What happened

The FBI on Wednesday unveiled a new cyber strategy designed to formalize and speed up its collaborative takedowns of malicious hacking activity. Brett Leatherman, assistant director of the FBI's Cyber Division, described the plan at the Billington Cybersecurity Summit in Washington, saying the bureau wants to move beyond the ad hoc way it runs disruptions today "to do it in a more steady state."

The strategy has four parts: how the FBI will investigate, attribute and disrupt cyberattacks; how it will quickly engage with victims and share useful information; how it will partner with other agencies and the private sector; and how it will build its own capabilities through recruitment, training and new tools. Threat-specific teams focused on Russia, China and cybercriminals will develop their own plans, and so will teams focused on offensive hacking and on operational technology breach investigations.

The FBI has already increased its disruption operations over the past few years, with recent takedowns hitting a Russian military intelligence agency's router botnet, domains the Chinese government used to target U.S. critical infrastructure, and the AlphV ransomware gang. But Leatherman said the environment "is becoming untenable for any one organization to defend alone," with teams sent out across the bureau's 56 field offices every day to help victims under attack.

A central goal is rebuilding private sector trust. Companies have grown hesitant to report hacks to the FBI, and Leatherman said the bureau wants to show it cares about helping victims and will not share their reports with regulators.

Why this is a GRC story

The strategy is as much about corporate behavior as about law enforcement operations. Many companies hold back from reporting intrusions because they fear what happens next: regulatory questions, disclosure obligations, public attention. The FBI's promise not to share reports with regulators targets the biggest blocker in that decision. Whether companies believe it will determine whether the strategy works.

For GRC teams the takeaway is to treat law enforcement engagement as a planned part of incident response, not an improvisation. Decide in advance who makes the call to report, what gets shared, and how legal and communications stay in step. Pre-incident relationships with the FBI and sector sharing groups make the post-incident call easier, because the contact list and the expectations already exist.

There is also a board-level message in Leatherman's line about defending alone. Cyber risk is collective risk. Companies that treat every threat report as pure liability starve the shared picture that lets law enforcement act before the next victim is hit.

What to watch

Watch for measurable change: the pace of disruption operations, how quickly victims get engaged after an intrusion, and whether company reporting actually rises. The promise that the FBI will not pass reports to regulators will be tested quickly, and it is the linchpin of the whole trust argument.

Also watch how the customized team plans change operations in practice. A strategy document is easy; the steady state the FBI says it wants will show up in whether victims see faster, more consistent help.

Attribution: Analysis based on Cybersecurity Dive and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News