The US needs a new cybersecurity strategy, but offensive cyber operations are unlikely to deter Chinese state-sponsored hacking and come with significant risk
Ever since China's ‘Salt Typhoon’ hacking operations against US telecom networks was uncovered, there's been a lot of discussion about “hacking back”.
Context & Ripple Effects
The debate follows the reported Salt Typhoon compromise of major US telecom networks, including potential access to wiretap systems, and warnings that Chinese actors were positioning within US critical infrastructure. It has renewed arguments for a more forceful response.
This article challenges that response at a moment when advocates of stronger US cyber offense were already being pressed to define the limits of escalation. It redirects attention toward a strategy that reduces exposure rather than assuming retaliation will change an adversary's behavior.
First-order effects
- The case for “hacking back” loses some policy momentum: US officials and cyber leaders must weigh escalation and operational risk against uncertain deterrent value.
- Telecom and other critical-infrastructure operators remain central to the immediate response, because the reported intrusion highlights the cost of relying on retaliation after access has already been gained.
Second-order effects
- Pressure grows for defensive requirements and coordinated remediation across infrastructure providers, extending the earlier shift from voluntary cooperation toward security oversight.
- Cybersecurity vendors and operators may see greater demand for prevention, detection, and resilience capabilities rather than tools framed chiefly around offensive response.
Third-order effects
- If this logic prevails, US cyber strategy could move further from episodic retaliation toward an ecosystem-defense model in which government and essential-service operators share responsibility for baseline resilience.
- The underlying trade-off will persist: offensive operations may remain a tool of statecraft, but their legitimacy will increasingly depend on whether they complement rather than substitute for domestic defenses.
The trend: State-backed intrusions into essential networks are pushing cyber policy toward collective infrastructure resilience over retaliation-led deterrence.