- The FBI Cyber Division has unveiled a new strategic roadmap
- The strategy spans four pillars addressing adversaries, victims, partnerships and capabilities
- FBI National Security Branch Operations Director Matt Fodor will keynote the 2026 Intel Summit

As cyberthreats against government and industry networks continue to evolve, intelligence professionals are placing growing emphasis on how emerging technologies reshape both offense and defense. The Potomac Officers Club’s 2026 Intel Summit on Sept. 24 will explore these developments. The event will feature a keynote address from Matthew Fodor, operations director for the FBI’s National Security Branch, along with panel discussions on AI’s role in elevating intelligence operations, OSINT, agentic AI and quantum risk, cybersecurity in the agentic AI era, and more. Save your spot now!
What Are the Strategy’s 4 Pillars?
- Investigate, disrupt and impose cost on cyber adversaries: The first pillar centers on identifying intrusions, attributing malicious activity to its source and taking action against actors who target U.S. networks and critical infrastructure.
- Support victims: The second pillar focuses on sharing threat intelligence quickly, engaging with affected organizations soon after an incident and delivering specialized resources to help victims recover.
- Increase impact through partnerships: The third pillar emphasizes coordination across government agencies, international allies and private industry to expand the bureau’s operational reach.
- Enhance FBI’s cyber capabilities: The fourth pillar addresses building the workforce, technical tools and artificial intelligence capabilities needed to keep pace with an evolving threat landscape.
What Did FBI Official Brett Leatherman Say About the New Strategy?
In a video announcing the new strategy, Brett Leatherman, assistant director of the FBI’s Cyber Division, said the bureau’s underlying mission remains constant even as the approach to carrying it out must adapt.
“That mission does not change. How we meet the threat must,” said Leatherman, who assumed his current role in 2025.
He described a threat environment shaped by nation-state actors positioning themselves inside U.S. networks and criminal groups targeting shared services in ways that create wider disruption, noting that both types of actors are turning to artificial intelligence to move faster.
Leatherman also addressed the bureau’s approach to industry collaboration, saying private-sector partners have a role to play alongside the FBI’s government and allied partnerships.
How Does the Strategy Aim to Enhance FBI’s Cyber Capabilities?
The fourth pillar is built around four objectives intended to strengthen the bureau’s workforce and technical readiness:
- Recruit and retain top cyber talent: The FBI will prioritize hiring and retaining special agents, intelligence analysts, computer scientists and other technical specialists, while pursuing training partnerships with academia, industry and government organizations.
- Develop cyber expertise: The bureau will expand training, mentorship and professional development for cyber leadership at headquarters and in field offices, supported by its Cyber Education and Training Unit.
- Implement new technical tools and techniques: FBI Cyber will continue upgrading investigative technology, including its Computer Network Operations program, while preparing its systems for the transition to post-quantum cryptography.
- Adopt AI to scale operations: The bureau will deploy AI-enabled tools to triage data, support attribution and accelerate malware analysis, with human review and legal controls governing their use.
How Does the FBI Cyber Strategy Translate Into Recent Operations?
Recent FBI activity spans both warning the public about emerging threats and taking direct action against them. The bureau joined the National Security Agency and Cybersecurity and Infrastructure Security Agency in warning of China-linked AI distillation campaigns targeting U.S. frontier models. On the enforcement side, it worked with the Department of Justice to seize domains tied to the China-linked QTFY hacking group, which had been used against U.S. agencies and critical infrastructure.
The FBI updated a joint advisory with CISA and the Environmental Protection Agency on Iranian cyber actors targeting critical infrastructure. It also alerted the public, in coordination with CISA, to a Russian phishing campaign targeting messaging app users. Separately, the bureau co-issued a StopRansomware advisory on the Gunra ransomware operation with NSA and international partners.
The bureau has moved to build out its own capabilities as well. It appointed Karl Robert Schumann as chief information officer to lead cyber resilience and modernization efforts. The agency also amended its request for proposals for enterprise AI hardware infrastructure as part of a contracting opportunity worth up to $88 million.




