FBI Maps Out Its Cyber Playbook
The FBI's first Cyber Strategy outlines four pillars for disrupting threat actors, from imposing costs to expanding victim support.
The FBI has long been the agency that shows up after a breach, arrests a suspect years later, and calls it a win. Its first-ever Cyber Strategy, published on September 9, tries to change that math. Instead of chasing prosecutions that may never arrive, the document lays out a plan to impose costs on attackers before they finish the job.
The strategy lands as financially-motivated criminals and state-sponsored operators keep hitting US targets from jurisdictions that place them out of immediate reach of American law enforcement. The bureau's answer is a four-pillar framework that leans hard on disruption, victim support, partnerships, and internal capability building.
Disruption Over Prosecution
The shift in emphasis is the strategy's most striking feature. Success in cybercrime enforcement has traditionally been measured by arrests, often years after the fact and sometimes never. The FBI's new document treats operational wins — taking infrastructure offline, seizing money, burning access, exposing tradecraft — as legitimate outcomes in their own right.
Gabrielle Hempel, security operations strategist at Exabeam, described the change as a meaningful broadening of what counts as a takedown.
“The emphasis on disruption over prosecution is an interesting shift. ‘Success’ in cybercrime enforcement has long been measured often by arrests that happen years later, if at all. Taking infrastructure offline, seizing money, burning access, exposing tradecraft, and forcing adversaries to rebuild can be operational wins. I like that the FBI is broadening what a successful takedown looks like.”
— Gabrielle Hempel, security operations strategist at Exabeam
The strategy's own language echoes that intent, framing disruption as a standing objective rather than a fallback when prosecution stalls.
“With this strategy as our roadmap, the FBI will impose cost on cyber actors who target the United States through decisive action, rapid victim support, integrated partnerships and continuous investment in tools and capabilities. FBI Cyber will disrupt adversaries before they can act, expose them when they do and hold them accountable wherever they hide,” the FBI wrote.
Inside the Four Pillars
The Cyber Strategy organizes the bureau's cyber work into four pillars, each covering a distinct slice of the mission. The first — investigate, disrupt, and impose cost on cyber adversaries — describes how the FBI's various cyber threat teams coordinate. It starts with identifying threats and alerting victims whose networks have been compromised, then moves into operations meant to dismantle adversary infrastructure, seize stolen cryptocurrency, disrupt nation-state intrusion campaigns, and take down pervasive ransomware variants.
To decide who leads each phase, the FBI said it uses a “best athlete” model — picking whichever partner has the strongest authority, access, or capability for that stage of an operation, rather than defaulting to a fixed chain of command.
The second pillar focuses on supporting victims, a function the strategy treats as both a recovery service and an intelligence loop. The FBI described rapid sharing of threat intelligence with organizations under attack, and said it aims to automate indicator-sharing to speed that exchange. The goal is to engage victims quickly during incidents and help them contain and recover — a priority the document ties especially to critical infrastructure.
As part of that effort, the agency is expanding its Industrial Control Systems (ICS) Coordinator program to designate dedicated personnel in every field office.
Partnerships as Force Multiplier
The third pillar commits the FBI to deepening relationships across government, international allies, and the private sector. The strategy calls for building systems and processes that let these partners share actionable intelligence quickly, rather than routing everything through slow formal channels.
On the private-sector side, the FBI named three programs it intends to expand: the CISO Academy, Cyber Executive Summits, and The Leadership in Cyber (LinCY) program. Each is aimed at pulling security leaders closer to the bureau's operational work.
The partnership pillar follows a broader move by the US government toward proactive disruption of cyber threat actors. In August, President Trump signed a memorandum authorizing federal law enforcement agencies to collaborate with private firms in conducting offensive cyber strikes on foreign threat actors targeting the US.
Building the Cyber Workforce
The fourth pillar addresses the FBI's own capabilities — recruiting and retaining cyber talent and adopting new technical tools, including AI. The agency said it will deliver technical and operational training across its cyber workforce through its Cyber Education and Training Unit (CETU).
On the technology side, the FBI committed to deploying AI-enabled tools for a set of specific tasks: triaging large datasets, accelerating malware analysis, prioritizing victim notifications, mapping adversary infrastructure, and supporting attribution. Each of those jobs traditionally consumes significant analyst time, and the strategy frames automation as a way to keep pace with the volume of incidents the bureau handles.
Where the Strategy Lands
Taken together, the four pillars describe an agency trying to compress the distance between detecting an intrusion and degrading the intruder. The first pillar handles the offensive side. The second tries to turn victim engagements into faster intelligence sharing. The third extends the bureau's reach through allies and industry. The fourth invests in the people and tools needed to sustain all of it.
The document is also explicit about the adversaries it has in mind: financially-motivated cybercriminals and state-sponsored actors who frequently operate from jurisdictions that put them beyond the immediate reach of US law enforcement. That geographic constraint is the reason the strategy leans so heavily on disruption — if you can't arrest someone, the logic goes, you can still make their operations expensive to rebuild.
For readers tracking how the US government's cyber posture is changing, the strategy is worth reading in full. It runs as a document published by the bureau, and it sets expectations for how the FBI says it will prioritize its cyber resources going forward.
Sources
- Infosecurity Magazine Original source
- document Also reporting
- signed a memorandum Also reporting
Continue Reading
Android password switch adds passkey support
Google's new Android feature moves passwords and passkeys between manager apps without CSV files, starting with three partners.
AI Workflows Bypass Identity Checks
Noma Labs research describes an authorization design flaw that lets unauthenticated input trigger privileged AI workflow actions.
LiteLLM's Default Admin Key Exposed
A Wiz Research scan found 294 exposed LiteLLM gateways accepted the example admin key sk-1234, granting access to stored provider credentials.