The US Federal Bureau of Investigation (FBI) has published its first-ever cyber strategy document, signalling a new era of public-private cooperation, AI-assisted law enforcement, and expanded authority to pursue both state-sponsored hackers and financially motivated cybercriminals.
What does the FBI's new cyber strategy say about public-private cooperation?
The strategy places private sector partnership at its center. Field offices in every region of the country will forge direct relationships with industry partners before a crisis occurs, rather than scrambling to establish contact in the middle of an incident.
"Field offices in every region of the country will forge direct relationships with industry partners, ensuring open channels of communication and trusted points of contact before crisis hits. A steady two-way exchange of information between the FBI and the private sector is essential to detecting adversary activity earlier, notifying victims faster, and disrupting infrastructure before campaigns can escalate," the strategy document states.
For cybersecurity professionals, the strategy represents a significant structural shift. The FBI is committing to build systems and processes to quickly share actionable intelligence — not just receive it — creating genuine two-way information flows rather than one-directional reporting obligations.
How will the FBI help organizations respond to cyberattacks?
The strategy details a range of methods the FBI intends to use to help victims contain and recover from cyber incidents. The agency has pledged to engage victims rapidly when incidents occur, with particular emphasis on critical infrastructure.
To deliver on that commitment, the FBI is expanding its Industrial Control Systems (ICS) Coordinator program to designate dedicated personnel in every field office. The move acknowledges that attacks on operational technology — power grids, water systems, manufacturing plants — carry consequences that extend well beyond data loss and demand specialist response capacity.
How is the FBI using AI to fight cybercrime?
Aware that adversaries are rapidly deploying artificial intelligence to accelerate and scale attacks, the FBI has committed to matching that capability. The strategy outlines a clear mandate for AI adoption across investigative operations.
"The FBI will use AI-enabled tools where they improve speed, scale, accuracy and operational decision-making… FBI will deploy AI-enabled tools to triage large datasets, surface relationships, accelerate malware analysis, prioritize victim negotiations, map adversary infrastructure, support attribution, and identify patterns that no human analysts could process at the required pace," the document states.
The applications listed span the full incident lifecycle — from early detection and threat attribution through to victim support and infrastructure disruption. The FBI's willingness to name specific operational use cases signals that this is an implementation roadmap rather than a high-level aspiration.
What authority does the FBI have to conduct offensive cyber operations?
The strategy follows President Trump's August 2026 memorandum authorizing federal law enforcement agencies to collaborate with private firms in conducting offensive cyber strikes against foreign threat actors targeting the United States. The FBI has extended this remit to encompass international gangs of financially motivated cybercriminals, not just state-sponsored actors.
That extension reflects a deliberate policy judgement: the line between criminal and state-sponsored activity has become sufficiently blurred that treating them as distinct categories is no longer operationally coherent. Nation states are known to use criminal infrastructure to conduct attacks while maintaining a degree of deniability — and to use the proceeds of cybercrime to fund strategic goals.
How does cybercrime fund state adversaries?
North Korea is the clearest documented case: the regime is assessed to have used cybercrime proceeds to fund its ballistic missile program, effectively weaponizing criminal hacking as a form of sanctions evasion. Other potentially hostile states have similarly enabled criminal gangs to attack Western critical infrastructure and financial systems, gaining a plausibly deniable offensive capability in return.
By bringing financially motivated international cybercrime within the same strategic framework as state-sponsored threats, the FBI is signalling that it intends to pursue both tracks with the same tools and the same urgency — including, where authorized, offensive measures.
What does the FBI cyber strategy mean for businesses?
The strategy creates concrete opportunities for companies across all sectors. Organizations that establish relationships with their regional FBI field office before an incident occurs will be better positioned to receive early threat warnings, access specialist ICS support, and benefit from the FBI's intelligence sharing infrastructure. The commitment to faster victim notification is particularly significant for security operations teams, who often learn of FBI-held intelligence about their own networks too late to act on it.
For critical infrastructure operators in particular, the expansion of the ICS Coordinator program means dedicated federal contacts are now available in every region — an operational resource worth engaging proactively rather than waiting for a crisis to trigger the introduction.


