For years, the standard advice to a company under cyberattack has been curiously one-sided: defend yourself, preserve the evidence, call the authorities — and do not strike back.
There were good reasons for that. Giving companies a licence to invade someone else’s computer systems risks hitting the wrong target, destroying evidence, violating another country’s sovereignty or turning a commercial dispute into something much more serious.

But there is another risk that has received rather less attention: what if the old rules simply leave the criminals with the advantage?
President Donald Trump’s administration has now taken a significant step towards answering that question. Under a presidential memorandum issued on August 12, vetted American companies will be allowed to participate in offensive cyber operations against foreign transnational criminal organisations.
That sounds, at first hearing, like the legalisation of corporate “hack back”. It is more constrained than that.
The operations are to be carried out under federal supervision. Participating companies must be vetted and contracted by the Justice Department or Department of Homeland Security. Individual operations require written approval. Companies may be required to maintain a bond or escrow of at least $1 million that can be forfeited for non-compliance.
Most importantly, the companies are not being handed a general licence to attack anyone they believe attacked them. They will act on behalf of, and under the authority of, the US government.

That distinction matters.
But so does the reason Washington believes such a program is necessary.
Cybercrime is no longer a peripheral law-and-order nuisance committed by clever teenagers in bedrooms. Large criminal networks now resemble multinational enterprises. They have specialists, infrastructure, customer-service operations, money-laundering networks and supply chains. Some sell ransomware as a service. Others run industrial-scale fraud centres.
The money involved is extraordinary. The FBI’s 2025 Internet Crime Report recorded more than one million complaints and reported losses exceeding $20 billion. Cyber-enabled fraud alone accounted for about $17.7 billion.
And the economics favour the attacker.
A criminal group may operate from a country unwilling or unable to arrest it. Its servers can be scattered across jurisdictions. Its members can hide behind layers of infrastructure, cryptocurrency wallets and stolen identities. By the time traditional international law-enforcement mechanisms begin moving, the criminals may have disappeared, reconstituted themselves under a different name or shifted their systems elsewhere.
A victim, meanwhile, is expected to remain almost entirely defensive.
Imagine a burglar repeatedly entering homes from a fortress across the border. The homeowners may install stronger locks, cameras and alarms. The police are allowed and empowered to investigate. Diplomatic requests can be sent to the country hosting the fortress. But nobody is permitted to disable the burglar’s getaway vehicles. That is roughly the imbalance Washington is trying to address.
The argument for using private cyber companies is also practical. Some of the world’s deepest knowledge of malicious networks does not reside solely inside intelligence agencies. It sits inside cybersecurity companies, cloud providers, telecommunications companies and specialist threat-intelligence firms that encounter attacks every day.
Indeed, government already relies extensively on private companies to detect, understand and contain cyber threats. The new policy extends that partnership from seeing the attacker towards, in carefully approved circumstances, disrupting the attacker.

The idea is not as radical as it sounds. Governments routinely use private capability to fulfil public objectives. Defence contractors build weapons and operate sophisticated systems. Commercial satellite companies provide imagery used for national security. Private logistics firms support military operations. Banks help governments detect and freeze illicit finance.
The important question has never been whether private expertise may serve the state. It is who controls its use. And that is where the Trump plan deserves support — provided its safeguards survive implementation.
There must be a bright line between a company defending its own interests and a company carrying out an operation authorised by the United States. The presidential memorandum explicitly attempts to draw one: approved operations remain under government operational control, and each package must receive written authorisation before action is taken.
There are also obvious dangers. Cyber attribution is notoriously complicated. A server used by a ransomware gang may actually belong to an innocent business whose system has been compromised. Criminal infrastructure can share networks with legitimate users. An operation aimed at disabling a criminal network might have consequences in a third country.
And cyber operations can escalate. Destroying a criminal server sounds uncomplicated until the server sits inside a country that regards the intrusion as an infringement of its sovereignty. Matters become even more delicate when criminals enjoy informal protection from officials or operate in the grey space between organised crime and state interests.
These are reasons for strict government control, however — not necessarily reasons for permanent passivity.
An uncomfortable assumption rests behind much of the opposition to offensive cyber action: that restraint by the victim produces restraint by the attacker. However, there is little evidence that criminals operate according to that bargain.
A ransomware gang does not stop because its target obeys international cyber etiquette. A fraud compound does not close because investigators are waiting for paperwork to travel through several jurisdictions. Criminal organisations exploit precisely the gaps between national legal systems.
Deterrence requires consequences. The US government has already demonstrated how public-private cooperation can make criminal operations harder. During a recent US Justice Department “Disruption Week”, government agencies worked with private companies to disrupt scam accounts and financial infrastructure associated with transnational fraud operations.
The logical question is whether such cooperation should sometimes go further.
If intelligence identifies a foreign criminal network actively stealing millions of dollars from American citizens, and if an operation can disable its infrastructure without causing wider damage, should Washington really refrain merely because the technicians capable of carrying it out receive private-sector salaries?
That would confuse the identity of the operator with the legitimacy of the operation.
Legitimacy should instead come from lawful authority, defined targets, proportionality, oversight and accountability.
In all this is also a larger strategic lesson for other countries, including India.

Cybersecurity policy has traditionally been built around walls: stronger passwords, better authentication, improved backups, faster detection, safer software. All of these are indispensable. But walls alone have never been a complete security strategy.
Banks do not merely buy thicker vault doors; governments also pursue bank robbers. Countries do not merely reinforce their borders; they try to dismantle trafficking networks. Maritime security does not consist solely of making ships harder to hijack.
Yet in cyberspace, the victim has often been expected to absorb the attack, repair the damage and wait for a criminal justice system built around geography to catch an adversary who deliberately exploits geography’s disappearance.
Trump’s policy is an attempt to correct that asymmetry. It could go wrong. Poor oversight could turn a useful instrument into a dangerous precedent. Operations could be misdirected. Commercial incentives could distort judgement. Governments will therefore need exceptional transparency about the rules even when individual operations must remain secret.
But refusing to develop offensive options carries risks too. The deeper mistake would be to assume that the internet remains a place where governments can protect citizens using policing doctrines designed for crimes committed inside clearly defined territorial jurisdictions.
Cybercriminals have already moved beyond that world. The state must move beyond it as well. Private companies should never receive an unrestricted licence to wage cyberwar. But neither should governments refuse to use private capability simply because an old distinction between public authority and private expertise feels reassuring.
The proper principle is simpler: private capability, public authority and public accountability. If Washington can preserve all three, its experiment may prove not to be the beginning of a digital Wild West, but the beginning of a more credible form of cyber deterrence.