It’s been more than a decade since the United States first publicly blamed another country for a cyberattack, an accusation detailed in a 31-count indictment against five members of the Chinese military who hacked into the systems of American nuclear, metal, and solar companies over a period of eight years. That public attribution of economic espionage in 2014 marked a major shift for the United States, which had previously worked behind the scenes to address digital intrusions that came from beyond its borders, if it did anything at all. Part of the rationale for naming and shaming the perpetrators was to deter bad actors from carrying out future hacks. Deterrence as a defense strategy, however, has so far proved to be something of a dud. Today, cyberattacks seem almost commonplace; breaches of public and private entities are everyday news. So-called ransomware attacks, in which hackers lock up an entity’s system or files and demand payment to restore functionality, have proliferated. In 2024, in a federal indictment, a North Korean intelligence operative was accused of using the proceeds from ransomware attacks he’d carried out against hospitals to fund additional cyberattacks on government entities around the world, among them two U.S. Air Force bases. Other attackers, including groups sponsored by countries such as China and Russia, do not announce their presence; their goal is to stay hidden long enough to steal information that can later be used for financial or geopolitical gain. By hacking into U.S. telecommunications companies in 2024, China apparently intercepted surveillance data that was meant for law enforcement agencies. Cyberattacks may be difficult to prevent, but that doesn’t mean policymakers, governments, and the sector have given up trying. Harvard Law School faculty and alumni who have worked on cybersecurity issues in their research and practice, some at the highest