A significant shift — but not a licence for UK businesses to “hack back”
TechCrunch reports that the United States will, for the first time, allow certain private companies to carry out cyberattacks under a defined authorisation framework. The full operational scope, eligibility criteria and safeguards will matter greatly, but the direction of travel is already notable: governments are considering whether carefully selected private-sector actors can play a more active role against hostile online infrastructure.
For a UK small or medium-sized enterprise, this is not principally a story about acquiring offensive capabilities. It is a warning that the cyber threat environment is becoming more complex. When state bodies and approved private providers disrupt criminal infrastructure, attackers may adapt faster, change tools, use more compromised systems and intensify efforts to conceal where attacks originate.
The practical implication is straightforward: UK SMEs need to distinguish robust defensive incident response from unlawful or uninsurable retaliation. Cyber insurance can help fund the former. It is highly unlikely to protect a business that chooses to take the latter into its own hands.
Why this US development matters to UK SMEs
Attribution remains difficult — and mistakes can be expensive
A ransomware note, a phishing domain or an IP address associated with an intrusion does not reliably identify the person responsible. Criminal groups routinely use rented cloud servers, hijacked devices, anonymising services and infrastructure belonging to innocent third parties. A machine appearing to attack a UK company may itself be another victim.
That makes private retaliation exceptionally risky. If a business, employee or contracted supplier attempts to disrupt suspected attacker infrastructure and gets attribution wrong, it could interrupt another organisation’s services, destroy evidence or trigger claims for losses. The reputational damage may be as serious as the original incident, particularly for a professional services firm, technology supplier or business handling customer data.
For insurers, poor attribution also complicates claims assessment. A policy is designed to respond to an unforeseen cyber event and the insured’s reasonable response to it. Deliberately accessing, altering or impairing someone else’s system is a fundamentally different exposure.
The threat landscape may become more volatile
Disruption operations can be valuable: taking down malicious infrastructure may reduce harm in the short term. However, cybercrime groups are commercially motivated and technically adaptable. They can move hosting, rotate domains, switch malware variants and recruit new affiliates.
UK SMEs should therefore not assume that action against criminal groups elsewhere automatically makes them safer. Instead, they should expect continued volatility in ransomware, business email compromise and supply-chain attacks. A smaller organisation is often targeted not because it is famous, but because it has weak identity controls, exposed remote access, limited monitoring or a valuable connection to a larger customer.
US permission does not alter UK law
Any US authorisation would apply within its own legal and policy framework and only to the parties it permits. It does not provide a UK company, a UK employee or a UK-managed service provider with permission to access overseas systems.
In the UK, the Computer Misuse Act 1990 creates offences relating to unauthorised access and unauthorised acts affecting computer systems. Even where a business believes it is recovering data, tracing an attacker or disabling a malicious server, it should obtain specialist legal advice and work through law enforcement, its insurer and approved incident-response professionals.
There is an important distinction between conducting defensive work on systems you own or are authorised to manage — such as isolating endpoints, blocking indicators of compromise and preserving logs — and taking action on an external system. The former is an essential part of resilience. The latter may create criminal, civil, regulatory and insurance consequences.
What this means for cyber insurance cover
Cyber insurance is not a substitute for cyber security, and it is not a blank cheque for active countermeasures. A well-structured policy can nevertheless be central to an SME’s response when an attack occurs.
Focus on response costs, not retaliation
Depending on the wording, cyber insurance may cover costs such as incident-response specialists, forensic investigation, legal advice, notification support, data restoration, business interruption and cyber extortion response. Policies vary substantially, including by limits, excesses, waiting periods, sub-limits and exclusions.
A specialist incident-response provider can help a business contain an attack while preserving evidence for law enforcement and potential recovery actions. This is far safer than asking an internal IT employee to identify or interfere with the alleged attacker’s infrastructure.
Before buying or renewing cover, an SME should ask its broker or insurer:
- Is a 24/7 incident-response helpline included, and must it be contacted before appointing suppliers?
- Are forensic investigation, legal counsel, customer communications and data restoration covered within the main limit or subject to sub-limits?
- How is business interruption calculated, and is there a waiting period?
