Going on the Offensive: Exploring Governments’ Shift in Cyber Strategy

Throughout October Cybersecurity Awareness Month, the Cybersecurity Tech Accord is publishing a four-part series featuring expert insights from across our signatories. The series examines a consequential shift in national cyber policies: as state-sponsored and criminal cyber activity intensifies, more governments are expanding offensive cyber capabilities and lowering the threshold for their use. This shift is not simply a change in operational doctrine. It carries legal, normative, diplomatic, and practical implications for governments, industry, and end-users alike. Offensive operations can impose costs on malicious actors, but they can also create spillover harm, incentivize the retention of vulnerabilities, fuel escalation, and blur the line between trusted technology providers and instruments of state power.

Since its founding, the Cybersecurity Tech Accord has been grounded in clear commitments: signatories commit to “oppose cyberattacks on innocent citizens and enterprises” and to “protect all customers everywhere,” regardless of nationality or geopolitical considerations. Signatories are also united by the principle of “no offense”, which reflects the private sector’s distinct responsibility to defend users, strengthen products, and avoid knowingly undermining the security of the online environment.

Against that backdrop, this series asks how governments can respond to escalation threats without normalizing practices that generate broader cyber instability. We begin by mapping the policy shift, examine its risks, hear perspectives from a former NATO cyber leader, and conclude with practical recommendations for governments and industry.

From defense-first strategies to more assertive cyber postures

National cybersecurity strategies have traditionally emphasized defensive postures: hardening networks, detecting intrusions, and recovering from harm. What is changing is that a growing number of countries are updating their cybersecurity strategies to include capabilities to disrupt adversary systems, to be used both in times of conflict and as a routine instrument of statecraft. According to security think tank RUSI, offensive cyber operations have now become “a significant tool of statecraft in the 21st century”. A January 2026 analysis by Binding Hook aims to sum up this shift: states are not abandoning cyber defense; however, they are increasingly adding offensive capabilities on top of it and lowering the thresholds for using them.

Although several states have defined “offensive cyber operations” in their respective national cybersecurity strategies, there is no definition under international law. For the purposes of this series, we use the Australian Strategic Policy Institute’s (ASPI) definition: “operations intended to manipulate, deny, disrupt, degrade, or destroy targeted computers, information systems or networks”.This definition helps distinguish offensive effects from defensive activity within systems an organization owns or is authorized to protect.

Updating the cyber rulebook: a global policy shift

The United States has provided one of the clearest recent signals of this shift. President Trump’s March 2026 Cyber Strategy for America commits the government to deploy both defensive and offensive cyber operations, shape adversary behavior, and create incentives for the private sector to identify and disrupt adversary networks.

This builds on earlier concepts: the U.S. Cyber Command has operated under the logic of “persistent engagement” and defend forward” since 2018, and the 2023 Biden National Cybersecurity Strategy emphasized imposing costs on malicious actors. However, the candor, scale of ambition, and emphasis on the proposed role for private companies mark an important development[1].

The shift became more apparent in August 2026 when the Presidential Memorandum “Expanding capabilities to combat transnational cyber-enabled crime”, set to establish a program authorizing participating private U.S. companies to conduct cyber surveillance operations and cyber effects operations against foreign cyber-enabled transnational criminal organizations under the control and oversight of the U.S. Federal Government.

“The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States. Yet, American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace. Thus, it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime. By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens.”

— Presidential memorandum “Expanding capabilities to combat transnational cyber-enabled crime”, August 2026

The Tech Accord has warned that involving private companies as operational actors of the State raises questions about trust, liability, oversight, accountability, vulnerability handling, and the growth of commercial offensive cyber markets. These concerns are set out in the Tech Accord’s statement on the risks of escalating offensive cyber postures.

The United States is not alone. The United Kingdom strengthened its institutional framework for coordinating offensive and defensive cyber capabilities in the 2025 Strategic Defence Review. The Ministry of Defence framed the move against a backdrop of more than 90,000 “sub-threshold” attacks on its networks over two years. The UK had already lowered the threshold for offensive cyber use in 2020.

Building on the offensive cyber doctrine first published in 2019, France also published in 2025 its National Strategic Review. The review treated cyberspace as an important arena where the state must be able to act offensively, conducting real-time information operations and inflicting losses on opponents.

