The FBI released its first ever Cyber Strategy on September 9, marking a shift toward proactive disruption of cyber threat actors rather than waiting to prosecute them after attacks occur. The new document addresses the mounting challenge posed by financially motivated cybercriminals and state-sponsored hackers who frequently work from countries where US law enforcement can't easily reach them. The strategy establishes a roadmap for the agency to impose consequences on adversaries targeting American networks through what it calls decisive action, rapid victim assistance, integrated partnerships, and ongoing investment in tools and capabilities.
The FBI's approach rests on four pillars: investigating, disrupting, and imposing costs on cyber adversaries; supporting victims; increasing impact through partnerships; and enhancing the agency's cyber capabilities. Under the first pillar, the bureau uses a "best athlete" model to partner with whichever authority, access, or capability is strongest for each phase of an operation. Operations include dismantling adversary infrastructure, seizing stolen cryptocurrency, disrupting nation-state intrusion campaigns, and taking down pervasive ransomware variants. The victim support pillar involves rapid sharing of threat intelligence with targeted organizations through automated indicator-sharing mechanisms, with quick engagement when cyber incidents happen to support containment and recovery. The agency is expanding its Industrial Control Systems Coordinator program to assign dedicated personnel in every field office, recognizing the particular importance of protecting critical infrastructure.
The partnership pillar commits the FBI to broadening relationships across government, with international allies, and throughout the private sector, building systems to quickly share actionable intelligence. The agency plans to expand private sector engagement through three programs: CISO Academy, Cyber Executive Summits, and The Leadership in Cyber (LinCY) program. On capabilities, the bureau will recruit and retain top cyber talent while deploying AI-enabled tools to support activities such as triaging large datasets, accelerating malware analysis, prioritizing victim notifications, mapping adversary infrastructure, and supporting attribution. The Cyber Education and Training Unit will provide technical and operational training across the FBI's cyber workforce. "With this strategy as our roadmap, the FBI will impose cost on cyber actors who target the United States through decisive action, rapid victim support, integrated partnerships and continuous investment in tools and capabilities," the agency wrote, adding that FBI Cyber will disrupt adversaries before they can act, expose them when they do, and hold them accountable wherever they hide.
The strategy represents what security operations strategist Gabrielle Hempel of Exabeam called "an interesting shift" away from measuring success primarily through arrests that may happen years later, if at all. Taking infrastructure offline, seizing money, burning access, exposing tradecraft, and forcing adversaries to rebuild can be operational wins even without prosecutions, Hempel noted. The document arrives as part of a broader pivot in US government strategy toward proactive disruption activities against cyber threat actors. In August, President Trump signed a memorandum authorizing federal law enforcement agencies to collaborate with private firms in conducting offensive cyber strikes on foreign threat actors targeting the US. The FBI's emphasis on disruption before attacks occur, combined with automated intelligence sharing and expanded field office capabilities for critical infrastructure protection, signals the agency expects to operate more aggressively in adversary spaces rather than waiting for incidents to reach American soil. For organizations facing persistent threats from actors beyond traditional law enforcement reach, the strategy offers a clearer picture of how the bureau plans to create friction and impose costs on attackers through infrastructure seizures and operational disruption rather than relying solely on arrests and indictments that may never materialize. This recalibration acknowledges that deterrence in cyberspace may require different metrics than conventional crime, where prosecution has historically served as the primary accountability mechanism.

