US Authorizes Select Private Firms for Offensive Cyber Operations

3 min readSources: TechCrunch

On August 13, 2026, the US authorized some private firms to launch offensive cyber operations.

Why it matters: This policy change affects how companies handle cyber threats and compliance, requiring legal teams to navigate new approval processes and risks for private-sector cyber responses.

  • August 13, 2026: The US issued an executive order allowing select firms to perform offensive cyber activities.
  • Private companies must meet strict criteria and obtain government approval from agencies including the Department of Homeland Security (DHS) and Cybersecurity and Infrastructure Security Agency (CISA).
  • The 2015 Executive Order 13694 previously prohibited private-sector offensive cyberattacks.
  • This update reflects evolving cyber threats and aims to enable more proactive defense by private entities under federal oversight.

On August 13, 2026, the US government issued an executive order permitting certain vetted private companies to conduct offensive cyber operations, a task historically limited to government agencies like the NSA and FBI.

Previously, Executive Order 13694, signed in 2015, explicitly barred private entities from engaging in "hack back" activities, reserving offensive cyber responses for authorized government actors.

The new policy requires private firms to meet rigorous eligibility standards and obtain explicit authorization from agencies including the Department of Homeland Security (DHS) and the Cybersecurity and Infrastructure Security Agency (CISA). This oversight ensures operations comply with legal frameworks and minimize collateral damage.

An official from DHS stated, "This order enables a more dynamic approach for defending critical infrastructure by allowing vetted private partners to act within clearly defined legal boundaries," clarifying that offensive actions must be coordinated and approved to avoid escalation or legal violations.

This development demands close attention from legal and cybersecurity professionals advising businesses. Legal teams must guide clients through compliance with authorization protocols, liability considerations, and the integration of offensive tactics into corporate cybersecurity strategies. It also impacts vendor agreements and incident response plans, necessitating updates to reflect new operational risks and responsibilities.

While the executive order lays out the framework, specific criteria for approval and operational limits are pending detailed guidance from DHS and CISA, expected in upcoming months.

By the numbers:

  • August 13, 2026 — date of the new executive order authorizing private offensive cyber operations
  • 2015 — year Executive Order 13694 banned private sector offensive cyberattacks
  • 2 agencies — DHS and CISA involved in approving private-sector offensive cyber activities

Yes, but: The new order's authorization process and operational scope remain somewhat undefined, creating uncertainty for firms considering participation until further guidance is issued.

What's next: DHS and CISA will release detailed authorization criteria and operational guidelines in the coming months to implement the executive order.