cyberattacks

New US policy empowers private firms to conduct cyberattacks

For decades, the U.S. held a firm line: private firms do not hack back. That line just vanished. A new order now permits select companies to carry out offensive cyber operations, sweeping aside long-standing policy in…

4 min readTechCrunch
New US policy empowers private firms to conduct cyberattacks

For decades, the line between defender and attacker in cyberspace was drawn with unusual clarity: companies could build walls, patch holes, and call for help, but they could not cross over into offensive action. That line has now been redrawn. The new order that allows private firms to conduct "hack back" attacks overturns a foundational rule of American digital policy, and it arrives not with a bang, but with the quiet finality of a policy reversal. For anyone who has watched the escalation of digital crime, the logic is tempting. But the execution, like the technology it unleashes, is far messier than the theory.

Consider the context we are already living in. The North Korean hackers linked to $351M Bitget crypto theft represent the kind of adversary that makes passive defense feel obsolete. State-backed groups do not wait for permission, and they do not limit their targets. Meanwhile, the Protecting Your Data: Kiteworks Advises Temporary Server Shutdown story shows how even the most cautious companies can find themselves one credible threat away from pulling the plug on their own operations. These are not abstract risks. They are the daily texture of doing business in a networked world. So when the government says, "You can now strike back," it is responding to a genuine frustration that many security teams have felt for years. We understand the impulse. But we also know that the first rule of any counterpunch is knowing where the punch is coming from, and attribution in cyberspace remains an inexact science at best.

The practical question for our readers is not whether hacking back is morally justified. It is whether it is operationally sound. When a private firm launches an offensive operation, it takes on legal liability, technical complexity, and the very real risk of collateral damage. A misdirected attack could hit a hospital, a power grid, or a third-party cloud provider, and the company that fired the shot would own the consequences. The order sweeps away decades of policy, but it does not sweep away the technical reality that the internet was never designed to support precise, proportionate, and accountable counterstrikes. We would tell any reader who asks: do not mistake permission for capability. The firms that will thrive here are not the most aggressive ones. They are the ones with the discipline to know when not to act, and the foresight to build response frameworks before they ever need them.

The deeper issue is one of accountability. If a private company conducts a hack back and gets it wrong, who answers? The government that authorized the policy, or the board that approved the operation? This is not a rhetorical question. It is the same tension that runs through every story we cover, from state-sponsored crypto thefts to defensive shutdowns. The line between public and private responsibility in cybersecurity is blurring, and this order accelerates that trend. We would watch for the first lawsuit, the first diplomatic incident, or the first civilian casualty attributed to a corporate attack. That is the moment when the policy will be tested, not in theory, but in practice. Until then, the smartest play for most organizations is to treat this as an invitation to audit their own defenses, not a green light to go hunting. The tools of offense are now available. The judgment to use them wisely is still the rarest commodity in the room.

From TechCrunch

The new order sweeps away decades of existing U.S. cybersecurity policy prohibiting private companies from conducting 'hack back' attacks or offensive cyber operations.

Read the original at TechCrunch