The New Age of the Privateer: The Cyberteer

Glomz-guy1 pts0 comments

Cyberteering: The Return of the Letter of Marque in Cyberspace

Privateering, updated for the digital age.

If you blinked, you missed it.

The White House posted a presidential memorandum on August 12. The title is the kind of bureaucratic mouthful that makes people scroll past: "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime."

Don't scroll past.

This might be the most significant shift in American cyber power projection in a generation. And it doesn't create a new government cyber command. It doesn't expand some existing agency. It does something that hasn't been done in centuries:

It authorizes private companies to conduct offensive cyber operations against foreign criminal networks — under federal direction and oversight.

In other words, the United States just revived privateering for the digital age.

What It Actually Says

The memo creates a program run out of the National Coordination Center (NCC). Private companies apply to participate. They get vetted. They sign contracts with DOJ or DHS. They post a bond — minimum $1 million, forfeited if they step out of line. And then they conduct cyber surveillance and effects operations against designated foreign cyber-enabled transnational criminal organizations (CE-TCOs).

Two executive directors co-run the thing — one from DOJ, one from DHS. They coordinate every operation. And they can't approve anything that would rise to the level of use of force or endanger life. That requires higher authorization.

There's a classified annex. There's a 60-day clock for operating procedures. Participating companies can take in threat intel from private sector clients and from federal, state, and local agencies — but everything flows through the NCC's approval chain.

The important part:

Cyber operations shall only be approved after coordination between the Program Executive Directors, and any resulting operational action will be exclusively conducted on behalf of and under the supervision of the Federal Government.

Companies don't freestyle. They execute approved packages on behalf of the United States.

Why I'm Calling It Cyberteering

"Cyber privateering" is clunky. "Authorized offensive cyber contracting" is the kind of phrase that dies in committee. Neither one lands.

Cyberteering is short. It's precise. It tells you exactly what's happening: the government is authorizing private actors to conduct offensive cyber operations on its behalf, under its control. That's privateering. The domain changed. The mechanism didn't.

Historical privateers sailed under letters of marque — licenses from the Crown to attack enemy shipping. The government got naval power it couldn't afford to build. The privateers got legal cover and a share of the spoils. Everyone understood the arrangement.

This is the same arrangement, translated into code.

The Third Path

For years, this debate has been stuck between two bad options:

The False Binary

Government-only cyber ops — capable but constrained. Bureaucracy moves slowly. Talent goes to the private sector. The mission set is too big for the workforce.

Private "hack-back" — uncoordinated, legally dubious, strategically dangerous. Companies acting alone risk escalation, collateral damage, and diplomatic incidents. Nobody wants this.

Cyberteering is the third option. Private sector speed and talent, government control and accountability. The state keeps the monopoly on legitimate force. The private sector does the technical work. Both sides are bound by contract, procedure, and oversight.

Is it risk-free? No. But it's more controlled than the status quo, which is private companies doing cyber operations anyway — just without a framework, without oversight, and without legal cover.

What This Means for OT Defenders

If you run OT systems — water, energy, manufacturing, transportation — this matters. Not because you'll be part of the program. Because the people on the other side are going to react.

Here's what happens next:

Escalation risk. The ransomware groups, fraud networks, and cyber-enabled criminal organizations that are now formal targets don't just roll over. They may accelerate operations, shift tactics, or hit harder before the program gets its footing. The near-term window could get noisier.

Attribution gets murkier. State-aligned actors have an incentive to mask their operations as criminal activity. When the US is authorizing private offensive ops against "criminal" targets, adversaries have cover to blur the line between criminal and state action. That makes everyone's job harder.

The bottom line: The policy is strategically sound. But strategic transitions create tactical friction. If you're defending critical infrastructure, expect the adversary pool to get more volatile before it gets more manageable. The fundamentals don't change — segment, monitor, assume breach, design for resilience — but the tempo might.

Why It Matters Here

This site is about control systems security. The nuts and...

cyber private operations government companies criminal

Related Articles