- Does the policy respond to dependent business interruption caused by a cloud, software or managed-service provider outage?
- What exclusions apply to deliberate, unlawful or unauthorised acts by directors, employees or contractors?
The final question deserves explicit attention. A board should make clear in its incident-response plan that no employee is authorised to “hack back”, pay a ransom, negotiate with criminals or engage external responders without following the documented escalation process.
Practical actions UK SME leaders should take now
1. Test the first 24 hours of your incident plan
Most damage is determined early. Write down who has authority to shut down systems, contact the insurer, engage the broker, instruct lawyers and communicate with customers. Include out-of-hours phone numbers rather than relying on access to a potentially compromised email system.
Run a short tabletop exercise based on a realistic scenario: an employee’s Microsoft 365 account is taken over, fraudulent invoices are sent to customers, and the attacker starts creating mailbox rules. Assess whether the team can contain access, preserve logs, notify the right parties and make decisions without improvising.
2. Reduce the openings attackers use most often
Prioritise multi-factor authentication for email, remote access, administrator accounts and cloud applications. Remove legacy authentication where possible, use phishing-resistant methods for privileged users, patch internet-facing systems promptly and maintain offline or immutable backups that are tested for restoration.
These controls are also increasingly relevant during cyber insurance underwriting. Insurers commonly seek evidence of MFA, backups, endpoint protection, patching and access management because these measures reduce both the likelihood and severity of a claim.
3. Manage suppliers as part of your own exposure
If accounting, payroll, customer relationship management, ecommerce or managed IT is outsourced, ask suppliers how they detect incidents, notify customers and restore service. Confirm contractual responsibilities, data-processing arrangements and whether their liability limits are realistic relative to the disruption they could cause.
A supplier’s security incident can halt your trading even where your own network is unaffected. That is why contingent business interruption cover and appropriate supplier due diligence should be considered together.
4. Preserve evidence; do not pursue the attacker
If suspicious activity is discovered, record timestamps, affected accounts, emails, screenshots and system alerts. Disconnect affected devices where appropriate, but avoid wiping or rebuilding them before forensic advice unless necessary to stop immediate harm. Notify your insurer promptly, because using unapproved suppliers or delaying notification can affect how a claim is handled.
The goal is recovery, containment and lawful reporting — not digital revenge. For UK SMEs, that approach is more likely to protect customers, preserve insurance options and support any police or regulatory investigation.
The strategic lesson: resilience beats counterattack
The US move described by TechCrunch may signal a future in which authorised private entities have a larger role in disrupting cyber threats. Yet that is a specialised, tightly governed activity, not an operational model for ordinary businesses.
UK SME leaders should treat the story as a reason to strengthen governance around cyber incidents. Know who can make decisions, understand the limits of insurance, retain competent response partners and make sure technical teams know that defensive containment is not the same as counterattacking. The most effective response to a cyber incident is usually rapid, disciplined recovery backed by tested controls and suitable insurance — not an attempt to strike back at an unknown adversary.
FAQ
Can a UK SME legally hack back after a ransomware attack?
Generally, no. Accessing or interfering with systems without authorisation can create serious legal risk under UK law, even if the target is believed to be connected to criminals. Contact your insurer, legal advisers, incident-response provider and law enforcement instead.
Will cyber insurance pay for a company to disrupt an attacker’s server?
Businesses should not assume so. Cyber policies typically support lawful incident response, forensics, restoration and related losses, subject to their wording. Deliberate or unlawful acts may be excluded. Check the policy and obtain insurer approval before incurring response costs.
Activate your incident plan, isolate affected systems where safe to do so, preserve evidence, reset or disable compromised accounts, notify your insurer through its required channel and engage approved specialists. Avoid communicating from potentially compromised accounts or altering evidence unnecessarily.
Does this US policy change cyber security obligations for UK firms?
No. It does not change UK legal obligations or provide UK businesses with authority to conduct offensive cyber activity. It does reinforce the need for strong prevention, tested response arrangements and an insurance policy aligned with your technology and supplier risks.
Source: TechCrunch — Thu, 13 Aug 2026 14:09:05 GMT