The bureau wants more frequent disruption operations and quicker warnings to victims as the Justice Department works through rules for expanded private sector participation in hacking cybercrime groups.
The FBI is seeking more frequent operations against hackers and a larger role for private companies under a new cyber strategy released Wednesday, with the bureau’s cyber chief saying teams are aiming to act more quickly to disrupt attacks and warn victims.
The strategy directs the bureau’s 56 field offices and overseas cyber personnel to coordinate investigations, help compromised organizations and expand partnerships with government agencies, foreign authorities and industry. It also calls for wider use of artificial intelligence tools that could cut the time needed to alert organizations about threats.
FBI cyber chief Brett Leatherman told reporters at the Billington Cybersecurity Summit that the bureau wants to move more regularly against hackers, including by helping partners act when the FBI is not entirely positioned to do so itself.
“If we can’t take action right now, let’s not wait six months till we’re positioned to take action,” he said, pointing to Cyber Command and authorities in Britain and Japan as potential partners.
Leatherman described the document as the FBI’s first comprehensive public cyber strategy covering both criminal and national security threats. Previous plans, he said, were classified or developed within teams responsible for specific threats.
The public strategy is unclassified and also has no classified annex, Leatherman said. Individual teams focused on specific foreign adversaries and cybercriminal threats are developing more detailed classified strategies to guide field office operations, he added.
The strategy comes as the Trump administration develops a program allowing vetted U.S. companies to conduct cyber operations against foreign criminal organizations under federal supervision.
A presidential memorandum issued last month directed the departments of Justice and Homeland Security to establish operating procedures and standards for participating companies. Implementation guidance for the initiative remains under development.
Nation-state groups are off the table as part of the new program. Asked about the risk of accidentally targeting entities connected to foreign governments, Leatherman said federal agencies would retain control and apply the same testing and scrutiny used in existing operations.
“I think the American public should understand that with DOJ, FBI [and] DHS oversight, that won’t change where industry gets involved,” he said. “This is not a situation where industry is going to pick targets and go after targets themselves.”
The strategy also puts greater emphasis on transmitting intelligence to victims more quickly, an approach Leatherman said has required a notable cultural change within the bureau.
But he also noted some companies have grown more reluctant to involve the FBI after a breach. He suggested that hesitation may stem from uncertainty about what help the bureau can provide and concerns about information reaching regulators.
“It worries me when an organization is breached by a nation-state actor and believes that bringing law enforcement in might be more risky than handling it on their own,” he said.
AI is another component of the plan. The strategy calls for tools to accelerate malware analysis, map hackers’ infrastructure, identify relationships in large datasets and prioritize victim notifications. The document says the work will remain subject to human review and legal controls.
Leatherman said the FBI is coordinating with CISA, NSA, Cyber Command and CIA as those agencies develop their own strategies to carry out the White House’s national cyber framework. Some of those plans may never become public, he said. He also pointed to the Pentagon’s forthcoming cyber strategy, which may be released sometime this week.
