The right to hack: How states are rewriting cyber defence

By: BRIJESH SINGH
Last Updated: August 23, 2026 03:17:27 IST

As foreign states go on mobilizing private technology firms and intelligence hybrids to neutralize external threats in real time, India faces a strategic question.

Picture the moment first: state-backed hackers slip into a country’s grid and the lights start to fail, or they slip into its hospitals and the machines start to falter, or they simply sit on its industrial data, hostage now, waiting on a ransom—and every citizen watching this feels the same reflex rise in it, unbidden, the oldest reflex there is, which is simply to hit back. And yet the record runs the other way, has run the other way for decades: democratic legal traditions built themselves around outlawing exactly that reflex, treating unauthorized intrusion into a computer system as a felony, and reserving the violence that states are permitted solely for the militaries and the police that answer to them. That old boundary, drawn after the Cold War and held for a generation, is not being debated away now; it is dissolving, quietly, almost without anyone marking the moment. Nobody is standing up in public arguing that corporations deserve some new statutory “right to hack back.” What is happening instead is quieter, and more consequential—major powers reinterpreting statutes that are half a century old, issuing executive orders that fold private technology firms into state-sanctioned digital warfare.

The legal acrobatics that make this pivot possible are worth sitting with, because they show just how unready a body of peacetime doctrine is for a war fought in wires and packets rather than in trenches. In the United States, one legislative attempt followed another—the Active Cyber Defense Certainty Act chief among them—and each one died in Congress, killed every time by the same bipartisan fear: that letting corporations act as vigilantes online would tip, sooner or later, into something like international armed escalation. So, rather than wait on a consensus that wasn’t arriving, the executive branch bypassed Capitol Hill entirely, leaning on an obscure, 40-year-old provision buried in the Computer Fraud and Abuse Act, a clause written for law-enforcement investigations; federal directives now quietly recruit vetted private contractors to carry out offensive cyber surveillance and disruptive-effects operations against foreign criminal syndicates, all of it kept, at least on paper, under federal oversight.

Strip away the modern vocabulary and what this mechanism resurrects is something much older, 18th-century privateering, ported wholesale into the digital realm. To manage the moral hazard that comes with letting corporations wage something like warfare, Washington has bolted on a set of commercial safeguards: participating firms are required to post million-dollar indemnity bonds, required to secure written operational sign-off before they act, and in exchange the state gets to outsource the friction, the risk, the messiness of offensive operations to private hands, while trying to keep its own diplomatic fingerprints off the outcome. But underneath the paperwork the legal foundation is exceptionally brittle; no appellate court has ever tested whether a carve-out written for ordinary law enforcement permits a private contractor to knock a foreign server offline, and the first cross-border misattribution, the first inadvertent scrap of collateral damage, will be the thing that finally drags it all into protracted litigation and foreign-policy fallout.

Across the Pacific, though, it is Japan that has undertaken the more historic shift of the two, and by some distance. For decades Tokyo was bound, tightly and without exception, by the strictly pacifist constraints written into Article 9 of its postwar Constitution—and now, against that backdrop, it has enacted the Cyber Response Capability Enhancement Act, formally authorizing civilian authorities and the police to infiltrate adversary command-and-control infrastructure abroad and neutralize it before any attack ever has the chance to fully unfold. To survive the domestic constitutional scrutiny owed to the absolute secrecy of communications, a right taken seriously in Japanese law, the drafters reached for a delicate technical fiction: state monitoring, they wrote, is strictly confined to routing metadata alone, things like IP addresses and command strings, leaving the actual content of any message untouched, sealed off, out of reach. Except that fiction is ageing badly, and ageing faster than its drafters could ever have planned for. In a modern digital network, where machine-learning classifiers can derive full operational intent directly from nothing more than a communication pattern, the old distinction between metadata and content is collapsing, rapidly, underneath the statute’s feet. Japan’s attempt to build a statutory, civilian-led active-defence architecture remains genuinely unprecedented, and yet its operational viability keeps running into practical bottlenecks; Tokyo has legislated ambitious pre-emption mandates on paper, but its national cybersecurity apparatus confronts an acute deficit of the specialized personnel needed to carry them out, exposing, plainly, a persistent and uncomfortable gulf between statutory ambition and actual state capacity.

European capitals, meanwhile, are fracturing along fault lines that contradict one another outright, each government drawing the boundary in its own place. In Germany, proposed legal revisions would empower civilian police bodies and interior-ministry agencies to strike foreign infrastructure directly, and pointedly exclude both foreign intelligence services and the military from that same authority—a choice that reads, on its face, as a deliberate act of institutional narrowing. France sits in stark contrast to all of this, maintaining a rigid institutional wall between the two functions, a wall it has held to for years: the civilian cybersecurity agency stays purely defensive, guarding its own trust with industry above all else, while offensive cyber counter-strikes are assigned, strictly and without exception, to military commands operating under the constraints of international humanitarian law.

At the international level, multilateral consensus has stalled entirely, and shows no real sign of resuming. The United Nations’ Open-Ended Working Group has tried, repeatedly, and repeatedly failed, to reach any agreed threshold for what level of digital disruption should count as an unlawful use of force under the UN Charter—a question that sounds technical and is, underneath, almost civilizational. In the absence of binding international treaties, states are left to unilaterally improvise their own thresholds, each on its own terms, and what has emerged instead of formal law is something quieter, a tenuous norm built through operational habit rather than through any treaty: national frameworks increasingly restrict authorized retaliation to the neutralization of intermediary infrastructure alone—a hijacked relay server, say, rather than the server farm behind it—rather than mounting destructive counter-strikes against a sovereign state’s own networks.

For India, watching all three of these stories unfold at once—across North America, across Europe, across East Asia—the implications land as genuinely urgent. New Delhi has built real, robust institutional defences: the Indian Computer Emergency Response Team on one side, a set of dedicated critical-infrastructure protection agencies on the other. And yet the Information Technology Act remains anchored to a framework that is reactive, compliance-heavy, built for reporting incidents after the fact rather than meeting them as they happen. As foreign states go on mobilizing private technology firms and intelligence hybrids to neutralize external threats in real time, India is left facing a strategic question: whether to keep relying on passive perimeter defence and post-incident reporting, or whether to construct a rigorous, constitutionally bounded active-defence framework of its own. What the global shift proves, if nothing else, is this—active cyber defence is no longer some theoretical debate; it is an operational reality, being forged right now, without international rules to hold any of it in place.

Brijesh Singh is a senior IPS officer and an author (@brijeshbsingh on X). His latest book on ancient India, “The Cloud Chariot” (Penguin) is out on stands. Views are person

Most Popular

The Sunday Guardian is India’s fastest
growing News channel and enjoy highest
viewership and highest time spent amongst
educated urban Indians.

The Sunday Guardian is India’s fastest growing News channel and enjoy highest viewership and highest time spent amongst educated urban Indians.

© Copyright ITV Network Ltd 2025. All right reserved.