U.S. computer security efforts are entirely defensive, since probing and/or disabling attacking foreign cyber criminals or rogue governments is strictly against the Cybersecurity Act of 2009. Any athletic team that plays only defense will lose the game. The first step in leveling the playing field is to explicitly articulate a new cyberdefense doctrine wherein violators might expect an immediate and possibly disproportionate response for even probing US private or government computer assets. Of course the President and Congress will have to set the ground rules, but this is that necessary first step.



