Declassified: The FBI's New Cyber Strategy and What It Means for Companies
On September 9, 2026, the Federal Bureau of Investigation (FBI) released its first-ever unclassified Cyber Strategy, organized around four pillars: disrupting adversaries, supporting victims, strengthening partnerships, and building capabilities. In this Legal Update, we summarize the strategy’s key features and assess its implications for companies and their counsel.
Background
The FBI’s Cyber Strategy is the Bureau’s first unclassified strategy document dedicated to its cyber mission and expressly operationalizes President Donald Trump’s Cyber Strategy for America, released in March 2026. The strategy arrives alongside an August 2026 national security presidential memorandum authorizing vetted U.S. private-sector entities to conduct offensive cyber operations against foreign cybercriminal organizations.
The Four Pillars
Pillar 1: Under the first pillar, the FBI establishes that its cyber workforce is organized into Cyber Threat Teams with deep subject-matter expertise, and can deploy specialized personnel within hours of a significant incident. Bureau operations follow a “best athlete” model in which the partner with the strongest authority, access, or capability leads the relevant phase, synchronizing criminal and counterintelligence authorities across jurisdictions and working with partners to counter nation-state pre-positioning on US critical infrastructure and defend US elections from foreign cyber threats. The FBI frames its evidence and intelligence gathering as underpinning sanctions, diplomatic action, and partner law enforcement actions, and commits to attributing malicious cyber activity wherever possible.
Pillar 2: The second pillar pledges that the FBI will “pursue the actor, not the victim,” limit evidence collection to the crime using the least intrusive feasible method, and will implement automated threat intelligence and indicator-sharing mechanisms with critical infrastructure owners and trusted private-sector partners to compress the gap between FBI threat detection and partner notification. The Bureau also will proactively notify compromised or at-risk organizations, place ICS Coordinators in every field office, and use the Recovery Asset Team to help financial institutions freeze fraudulent transfers and recover funds. For major incidents, the Cyber Action Team can provide a specialized response drawn from across the FBI.
Pillar 3: Under the third pillar, the FBI will deepen partnerships across government, industry, and allied nations through the FBI-led National Cyber Investigative Joint Task Force (NCIJTF), which integrates more than 30 member agencies, and the Joint Ransomware Task Force, co-chaired with CISA. Private-sector engagement will continue through InfraGard, the National Cyber-Forensics and Training Alliance (NCFTA), and the National Defense Cyber Alliance (NDCA), while executive engagement will include the CISO Academy and Leadership in Cyber (LinCY) program. Cyber Assistant Legal Attachés (Cyber ALATs) stationed at US embassies will help build coalitions with allied cyber services.
Pillar 4: The fourth pillar addresses the workforce, tools, and technology the FBI needs to keep pace with modern cyber threats, including recruitment across specialist roles such as special agents, computer scientists, data scientists, malware analysts, and cryptocurrency specialists, and a Computer Network Operations (CNO) program for court-authorized remote collection, surveillance, and disruption tools when traditional investigative techniques are insufficient. The FBI also is preparing its evidentiary and tradecraft systems for the post-quantum cryptographic transition and deploying AI-enabled tools, including agentic AI subject to human review and legal controls.
Implications for Companies
Faster FBI Engagement and the “Pursue the Actor” Pledge
The strategy’s emphasis on incentivizing private-sector communication is most visible in its victim-engagement commitments. The strategy aspires to automated threat-intelligence sharing, compressing notification timelines, and urges building relationships before an incident so that FBI agents knows the right company contacts beforehand. Companies should consider designating an FBI point of contact and establishing a decision framework for early engagement following an incident. The “pursue the actor, not the victim” posture, including collection scoped strictly to the crime and use of the least intrusive feasible method, is designed to address concerns about involving law enforcement and exposing a company to broader scrutiny.
Government Joint Operations Meet Private-Sector Offensive Cyber Actions
The strategy reframes disruption as a joint enterprise rather than a solely government-led effort. While the FBI’s own operations will continue to dismantle adversary infrastructure, seize stolen cryptocurrency through the Virtual Assets Unit, and take down ransomware variants, the August 2026 presidential memorandum extends the disruption mission to the private sector for the first time—establishing a framework that would authorize US companies to conduct vetted offensive cyber operations against foreign cybercriminal organizations under DOJ and DHS supervision. Read together, the strategy and the memorandum envision a coordinated disruption pipeline in which government and industry act in sequence, but the legal architecture for that coordination is still being built.
AI Adoption and Incident Data
The strategy commits the FBI to use AI-enabled tools to triage datasets, accelerate malware analysis, prioritize victim notifications, map adversary infrastructure, and support attribution, while rapidly adopting agentic AI where appropriate. It states that this work will remain subject to human review, legal controls, and safeguards for civil liberties, accuracy, and operational security. Companies should consider that incident data shared with, or collected by, the FBI may be processed through evolving AI systems, and factor that possibility into privilege and data-protection assessments.
Key Takeaways
The FBI’s first unclassified Cyber Strategy marks a significant step toward institutionalizing public-private cyber collaboration, and memorializes the FBI’s oft-stated commitment to avoid revictimizing victims. Companies and their incident responders may find passages of the strategy helpful in deciding when and if to report an incident to the FBI and might point to the aspirations of the strategy if there are circumstances where the engagement is less than satisfactory. This is also a good opportunity to revisit their incident-response frameworks, information-sharing practices, and points of contact with law enforcement, to ensure they are current.


