Private firms hack back policy stops short of authorization
A White House order seeks private-sector cyber expertise, but it does not give companies a license to access criminals’ networks.
By Dev Ramirez · Crypto Correspondent
· 3 min read
The White House has not given private firms a blanket right to hack back against cybercriminals. For businesses and investors following the private firms hack back debate, the distinction is material: a March 6 executive order calls for federal planning and potential use of commercial cyber expertise, while a legal analysis says the related national strategy does not expressly authorize companies to run offensive operations on foreign adversaries’ systems.
Executive Order 14390 says the United States will protect Americans and strengthen financial and digital systems against cybercrime, fraud and related schemes. It says responses may include law enforcement, diplomacy and potential offensive actions. The order, however, assigns the work to federal agencies and says implementation must follow applicable law. It also creates no enforceable right or benefit for private parties, according to the White House order.
Does the White House authorize private firms to hack back?
No explicit authorization appears in the available policy text. Lawfare’s analysis of the administration’s March 6 National Cybersecurity Strategy says the document proposes incentives for the private sector to help identify and disrupt adversary networks. But the analysis concludes that the strategy stops short of directly permitting private companies to conduct cyber operations against foreign adversaries.
That boundary matters because defensive security and offensive activity are different. Lawfare describes ordinary defensive work as monitoring a company’s own network and blocking malicious traffic. “Hack back,” also called active defense, typically means taking action on another party’s network. That can raise significant legal and compliance questions, Lawfare said, particularly because the strategy provides little detail on either the promised incentives or private companies’ exact role.
What the executive order requires
The order directs the secretaries of State, Treasury, War and Homeland Security, along with the attorney general, to review relevant operational, technical, diplomatic and regulatory frameworks within 60 days. Within 120 days, they must deliver an action plan identifying transnational criminal organizations connected to scam centers and cybercrime and proposing ways to prevent, disrupt, investigate and dismantle them.
That plan is set to establish an operational cell within the National Coordination Center to coordinate federal action against foreign criminal networks that target U.S. people, businesses, critical infrastructure or public services. The order says that effort may involve the private sector where appropriate.
It also instructs the plan to explain how the attorney general and Homeland Security secretary can use commercial cybersecurity firms’ technical capabilities, threat intelligence and operational insights to improve attribution, tracking and disruption of malicious actors, consistent with applicable law. The language contemplates cooperation and information-sharing; it does not establish a government purchasing program, spending commitment or a legal shield for vendors.
What businesses can take from it
The policy leaves private-sector participation to future federal planning and existing legal limits. For routine protection, CISA’s general guidance urges organizations to manage risks through measures such as software updates, multifactor authentication, caution with suspicious links and cybersecurity plans tailored to their operations. Those are defensive practices, not permission to operate on someone else’s systems.
This story draws on original reporting from Decrypt.