For decades, the golden rule of cybersecurity has been strictly defensive: patch your systems, plug the holes, and never, ever strike back. That doctrine is about to be rewritten. The Trump administration is preparing to let vetted private companies go on the offensive against international criminal gangs and hackers — a policy shift laid out in a presidential memorandum issued in August 2026.
In plain terms, Washington wants to authorize firms to hack the hackers. It’s a dramatic departure from the current legal landscape, where offensive cyber operations are effectively the exclusive domain of government agencies and intelligence services. Under the new approach, carefully screened companies could be cleared to launch their own counter-operations against ransomware crews, botnet operators and other digital adversaries operating from abroad.
The concept isn’t entirely new in theory — the idea of “hacking back” has been kicked around in security circles for years — but it has always run into the same wall. Retaliatory strikes are messy. Attribution in cyberspace is notoriously slippery, and a hasty counterattack can easily hit an innocent third party whose machine was hijacked as a relay. Critics have long warned that legitimizing private offensive operations risks turning the internet into a free-fire zone, where corporate security teams and criminals trade blows with collateral damage in between.
Supporters, on the other hand, argue that the defenders have been fighting with one hand tied behind their backs. Ransomware attacks against hospitals, pipelines and municipal governments have grown relentlessly, and the criminal groups behind them often operate from jurisdictions beyond the reach of law enforcement. Letting private specialists disrupt those operations directly — seizing infrastructure, neutralizing servers, clawing back stolen data — could, in theory, raise the cost of doing business for the attackers.
The key word throughout is vetted. This is not a blanket license for any IT department with a grudge. The framework is expected to limit authorization to approved companies, presumably with oversight and rules of engagement designed to keep operations pointed at genuine criminal targets rather than competitors or convenient scapegoats.
What remains unclear is how the guardrails will actually work in practice. Who decides which companies qualify? What happens when a sanctioned counter-strike goes wrong and knocks out a legitimate service? And how will other nations respond when American corporations start reaching across borders to dismantle infrastructure on foreign soil? Those are diplomatic and legal minefields that a memorandum alone can’t defuse.
For the security industry, this could open an entirely new market segment — offensive-defense as a service — and reshape how enterprises think about protecting themselves. For everyone else, it raises an uncomfortable question: in a world where private firms are cleared to fight fire with fire, who exactly is holding the extinguisher?