The lesson is not that companies should become cyber vigilantes. It is that offensive capability without institutional governance can become a risk multiplier.
As private-sector organizations are increasingly drawn into national cyber defense—and potentially given greater authority to disrupt malicious infrastructure—traditional cybersecurity policies are no longer enough.
The organization needs something more fundamental: a governance framework capable of controlling powerful technology at machine speed.
Governance Before Action
If an organization has the capability to disrupt, deceive, disable or otherwise interfere with hostile infrastructure, the critical question is not simply whether it can act.
It is whether it has established the authority, evidence, controls and accountability required to act responsibly.
A mature governance framework should define, in advance:
- Authority and delegation — who can authorize an operation and within what limits
- Target-selection criteria — which targets are permissible and which are prohibited
- Attribution thresholds — what evidence is required before action is taken
- Legal and regulatory review — which rules, jurisdictions and obligations apply
- Rules of engagement — what the organization may and may not do
- Human approval and escalation — when human intervention is mandatory
- Technical safeguards — what controls prevent unauthorized or excessive action
- Real-time monitoring and logging — how actions are observed and recorded
- Emergency-stop mechanisms — who can halt an operation immediately
- Independent oversight — who challenges the decision and reviews its execution
- Post-operation review — how outcomes, failures and lessons are assessed
- Evidence preservation and auditability — how the organization proves what happened
- Accountability for unintended consequences — who owns the outcome when reality differs from the plan
These are not merely cybersecurity controls.
They are governance controls.
And this is where cybersecurity governance, enterprise risk management and AI governance increasingly converge.
The question is no longer simply:
“Can the technology act?”
It is:
“Can the organization govern that action at the same speed?”
The Bigger Lesson for Organizations
The most important issue is not whether a particular cyber policy succeeds or fails.
It is the direction of travel.
The boundaries between government security operations, private-sector cybersecurity and autonomous technology are becoming increasingly blurred.
Organizations are already deploying AI systems capable of making decisions, executing workflows, interacting with external systems and taking actions with limited human intervention.
At the same time, selected private-sector organizations may gain greater authority to participate in offensive cyberoperations.
These developments point to one fundamental governance principle:
Capability cannot be separated from accountability.
If an organization has the power to act, it must also have the governance to control that power.
And if AI is given the ability to act, the organization must be able to demonstrate:
- Who authorized it?
- What boundaries were imposed?
- What safeguards were applied?
- Who was monitoring the action?
- And what happens when those boundaries are approached or breached?
Without clear answers, autonomy becomes exposure.
The CAIO and CISO Agenda Is Converging
For the CISO, the challenge is defending the organization against increasingly autonomous, sophisticated and aggressive threats.
For the CAIO, the challenge is governing AI systems that may increasingly participate in those defenses—and potentially support offensive capabilities.
For the board, the question is broader:
Does our governance framework distinguish between an automated action, an authorized action and an accountable action?
That distinction is becoming critical.
An automated action is something a system can perform.
An authorized action is something the organization has permitted.
An accountable action is something for which a person, governance body and decision process can ultimately be identified and held responsible.
Those are not the same thing.
From Stronger Walls to Controlled Power
The future of cybersecurity will not simply be about building stronger walls.
It will also be about deciding when, how and under whose authority an organization is permitted to cross the wall.
That is a fundamentally different governance challenge.
The organization must be able to distinguish between:
defending itself,
disrupting an attacker,
taking offensive action,
and crossing a legal, operational or ethical boundary.
Technology may be capable of making that distinction at machine speed.
Governance must be able to do the same.
The Governance Principle
The ability to fight back is not the same as the authority to fight back.
As cyber operations become faster, more automated and increasingly intertwined with AI, organizations will need more than sophisticated technical controls.
They will need clear authority, accountable leadership, independent oversight and auditable decision-making.
That is the foundation of trusted cyber power—whether an organization is defending, disrupting or simply deciding whether it should act at all.
For boards, the question is therefore no longer simply:
“Can we respond?”
It is:
“If we can act, who authorized us to do so—and can we prove that the decision was governed?”
Because in the age of AI-enabled cyber operations, the ultimate control is not the ability to act. It is the ability to govern action.