Dominic Jainy is an IT professional whose deep dive into emerging technologies like machine learning and blockchain provides him with a unique vantage point on the evolving digital battlefield. As the United States moves to integrate private sector innovation into its offensive cyber arsenal, the lines between corporate defense and national security are blurring more than ever before. In our discussion, we explore the implications of the latest National Security Presidential Memorandum, which authorizes federal law enforcement to collaborate with private firms on offensive strikes. We navigate the staggering economic toll of cyber-enabled crime—where billions are lost annually—and the precarious technical hurdles of digital attribution that could lead to unintended international escalations.
The National Coordination Center is establishing a program co-led by the Department of Justice and the Department of Homeland Security; how do you envision this leadership structure bridging the gap between federal oversight and private sector agility?
This leadership structure is a calculated move to harmonize the “innovative and technologically advanced” nature of our private sector with the legal weight of the federal government. By having Executive Directors from both the DOJ and DHS at the helm, the program creates a direct conduit for firms to move past the “underutilized” status mentioned in the memorandum. It isn’t just about sharing data; it’s about establishing a framework where private entities can propose actual cyber operations designed to disrupt criminal networks. The presence of high-level federal oversight ensures that while we tap into corporate ingenuity, every action remains anchored to the US Constitution and specific legal mandates. This formalizes a relationship that has historically been somewhat fragmented, allowing for a more unified front against sophisticated transnational threats.
With US consumers reportedly losing over $20.8 billion to cyber-enabled crime in 2025, what does this massive economic impact tell us about the limitations of our current defensive strategies?
The loss of $20.8 billion in a single year is a staggering realization that our traditional “perimeter defense” mindset is failing to stem the tide. When you consider that 73% of U.S. adults have already experienced some form of online scam or attack, it becomes clear that cybercrime has reached a saturation point in the American experience. These numbers represent more than just ledger entries; they reflect the stolen savings of families and the operational paralysis of small businesses. The White House’s decision to deploy “every available tool” suggests an admission that staying purely on the defensive is no longer sustainable. We are shifting toward a proactive posture because the sheer scale of the damage has made the cost of inaction far higher than the risks associated with offensive collaboration.
Given that experts like Nick Carr have raised concerns about the extreme difficulty of attribution, how can the program ensure that offensive strikes don’t accidentally target the wrong actors?
Attribution is arguably the most “ghostly” and difficult aspect of digital warfare, and the concern that organizations can be “willingly wrong” on important incidents is very real. Even government agencies struggle with the smoke and mirrors used by transnational groups who excel at masquerading as other entities. The new program aims to mitigate this by implementing “rigorous procedures” for the review of any proposed limited cyber operations. This means a private firm can’t just launch a strike based on a hunch; they must enter into formal agreements to gather threat intelligence that stands up to federal scrutiny. The hope is that by combining the massive data sets held by the private sector with the investigative resources of the DOJ, the accuracy of identifying these perpetrators will see a significant boost before any “destroy” order is ever given.
How does this memorandum represent a “big shift” in policy compared to the controversial idea of companies “hacking back” on their own?
This policy is a sophisticated evolution rather than a Wild West “hack back” free-for-all. As Chris Wysopal noted, this is a major expansion of the private sector’s role, but it remains strictly under the direction and thumb of the US government. Unlike independent hacking back, which could lead to legal chaos and vigilante errors, this memorandum establishes a controlled environment where private firms act as an extension of national policy. It creates a “limited” scope for operations, ensuring that actions are compliant with international agreements and domestic laws. The distinction is crucial because it provides companies with a legal “shield” and a clear set of rules, ensuring their technical expertise is used as a precision instrument rather than a blunt, unauthorized weapon.
Looking at the UK’s creation of the National Cyber Force in 2020, what lessons should the US take regarding the risk of interstate escalation when disrupting cyber-controlled infrastructure?
The UK’s experience with the NCF highlights that offensive capabilities should be a “rarely deployed” tool, used only when other responses are poorly suited for the challenge. Dr. Lukasz Olejnik’s warning about the destruction of cyber-controlled infrastructure is particularly poignant because what looks like a criminal node might actually be intertwined with state-linked systems. If a US-backed private operation inadvertently cripples a foreign government’s infrastructure, the risk of shifting from a crime-fighting mission to an interstate conflict is high. We must learn from the UK’s published principles by maintaining extreme transparency within the government about the potential “blast radius” of any disruption. The goal is to act as a deterrent, but without a careful, measured approach, these strikes could unintentionally provoke the very hostilities they are meant to suppress.
What is your forecast for the evolution of private sector involvement in national cyber defense over the next decade?
I expect we will see a permanent blurring of the lines between corporate security teams and national defense intelligence. As these public-private partnerships mature, we will likely move toward real-time, automated intelligence sharing where the federal government provides the legal authority and the private sector provides the “eyes and ears” across global networks. We may see the emergence of specialized “cyber-defense contractors” whose entire business model is built around these DOJ and DHS-led programs, much like traditional defense contractors in the physical world. However, the success of this shift will depend entirely on our ability to maintain the “rigorous procedures” promised today. If we can master the art of accurate attribution and controlled disruption, this model could become the global standard for combating the $20 billion-plus threat that looms over our digital economy.
