The session brought together experts from cybersecurity, cyber diplomacy, law and civil society to discuss the growing participation of the private sector in cyber operations. The closed ad hoc session of the Geneva Dialogue opened with introductory remarks on industry-government engagement in cyberspace and the legal frameworks governing private participation in cyber operations.
Interested in joining our regular virtual closed-door discussions? Reach out at genevadialogue@diplomacy.edu.
Summary of the discussion is prepared by Anastasiya Kazakova, Geneva Dialogue Project Coordinator; Cyber Diplomacy Knowledge Fellow at DiploFoundation.
For years, ‘hack back’ – a victim striking back at the systems of its attacker – has been treated as a line companies should not cross. In many jurisdictions, unauthorised access to someone else’s system is a crime, regardless of the motive. What brought our experts together for this Ad Hoc Session was the sense that this question is now also being posed from the other direction: not whether companies may hit back on their own, but whether governments should enlist companies in operations against the attackers. In the United States, a presidential memorandum of 12 August 2026 directed the creation a government-supervised programme in which vetted companies may conduct operations against foreign criminal groups.
At the session, we explored whether this is an isolated step or part of a wider shift, and whether it reopens the hack back debate. To find out, we put two questions to participants:
- Q1: Addressing the legal grey zone existing for years around cyber operations, do you think that the ambiguity is deliberate – a feature, not a bug – for both states and companies?
- Q2: Active cyber defence and hack back are often treated as distinct concepts. Is that distinction still meaningful in 2026, or is it a rhetorical convenience?
Q1: Addressing the legal grey zone existing for years around cyber operations,do you think that the ambiguity is deliberate – a feature, not a bug – for both states and companies?
The participants did not fully agree that there is a grey zone at all. One view was that it does not exist: international law already applies to cyber operations, and the task is to clarify how, not to write new rules. A relevant precedent is the Montreux Document. In the 2000s, private military and security companies in Afghanistan and Iraq were said to have operated in a legal vacuum. Around 2008, Switzerland and the International Committee of the Red Cross (ICRC) launched the Montreux Document, which explained how existing international law applies to the states that hire such companies, the states where they operate, and the companies themselves, without creating new obligations. An industry code of conduct followed. The more recent Pall Mall Process, on tackling the use of cyber intrusion tools, has followed the same two steps: states first clarified their own obligations in a code of practice, and now work is under way on a code of conduct for the companies themselves. Other participants did see a grey zone, but rather in practice, not in the rules. Consider a ransomware attack: is the group acting on its own, or with a state’s backing? The rules differ in each case, and in the initial hours after an attack nobody can tell which applies.
The two views are less opposed than they seem, because the term ‘grey zone’ can mean three different things. The first is the law itself: whether international law applies to cyber operations. Here the participants agreed that it does. The second is one of practice: establishing who is behind an operation. Attribution in cyberspace is difficult, resource-intensive and slow, and the links between certain criminal groups and state authorities are hard to establish. The third is vocabulary. Terms such as cyber operation, active cyber defence, and hack back carry different assumptions about legality, intent, and authority depending on who uses them. This is why a shared lexicon was developed around what an activity does, and not what it is called.
The ambiguity in rules may not always be deliberate, but it costs governments and companies differently. By ‘ambiguity’ we mean uncertainty about which rules apply to an operation in cyberspace, mostly because it is unclear who is behind an attack: criminals or a state. As governments bring companies into operations, this uncertainty falls unevenly.
For governments, it leaves room for choice. One participant noted that almost every unauthorised intrusion is potentially a cybercrime, so whether a case is handled as a crime or as a national security matter is a government choice, and that choice shapes what role the private sector may play.
For companies, it means legal risk. Take a company deciding whether to join the US programme. Its operations would be approved and supervised by the US government. But the targets are foreign groups, and the operations will reach systems in other countries. The memorandum’s public text does not say whether US legal protection extends abroad, or what happens under the law of the country hosting the targeted systems, where disrupting servers could be considered a crime. Participants highlighted that many companies need answers before they would even consider joining.
One reading of the US Memorandum (mentioned earlier) is that the ambiguity is not a feature for both sides: the judgement stays with governments, while the legal risk moves to companies. The risk is also uneven among the companies, since multinationals with global operations have more to lose abroad than smaller firms. This raises the question of who governments will end up relying on.
Q2: Active cyber defence and hack back are often treated as distinct concepts. Is that distinction still meaningful in 2026, or is it a rhetorical convenience?
On the second question, the experts were sceptical of the labels, and more interested in three practical boundaries. One approach is to define an activity by what it does, and what effect it has. Participants added two cautions. One noted that a defensive position routinely includes tactical offensive action, so the line between offence and defence is hard to draw. Another warned against using ‘persistent engagement’ and ‘active defence’ interchangeably, since the states that adopted such policies at different times are at different stages of explaining them publicly.
What seemed to matter instead, were the following three questions:
The first is whose network: what can a company do on its own systems, under its own authority, and the point at which it must engage the government. Participants suggested a tabletop exercise precisely on this pivotal point.
The second is where the effects land, since acting against infrastructure in another state raises the legal questions mentioned above.
The third is who initiates: who starts an operation and who approves it.
