If You Don't Secure It, They’ll Remove It: What the New CE-TCO Offensive Cyber Memorandum Means for Industrial Operators

If You Don't Secure It, They’ll Remove It: What the New CE-TCO Offensive Cyber Memorandum Means for Industrial Operators

Key Takeaways

  • The August 12 presidential memorandum authorizes vetted U.S. private companies to conduct offensive cyber operations against foreign criminal groups, with every operation requiring written approval from DOJ and DHS co-directors and a bond of at least $1 million.
  • Industrial control systems and embedded processors and controllers are named explicitly in the memo's definitions of both surveillance and effects operations, putting OT infrastructure squarely inside the program's scope.
  • The program targets criminal organizations rather than nation-states.
  • Exposed devices conscripted into criminal relay infrastructure become legitimate disruption targets, and Section 5(c) of the memo creates no legal recourse for owners whose equipment is affected.
  • Protections in the memo extend only to U.S. persons and U.S.-located systems, leaving overseas industrial assets with materially less cover and making asset visibility and internet-exposure remediation the highest-priority steps.

On August 12, the White House issued a National Security Presidential Memorandum (NSPM) titled "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime." It authorizes vetted U.S. private companies to conduct offensive cyber operations, both surveillance and disruptive effects, against foreign criminal organizations that target Americans. The program runs through the National Coordination Center, with co-Executive Directors from the Department of Justice and the Department of Homeland Security who must approve every operation in writing before anyone acts.

The federal government is contracting private security firms to go on offense against overseas criminal gangs… This is a program pointed at ransomware crews, fraud networks and the criminal service economy that supports them.

Most of the coverage so far has framed this as an IT security story, or a national security story, or a story about the private sector finally being let off the leash. For those of us who spend our time inside plants, substations and treatment facilities, it is something more specific. Read the definitions section carefully and you will find that both "Cyber Effects Operation" and "Cyber Surveillance Operation" explicitly name industrial control systems and embedded processors and controllers among the infrastructure in scope.

That language was not an accident. It is worth understanding what it implies.

What the Offensive Cyber Memorandum Actually Does

Strip away the terminology and the structure is simple. The federal government is contracting private security firms to go on offense against overseas criminal gangs. The firms do not pick their own targets. They propose an operation, two federal officials sign off in writing, and the firm posts at least a million dollars of its own money that it forfeits if it breaks the rules. Operations that risk killing someone are prohibited outright. Operations touching Americans or systems inside the United States require legal review and, where applicable, judicial authorization.

The target definition matters as much as the mechanism. The program is aimed at what the memo calls Cyber-Enabled Transnational Criminal Organizations, defined as foreign groups that are not an institutional part of a foreign government. Nation-state actors are explicitly out of scope. This is a program pointed at ransomware crews, fraud networks and the criminal service economy that supports them.

For industrial operators, that is the right target. The incidents that actually halt production are overwhelmingly financially motivated, not espionage.

Public discussion of threats to critical infrastructure has been dominated by nation-state narratives for a decade. The operational reality inside plants is different, and the gap between the two is widening. A subset of our telemetry from critical infrastructure and operational technology environments shows the balance inverting over the course of this year. In January 2026, state-attributed activity outnumbered criminal activity by nearly five to one, and in February by almost seven to one. March was the crossover month, with criminal activity edging past state-attributed for the first time at 51.6%. It has not gone back. Criminal share climbed to roughly two-thirds through May, June and July, and in the first two weeks of August it reached 75.7%, better than three criminal incidents for every state-attributed one. In manufacturing specifically, we are seeing triple-digit growth in ransomware detections year over year. The federal picture points the same way. The FBI's 2025 Internet Crime Report recorded more than 2,100 ransomware incidents against U.S. critical infrastructure, with every one of the 16 critical infrastructure sectors reporting attacks and critical manufacturing among the most heavily targeted. Total reported cybercrime losses reached $20.9 billion, up 26% in a single year. Reports vary and the mix will keep moving, but the trend is not ambiguous. Cybercrime is not going away.

The executive memorandum is aimed at the half of the problem that is growing fastest.

Reaching Into the Bag

Here is the part that should interest anyone who thinks about deterrence.

Criminal operations against industrial targets have been, for years, a low-risk proposition. Reach into the bag, pull out a target, encrypt it, negotiate. The worst plausible outcome was an indictment that would never be served, or the inconvenience of standing up new infrastructure after a takedown. The economics were almost entirely one-directional.

This program aimed at foreign criminal organizations changes what might be in the bag. Not for every target, and not predictably, which is precisely the point. A crew running an operation now has to price in the possibility that the environment they are reaching into is connected to a program capable of dismantling their infrastructure. It is a bag that used to hold treasure and now might hold porcupines and snakes. Most of the time it will not. The uncertainty is the deterrent, and uncertainty is cheap to manufacture and expensive to ignore.

