FBI cyber leader details bureau’s first unclassified cyber strategy | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


The FBI released its first agency-wide, unclassified cyber strategy on Wednesday, with the goal of unifying efforts across the bureau’s 56 field offices to counter both nation-state threats and cyber criminals.

The 17-page strategy details a four-pillar approach to countering cyber threats across the bureau. Brett Leatherman, assistant director of the FBI’s Cyber Division, said previous cyber strategies for the bureau have either been classified or focused on specific threats, like countering China.

“This is a comprehensive strategy that directs our teams, our field offices, our global presence, and how we are to align all our efforts to counter this work,” Leatherman told reporters after speaking at the Billington Cybersecurity Summit in Washington on Wednesday morning.

“We know that cybercrime and nation-state hacking right now is continuing to increase in complexity, sophistication, tempo, and for us, it’s important that we prioritize how we approach this, because when you can’t handle every little thing that happens out there, you’ve got to prioritize what you do and how you do it as well,” Leatherman continued. “And it also signals to our adversaries, like I said on stage, how we intend to counter them more persistently in cyberspace operations through our joint sequenced operations as well.”

The pillars of the strategy are investigating, disrupting and imposing costs on cyber adversaries; supporting victims; increasing “impact” through partnerships; and enhancing the FBI’s own cyber capabilities.

Leatherman said FBI teams focused on specific threats and technical areas – such as China or operational technology – will develop “concrete lines of effort” based on the new cyber strategy.

“We’ll have strategies that don’t just align to threats, but important lines of effort where the FBI is positioned to have an impact,” he said.

The FBI strategy follows the release of the Trump administration’s national cyber strategy in March. It comes amid what the FBI document acknowledges is an “escalating” cyber threat to the United States. In early August, for instance, cyber attacks targeted, and in some cases disrupted, operational systems in water utilities across 12 states.

The FBI is focused on threats ranging from ransomware gangs and fraudsters to foreign military hacking units and intelligence services. In addition to the new strategy, Leatherman also announced an initiative called “Secure 2027” focused on working with other agencies and industry to strengthen the cyber defenses of critical infrastructure systems that could be targeted in advance of a potential Chinese invasion of Taiwan.

Leatherman said the success of the bureau’s cyber strategy won’t just be measured by traditional law enforcement metrics, like arrests and money recovered, but victim engagements as well. The strategy points to efforts to share more timely cyber threat intelligence, “quickly” engage with victims after incidents, and delivering “specialized capabilities” to victims.

“It’s important for us that even when we can’t take enforcement action, if we can give victims reprieve from some of these cyber attacks, we’ll do that as well,” Leatherman said. “So impact is measured through that. Part of that also is acting with urgency in how we engage victims.”

Private sector role

Leatherman also repeatedly emphasized how the FBI wants to more closely partner with private industry.

In recent years, he said the FBI has seen “a lot of hesitation” from organizations to provide information about cyber incidents that could support law enforcement operations.

“I don’t know exactly why that is,” Leatherman said. “I think in part it is bred by what I talked about a little bit on stage: uncertainty about the FBI’s value in cyber and coming to an organization and providing threat intelligence or tools. I think part of it is concern about the regulatory environment and what the FBI may or may not share with regulators.”

He added that the FBI “is trying to be very vocal” about its obligations to protect information provided by cyber incident victims. The strategy also says the FBI will provide more timely and actionable cyber threat intelligence to the private sector.

Meanwhile, the FBI also wants to get private industry more involved in operations to target cyber adversaries. Leatherman pointed to recent operations targeting adversary infrastructure that involved the FBI working with companies including CrowdStrike, Microsoft and Google, respectively.

“Wherever an organization has an opportunity to take action, and the FBI can move upstream against command and control infrastructure or online infrastructure, or seize cryptocurrency that actors are using to procure, or as a result of ransomware attacks,” Leatherman said. “When we do that together, we have outsized impact than if we just do it alone. Our strategy is really focused on moving beyond the ad hoc way that we do that right now, which is, ‘Hey, let’s hatch these good ideas and work together,’ to doing it more steady state.”

Last month, President Donald Trump signed a national security presidential memorandum that would allow the private sector to conduct offensive cyber operations against foreign cyber criminal organizations. The memo directs the Justice Department and the Department of Homeland Security to establish the program and oversee those operations, including by authorizing specific targets.

Leatherman said agencies are still in the “implementation” phase of building that program.

“But the FBI, DoJ, DHS, and others are crafting that strategy,” Leatherman said. “Our strategy is meant to close those gaps and to make industry an operational partner in this fight, as opposed to just somebody we share threat intelligence back and forth with. That’s still important, to share threat intelligence. Operational outcomes matter, though.”

Workforce, AI

The new cyber strategy also claims that the FBI will “compete for and retain the best cyber talent in the nation.”

The bureau plans to prioritize hiring, development and retention across key roles, including special agents, intelligence analysts, computer scientists, data scientists, malware analysts, cryptocurrency specialists, technical operations and field cyber leaders.

The FBI’s Cyber Division also plans to provide training, mentorship and professional development opportunities for both leaders and technical experts, according to the strategy. It mentions that the FBI’s Cyber Education and Training Unit will spearhead that work through classroom instruction, vendor training, technical certifications and hands-on scenarios.

Meanwhile, the strategy also highlights the need to implement “new technical tools and techniques” to investigate, attribute and disrupt cyber adversaries.

And with cyber adversaries using AI to improve their attacks, the strategy declares that the FBI will use “AI-enabled tools where they improve speed, scale, accuracy and operational decision-making under FBI authorities.”

The strategy mentions how AI tools can help “triage large datasets, surface relationships, accelerate malware analysis, prioritize victims’ notifications, map adversary infrastructure, support attribution, and identify patterns than no human analyst could process at the required pace.”

Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.



——————————————————-


Click Here For The Original Source.