Statement from the Cybersecurity Tech Accord on the risks of escalating offensive cyber postures

BRUSSELS, BELGIUM — The Cybersecurity Tech Accord and its signatories are concerned that more governments are expanding the role of offensive cyber capabilities in national cyber policy. States have legitimate national security responsibilities and may use cyber capabilities where authorized by domestic and international law. But lowering the threshold for offensive actions risks fueling escalation, weakening trust, and increasing harm to civilians, enterprises, and critical digital infrastructure. National security is better served by resilience lawful accountability, coordinated vulnerability disclosure, and international cooperation than by normalizing offensive action.

For clarity, we distinguish between: lawful defensive cybersecurity activity in  systems an organization owns or is authorized to protect; government-led disruption under clear legal authority, which may include lawfully bounded private-sector technical assistance; and private “hack back”, meaning retaliatory activity beyond a defender’s own environment. These are not the same. The Cybersecurity Tech Accord’s  concern is the normalization of offensive cyber operations and private retaliation that weaken safeguards, create systemic risk, undermine coordinated vulnerability disclosure, or cause unintended harm.

Since its founding, the Cybersecurity Tech Accord has been grounded in a clear commitment to  oppose cyberattacks on innocent citizens and enterprises and to protect all customers everywhere. That commitment includes a firm private sector “no offense” principle: technology companies defend users, strengthen products, support lawful accountability, and cooperate with appropriate authorities — not conduct offensive cyber operations or vigilante retaliation. This is reinforced through support for initiatives such as the Paris Call, including its opposition to private hack back.

A defense-first posture is not passive. It is the most scalable and responsible path to security. Firstly, offensive cyber operations, including “hack back”, depend on discovering, retaining, or purchasing vulnerabilities. Wider reliance on such methods will incentivize non-disclosure, expand markets for offensive tooling, and leave users exposed when vulnerabilities are not  responsibly disclosed and patched. Further, attribution challenges further increase the risk of miscalculation or misattribution, misdirected retaliation, collateral damage and escalation. AI-enabled speed in reconnaissance, vulnerability discovery, and exploit development makes these risks more acute by compressing the time available for human judgment, legal review, and diplomatic de-escalation.

Governments should therefore ensure that any use of such capabilities remains exceptional, lawful, necessary, proportionate,  authorized and subject to oversight. Such actions should minimize foreseeable civilian, cross-border, and supply chain harm; and remain consistent with international law and the framework for responsible state behavior in cyberspace. Clear limits are essential: restraint, oversight, and accountability are not obstacles to security; they are conditions for legitimacy and stability.

At the same time, restraint must not mean impunity. Cybercriminals, cyber mercenaries, and the actors that enable, finance, shelter, or knowingly tolerate them must face consequences. Governments should make fuller and more consistent use of lawful tools, including criminal investigations and prosecutions, extradition and mutual legal assistance, coordinated disruption of malicious infrastructure, asset freezes, travel bans, targeted sanctions, public and diplomatic attribution, and action against entities that provide material, technical, or financial support for malicious cyber activity. These measures should be evidence-based, proportionate, rights-respecting, and coordinated across jurisdictions. They also need to be applied far more consistently across incidents and geographies. Sporadic or selective consequences make cybercrime profitable and predictable; consistent consequences change incentives, strengthen deterrence, and reduce pressure for escalatory offensive responses.

Industry has a critical role to play, but that role must remain defensive and lawful. Companies should continue investing in foundational defensive practices — including secure-by-design engineering, cyber hygiene, vulnerability management, patching, phishing-resistant authentication, logging, monitoring, incident response, and recovery readiness. Measures such as honeypots, sandboxing,  threat intelligence sharing, and carefully governed beaconing, can  support detection and response when used within systems an organization owns or is authorized to protect, or where undertaken with clear legal authority. Actions affecting systems that environment require separate legal and operational assessments, and safeguards for customers and third parties.  

The Cybersecurity Tech Accord calls on governments to reaffirm restraint, preserve legal limits and oversight on offensive cyber activity, reject private hack back, support coordinated vulnerability disclosure, strengthen law-enforcement cooperation and impose lawful consequences on cybercriminals and those who enable them. We call on industry to remain focused on collective defense, secure products, transparent vulnerability handling, and customer protection regardless of nationality or geopolitical context. At a time of heighted geopolitical tension, the path to a safer cyberspace is not more actors taking offensive action into their hands. It is resilience, lawful accountability, and sustained cooperation.