy and Cybersecurity Practice. He advises clients on cybersecurity and national security matters, including crisis management and incident response, risk management and governance, government and internal investigations, and regulatory compliance. Ashden also serves as lead counsel in criminal, civil, and internal investigations involving cybersecurity, insider risk, and U.S. national security issues.

Ashden regularly counsels clients on preparing for and responding to cyber-based attacks, assessing security controls and practices for the protection of data and systems, developing and implementing cybersecurity risk management and governance programs, and complying with federal and state regulatory requirements. Ashden frequently supports clients as the lead investigator and crisis manager for global cyber and data security incidents, including data breaches involving personal data, advanced persistent threats targeting intellectual property across industries, state-sponsored theft of sensitive U.S. government information, extortion and ransomware, and destructive attacks.

Ashden also assists clients from across industries with leading internal investigations and responding to government inquiries related to U.S. national security and insider risks. He frequently represents government contractors in False Claims Act matters involving cybersecurity and national security. Additionally, he advises aerospace, defense, and intelligence contractors on security compliance under U.S. national security laws and regulations including, among others, the National Industrial Security Program (NISPOM), U.S. government cybersecurity regulations, FedRAMP, and requirements related to supply chain security.

Before joining Covington, Ashden served on active duty in the U.S. Army as a Military Intelligence officer and prosecutor specializing in cybercrime and national security investigations and prosecutions — to include serving as the lead trial lawyer in the prosecution of Private Chelsea (Bradley) Manning for the unlawful disclosure of classified information to Wikileaks. Ashden is a retired U.S. Army officer.

Read more about Ashden FeinEmail
Show more Show less
Photo of Micaela McMurrough Micaela McMurrough

Micaela McMurrough serves as co-chair of Covington’s global and multi-disciplinary Technology Group, as co-chair of the Artificial Intelligence and Internet of Things (IoT) initiative. In her practice, she has represented clients in high-stakes antitrust, patent, trade secrets, contract, and securities litigation, and other…

Micaela McMurrough serves as co-chair of Covington’s global and multi-disciplinary Technology Group, as co-chair of the Artificial Intelligence and Internet of Things (IoT) initiative. In her practice, she has represented clients in high-stakes antitrust, patent, trade secrets, contract, and securities litigation, and other complex commercial litigation matters, and she regularly represents and advises domestic and international clients on cybersecurity and data privacy issues, including cybersecurity investigations and cyber incident response. Micaela has advised clients on data breaches and other network intrusions, conducted cybersecurity investigations, and advised clients regarding evolving cybersecurity regulations and cybersecurity norms in the context of international law.

In 2016, Micaela was selected as one of thirteen Madison Policy Forum Military-Business Cybersecurity Fellows. She regularly engages with government, military, and business leaders in the cybersecurity industry in an effort to develop national strategies for complex cyber issues and policy challenges. Micaela previously served as a United States Presidential Leadership Scholar, principally responsible for launching a program to familiarize federal judges with various aspects of the U.S. national security structure and national intelligence community.

Prior to her legal career, Micaela served in the Military Intelligence Branch of the United States Army. She served as Intelligence Officer of a 1,200-member maneuver unit conducting combat operations in Afghanistan and was awarded the Bronze Star.

Read more about Micaela McMurroughEmail
Show more Show less
Photo of Ali Cooper-Ponte Ali Cooper-Ponte

Ali Cooper-Ponte draws on her experience at the U.S. Department of Justice to advise clients on complex and sensitive national security, cybersecurity, and online safety matters across regulatory, investigations, enforcement, and litigation contexts.

In her investigations and litigation practice, Ali guides clients through…

Ali Cooper-Ponte draws on her experience at the U.S. Department of Justice to advise clients on complex and sensitive national security, cybersecurity, and online safety matters across regulatory, investigations, enforcement, and litigation contexts.

In her investigations and litigation practice, Ali guides clients through both internal and government investigations. She helps clients across industries navigate significant enterprise risks, including insider, criminal, and advanced persistent or nation-state threats, as well as challenges relating to emerging technologies. She has also helped clients proactively engage with or respond to inquiries by the U.S. Department of Justice, state Attorneys General, and the Federal Trade Commission.

