A changing U.S. cybersecurity policy raises a fundamental question for boards, CISOs and AI leaders: who should be allowed to fight back in cyberspace—and under whose authority?
For decades, the division of responsibility in cybersecurity was relatively straightforward: companies defended their systems; governments conducted offensive cyberoperations.
That boundary is now being tested.
A new U.S. policy framework is opening the door for selected private-sector companies to participate in offensive cyberoperations against foreign criminal hacking groups, subject to government authorization and oversight. The stated objective is clear: confront ransomware, cybercrime and fraud at a scale that traditional defensive measures increasingly struggle to contain.
But the governance implications are far less straightforward.
This is not simply another cybersecurity capability. It could represent a significant shift in the relationship between government, business and cyber power—and it raises questions that boards and organizations operating critical digital infrastructure should be watching closely.
From defending the perimeter to fighting back
The emerging model envisages a controlled program in which vetted companies could work with government authorities to conduct intelligence-driven operations against specified transnational criminal organizations.
Under defined circumstances, those operations could involve actions intended to disrupt, manipulate or disable information systems and infrastructure.
This is clearly not intended to create a digital free-for-all.
Participating organizations would require approval, operate under defined contractual arrangements and obtain authorization before conducting operations. Activities that could cause loss of life or serious injury, or cross the threshold of a use of force or armed attack under international law, would remain outside the permitted scope.
On paper, those requirements create guardrails.
In practice, however, the hardest governance questions begin precisely where those guardrails end.
Attribution remains the Achilles’ heel
One of the most difficult problems in offensive cyberoperations is determining who is actually behind an attack.
A ransomware group may appear independent while maintaining links to a state. Criminal infrastructure may be rented, compromised or deliberately disguised. Threat actors can operate through multiple jurisdictions, identities and technical layers.
The fundamental problem is simple:
The attacker you identify is not necessarily the attacker you are actually confronting.
That creates an enormous governance challenge.
If a private company misattributes an attack and launches an offensive operation against the wrong infrastructure, the consequences could extend far beyond the organization itself.
The target could be another criminal group.
It could be an innocent third party.
It could be critical infrastructure.
Or it could be an organization with undisclosed connections to a foreign government.
The difference between a successful counteroperation and a geopolitical incident may depend on intelligence that is incomplete, outdated or deliberately manipulated.
The private-sector risk equation changes
For corporate leaders, the critical question may not be whether offensive cyberoperations are technically possible.
It is whether a company can absorb the legal, operational, financial and reputational risks that come with conducting them.
A company authorized to fight back is still a company.
It has customers, employees, shareholders, contractual obligations, regulatory responsibilities, insurance arrangements and data-protection obligations. It may also have disclosure duties when an operation creates a material risk or incident.