Georgia has made headlines twice in recent months for cybersecurity incidents, and both isolated cases have questioned how organizations should respond after a cyberattack.

Shortly after Atlanta disclosed a citywide ransomware attack, the state government proposed a cybercrime bill that was immediately criticized by the security industry, including those who were helping Atlanta recover from the ransomware crisis.

Proponents of the "hack back" bill believe it will ultimately benefit the cybersecurity community. Georgia Governor Nathan Deal disagreed, but his official statement hinted at further discussions to refine the bill.

The hack back bill is based on the same rationale as any other law designed for self-protection, but in an era of increasingly sophisticated cyberattacks, taking the risk of striking back may not be worth the cost of a momentary emotional release.

The original bill's wording was considered too vague because it stipulated that any unauthorized access to a computer system would constitute a crime, punishable by fines and up to one year in prison.

Such legislation could discourage researchers from conducting "responsible disclosure," SecurityScorecard CEO Alex Yampolskiy told CIO Dive. If companies choose to file lawsuits, the bill would effectively criminalize those engaged in ethical security research.

Furthermore, the bill would legalize retaliatory intrusions into the systems of suspected attackers. Experts generally believe that bills legalizing hack back are merely "desires stemming mainly from frustration," Herbert Lin, senior research scholar for cybersecurity and policy at Stanford University's Center for International Security and Cooperation, told CIO Dive.


Supporters of hack back are like the "NRA of cyberspace."

c26dbb7f8ae5524841267a35b6468bcbecf9efd7dcf6efba56bf278ef43ecb45.png

Herbert Lin

Senior research scholar for cybersecurity and policy at Stanford University's Center for International Security and Cooperation


Lin said supporters of hack back are like the "NRA of cyberspace" because no one wants to be a victim. However, when bare-knuckle boxing becomes fair game in cyberspace, anyone could "accidentally hit" the wrong target.

Georgia's bill is a "clumsy attempt to create anti-intrusion laws for the digital age," Coronet CISO Dror Liwer said in an email statement to CIO Dive. The ambiguity surrounding such bills has instead opened up discussions about hacker ethics.

Why the bill was proposed

The bill was initiated at the request of law enforcement, Georgia Republican State Representative Christian Coomer told CIO Dive. Coomer is one of the state legislators sponsoring the bill because it aims to "serve as a deterrent to malicious actors."

During committee hearings, the bill added several "safeguards" in an attempt to more clearly define the boundaries of hack back without harming legitimate business practices.

However, Coomer said the argument about misattribution was never raised during deliberations, leaving him unfamiliar with the term.

"I know my limitations," he said, but since the issue was never raised in committee proceedings, Coomer concluded that the "big tech companies" criticizing the bill "had no intention of fixing it." Instead, they focused on blocking it entirely, which led to "unintended consequences," such as attribution issues.

Coomer encouraged industry experts to participate in committee proceedings, telling lawmakers what they did wrong and how to fix it. Ultimately, the big companies criticizing the bill, such as Microsoft and Google, simply "didn't come to the table," Coomer said.

The federal government struggles to keep pace with technology

Georgia's bill is a response to the current Computer Fraud and Abuse Act (CFAA). According to the U.S. Department of Justice, the CFAA was enacted in 1986 as an amendment to the Comprehensive Crime Control Act in response to the emerging computer age. Over the past decades, the CFAA has been amended multiple times to adapt to increasingly sophisticated technology.

However, although federal law criminalizes any unauthorized computer access, the law fails to clearly define the extent of intrusion or what constitutes unauthorized access.

For example, if someone sends "active content" such as a PDF file or Word document containing macros that run on the recipient's computer, it could technically violate the CFAA, Lin said.

Georgia's legislation aims to "relax" certain aspects of the CFAA. Lin noted that under the current CFAA, hack back remains illegal because it still means accessing someone else's system without permission.