In her advisory practice, Ali helps clients strategically manage rapidly-changing regulatory and technological landscapes. She counsels clients on compliance with national security, cybersecurity, data privacy, content moderation, and child exploitation laws. She has particular expertise on issues relating to government access to data, including the Electronic Communications Privacy Act and the Foreign Intelligence Surveillance Act and the Fourth Amendment. She also has significant experience with new Federal and state laws implicating Section 230 of the Communications Decency Act and the First Amendment. Here, her experience spans industries (including the technology, healthcare, cryptocurrency and financial services, and aerospace and defense industries) and includes providing practical advice on new legislation, regulatory frameworks, and court rulings as well as developing legislative proposals and potential challenges to new legislation and government action.

Previously, Ali served in the U.S. Department of Justice as Senior Counsel in the Office of the Assistant Attorney General for the Criminal Division, where she focused on the cyber and child exploitation portfolios, and as a Trial Attorney in the National Security Division’s National Security Cyber Section and the Criminal Division’s Computer Crime and Intellectual Property Section. She joined the Justice Department as part of its inaugural class of Cyber Fellows, which gave her broad exposure to the Department’s work to address cyber and cyber-enabled threats.

Earlier in her career, Ali clerked for Judge José A. Cabranes on the U.S. Court of Appeals for the Second Circuit. Prior to law school, Ali worked as a legal investigations specialist focused on electronic surveillance and law enforcement access issues at a large technology company.

In addition to her regular practice, Ali leverages her experience to counsel pro bono clients engaged in work to protect children and civil liberties.

Read more about Ali Cooper-PonteEmail
Show more Show less
Photo of Shayan Karbassi Shayan Karbassi

Shayan Karbassi helps clients across industries navigate complex national security and cybersecurity matters to include government and internal investigations, incident and crisis response, regulatory compliance, and litigation.

As part of his cyber practice, Shayan assists clients with cybersecurity incident response and notification obligations…

Shayan Karbassi helps clients across industries navigate complex national security and cybersecurity matters to include government and internal investigations, incident and crisis response, regulatory compliance, and litigation.

As part of his cyber practice, Shayan assists clients with cybersecurity incident response and notification obligations, government and internal investigations of False Claims Act (FCA) issues and insider threats, and compliance with new and evolving federal and state cybersecurity regulations. Shayan also advises U.S. government contractors on security compliance under U.S. national security laws and regulations including, among others, the National Industrial Security Program (NISPOM), Federal Risk and Authorization Management Program (FedRAMP), and other U.S. government cybersecurity regulations.

More broadly, Shayan helps clients navigate potential civil and criminal legal risks stemming from operations in certain high-risk jurisdictions. This includes advising clients on U.S. criminal and civil antiterrorism laws, conducting internal investigations of terrorism-financing and related issues, and litigating Anti-Terrorism Act (ATA) claims.

Shayan maintains an active pro bono litigation practice with a focus on human rights, freedom of information, and free media issues.

Before joining Covington, Shayan served as a member of the U.S. intelligence community, where he routinely provided strategic analysis to the President and other senior U.S. policymakers.

Read more about Shayan KarbassiEmail
Show more Show less
Photo of Bryan Ramirez Bryan Ramirez

Bryan Ramirez is an associate in the firm’s San Francisco office and is a member of the Data Privacy and Cybersecurity Practice Group. He advises clients on a range of regulatory and compliance issues, including compliance with state privacy laws. Bryan also maintains…

Bryan Ramirez is an associate in the firm’s San Francisco office and is a member of the Data Privacy and Cybersecurity Practice Group. He advises clients on a range of regulatory and compliance issues, including compliance with state privacy laws. Bryan also maintains an active pro bono practice.

Read more about Bryan RamirezEmail
Show more Show less
  • Posted in:
    Criminal, Government and Public Policy, Privacy and Cybersecurity
  • Blog:
    Inside Privacy
  • Organization:
    Covington & Burling LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo