The Trump administration is moving to create a federal program that would let approved private security firms take part in government-authorized cyber operations against overseas criminal groups, according to Ars Technica. Ars reports that President Donald Trump issued a National Security Presidential Memorandum on Thursday directing the National Coordination Center, which operates under the Homeland Security Task Force, to develop a program for specific cyber operations against foreign transnational criminal organizations. The memo, as described by Ars, applies to groups that conduct cyber-enabled crime against the US government, US persons, or US interests and are not part of, or wholly directed by, a foreign government. The program is not described as an open license for private companies to hack back on their own. Ars reports that the Departments of Justice and Homeland Security would provide oversight, and participating companies would first need approval after vetting by those departments. The memo also calls for minimum standards covering technical proficiency, prior cyber-operations performance, facility security, personnel vetting, competence, reliability, and other factors. The accompanying fact sheet, according to Ars, identifies ransomware, sextortion, phishing campaigns, financial fraud, and impersonation scams as eligible activities for targeting. The memo says approved firms may conduct “Cyber Surveillance Operations” and “Cyber Effects Operations” against qualifying cyber-enabled transnational criminal organizations. Ars frames the policy as a notable shift: it reports that this would be the first time the federal government authorizes private companies to conduct offensive cyber operations against overseas hackers. Until now, Ars notes, private-sector actors have generally been prohibited from taking such actions without court-authorized approval. The reported authorities also appear broad, though bounded. Ars says the memo appears to permit participating companies to use spyware or offensive attacks intended to destroy criminal groups’ data or systems. Ars also reports that the memo does not rule out some disruptive techniques, including attacks that use encryption to lock targets out of networks or distributed denial-of-service attacks. The memo sets limits on the program’s permissible outcomes. According to Ars, Cyber Effects Operations and Cyber Surveillance Operations may not create “Critical Outcomes,” including loss of life, serious injury, or effects that rise to the level of use of force or armed attack under international law. The policy also raises incentive questions for the security industry. Ars quotes independent security researcher Kevin Beaumont as saying there is merit in hacking ransomware groups and that such activity already happens, while cautioning that “the correct incentives” need to be in place. Beaumont also argued, according to Ars, that some private cyber companies have benefited financially from the status quo around ransomware response, making the choice of operators important. The immediate next step is program design, not a list of missions or vendors. The memo directs the National Coordination Center to build the program, while the public account provided here does not name participating firms, specific targets, timelines for operations, or the procedures DOJ and DHS will use to approve individual companies or activities. Who benefits: Vetted security firms could gain a new role in federally authorized cyber operations. US agencies may gain additional technical capacity against overseas criminal groups targeting US persons, organizations, and government entities. Who's exposed: Foreign cyber-enabled criminal organizations are the stated targets. Participating firms will also be exposed to strict approval standards and scrutiny over whether their operations stay within the memo’s limits.