For years, cybersecurity has been built around a simple principle: defend, detect and recover. But as ransomware groups, cybercriminal networks and state-backed hackers become more persistent, governments are increasingly considering a more aggressive question—should private companies be allowed to fight back?