Skip to content
TECH CEO Daily

Sean Cairncross defends White House private-sector hacking program, urges security basics

The national cyber director called the plan a tightly overseen way to scale action against cybercrime gangs, while telling companies to patch and replace old gear first.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1National Cyber Director Sean Cairncross defended a program letting vetted companies disrupt foreign cybercrime gangs' computer systems.
  • 2Justice and Homeland Security would vet proposals and oversee operations, Cybersecurity Dive reported.
  • 3Baker McKenzie says firms must post a bond of at least $1 million and get no explicit civil immunity.

The news

National Cyber Director Sean Cairncross has defended the Trump administration's private-sector hacking program, a plan to let vetted companies go on the offense against foreign cybercrime gangs. Speaking at a USTelecom event in Washington, reported by Cybersecurity Dive on September 30, 2026, he also pressed organizations to fix basic security weaknesses.

Under the program, the departments of Justice and Homeland Security will review proposals from private companies to disrupt the computer systems of foreign criminal groups, then oversee the operations, Cybersecurity Dive reported. That oversight includes deconflicting with military and intelligence activity and checking that operations comply with US law.

Cairncross described it as "a very specific program, overseen by the government," intended to help Washington scale up its efforts against these actors, according to Cybersecurity Dive. He argued that people deciding whether to harm the United States respond to incentives, framing the effort as a matter of deterrence. The outlet said his remarks were among the first from a senior official about the initiative, which President Donald Trump announced in August.

The program rests on a National Security Presidential Memorandum signed on August 12, 2026, titled "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," according to an analysis by law firm Baker McKenzie. The firm says it covers two kinds of activity: surveillance operations involving covert, unauthorized access to systems to gather intelligence, and effects operations meant to disrupt, degrade or destroy criminal systems or data.

Cairncross also turned to defense. He told the audience that new technology is not the only answer and urged patching and replacing legacy technology, including end-of-life edge devices such as old routers and firewalls, Cybersecurity Dive reported. He said the administration is working with frontier AI labs to bring vulnerability-detection tools into critical infrastructure networks, and that it is committed to harmonizing incident reporting rules as the Cybersecurity and Infrastructure Security Agency (CISA) finalizes its own.

The numbers

Memorandum signed
August 12, 2026
Minimum bond or escrow for participants (per Baker McKenzie)
$1 million

Why CEOs should care

For general counsel and boards, the program is an opportunity with real legal exposure. Baker McKenzie says participants must contract with DOJ or DHS, post a forfeitable bond or escrow of at least $1 million, pass a vetting review and be reassessed every year. The firm also notes the memorandum does not give companies explicit civil immunity, and operations must still comply with the Computer Fraud and Abuse Act (the main US anti-hacking law). Before any firm volunteers, its leadership should ask who pays if an operation damages an innocent third party's system, and whether insurers will cover it.

CISOs should think about retaliation. A company publicly known to be attacking a ransomware gang's servers could become a target itself. Questions to settle in advance: is our own house in order, can we absorb a revenge attack, and how would participation affect information we share with peers or regulators? Baker McKenzie flags possible conflicts with communications privacy laws and with legal privilege over threat data.

For most organizations, the more practical message is Cairncross's call for basics. Inventory end-of-life edge devices, set deadlines to replace them, and track patching speed on internet-facing systems. That work is cheaper than any offensive program and addresses the weaknesses criminals use most.

The bigger picture

For years, US law and policy discouraged "hack back" by private companies, leaving offensive cyber operations to the government. This memorandum creates a supervised path instead of a free-for-all, but it shifts some of the risk to companies. Firms in technology, cybersecurity, financial services, healthcare, energy and transportation are likely candidates, according to Baker McKenzie.

What’s next

Watch for DOJ and DHS to publish how companies can apply, for the first approved operations, and for CISA's final incident reporting rules, which Cairncross said the administration wants to align with other reporting requirements.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Sean CairncrossWhite HouseCybercrimeHack back

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.