The White House is moving to formalize a role for private cybersecurity companies in offensive operations against foreign cybercrime groups, according to BleepingComputer. The outlet reports that a new national security presidential memorandum signed by President Donald Trump directs the National Coordination Center to create a program through which private security firms could apply for approval to conduct cyber operations against foreign criminal organizations. The program, as described by BleepingComputer, would place those operations under the control and authority of the U.S. government. The National Coordination Center is identified as part of the Homeland Security Task Force, and the memorandum is framed around transnational criminal organizations rather than ordinary vulnerability research or private corporate incident response. According to the report, the White House fact sheet says the program’s executive directors and the Homeland Security Council must create procedures for reviewing and conducting “limited cyber operations” while complying with the U.S. Constitution, federal law and applicable international agreements. That distinction matters: the memo does not appear, from the provided reporting, to create a free-standing private right to hack back. It creates an approval and contracting structure for companies acting within a government-directed program. Governance would sit with executive directors designated by the Justice Department and the Department of Homeland Security, BleepingComputer reports. Security firms would be vetted before entering into contracts with one of those departments. Participating companies would also be allowed, under the framework described in the report, to enter agreements with other private entities and with federal, state, local, tribal and territorial agencies to gather threat information and propose operations. The memo also includes financial and operational guardrails. BleepingComputer reports that participating companies would have to maintain a bond or escrow of at least $1 million, which could be forfeited if they fail to comply with their contractual obligations. Firms would also be required to immediately stop an operation and notify the National Coordination Center if they discover activity outside approved limits, including unintended targeting of U.S. citizens or U.S.-based systems. The White House’s stated target set is foreign criminal activity tied to ransomware, phishing campaigns, financial fraud, sextortion schemes and impersonation scams, according to BleepingComputer. BleepingComputer reports that the White House said U.S. consumers have reported losing more than $20.8 billion to cyber-enabled crime in 2025. The policy would mark a larger formal role for private-sector security companies in offensive cyber activity, if implemented as described. BleepingComputer cites Veracode co-founder Chris Wysopal calling the memo a major shift in U.S. cyber policy and an expansion of the private sector’s role in offensive operations. It also cites Automox CTO Jason Kikta, a former Cyber National Mission Force leader, warning that the structure could become a “perpetual motion machine for billable threats.” The key unresolved issue is execution. The report describes a government-directed program with vetting, contracts, review procedures and stop-work obligations. For now, the supported takeaway is narrower than “private hack-back is legal”: the White House has reportedly directed agencies to build a controlled program for approved private-sector offensive operations against foreign cybercrime groups. Who benefits: Cybersecurity firms with offensive operations, threat intelligence and government-contracting capacity could benefit if the program moves into implementation. Federal agencies may also gain access to private-sector capabilities against foreign criminal groups. Who's exposed: Participating firms would carry operational, legal and reputational risk if activity exceeds approved limits. Organizations whose infrastructure is misidentified or unintentionally touched by an operation could also face exposure, which is why the reported stop-and-notify requirement is material.