
Should Private Firms Hack Back? Canada Weighs the Risks
A U.S. policy shift allowing vetted private companies to participate in government-supervised offensive cyber operations is forcing a debate in Canada over whether private firms should ever be allowed to go on the attack — and what it could cost them if they do. digitaljournal
Key facts
What happened: In August 2026, the White House issued a National Security Presidential Memorandum creating a framework for vetted private-sector organizations to join government-supervised offensive operations against foreign cybercriminal networks digitaljournal
Canada's position: No Canadian policy currently permits private firms to conduct offensive cyber operations; the National Cyber Security Strategy remains fundamentally defensive digitaljournal
Key risks flagged: courtroom discovery exposing proprietary tools, and criminal retaliation against participating firms
Who should care: Canadian security vendors, and any business weighing the second-order effects of "hack back" policies
What did the U.S. policy change?
The White House memorandum states the U.S. intends to leverage private-sector capabilities to combat transnational cyber-enabled crime — one of the most significant shifts in American cybersecurity strategy in decades, moving beyond defence and threat intelligence toward active disruption of criminal actors. digitaljournal
Canada has taken a different path. Its National Cyber Security Strategy emphasizes partnership, resilience and coordinated disruption involving government, industry, academia and law enforcement, including a new public-private Canadian Cyber Defence Collective and investment in a Cyber Attribution Data Centre. digitaljournal
What is the "criminal discovery trap"?
Discovery is the legal process in which defence lawyers can demand evidence relevant to a prosecution. Rajeev Raghavan, a partner in Crowell & Moring's Privacy & Cybersecurity Group and former Special Counsel to the FBI Director, has flagged that if a private firm's offensive operation contributes to a criminal prosecution, discovery could force disclosure of proprietary software, forensic tools, intelligence-gathering techniques or undisclosed vulnerabilities. For specialized Canadian cybersecurity companies, that intellectual-property exposure could be an unacceptable commercial risk — and staff could face cross-examination on their methods. digitaljournaldigitaljournal
Could companies face retaliation?
That's the second major concern. Governments have institutional protections, legal authorities and diplomatic backing; private companies generally do not. Cybercriminal groups have repeatedly shown they adapt quickly, and retaliation can include DDoS attacks, data theft, extortion, reputational attacks and the targeting of employees or executives. Participation in offensive operations could transform a company from a victim of cybercrime into a deliberate target — with fallout potentially extending to customers, partners and foreign courtrooms. digitaljournaldigitaljournal
How does AI complicate this?
Legal analysts have read the memorandum as opening the door to more automated offensive capabilities. Autonomous, agentic AI systems act faster than human decision-makers — meaning an error in an offensive operation could extend beyond approved targets before anyone can intervene. Attribution — determining who is actually behind an attack — remains one of cybersecurity's hardest problems, and an offensive response based on wrong attribution could carry legal, diplomatic or financial consequences. digitaljournaldigitaljournal
Proponents counter that private firms often have advanced capabilities and can move faster than government agencies against criminal groups that exploit jurisdictional boundaries. For now, Canadian policymakers face the question of whether those advantages outweigh risks that governments have traditionally absorbed. digitaljournal