\n\n

On September 9, 2026, the U.S. Federal Bureau of Investigation (“FBI”) announced the publication of the FBI Cyber Strategy (the “Strategy”).  The Strategy, which “provides a roadmap for defending the American people and the nation’s critical infrastructure in cyberspace,” is broken into four pillars:

  1. Investigate, Disrupt, and Impose Cost on Cyber Adversaries;
  2. Support Victims;
  3. Increase Impact Through Partnerships; and
  4. Enhance FBI’s Cyber Capabilities.

The Strategy may be of interest to organizations as they develop and assess their own threat monitoring and incident response programs, particularly because of the Strategy’s emphasis on the FBI’s continued cooperation and information sharing with the private sector.  For purposes of this blog post, we have focused on the first three pillars, as the fourth pillar primarily focuses on the FBI’s internal capabilities.

Investigate, Disrupt, and Impose Cost on Cyber Adversaries

Although this pillar outlines three separate objectives focused primarily on efforts by the FBI to investigate and take action against threat actors, it also underscores the important role the private sector can play in supporting FBI operations to counter cyber threats.  The Strategy emphasizes that “[v]ictim reporting and the technical evidence that comes with it are essential” to the FBI’s efforts to investigate cyber intrusions and “fuel both individual investigations and the development of disruption operations that extend well beyond any single case.”  The Strategy notes that the FBI’s attribution of threat actors often leverages, among other things, “private-sector telemetry” and “victim reporting.”

Support Victims

This pillar expressly prioritizes supporting and working collaboratively with victims of cybercrime, including by pursuing the following four objectives:

  1. Share Cyber Threat Intelligence with Urgency: The Strategy notes that the FBI “will pursue capabilities that enable urgent, automated sharing of cyber threat intelligence with critical infrastructure owners and trusted private-sector partners.”  Specifically, the FBI will develop “automated indicator-sharing mechanisms that narrow the gap from FBI threat detection to partner notification from days to hours, and from hours to minutes” with the goal of “build[ing] the closer public-private partnership the threat demands, giving victims and trusted partners information they can use to defend systems, contain intrusions, and recover operations.”
  2. Quickly Engage After Incidents: The Strategy emphasizes that the FBI will engage victims with “urgency and operational rigor” and that the FBI “pursues the threat actor, not the victim.”  The Strategy states that the FBI “will notify victims and targeted entities directly and provide intelligence and support to help them defend, contain, and recover” when the FBI identifies that a device, network, or account is being targeted by threat actors.  The Strategy also emphasizes that the FBI will “continue to identify and proactively notify organizations that have been compromised or are at imminent risk,” and continue to invest in establishing relationships before an incident occurs.
  3. Deliver Specialized Capabilities to Victims: The Strategy notes that the FBI will continue to build specialized teams and programs to support victims.  The Strategy identifies various FBI capabilities, including the Industrial Control Systems (“ICS”) Coordinator program, which is designed to build operational technology expertise and support operators of critical infrastructure; the Recovery Asset Team, which works directly with financial institutions to freeze fraudulent transfers; and the Cyber Action Team, which leverages specialized personnel “to respond to major cyber threats and attacks against critical services.”
  4. Facilitate Reporting of Cyber Incidents: The Strategy notes that “[e]arly reporting gives the FBI the evidence, indicators, and financial details needed to advance investigations, notify other victims, and move against the actors responsible.”  To facilitate incident reporting, “all FBI field offices will prioritize building direct relationships with local businesses and organizations to ensure open channels for swift reporting of cyber incidents.”

Increase Impact Through Partnerships

This pillar emphasizes that the FBI is committed to expanding and deepening its relationships with partners, including but not limited to partners across the private sector.  This is further emphasized by the third objective in this pillar, “join[ing] forces with the private sector,” which notes that “[a] steady, two-way exchange of information between the FBI and the private sector is essential to disrupting adversary activity earlier, notifying victims faster, and disrupting infrastructure before campaigns can scale.”  Under this objective, the Strategy re-emphasizes its commitment to “forge direct relationships with industry partners,” including establishing “open channels of communication” and “trusted points of contact before a crisis hits.”

The Strategy further emphasizes that the FBI will seek to strengthen its existing engagement with the private sector through established programs and the expansion of its executive engagement channels.  Specifically, the Strategy cites three established programs (InfraGard, the National Cyber-Forensics and Training Alliance, and the National Defense Cyber Alliance) and three executive engagement channels (CISO Academy, Cyber Executive Summits, and the Leadership in Cyber program).

Conclusion

The FBI Cyber Strategy demonstrates the U.S. government’s continued focus on public-private collaboration to counter cyber and cyber-enabled threats, which was a key theme of the current Administration’s National Cyber Strategy and the National Security Presidential Memorandum on Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.  Private organizations should expect continued government engagement on countering cyber threats, and should consider both the potential benefits and risks associated with such engagement.