Another significant shift comes from Germany, a country that has historically been among the most cautious states when it comes to offensive cyber operations. Following a cabinet decision in August 2025, Berlin advanced draft legislation on “active cyber defense” which includes “hack back” powers that would for the first time let the foreign intelligence service (BND) conduct offensive operations against hostile systems. This draft legislation, which still requires parliamentary approval, has drawn significant internal criticism over oversight and collateral damage risks. Sweden, Denmark, and Finland,with Finland historically maintaining a predominantly defensive posture, are also expanding into offensive capabilities, particularly influenced by the escalation of Russian threats.

Japan has made a historic shift in the same direction. In 2025 the Japanese parliament passed the Active Cyber Defense Law, which authorizes the police and Self-Defense Forces to access and neutralize hostile servers abroad before an attack lands, using analysis of cross-border traffic metadata under an independent oversight body. South Korea signaled a comparable turn in its 2024 National Cybersecurity Strategy and the follow-on Basic Plan of 100 tasks, explicitly reorienting from a defensive to an “offensive cyber defense” posture against North Korea and other threats, language that consciously mirrors the U.S. “defend forward” concept.

Australia and Canada are moving in the same direction. The Australian Signals Directorate has publicly acknowledged it conducts offensive operations, signaling a more assertive offensive posture. Similarly, Canada’s Communications Security Establishment has reported conducting offensive cyber operations in its 2025–2026 annual report. While these approaches differ significantly in legal authority, doctrine, oversight and operational scope, collectively they point to a wider trend: offensive cyber capabilities are becoming a more visible and normalized component of national security policy.

Why governments are changing course

Governments are responding to a threat environment in which cyber operations can disrupt essential services, threaten national security, and impose major economic costs at unprecedented speed, scope, and scale. For instance, cyber incidents from Russia surged by 800% in the lead-up to the invasion of Ukraine in February 2022. Pro-Russian groups have also targeted other European countries, including a Norwegian dam and Poland’s power grid.

China has similarly expanded its cyber activities. U.S. and allied agencies have tracked a family of intrusions linked to China dubbed the “Typhoons”, which infiltrated U.S. critical infrastructure, apparently to pre-position access to disrupt essential services in a future crisis. In particular, Salt Typhoon compromised at least nine U.S. telecommunications companies and reached systems used for court-authorized surveillance.

North Korea-linked actors are similarly active. In 2025, they stole more than U.S. $2 billion in cryptocurrency, including roughly U.S. $1.46 billion from the Bybit exchange in what is believed to be the largest cryptocurrency theft in history.

At the same time, while artificial intelligence has enhanced cyber defense capabilities, it has also lowered barriers to malicious cyber operations. State-linked actors are increasingly using AI to automate reconnaissance and attacks, accelerate vulnerability research, enhance social engineering campaigns, and support malware development.

Taken together, these trends have persuaded many governments that a purely defensive approach is no longer sufficient.

What is at stake for industry and users

While states need to be able to defend themselves in the current environment, this trend towards offensive activities also carries important risks:

  • Systemic exposure: Wider use of offensive tooling depends on discovering and retaining software vulnerabilities rather than disclosing and fixing them, leaving everyone who relies on the affected technology exposed.
  • Miscalculation and spillover: The inherent challenges of accurately attributing cyber operations increase the risk of miscalculation while the normalization of offensive action may erode the norms of responsible state behavior that are meant to keep critical infrastructure and civilian services out of the line of fire.
  • Escalation and unintended harm: Offensive cyber operations can contribute to escalatory dynamics that rarely remain confined to governments, with consequences often spilling over to businesses, critical infrastructure operators, and ordinary users.
  • Trust and role confusion: Drawing private companies into offensive operations can expose them to conflicting legal obligations and liability, undermine customer trust, and cause governments to view global providers as extensions of foreign state power.

A defend forward posture is not a passive stance. Technology companies can support public safety through threat intelligence sharing, incident response, malware analysis, victim assistance, secure-by-design engineering, coordinated vulnerability disclosure, and lawfully bounded technical assistance. These contributions strengthen collective security without turning private providers into operational proxies of any one country.

The policy choices being made now will shape not only how states respond to cyber threats, but also whether the global digital ecosystem remains open, trusted, and resilient. The stakes extend well beyond national security issues and reach every business, public service, and individual that depends on connected technology. Tune in to the next blog in our series where we examine the risks associated with the shift toward cyber offense, drawing on concrete examples and the perspectives of those responsible for defending enterprises and critical infrastructure every day.


[1] Congressional Research Service, Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, IN12667, U.S. Congress, August 2026, available at: Congressional Research Service Report IN12667.