U.S. Allows Private Firms to Counter Cyberattacks
米国、民間企業によるサイバー攻撃への反撃を容認
更新日: 2026年8月14日 01:30
In recent years, the debate over whether private companies should be allowed to 'hack back' against cyberattackers has intensified.
近年、民間企業がサイバー攻撃者に対して「ハックバック(反撃)」を行うことを許可すべきかどうかという議論が激化しています。
While headlines sometimes suggest a shift in policy, it is important to clarify that no federal law in the United States currently permits private entities to launch counterattacks.
報道の見出しが政策の転換を示唆することもありますが、現在米国の連邦法において、民間組織による反撃を認めるものは一切ないという点を明らかにしておく必要があります。
Current regulations, such as the Computer Fraud and Abuse Act (CFAA), strictly forbid unauthorized access to external systems, restricting companies to passive defenses like firewalls and monitoring.
コンピュータ詐欺および乱用防止法(CFAA)などの現行の規制は、外部システムへの無許可アクセスを厳しく禁じており、企業はファイアウォールや監視といった受動的な防御手段に限定されています。「
Proponents of 'active defense' argue that these passive measures are no longer sufficient to stop sophisticated, state-sponsored cyber threats.
積極的防御」の支持者たちは、これら受動的な対策では、国家が支援する高度なサイバー脅威を防ぐにはもはや不十分であると主張しています。
Potential risks include accidental escalation into international conflict, the possibility of misidentifying an innocent party’s system as the source of an attack, and the violation of international norms.
潜在的なリスクとしては、意図せぬ国際紛争への拡大、罪のない第三者のシステムを攻撃元と誤認する可能性、そして国際規範への違反などが挙げられます。
Legislative efforts like the ACDC Act have attempted to find a middle ground by proposing strict oversight for such actions, but the policy remains contentious.
ACDC法などの立法の試みは、こうした行為に対して厳格な監視を提案することで中立な立場を見出そうとしてきましたが、その政策をめぐる論争は続いています。
