Offense, Defense, and a New Federal Cybersecurity Policy
On August 12, the White House issued a presidential memorandum, "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime." It's worth a close read, because it changes who is allowed to conduct offensive cyber operations on America's behalf. The policy creates a new class of "Participating Companies", private firms that, under contract with the Department of Justice or Department of Homeland Security, can carry out offensive operations against transnational criminal organizations. These aren't pen testers probing their own networks. The memo authorizes two categories of activity: "cyber surveillance operations," which involve unauthorized access into foreign systems to collect intelligence while staying undetected, and "cyber effects operations," which manipulate, disrupt, or destroy foreign infrastructure outright. Companies that want in must undergo vetting, post a bond of at least $1 million, and disclose their contractual relationships to a new National Coordination Center.
For organizations in healthcare, finance, defense, energy, and other regulated industries, the policy itself won't change day-to-day operations, you won't be signing up to be a Participating Company, and you shouldn't want to. But it's a useful prompt to get clear on something a lot of people conflate: what offensive cyber actually is, what defensive cyber actually is, and how the two fit together, especially in industries that are both heavily regulated and constantly targeted.
Defining offense
Offensive cyber means taking action against an adversary's own infrastructure. It requires legal authority, because most of it is illegal without one since you're accessing or altering systems you don't own. A few concrete examples: the FBI's 2023 court-authorized takedown of the Hive ransomware group's servers, which let investigators quietly collect decryption keys before shutting the operation down; Microsoft's Digital Crimes Unit using civil court orders to seize domains that botnets like Necurs relied on for command-and-control; and, more broadly, the kind of signals-intelligence collection intelligence agencies run inside adversary networks to understand a threat before it's ever launched. The new memo extends a version of that authority to vetted private companies operating under DOJ and DHS oversight, specifically against transnational criminal organizations, not nation-states, and not on behalf of an individual company defending itself.
Defining defense
Defensive cyber means protecting an environment you're responsible for: detecting intrusions, containing them, recovering from them, and building systems resilient enough that an incident doesn't become a catastrophe. In practice, that's a security operations center triaging alerts overnight, a managed detection and response team hunting for lateral movement inside a hospital network, an OT engineer segmenting a plant floor so a ransomware infection can't reach machinery that controls physical safety, or a compliance team closing gaps a CMMC or HIPAA assessor would flag. Defense doesn't need special legal authority, because the whole point is protecting what's already yours.
Where the two meet
The interesting part isn't that offense and defense are different, it's how much they depend on each other, especially in target-rich, highly regulated environments. Hospitals, defense contractors, utilities, financial institutions, and other regulated organizations sit at the intersection of two things adversaries want: valuable, sensitive data and outsized leverage, since disrupting a hospital's systems or a utility's grid controls creates pressure a disruption to a retail website never would. That's exactly why these sectors are the most frequent targets of ransomware and nation-state-linked intrusions, and exactly why offensive disruption efforts, however well-executed, will never be the whole answer.
Here's the connective tissue. When a defender inside a regulated organization detects and documents an intrusion — the malware samples, the command-and-control domains, the tactics used — that telemetry often becomes the evidence base that eventually supports an offensive takedown somewhere else in the ecosystem. And when an offensive operation succeeds in disrupting a ransomware group's infrastructure, defenders benefit directly: fewer active campaigns, published indicators of compromise to hunt for, sometimes even recovered decryption keys. Offense buys time and imposes cost upstream; defense is what determines whether an organization survives the attacks that get through in the meantime, which, in a target-rich environment, is never zero. Resiliency — the ability to actually recover, not just detect, is the load-bearing piece of that equation for critical industries.
That's also why compliance frameworks like CMMC, HIPAA, and FedRAMP function as a floor rather than a ceiling. Meeting the letter of a regulation doesn't guarantee an organization can detect and recover from a sophisticated adversary in the time it actually has — genuine cyber maturity means building well past the compliance checklist. And for organizations running OT and ICS environments, think manufacturing floors, utilities, ports, and the like, the cost of being caught unprepared is measured in downtime, safety incidents, and market access, not just data loss. Securing that industrial edge has become a genuine competitive advantage, not just table stakes.
The new policy is a bet that giving vetted private companies more room to operate offensively will help disrupt the criminal ecosystem targeting American organizations. It's a reasonable bet, and one worth understanding well. But it operates one layer removed from the organizations actually holding the data, running the plants, and treating the patients. For those organizations, the work that matters most hasn't changed: building the detection, response, and recovery capability to withstand whatever reaches them, regardless of who's operating upstream. Offense and defense are two halves of the same effort to stay ahead of adversaries who have every reason to keep targeting the industries with the most at stake.