"The whole concept of causing harm to the source of an attack, I think that's completely futile."

c26dbb7f8ae5524841267a35b6468bcbecf9efd7dcf6efba56bf278ef43ecb45.png

Dr. Salvatore Stolfo

Professor of computer science at Columbia University and cybersecurity researcher


Legislation introduced by Georgia Republican U.S. Representative Tom Graves, called the Active Cyber Defense Certainty Act, has undergone multiple rounds of amendments. McAfee Chief Public Policy Officer Tom Gann told CIO Dive that the latest amendments include joint cooperation with law enforcement and limits on how aggressive the private sector can be in offensive activities.

Graves' bill went through a more "deliberative process" to better achieve cyber defense measures and thus "act in a more predictable manner," Gann said. Such policy changes could streamline data sharing between the public and private sectors, making the understanding of cyber defense more contextual.

Despite experts calling for greater collaboration, communication between the two sectors remains a point of contention among security experts.

Most importantly, organizations need better ways to assess exploitable flaws in their systems. By adopting artificial intelligence and machine learning technologies, defenses will become more proactive rather than reactive.

Where will hack back bills go?

Amendments to the current bill could prevent it from being rejected again.

However, "the whole concept of causing harm to the source of an attack, I think that's completely futile," Dr. Salvatore Stolfo, professor of computer science at Columbia University and cybersecurity researcher, told CIO Dive. In rationally responding to the reality of attacks, such bills also seem to deviate from organizational goals.

But beacon files remain a legitimate means of circumventing privacy laws such as the EU's GDPR. Beacon technology is a bit like "GPS for data," Stolfo said. If a beacon file executes on a machine that has been taken from its original owner's computer, it alerts the original owner that the file now "resides" on another computer and sends its location information (such as an IP address), Lin said.

However, Lin believes beacon technology adds to the confusion surrounding hack back bills and the CFAA, and is "at a higher level of complexity," because technically, even if a program was originally stolen, it is still a program running on another machine without authorization.

Hack back bills are unlikely to pass in the short term

Cybersecurity is a top concern, but most experts say unnecessary cyber warfare is not the right way to solve the problem.

Whether bills like Georgia's can pass depends on the "functionality of the language and definitions" of what constitutes malicious intrusion, Stolfo said.

But the current definition of hack back is "useless" and fuels retaliatory behavior, which "is not aimed at solving the problem of preventing data loss," Stolfo said.


"Always being purely defensive is not a winning strategy."

c26dbb7f8ae5524841267a35b6468bcbecf9efd7dcf6efba56bf278ef43ecb45.png

Tom Gann

Chief Public Policy Officer at McAfee


The trickiest part of hack back legislation is defining criminal conduct and subsequent enforcement.

Liwer believes hack back laws can only be enforced "selectively," which by definition makes the law "irrelevant."

Non-lethal defense

Security professionals have been told repeatedly that the best cyber defense is not reactive, but proactive and rooted in foundational work. Patching, multi-factor authentication, and employee training programs all help build a protective moat around organizations. When the right defenses are in place, there is no need to strike back.

"Always being purely defensive is not a winning strategy," Gann said. Organizations need a "lifecycle" defense strategy to protect IT environments in real time.

Proactive security protocols are the best solution for security teams facing cyber threats. If organizations can catch attackers while they are inside their networks, that is far more effective than guessing the true attribution of an attack.

Hackers can lurk in systems for months, as the Equifax case showed. They can hide in systems for long periods, slowly stealing data at an imperceptible pace, and all of it is "free," Stolfo said. He proposed a more "non-lethal" approach that makes cyber attackers pay for their actions through "deep deception."

Stolfo suggests strategically placing data decoys or fake data within an organization's operational network. If hackers gain access and begin collecting decoy data mixed with real data, they will ultimately pay a cost in resource consumption. Hackers would then need to spend time sifting through real and fake data to determine what is factual.

Decoy data can serve as an additional layer of protection while gaining a means to "break the asymmetry of attacks," Stolfo said.