Your network, their network
Inside its own environment, a company generally has wide latitude to watch, block, and isolate. The line moves once a measure reaches outside, and so-called hacking back into an attacker's infrastructure can itself be unauthorized access under federal and state computer crime laws, whatever the motive. That can include logging into a server the attacker controls using credentials found during the investigation. Deception tools such as decoy files and honeypots are widely used, but design matters, for instance whether a beacon reports back from someone else's machine. Before trying anything that touches a system you do not own, the safer course is to involve law enforcement or the relevant provider.
Watching your own people
Monitoring sits at the center of cyber defense, and it is also where employment and privacy law meet. New York requires private employers that monitor employee phone, email, or internet use to give prior written notice and to post that notice, and other states have their own rules on monitoring and recording communications. Reading the contents of personal accounts accessed from a work device raises different questions from reviewing company systems. Biometric sign-in tools can trigger specific statutes in some states. A defensible monitoring program usually rests on a written policy employees have acknowledged and on a clear security purpose, with access to what is collected kept narrow.
Sharing what you learn
Exchanging threat information with peers, industry groups, and government partners helps everyone, and federal law has offered certain protections for sharing cyber threat indicators through recognized channels. Those protections come with conditions, including removing personal information not needed to describe the threat, and their status has not been static. Contracts with customers and vendors may also restrict what you can disclose about an incident or a vulnerability. When companies ask us about defensive measures, we review the proposed tool or practice against the systems it touches, the data it collects, and the agreements already in place, so the security team knows where the boundaries are before an incident tests them.