President Trump has signed a memo allowing US government agencies to contract private cybersecurity companies for operations against cyber-enabled transnational criminal organizations, according to The Register. The report says the policy formalizes a strategy the White House had signaled earlier this year: using private-sector capabilities to identify, surveil and disrupt foreign criminal cyber networks targeting US interests. The authority is not described as a general permission slip for companies to “hack back” on their own. The Register reports that participating firms would support national operations under government contracts, with vetting, operational procedures and agency oversight. The covered targets are foreign groups conducting cyber-enabled crime against the US government, US persons or US interests. The memo reportedly separates two types of activity. One is cyber surveillance, aimed at intelligence gathering and designed to remain undetected. The other is “Cyber Effects Operations,” which The Register says covers activity that can manipulate, disrupt, deny, degrade or destroy information systems, networks, infrastructure controlled by information systems, or information residing on them. That distinction may be operationally narrow. According to The Register, the memo acknowledges that surveillance missions may still require some manipulation or disruption of systems in order to collect intelligence. The policy therefore appears to create a framework for private firms to conduct or support active technical operations, not only passive monitoring. The target set is also bounded. The Register reports that the memo’s definition excludes entities directly associated with, or operating wholly on behalf of, foreign governments. That matters because the memo, as described, is aimed at cyber-enabled transnational criminal organizations rather than state-backed threat actors. The compliance structure is material. Participating companies would be subject to rigorous vetting, annual evaluations of their technical capabilities and strict operational procedures. Those procedures are to be written within 60 days by program executive directors working with the Homeland Security Council, according to The Register. The Justice Department would have a role in authorizing operations, especially when targets involve US residents or domestic legal issues. The Register also reports that contractors would be barred from operations that could produce “critical outcomes,” including loss of life or serious injury, or actions that could be viewed as an armed attack under international law. The financial requirement is explicit: participating companies would need to maintain a bond or escrow of at least $1 million, which could be forfeited if they violate contract terms. The Register says the program is intended to include both large, highly resourced organizations and smaller firms suited to specialized or discrete tasks. The policy follows a White House cyber strategy document published in March, which The Register says promised to “unleash the private sector” by creating incentives to identify and disrupt adversary networks. The key unresolved details now sit in the operational rules due within 60 days: how targets are approved, how contractor actions are supervised, and how the government limits spillover from private-sector cyber operations. Who benefits: Vetted cybersecurity firms with advanced technical operations teams may gain access to new federal contracting opportunities. Smaller specialist firms could also benefit if the procedures preserve access for discrete tasks, as The Register reports the memo instructs program managers to do. Who's exposed: Foreign cyber-enabled criminal groups targeting US interests are the stated focus. Contractors are also exposed to compliance and financial risk, including possible forfeiture of at least $1 million in bond or escrow for contract violations.