Private-actor countermeasures are the sharpest unresolved question in this subject. Companies own most of the infrastructure that state-linked cyber operations target, absorb the loss when it fails, and hold none of the legal privileges that the law of state responsibility reserves to injured states. What a company may lawfully do in response, and who bears the loss when it does nothing, is where the Journal's private-sector scholarship concentrates.
Where corporate active defence runs out
Cyber Countermeasures by Private Actors sets the constraints out in sequence. The doctrine of countermeasures permits an injured state to take proportionate action in response to an internationally wrongful act attributable to another state, subject to strict conditions; it presumes state action, and corporations lack the sovereign standing to invoke it. The United Nations Charter's prohibition on the use of force addresses states rather than private entities, but a corporate operation producing significant cross-border effects may be attributed to the territorial state where that state exercises control or acquiesces. Extraterritorial disruption — reaching into foreign infrastructure to disable malicious servers — engages territorial sovereignty and the principle of non-intervention even in the absence of kinetic force. Domestic computer-misuse statutes generally prohibit unauthorised access even to systems hosting malicious infrastructure; collateral harm to vendors, service providers and innocent intermediaries carries civil exposure; insurance may not extend to offensive countermeasures; and directors and officers may face fiduciary scrutiny. Attribution compounds all of it, since proxies, criminal affiliates and layered infrastructure make premature identification a real risk of directing disruption at the wrong party.
The article's answer is a tiered model. Passive defence — hardening, segmentation, logging, threat-intelligence sharing and internal remediation — is lawful and should be the default. Containment within a company's own infrastructure, including blocking command-and-control communication and collecting forensic indicators, remains internal. Measures that reach into foreign infrastructure require state authorisation, and if states want corporate participation in active defence, the article argues they should legislate for it with oversight and rules of engagement rather than rely on informal tolerance. A contrasting position appears in If You Wish Cyber Peace, Prepare for Cyber War: The Need for the Federal Government to Protect Critical Infrastructure From Cyber Warfare, which proposes active cyber defences together with increased government oversight of critical-infrastructure networks.
Who bears the loss: the war exclusion and the reporting clock
Cyber Insurance and Corporate Risk in Cybercrime takes up what happens when a company does not strike back and instead claims. War exclusions in cyber policies were drafted for kinetic armed conflict between sovereign states, and insurers have invoked them as state-attributed cyber operations have increased. The article frames the resulting bind without resolving it: read broadly, exclusions shrink corporate coverage precisely as systemic risk rises; read narrowly, insurers face aggregation exposure they may not sustain. It also observes that underwriting requirements — multi-factor authentication, endpoint detection, privileged access management — function as a regulatory proxy where statutory cybersecurity mandates remain uneven, that sanctions compliance constrains ransom payment, and that a functional classification turning on intent and objective, scale and systemic impact, degree of state direction, and target selection would align coverage with harm rather than with political labelling. Comparative Cyber Incident Response covers the reporting side of the same incident across the United States, European Union, China and India, and recommends a federated forensic model for companies that cannot centralise investigative data across jurisdictions.
Sector exposure and the automation of ordinary fraud
The Ransomware Assault on the Healthcare Sector examines the vulnerabilities created by the move to electronic health records, the ransomware-as-a-service model that lowers the barrier to entry for less capable attackers, and the WannaCry attack that disrupted the United Kingdom's National Health Service. The Internet of Things (IoT) in a Post-Pandemic World surveys the security threats that accompany the growth of connected sensory devices and the regulatory landscape around them. AI‑Powered Phishing: Regulating Social‑Engineering Campaigns addresses the entry vector for much of this exposure, arguing that fraud statutes assume a human author and proposing an offence of automated deceptive communications together with transparency obligations on providers of high-capacity mailing services.