Three models came up. In the first one, government leads and companies support, by helping take down criminal infrastructure through legal processes, for example. This is already happening (for instance, in August 2026 Europol shared about an international operation, implemented by the public-private partnership, which has disrupted the Sality peer-to-peer (P2P) botnet). In the second one, a company proposes an operation and the government reviews it and, if it agrees with it, ‘blesses’ it. This is the newer and more contested model. One participant stressed that the two are very different conversations. In the third one, companies act entirely on their own, and no one supports that. What separates the three models is the issue of where the decision sits: with the government, shared between the government and a company, or with the company alone. Many companies appear to treat the line against acting alone as real: the Cybersecurity Tech Accord, an industry initiative that has grown from 30 to about 150 companies, includes principles of defence only, and no hack back.
Participants were cautious about industry impact. One proposed middle ground was more cooperation with the government on taking down clearly malicious infrastructure, under legal process and oversight, without companies acting on their own. One participant asked whether the benefits would justify the costs, noting that earlier cooperation on sharing threat information ran into problems of trust, structure, jurisdiction, and usefulness, and that operational cooperation would inherit them. Another participant took the view that, if measures such as hack back are ever necessary, they should remain with the states, while companies protect their own systems within the law of each country they operate in.
Suggestions for a way forward were practical. At the end, the session summarised a path built on what companies can offer that is clearly legal and safe: risk assessment, threat intelligence, and support for takedowns of criminal infrastructure through legal processes. Participants also urged building on what already exists, instead of starting from scratch. The Montreux and Pall Mall processes show how to bring states, industry and civil society together, and the Cybersecurity Tech Accord has already drawn up principles for companies that mirror the UN norms of responsible state behaviour.
One participant went further and suggested that industry codes of conduct, since they are negotiated among industry actors, can be developed faster and more flexibly than the UN norms, and can help rehearse ideas that later feed into state discussions. The same participant added one limit: industry should not act as an independent player in the diplomatic system, because responsibility ultimately leads back to a state.
What the wider picture may show. The US programme, established by the Memorandum, would authorise participating companies to conduct operations under the direction of the US government. It would require contracts with the Justice Department or the Department of Homeland Security, vetting, and written government approval of every operation package. That resembles the situation the Montreux Document addressed – states contracting private companies – more than it resembles a victim striking back. Under the law of state responsibility, conduct of persons acting on a state’s instructions, or under its direction or control, is attributable to that state (Article 8 of the ILC Articles on State Responsibility). If that logic applies, the warnings heard in the session about state responsibility concern not only companies acting alone, but also government approved operations. The public text does not say whether the states in which targeted systems sit would be notified, nor does it address liability abroad, which both are the questions raised in the session.
Elsewhere, governments are strengthening their own capabilities more than enlisting companies. Japan’s active cyber defence law reserves the neutralisation of attacker infrastructure for state agencies, leaves private hack back unlawful, and gives companies mainly reporting and information-sharing roles. In Germany, a draft law debated in the Bundestag in June 2026, would give federal agencies powers to intervene in attackers’ systems, and an opposition motion objects to provisions that could oblige DNS providers and digital services to redirect traffic. The debate also shows how labels get used: the new powers are presented as active cyber defence, not hack back, while others say that they are just hack back under a different name. Is the ‘right’ label used as a claim about legitimacy?
Taken together, three things appear to be shifting at once.
The first is that defence increasingly includes disrupting adversaries. Japan’s law is presented as a move from a ‘passive’ posture, built on firewalls and cybersecurity protection confined to the victim’s own network, to an active one. The bill was described as a switch from reconnaissance to defence, with attackers expected to be disrupted in their own infrastructure. A national cyber strategy issued in March 2026 declared that the government would increasingly use the private sector as part of a more offence-oriented approach.
The second is that certain governments now describe offensive cyber capability more openly, and perceive it as a tool against crime. One government describes its offensive cyber capability as a criminal investigation tool used against top-tier cybercriminals. Public materials from another jurisdiction set out an offensive cyber approach in 2023, although much stays secret, and public statements have indicated that many examples of its actions must remain secret.
The third is that where the limits fall is decided by legal and political choices, not by what the technology can do. The same intrusion can be lawful or unlawful depending on who approves it, what limits apply, and how sure the attribution is. In the US programme, established by the Memorandum, every operation needs written government approval, and operations likely to cause loss of life or serious injury, or to amount to a use of force or armed attack, cannot be approved. In the German debate, a question was raised about who was responsible if a wrong attribution led to a critical-infrastructure operator’s server being hit. Both examples turn on a decision, and not on a technique: who decides, and what happens if the decision is wrong.
The session closed with two things worth carrying forward. The first is to start from existing law and frameworks, not from a blank page. The law applies, and the gap lies in application and accountability. The second is to set and ask the boundary questions before companies take part, not after: whose authority applies, who decides whether a target is state-linked, what protection exists abroad, and who is responsible if attribution proves wrong. Other questions remain open, among them how multinational companies can be held accountable in practice, how effects on physical critical infrastructure change the legal assessment, how cybercrime conventions can help when UN norms address states rather than companies, and how attribution works when AI agents are involved and whether the companies deploying them know what they do. The discussion generated more questions than answers, and it is the beginning of a bigger conversation.
The Geneva Dialogue on Responsible Behaviour in Cyberspace is a multistakeholder initiative of the Swiss Federal Department of Foreign Affairs, implemented by DiploFoundation. This session was conducted under the Chatham House Rule.





