The FBI on Wednesday released its first-ever public cybersecurity strategy that details how the agency will combat malicious hackers and digital criminal gangs.
“This is a comprehensive strategy that directs our teams, our field offices, our global presence, and how we are to align all our efforts to counter this work,” Brett Leatherman, assistant director of the FBI’s Cyber Division, told reporters during a roundtable discussion at the Billington Cybersecurity Summit in Washington, D.C.
“We know that cybercrime and nation-state hacking right now is continuing to increase in complexity, sophistication and tempo,” he added. “For us, it’s important that we prioritize how we approach this because when you can’t handle every little thing that happens out there, you’ve got to prioritize what you do and how you do it as well.”
The bureau has had similar strategies in place before, however they have either been classified or largely handled by specific threat units. The 17-page document, which has no classified annex, comes after the FBI has conducted 50 so-called “sequenced operations” since the start of 2025, including high-profile efforts to drive Russian military intelligence services from vulnerable U.S. home routers and a joint endeavor with Microsoft to take down the infrastructure of the Lumma malware.
Leatherman said the document builds on the Trump administration’s cybersecurity strategy, the recent executive order on countering digital criminals and fraud and the memorandum issued last month that will allow for private industry to participate in disruptive online operations.
‘Pillars’ for cyber ops
The inaugural document details four “pillars” for how the bureau will operate under its criminal and national security cyber authorities, from imposing costs on adversaries and victim support to working with industry and boosting the FBI’s own digital capabilities.
Leatherman said the overarching plan would spur the Cyber Division’s threat teams — devoted to countering China, Russia, criminal gangs and more — to develop their own classified strategies that will eventually be welded together. However, there is no implementation plan yet.
“We’re working on that portion next, but there’s no time limit by which to do it,” he told reporters. “Many of the teams already have strategies in place that they will adjust to to conform to this strategy.”
He said the Cyber Division would use the same metrics as the rest of the law enforcement agency to determine its success, such as how many people are arrested, how much money is recovered and how many victims are engaged.
“The most important change I hope people will see is that we don’t sit and wait for the best opportunity to take action,” according to Leatherman. “As opposed to waiting for large joint sequenced operations that happen half a dozen times a year, you’re going to start to see many more of those of consequence because we are engaged in that urgent steady state opportunity to disrupt adversaries.”
The increased tempo, coupled with the bureau’s recent actions, will “hopefully” lead to a reduction in digital threats, he said.
“We’re not under the illusion that we’ll ever negate the cyber threat directive in the United States, but our goal is to change behavior, and I believe we’re doing that,” Leatherman said, pointing to dips in ransomware payments and what he described as behavior changes by companies that support nation-state hacking regimes.
“I believe that we’re having an impact. I believe that signaling what we’re what we’re doing here over the last six months and will continue to do here in the next six to 12 months, I believe will have a determined impact. Americans will see a positive change to the result of that.”
Click Here For The Original Source.
