The US government needs to delineate what kinds of “active defenses” are permissible under different circumstances. In particular, the Computer Fraud and Abuse Act needs to be updated to better reflect the circumstances that companies face today. For example, it may be necessary to clarify what actions companies can take to track the theft of their intellectual property outside of corporate networks.