Hacking Back
8-17-2026 (Monday)
Hello, and welcome to The Intentional Brief - your weekly video update on the one big thing in cybersecurity for middle market companies, their investors, and executive teams.
I’m your host, Shay Colson, Managing Partner at Intentional Cybersecurity, and you can find us online at intentionalcyber.com.
Today is Monday, August 17, 2026, and we’re going to take a break from both the AI sandbox escapes and the Strait of Hormuz tracking to cover an adjacent space this week, specifically a White House announcement about privately run offensive cyber operations, and what that might mean for you.
Hacking Back
On Wednesday of last week, President Donald Trump signed a “national security presidential memorandum (NSPM) enables the NCC (part of the Homeland Security Task Force) to leverage the U.S. private sector's capabilities to conduct cyber operations targeting transnational criminal organizations under the control and authority of the U.S. Government.”
Reporting indicates the “memo appears to permit companies participating in the program to use spyware or launch offensive attacks intended to destroy TCO data or systems. The memo doesn’t rule out certain types of offensive attacks, such as those that use encryption to lock targets out of their networks or performing distributed denial-of-service attacks.”
From a details perspective, they’re still relatively light, but do note that “Cyber Effects Operations and Cyber Surveillance Operations may not result in “Critical Outcomes,” meaning those that result in the loss of life or serious injury or “rise to the level of use of force or armed attack under international law.” The memo also notes:
“[M]inimum standards that Participating Companies must meet in order to take part in the Program, which shall include appropriate levels of technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence, reliability, and other factors that the Program Executive Directors, in coordination with the Homeland Security Council, determine are relevant or necessary for guaranteeing high confidence in a Participating Company’s ability to perform successfully.
Participating companies must also deposit $1 million in an escrow account. The deposit will be forfeited “should the Participating Company enter non‑compliance with its contractual agreement described” in the memo.
But, beyond that, we’re left to fill in the blanks ourselves.
Traditionally, the notion of hacking back by private actors has been eschewed because of the difficulty around attribution, a concern that remains ever-present today. In fact, you could argue that in a world of AI-driven content, attribution is even more difficult (you can imagine directing your AI-agent to use TTPs that might resemble a particular threat actor, for example).
The other piece that has traditionally constrained these efforts is the lack of offensive cybersecurity talent in the private sector, as these skills were typically limited to military and intelligence groups, then converted in to testing and defensive skills in the private sector. But now with AI, what’s to stop the development of these capabilities but a few guardrails put in by some - but not all - of the AI model builders.
And what happens when something goes wrong? Nobody can really say, though you can imagine that beyond the $1M escrow, there might be actual business ramifications for firms that engage in these sort of operations that go sideways. Or, may have implications for publicly-traded companies who are considering this avenue. There’s also the reality that it may actually make these private actors more of a target by nation-state actors, as they’re now “on the battlefield” so to speak.
From a legal perspective, we’re already seeing challenges around the autonomous agent hacks we’ve covered in the past couple of weeks, with the answer being “it’s complicated.”
And about to get much more complicated.
The regulatory landscape will continue to change, including some newly drafted Cyber Resilience standards out of the European Union, and recommendations for AI regulations here in the US.
As always, I think the prudent path here is to focus on what you can control. I would not recommend spinning up an offensive capability to enter this newly defined market, but that doesn’t mean everybody won’t. Public-private collaboration here is one thing, but the idea that we can move fast enough in partnership to target these threats is another thing entirely.
Watch this space - amongst all the others we’ve got our eyes on.
Fundraising
From a fundraising perspective, much more reasonable numbers this week, with just over $7b in newly committed capital:
Led by Accel, who raised $3.5b in new funds, including a $1.35b global expansion fund, $800m for a U.S. fund, $800m for a Europe/Israel fund, and $550m for an India fund; while
1789 Capital has closed a $1.2b real estate development fund.
A reminder that you can find links to all the articles we covered below, find back issues of these videos and the written transcripts at intentionalcyber.com.
We’ll see you next week for another edition of the Intentional Brief.
Links
https://www.politico.com/news/2026/08/13/white-house-memo-cybercrime-01036176
https://www.noahpinion.blog/p/23-low-regret-recommendations-for