Breaking NewsUpdated as information becomes available
Breach Analysis·14 August 2026·Breaking

US directive allows private firms to conduct offensive cyber operations

US President Donald Trump has signed a memorandum permitting private firms to execute offensive cyber operations. The move raises new risks of retaliatory attacks and collateral system disruptions.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
3 min read
Share
Abstract digital concept representing offline network security and physical data storage
Breach Analysis

Article record

Breach AnalysisCategory
14 August 2026Published
3 min readReading time
Mark FermorWritten by
Abstract digital concept representing offline network security and physical data storage

Why it matters

What this means for organisations holding critical data

US President Donald Trump has signed a memorandum permitting private firms to execute offensive cyber operations. The move raises new risks of retaliatory attacks and collateral system disruptions.

According to reporting by The Guardian, United States President Donald Trump has signed a national security presidential memorandum that authorises private sector organisations to conduct offensive cyber operations against foreign criminal entities. The directive permits vetted commercial companies to carry out digital actions under the direction, control, and authority of federal agencies.

What happened

The presidential memorandum establishes a legal framework for commercial firms to partner with federal, state, local, tribal, and territorial agencies. Participating companies will collect intelligence on foreign criminal groups, officially designated as transnational criminal organisations, and propose offensive digital operations to disrupt those threats.

Overseen by the Department of Homeland Security and the Department of Justice, the initiative will run through the national coordination centre of the homeland security taskforce. Vetted commercial firms will be authorised to carry out cyber surveillance operations and cyber effects operations against designated foreign targets. Official White House documentation defines cyber effects as actions that manipulate, disrupt, deny, degrade, or destroy information systems, networks, and physical or virtual infrastructure.

To participate, private companies must maintain an escrow or financial bond of at least 1,000,000 dollars. The White House highlighted that foreign criminal groups pose ongoing threats through ransomware attacks and financial fraud. The executive action follows national policy documents published in March that proposed expanding commercial involvement in cyber operations. This comes after recent cyber incidents in the United States, such as targeted attacks against operational technology across more than 30 water facilities in Minnesota.

What the data means for the sector

The policy marks a significant shift in national security practice by granting private organisations duties traditionally restricted to government agencies. Allowing commercial entities to execute active cyber disruptions against foreign criminal groups creates new complexities for legal risk, international conflict, and threat management.

Legal analysts and security experts have highlighted risks regarding escalation, collateral damage, and inter-agency coordination. When commercial organisations engage in cyber surveillance or destructive operations against foreign entities, those groups are likely to launch counter-attacks against the participating firms or their connected business partners. Furthermore, identifying criminal servers without affecting shared commercial infrastructure remains technically challenging. An offensive action intended for a criminal target could inadvertently degrade legitimate systems or impact innocent third parties.

For commercial enterprises, the digital risk environment is becoming increasingly unpredictable. As the distinction between government operations and private defense blurs, non-participating organisations may still face indirect disruption or retaliatory strikes directed at broad supply chains.

The Firevault view

Mark Fermor, senior editor at Firevault, notes that privatising offensive digital actions will inevitably escalate risks for connected business infrastructure. When cyber operations actively involve commercial networks, the probability of destructive counter-attacks and unintended system degradation increases for all connected entities.

In a landscape where active digital disruption is encouraged, relying exclusively on network-attached security controls creates serious vulnerability. Firevault advocates for Offline Secure Storage® (#OSS) to protect mission-critical information. Maintaining an air gapped, physically controlled copy of vital records keeps key assets disconnected from public and private networks. Should retaliatory strikes or collateral network disruptions compromise online systems, #OSS ensures that essential data remains completely protected and available for restoration.

What to do next

Organisations assessing their risk exposure under this shifting cyber framework should implement the following measures:

  • Identify and audit all critical digital assets, customer records, and operational databases.
  • Assess supply chain risk to determine if key technology partners participate in offensive cyber initiatives.
  • Implement #OSS to maintain air gapped, unalterable physical copies of core data.
  • Regularly test offline recovery processes to ensure rapid operational restoration following network disruption.

Sources

Where this reporting comes from

01
Original reportPrimary coverage referenced in this analysisView original article

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

HardwareYour data sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
CommandAccess windows and retrieval under your control
LocationHeld in a secure Firevault Bunker

Share this article

Breaking News
Breach Analysis14 August 20263 min read

US directive allows private firms to conduct offensive cyber operations

US President Donald Trump has signed a memorandum permitting private firms to execute offensive cyber operations. The move raises new risks of retaliatory attacks and collateral system disruptions.

US directive allows private firms to conduct offensive cyber operations
Mark Fermor
Published by Mark Fermor, Director & Co-Founder

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy