Latest edition: 17 August 2026London — published continuously since 2026Free forever
The Founder Gazette
Startup news, held to newspaper standards
Policy

White House programme would let private firms run cyber attacks on a $1m bond

A new federal programme will enlist private companies for offensive cybersecurity work, with a $1 million bond as the entry price. The terms founders would sign up to have not been published.

By The Gazette desk17 August 202686

The White House has established a programme to enlist private companies in offensive cybersecurity operations, according to reporting on the plan.

Companies wanting in would post a bond of $1 million.

That is the one hard number attached to the scheme so far. What the bond secures, who forfeits it and under what circumstances have not been set out publicly.

Nor has the eligibility bar. It is not clear whether the programme is open to any firm that can post the money, or restricted to contractors already holding federal clearances.

The distinction matters commercially. A clearance requirement makes this a closed shop for incumbents; an open bond requirement makes $1 million the price of a licence to do work that has, until now, been the preserve of government agencies.

Liability is the other unanswered question. Offensive operations can hit the wrong target, cross a border, or take down infrastructure that was not the intended objective. Whether the contracting firm, its insurers or the federal government carries that exposure is not something the announcement has settled.

For a founder in security, the practical reading is narrow for now. There is a number to plan against and no published rulebook to plan with.

Anyone weighing it should wait for the programme documents before committing capital to a bond, and should ask their insurer whether an offensive engagement is covered at all. Most cyber policies are written for defenders.