Cybersecurity Policy Report, Cairncross: Enlisting Private Sector in Cyber Defense Won’t Involve ‘Hacking Back’, (Mar 17, 2026)
Organizations Mentioned:Auburn University
The Trump administration’s plan to “unleash the private sector” to counter U.S. cyber adversaries doesn’t mean that private-sector organizations will be enlisted for offensive cyber operations, according to Sean Cairncross, director of the White House Office of the National Cyber Director.
“That's not what we're talking about,” Mr. Cairncross said today at an event hosted by Auburn University’s McCrary Institute for Cyber and Critical Infrastructure Security.
“What I'm talking about are the technical capabilities, the ability of our private sector to illuminate the battlefield from what they're seeing, to inform and share information so that the USG [U.S. government] can respond to get ahead of things,” he said.
Mr. Cairncross was discussing the White House “Cyber Strategy for America” that was issued earlier this month (CPR, March 6). The strategy calls for the U.S. to adopt a more aggressive posture to change what Mr. Cairncross calls the “risk calculus” of nations and groups planning cyber attacks on the U.S.
Achieving deterrence in cyberspace has long been a goal of U.S. cyber defenders who too often find themselves reacting to attacks, while cyber adversaries suffer too few consequences, Mr. Cairncross indicated.
“This is a particular frustration of mine, and it has been for some time. The risk calculus on our adversary side in this space doesn't seem to be calibrated correctly,” he said.
In the physical world, an attack on U.S. critical infrastructure “is something that an adversary would not consider doing, ... primarily because they know the response from the United States would be rather dramatic. And so that same level of thinking should have to be applied when they are making calculations in this [cyber] domain,” he said.
The private sector’s role in helping the federal government deter cyber adversaries has been a topic of discussion in recent years, and some members of Congress have proposed allowing companies to engage in a certain amount of “hacking back” when their networks are under siege. Last year, Rep. David Schweikert (R., Ariz.) introduced legislation that would offer licenses—or “letters of marque”—to cyber privateers (CPR, Aug. 20, 2025).
But that isn’t what the Trump administration envisions, Mr. Cairncross said. Instead, it wants closer collaboration and better information-sharing with the private sector, he said.
“We want to make sure that we're positioned as the USG to work with the private sector—that we're seen as a helpful partner,” he said. “It's not your job to defend against the Chinese or the Russians or the Iranians. That's the United States government's job. We're asking to work with you to get that done.”
News: FederalLegislation DataSecurity