On September 9, the Federal Bureau of Investigation (FBI) released its Cyber Strategy, outlining its approach to defending the homeland in cyberspace and imposing costs on cyber adversaries. With the strategy—the FBI’s first public cyber strategy—the FBI Cyber Division intends to operationalize President Trump’s Cyber Strategy for America

In the strategy, the FBI intends to counter the evolving and escalating cyber threat through objectives organized into four pillars: (1) investigate, disrupt, and impose cost on cyber adversaries; (2) support victims; (3) increase impact through partnerships; and (4) enhance the FBI’s cyber capabilities. Rather than a narrow focus on individual incidents, the strategy indicates a shift by FBI Cyber toward proactive disruption of the broader ecosystem that enables malicious cyber activity, with significant emphasis on operational partnership with the private sector. 

In terms of next steps, the FBI Cyber Division is working on an implementation strategy: teams focused on specific cyber threats will develop their own strategies defining specific lines of effort within each pillar:

Pillar I

The first pillar, Investigate, Disrupt, and Impose Costs on Cyber Adversaries, outlines the FBI’s effort to disrupt and impose costs on cyber adversaries targeting the United States. This begins with investigations and analysis to identify adversarial infrastructure and techniques, followed by operations to disrupt. 

  • Investigate Cyber Intrusions: Objective 1.1 notes the FBI’s work with the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and international partners to disrupt pre-positioning campaigns on critical infrastructure, FBI’s investigation and disruption of foreign actors targeting election infrastructure, and FBI’s investigation of cyber-enabled theft of American innovation. 
  • Prioritize Joint, Sequenced Operations: The strategy describes that “the FBI will use the full range of its authorities and support cost imposition across every instrument of national power.” FBI Cyber will monitor shifts in adversary operations and intent, disrupt their operations, and bring offenders to justice. To achieve maximum impact, Objective 1.2 states that FBI Cyber will continue to execute joint, sequenced operations at speed and scale to accomplish a range of objectives, including dismantling adversaries’ infrastructure, seizing stolen funds, and disrupting intrusion and ransomware campaigns.
  • Attribute Malicious Cyber Activity: Objective 1.3 states the FBI will continue to strengthen its ability to attribute malicious cyber activity with confidence. This includes continuing to integrate the spectrum of knowledge, including private-sector telemetry, Intelligence Community and foreign partner intelligence, and victim reporting. 

Pillar II

The second pillar, Support Victims, defines objectives related to FBI Cyber’s pledge to victims: to “always treat victims with dignity and respect, protect their privacy and data, and rigorously adhere to the U.S. Constitution; applicable laws, regulations, and policies; and the FBI’s Core Values.”

  • Share Cyber Threat Intelligence with Urgency: Objective 2.1 is to pursue capabilities to enable urgent, automated sharing of cyber threat intel with critical infrastructure and trusted private-sector partners, in an effort to significantly shorten the time between FBI threat detection and partner notification. 
  • Quickly Engage After Incidents: With Objective 2.2, the FBI will engage directly with victims to help them defend, contain, and recover. Under this objective, the strategy notes continued proactive notification of known or imminent compromises. 
  • Deliver Specialized Capabilities to Victims: Under Objective 2.3, FBI Cyber describes specialized support for victims in particularly demanding incident response, including the Recovery Asset Team and the Cyber Action Team. To strengthen support for critical infrastructure, FBI Cyber will expand its Industrial Control Systems (ICS) Coordinator program and designate coordinators in each field office to build OT expertise to support victim engagement in those environments.  
  • Facilitate Reporting of Cyber Incidents: Objective 2.4 will enable early reporting, particularly through the Internet Crime Complaint Center (IC3). IC3’s tools and technology will be enhanced, and field offices will prioritize developing direct relationships with local organizations. 

Pillar III


In the third pillar, Increase Impact Through Partnerships, FBI Cyber acknowledges the necessity of working with a range of stakeholders on cyber investigations, including the private sector, stakeholders across government, and international allies. The strategy notes that private industry is an operational partner in this fight, that “behind the FBI’s most significant cyber operations are industry partners whose intelligence, technical expertise, or operational coordination made the outcome possible.”