Whether that deterrence materializes depends entirely on execution, and execution is what the next 60 days will determine. The memorandum requires the program's operating procedures to be established within 60 days of August 12. Those procedures, not the memo itself, will decide whether this becomes a meaningful capability or a well-intentioned document.

If Your Equipment Is Conscripted, A Private Contractor Can Take It Down

Now the part that should concern asset owners rather than reassure them.

Criminal networks do not build most of their infrastructure. They borrow it. Internet-facing industrial gear, remote access appliances, cellular gateways at unmanned sites, cameras and the long tail of embedded devices that nobody has looked at since commissioning: all of it gets quietly conscripted into relay chains, staging servers and proxy networks. The owner is frequently unaware. In many cases, the owner does not know the device is reachable from the internet at all, because nobody has ever produced a complete inventory of what is out there.

Under the CE-TCO program, that borrowed infrastructure becomes a legitimate target for disruption.

Think about what that means in practice. An organization that leaves a device exposed with default or absent credentials has always been accepting a risk, but the risk used to be that criminals would use it. The new risk is that someone will come and take it down. The owner may never have been breached in a way they would recognize. They may learn about it when the device stops responding, or when a process that depended on it stops behaving.

Two details magnify the risk considerably:

  1. The memo's protections are written around U.S. persons and U.S.-located systems. An industrial operator with facilities in Europe, Latin America or Asia has materially less cover for exposed assets sitting at those sites.
  2. This is the line most readers will skim past: Section 5(c) states plainly that the memorandum creates no right or benefit enforceable at law by any party against the United States. There is no recourse built into this document for an owner whose equipment gets caught up in an operation.

The practical translation is blunt. If you do not fix your exposed infrastructure, someone eventually will, and you will have no say in how or when.

Everything Rests on Correct Attribution

There is one more risk worth naming, because it is a real design consideration for whoever writes those operating procedures.

Every offensive response framework rests on attribution being correct. Attribution is forgeable. Infrastructure can be rented, tooling can be borrowed, language artifacts can be staged. The memo's safeguards, including the prohibition on operations causing loss of life and the protections for U.S. persons, all assume the target has been correctly identified. The memo also presumes a group is non-state absent clear intelligence establishing otherwise, which widens the target set into genuinely ambiguous territory.

The failure mode is not hypothetical. Under a framework like this, a sophisticated adversary's most efficient play is no longer to attack a target directly. It is to arrange for someone else to attack that target on their behalf. That is a problem worth solving on paper, before it has to be solved in practice.

What Industrial Operators Should Do in the Next 30 Days

Nothing in the new program to combat TCO criminals changes the fundamentals of OT defense. It does change the urgency of a few specific items.

  • Find your internet-facing OT before anyone else does. Run your external ranges through Shodan or an equivalent. Look specifically for Modbus TCP (502), DNP3 (20000), EtherNet/IP (44818), and web-based HMIs on 80 and 443. Anything resolving externally that does not need to should go behind a DMZ with MFA and IP allowlisting, or come off the internet entirely.
  • Build the asset inventory you have been deferring. You cannot defend, argue for, or account for an asset you do not even know you own. This is no longer a compliance exercise. It is the difference between managing your own equipment and having someone else decide its fate.
  • Rotate credentials on everything reachable. Default and reused credentials remain the primary enabler in nearly every publicly documented industrial intrusion of the last three years. The pattern has not changed because the underlying practice has not changed.
  • Watch your own outbound traffic. A device that has been conscripted into criminal infrastructure behaves differently than one that has not. It talks to destinations it has no operational reason to talk to. Baselining normal communications and flagging deviations is how you find out that your gear is working for somebody else before it becomes somebody else's target.
  • Extend the same scrutiny to non-U.S. sites. The protections in this memorandum stop at the border. Your operations do not.

The Best Cyber Defense Is the Porcupine Strategy

Offensive operations extend the government's reach. They do not extend yours.

There is a defense doctrine sometimes called the porcupine strategy: rather than matching an adversary's offensive capability, make yourself expensive enough to attack that the attack stops being worth attempting. That’s how a porcupine defends itself, and it’s the position nearly every industrial operator should adopt. This memorandum does not change that. Federal offensive capability and asset-level defensive capability are complementary, not substitutes.

A porcupine that cannot detect the predator until contact is just a rodent. Deterrence at the plant starts with knowing what is in your environment, what it is talking to, and what has changed.

Nozomi Networks provides passive OT and IoT asset discovery, continuous anomaly detection and threat intelligence purpose-built for critical infrastructure environments. If you want help understanding what is on your network and where your exposure actually sits, request a demo or contact us directly.

No items found.
No items found.
No items found.