Malik Haidar is a veteran cybersecurity strategist who has spent years defending multinational corporations from sophisticated state actors and criminal syndicates. His unique vantage point combines high-level intelligence analytics with the practical realities of protecting corporate infrastructure, making him a crucial voice as the U.S. government shifts toward offensive private-sector partnerships. This discussion explores the tactical shift of authorizing private firms to engage in offensive cyber strikes, the logistical framework under the Department of Justice and DHS, and the profound risks of misattribution and international escalation. We delve into how the National Security Presidential Memorandum aims to harness underutilized private innovation to disrupt transnational crime while navigating the legal and ethical minefields of “hacking back.”
The recent authorization allowing private firms to participate in offensive cyber operations marks a seismic shift in national policy; how do you see this changing the day-to-day reality for security teams who have traditionally been restricted to defensive maneuvers?
For years, security practitioners have felt like they were fighting with one hand tied behind their backs, watching threats loom without the power to strike the source. This new memorandum, signed on August 12, changes that frustration into a proactive stance, essentially letting the most innovative and technologically advanced minds in the private sector join the fray. It feels like the air in the room has changed from a posture of “wait and see” to a calculated, government-sanctioned pursuit that builds on the foundations laid in the Executive Order from March. We are moving toward a reality where “rigorous actions” aren’t just a tagline but a set of procedures that allow us to actually disrupt the criminal networks that have been operating with impunity in our digital backyard. The knowledge that we can finally utilize our capabilities to identify and disrupt these actors provides a sense of empowerment that has been historically underutilized in the fight against cybercrime.
With data showing that Americans lost over .8 billion to cybercrime in 2025 alone, what does this massive financial toll tell us about the limitations of our current purely defensive strategies?
When you look at the sheer scale of that $20.8 billion loss, it hits you like a physical weight; it represents families losing their life savings and businesses shuttering their doors due to relentless digital predation. The fact that 73% of U.S. adults have experienced some form of online scam or attack is a jarring reminder that the current shield-only approach is failing to provide real safety to the average citizen. We’ve realized that every available tool must be deployed because the damage is no longer just digital—it’s visceral, emotional, and deeply personal for millions of people across the country. This policy shift acknowledges that we cannot simply absorb these blows indefinitely; we have to go after the infrastructure of the transnational groups causing this havoc. By bringing in private sector firms to propose cyber operations designed to disrupt these actors, we are finally acknowledging that the cost of inaction has become far too high to bear.
Critics often worry about the “fog of war” in digital space, specifically regarding attribution; how can a program like this navigate the risk of mistakenly targeting the wrong actor or escalating tensions with state-linked systems?
The risk of getting it wrong is perhaps the most gut-wrenching aspect of this entire shift, as misattribution can lead to a domino effect of unintended consequences that spiral out of control. We’ve seen how even seasoned government agencies can be “willingly wrong” on significant incidents because identifying perpetrators in the shadows of cyberspace is an incredibly messy and complex science. If a private firm accidentally destroys a system that turns out to be state-linked, the risk of interstate escalation or even open conflict becomes a terrifyingly real possibility that keeps many of us up at night. That’s why the “rigorous procedures” mentioned in the memorandum are so critical; we need more than just intent—we need a surgical level of accuracy that many organizations currently struggle to achieve repeatably. We must ensure that the license to destroy cyber-controlled infrastructure does not inadvertently strike at the heart of a foreign government’s sensitive networks.
The memorandum establishes a framework involving the Department of Justice and the Department of Homeland Security to oversee these strikes; how do you envision this partnership between private industry and federal oversight working on a practical level?
The structure is designed to bring some order to what could otherwise be a chaotic “wild west” scenario, with two Executive Directors heading up the program to ensure everything stays within the bounds of the law. Private firms won’t be acting as lone wolves; instead, they will enter into formal agreements with other firms and government bodies to gather threat intelligence and propose specific operations. It’s a delicate dance of utilizing the private sector’s agility while keeping the steering wheel firmly in the hands of federal authorities to ensure compliance with the U.S. Constitution. This collaborative model, managed by the Homeland Security Task Force’s National Coordination Center, aims to bridge the gap between underutilized private innovation and the strategic oversight that only a sovereign nation can provide. By keeping these operations “limited” and under the direct direction of the government, the hope is to create a focused, legal, and effective offensive front.
What is your forecast for the future of private sector involvement in offensive cyber operations over the next decade?
I believe we are entering an era of “managed aggression” where the line between national defense and private enterprise will become increasingly blurred as the digital battlefield expands. Over the next ten years, we will likely see specialized firms emerging that are vetted specifically for these types of operations, much like the National Cyber Force has been doing in the UK since 2020. However, the success of this shift will hinge entirely on our ability to maintain the “limited” nature of these operations to avoid a global free-for-all that could destabilize the entire internet. If we can master the attribution piece and keep these strikes surgical and data-driven, we might finally turn the tide against transnational crime and reclaim some of the territory lost to hackers. But we must remain vigilant, as the potential for escalation is always present, and we must ensure that these powerful tools are only deployed when other responses are clearly ill-suited for the challenge.