  • Share Actionable Intelligence: With Objective 3.1, the FBI describes turning intelligence into action by disseminating timely intelligence crafted to enable joint action, direct resources where they are most urgent, and provide partners with insight into the threat. Specifically, the FBI will deliver clear, authoritative intelligence to the National Security Council (NSC), the Office of the National Cyber Director (ONCD), and other policymakers, and threat information to network defenders via Joint Cybersecurity Advisories. 
  • Strategically Partner Across U.S. Government and with Allies: Objective 3.2 describes close coordination with government  partners, including with ONCD and NSC, through the National Cyber Investigative Joint Task Force (NCIJTF) and the Joint Ransomware Task Force, and alongside state, local, tribal, and territorial partners via FBI field offices. Objective 3.2 also notes international engagement through the Five Eyes, Cyber 9, Europol, and bilateral cooperation. The FBI will continue to strategically station and support Cyber Assistant Law Enforcement Attachés internationally to maintain global reach. 
  • Join Forces with the Private Sector: Under Objective 3.3, field offices across the country will directly engage with industry partners to ensure trusted points of contact and two-way information exchange, which the strategy notes “is essential to detecting adversary activity earlier, notifying victims faster, and disrupting infrastructure before campaigns can scale.” FBI Cyber will continue to strengthen private-sector partnerships through existing programs such as InfraGard, the National Cyber-Forensics and Training Alliance (NCFTA), and the National Defense Cyber Alliance (NDCA). FBI Cyber will also increase engagement with industry executives via three convenings: the CISO Academy at the FBI headquarters, Cyber Executive Summits at regional field offices, and the Leadership in Cyber (LinCY) program focused on coordinated action during major incidents. 

Pillar IV

The final pillar, Enhance the FBI’s Cyber Capabilities, asserts a commitment to developing the cyber workforce and equipping its talent with necessary training and technical tools to combat the cyber threat. 

  • Recruit and Retain Top Cyber Talent: Objective 4.1 prioritizes the hiring, development, and retention of a range of FBI Cyber roles, including “special agents, intelligence analysts, computer scientists, data scientists, malware analysts, cryptocurrency specialists, technical operators, and field cyber leaders.” FBI Cyber will partner with academia, industry, and other government organizations on this effort. 
  • Develop Our Cyber Expertise: In Objective 4.2, the strategy promotes training, mentorship, and professional development efforts to strengthen cybersecurity expertise. 
  • Implement New Technical Tools and Techniques: Objective 4.3 outlines a continuous effort to improve the FBI’s technical capabilities by adopting, developing, and acquiring new hardware, software, and analytical platforms. FBI will further develop its Computer Network Operations (CNO) program, which provides investigators lawfully authorized enhanced threat detection and hunting tools to remotely conduct surveillance and disrupt cyber threat actors’ operations. Objective 4.3 also points to the FBI's preparation for the post-quantum cryptographic transition.
  • Adopt Artificial Intelligence to Scale Operations: Finally, noting cyber adversaries’ use of AI, Objective 4.4 asserts that the FBI will use AI-enabled tools to scale operational decision-making to impose costs on adversaries. The strategy says that the FBI will incorporate appropriate civil liberty, accuracy, and operational security safeguards. 

According to the Strategy, wherever achievable, FBI Cyber executes legal action (i.e. arrests, prosecutions, and extraditions), but these actors typically operate in permissive jurisdictions that often limit the FBI’s available actions and reach. As a result, the FBI “measures success against a broader set of outcomes that reduce harm and bring relief to victims,” such as dismantling tools and infrastructure and seizing funds to impose consequences.

Read Next

Event Recap: LATAM CISO Summit 2026 Brings Together Cybersecurity Leaders from Across the Americas

The 2026 Summit demonstrated both the scale of the cybersecurity challenges facing the Americas and the growing willingness of leaders across the region to address them collaboratively.

A Practical Cybersecurity Roadmap for Nations’ Cybersecurity Strategies in the Age of Frontier AI

The new playbook is intended to provide governments with a practical framework for making those choices—starting with national risk, strengthening foundational capabilities, identifying targeted opportunities for AI, and scaling investment.

Expanding Cyber Capabilities Against Transnational Crime

Key details of a new presidential memorandum authorizing companies to conduct cyber operations against transnational criminal organizations remain to be developed.