Control Systems Security

Cyberteering

Private Cyber Contractors, Government Oversight, and the Contract That Replaces the Letter of Marque

Storm-tossed cyberpunk pirate ship with glowing blue circuitry on sails and hull, American flag and neon green skull-and-crossbones banner flying from the masts, blue energy arcing from cannons and rigging

Privateering, updated for the digital age.

If you blinked, you missed it.

The White House posted a presidential memorandum on August 12. The title is the kind of bureaucratic mouthful that makes people scroll past: "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime."

Don't scroll past.

This might be the most significant shift in American cyber power projection in a generation. And it doesn't create a new government cyber command. It doesn't expand some existing agency. It does something that hasn't been done in centuries:

It authorizes private companies to conduct offensive cyber operations against foreign criminal networks — under federal direction and oversight.

In other words, the United States just revived privateering for the digital age.

What It Actually Says

The memo creates a program run out of the National Coordination Center (NCC). Private companies apply to participate. They get vetted. They sign contracts with DOJ or DHS. They post a bond — minimum $1 million, forfeited if they step out of line. And then they conduct cyber surveillance and effects operations against designated foreign cyber-enabled transnational criminal organizations (CE-TCOs).

Two executive directors co-run the thing — one from DOJ, one from DHS. They coordinate every operation. And they can't approve anything that would rise to the level of use of force or endanger life. That requires higher authorization.

There's a classified annex. There's a 60-day clock for operating procedures. Participating companies can take in threat intel from private sector clients and from federal, state, and local agencies — but everything flows through the NCC's approval chain.

The important part:

Cyber operations shall only be approved after coordination between the Program Executive Directors, and any resulting operational action will be exclusively conducted on behalf of and under the supervision of the Federal Government.

Companies don't freestyle. They execute approved packages on behalf of the United States.

Why I'm Calling It Cyberteering

"Cyber privateering" is clunky. "Authorized offensive cyber contracting" is the kind of phrase that dies in committee. Neither one lands.

Cyberteering is short. It's precise. It tells you exactly what's happening: the government is authorizing private actors to conduct offensive cyber operations on its behalf, under its control. That's privateering. The domain changed. The mechanism didn't.

The term itself has prior academic use. It appeared in SSGRR conference papers circa 2002 as shorthand for cyber-racketeering, and was later developed by Still (2011, GW ScholarSpace) into a formal framework for government-licensed private cyber counterattack — complete with headings like "Legality of Cyberteering Legislation" and "Regulating and the Effects of the Cyberteering Program." The concept was later discussed in Harašta & Bátrla's "Of Hackers and Privateers" (Masaryk University), which references the "attribution-cyberteering concept and reinstitution of Letters of Marque proposed by Still." All of that was theoretical. None of it was tied to an actual, active US government program — because no such program existed.

Historical privateers sailed under letters of marque — licenses from the Crown to attack enemy shipping. The government got naval power it couldn't afford to build. The privateers got legal cover and a share of the spoils. Everyone understood the arrangement.

That's the same arrangement, translated into code — but with one critical distinction.

This Is Not a Letter of Marque

The memo is a contract vehicle, not a letter of marque. There is a real difference.

Pending in Congress right now are the actual statutory vehicles for cyber letters of marque: Senator Mike Lee's Cyber Letters of Marque and Reprisal Act (S. 5000, introduced July 15, 2026, House companion by Rep. Tim Burchett). Those bills would create the constitutional framework for private commissions under Article I, Section 8. They have not passed. They may never pass.

Instead, the White House memo does this through executive authority and DOJ/DHS contracting. Companies don't get a letter of marque. They get a contract. They don't operate under congressional commission. They operate under federal procurement and supervision. The operational result — private companies conducting offensive cyber on behalf of the government — is similar. The legal foundation is entirely different.

That matters. Contracts can be modified, suspended, or terminated by the executive branch. Letters of marque require congressional action. If the next administration reverses course, these contracts disappear. If Congress passes S. 5000, the framework shifts from contracting to constitutional commission. Watch both tracks.

The Third Path

For years, this debate has been stuck between two bad options:

The False Binary

Cyberteering is the third option. Private sector speed and talent, government control and accountability. The state keeps the monopoly on legitimate force. The private sector does the technical work. Both sides are bound by contract, procedure, and oversight.

Is it risk-free? No. But it's more controlled than the status quo, which is private companies doing cyber operations anyway — just without a framework, without oversight, and without legal cover.

What This Means for OT Defenders

If you run OT systems — water, energy, manufacturing, transportation — this matters. Not because you'll be part of the program. Because the people on the other side are going to react.

Here's what happens next:

The bottom line: The policy is strategically sound. But strategic transitions create tactical friction. If you're defending critical infrastructure, expect the adversary pool to get more volatile before it gets more manageable. The fundamentals don't change — segment, monitor, assume breach, design for resilience — but the tempo might.

Why It Matters Here

This site is about control systems security. The nuts and bolts of keeping critical infrastructure running when the people trying to break it are organized, funded, and patient.

The cyberteering memorandum changes what those people are worried about. It doesn't change what defenders need to do. The work is still the same. But the environment just got more complicated.

And complexity favors whoever plans for it first.

Primary Source

The full text of the presidential memorandum:

whitehouse.gov — Expanding Capabilities to Combat Transnational Cyber-Enabled Crime

Related: How Cyberteering Will Actually Work — a speculative look at the application process and operational workflow.

OTFeed matches public ICS advisories to the gear a customer actually runs. otfeed.com

The views expressed are the author's alone and do not represent the positions, strategies, or opinions of any government agency, department, or employer. This article is commentary on publicly reported policy and does not disclose classified, sensitive, or non-public information.