New FBI cyber strategy promises increase in adversary disruptions | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


WASHINGTON — The FBI on Wednesday said it intends to formalize and speed up its collaborative takedowns of malicious hacking activity.

The bureau’s new four-part strategy describes how it will investigate, attribute and disrupt cyberattacks; quickly engage with victims and share useful information; partner with other agencies and the private sector; and enhance its own capabilities through recruitment, training and new tools.

“Our strategy is really focused on moving beyond the ad-hoc way that we do [disruptions] right now … to do it in a more steady state,” Brett Leatherman, the assistant director of the FBI’s Cyber Division, said during a talk here at the Billington Cybersecurity Summit.

The FBI has already significantly increased the number of disruption operations it has led and participated in over the past few years. Recent high-profile takedowns have targeted a Russian military intelligence agency’s router botnet, domains that the Chinese government used to target U.S. critical infrastructure and the AlphV ransomware gang. But the bureau’s new strategy reflects government officials’ fear that even this increased tempo has not been enough.

The cyber threat environment “is becoming untenable for any one organization to defend alone, and we have to bring consistency in how we approach it,” Leatherman said. “Every day, we’re having to send teams out across the [FBI’s] 56 field offices to help victims who are continually under attack.”

As part of the new strategy, FBI teams focused on countering specific threats, from Russia to China to cybercriminals, will develop their own customized plans. Teams focused on specific kinds of operations, including offensive hacking and investigating operational technology breaches, will also develop tailored strategies.

Reassuring reluctant companies

One of the cyber strategy’s goals is to convince companies that they should report hacks to the FBI because it cares about helping them and won’t share their reports with regulators.

“We have [seen] a lot of hesitation recently from organizations to quickly provide information that would support law enforcement operations,” Leatherman told reporters after his talk.

The FBI has seen a reduction in companies’ willingness to share information over the past few years, a continuation of a long-running trend. “I don’t know exactly why that is,” Leatherman said. He attributed it partly to “uncertainty about the FBI’s value in cyber” and partly to “concern about the regulatory environment and what the FBI may or may not share with regulators.”

The bureau is trying hard to address companies’ concerns, including through summits with law firms that specialize in advising companies on incident response.

“It worries me,” Leatherman said of companies’ reluctance to engage with the FBI. “It worries me when an organization is breached by a nation-state actor and believes that bringing law enforcement in might be more risky than handling it on their own. That should worry all of us.”

No company, he argued, is better positioned to evict Chinese government hackers from their networks on their own than they would be with the FBI’s help.

“We see things through our cyber authorities that no incident response company sees,” Leatherman said during his Billington talk. “If you reach out to us early, we can bring threat intelligence tools and capabilities to bear that you can’t get elsewhere.”

Leatherman urged executives to meet with their lawyers now to increase their comfort with engaging the FBI. “Too often, I see weeks move by where outside counsel is the gatekeeper of information going to the FBI,” he said. “Discussions happen on breached networks, and as a result of that, actors [have a] leg up and they can move in and entrench themselves even harder.”

Collaboration also benefits the broader ecosystem, he noted. “Victims reporting early and providing information early allows us to move upstream against actors that are quickly moving across infrastructure in the U.S., Europe and beyond.”

In the past, the FBI has been reluctant to share significant information with organizations that could help them protect themselves, for fear of jeopardizing its sensitive investigations. That has changed in recent years, Leatherman told reporters.

“We have changed significantly our perspective on sharing quickly and more often than maybe what we did in years past, where we would preserve it for operational opportunities,” he said.

——————————————————-


Click Here For The Original Source.