Published September 15, 2026 - Washington, D.C. The FBI published its first-ever comprehensive cyber strategy on September 10, 2026, focusing on disrupting threat actors through four pillars: Disrupt, Pursue, Protect, and Prepare. CISA and NSA contributed to the strategy's development.
Data last verified September 15, 2026 from FBI Cyber Strategy document, CISA joint statement, NSA statement, and Cyber Threat Alliance analysis.
Quick Answer
The FBI's first comprehensive cyber strategy was published September 10, 2026 with four pillars: Disrupt, Pursue, Protect, Prepare. Disrupt is the key shift from reactive investigation to proactive operations. CISA and NSA contributed. Last verified: Sep 15, 2026.
At a glance
- Publication date: September 10, 2026
- Pages: 56
- Four pillars: Disrupt, Pursue, Protect, Prepare
- Lead agency: FBI
- Contributing agencies: CISA, NSA
- Key shift: Disrupt pillar enables proactive cyber operations
- Target: threat actors, not just networks
The four pillars explained
The four pillars represent a comprehensive approach spanning proactive operations, legal action, defensive capability, and future preparation. Disrupt is the most operationally significant pillar.
| Pillar | Focus | Key activities |
|---|---|---|
| Disrupt | Proactive cyber operations | Take down botnets, seize crypto, disrupt payment systems |
| Pursue | Legal action against threat actors | Indictments, international cooperation, arrest warrants |
| Protect | Defensive capability for US organizations | Threat intel sharing, vulnerability disclosure, victim support |
| Prepare | Future threat capability | AI-driven attacks, quantum computing threats, deepfake threats |
Source: FBI Cyber Strategy document, September 10, 2026; CISA joint statement, September 2026.
The Disrupt pillar in detail
The Disrupt pillar authorizes the FBI to conduct proactive cyber operations against threat actor infrastructure. This represents a significant expansion of FBI cyber authority.
Previous FBI cyber operations were reactive: investigating after incidents occurred, collecting evidence, pursuing indictments. The Disrupt pillar enables pre-emptive action when credible intelligence indicates an imminent or ongoing threat. Examples of Disrupt operations include: (1) taking down botnets used for credential stuffing or DDoS attacks, (2) disrupting ransomware payment systems by seizing cryptocurrency exchanges and wallets, (3) seizing infrastructure used by threat actors for command-and-control, (4) conducting offensive operations to disrupt APT campaigns. The Disrupt pillar formalizes what the FBI has been doing in ad hoc operations since at least the 2023 Hive ransomware takedown (FBI Cyber Strategy Disrupt section, September 10, 2026; Cyber Threat Alliance analysis, September 2026).
The Pursue pillar
The Pursue pillar formalizes the FBI's legal action against cyber threat actors through indictments, arrests, and international cooperation. Recent successes include several high-profile indictments.
| Year | Target | Outcome |
|---|---|---|
| 2022 | LockBit affiliate | Indictment, cooperation with UK NCA |
| 2024 | Hive ransomware operators | Infrastructure seized, no arrests |
| 2025 | BlackCat (ALPHV) operators | Indictment, infrastructure disruption |
| 2026 | Volt Typhoon operators | Indictments, attribution to PRC |
Source: FBI Cyber Strategy Pursue section, September 10, 2026; DOJ indictments, 2022-2026.
The Protect pillar
The Protect pillar focuses on threat intelligence sharing and defensive capability for US organizations. CISA is the primary implementing partner.
The Protect pillar includes: (1) real-time threat intelligence sharing with critical infrastructure operators, (2) vulnerability disclosure through CISA's Known Exploited Vulnerabilities catalog, (3) victim support through FBI field offices and CISA regional offices, (4) sector-specific threat briefings for healthcare, finance, energy, and transportation, (5) free cybersecurity assessments for critical infrastructure. The Protect pillar reflects the FBI's traditional strength in working with victims and providing defensive support (FBI Cyber Strategy Protect section, September 10, 2026; CISA industry guidance, September 2026).
The Prepare pillar
The Prepare pillar addresses emerging threats including AI-driven attacks, quantum computing threats, and deepfake-enabled fraud. The FBI is building capability for threats that don't yet have widespread impact.
| Emerging threat | Timeline | FBI preparation |
|---|---|---|
| AI-driven social engineering | Now (active) | Forensic AI detection tools, deepfake analysis |
| AI-generated malware | 1-2 years | Capability to analyze and attribute |
| Quantum computing threats to encryption | 3-5 years | Post-quantum cryptography partnerships |
| Deepfake-enabled fraud | Now (active) | Voice and video authentication standards |
| AI-powered vulnerability discovery | 1-2 years | Defensive AI capability |
Source: FBI Cyber Strategy Prepare section, September 10, 2026; NSA statement on emerging threats, September 2026.
Coordination with CISA and NSA
The FBI strategy integrates CISA's defensive mandate with NSA's offensive capability and the FBI's law enforcement authority. The three-agency coordination is unprecedented in scope.
CISA operates under the Department of Homeland Security with a defensive and informational mandate: it shares threat intelligence, coordinates incident response, and manages vulnerability disclosure. NSA operates under the Department of Defense with offensive and signals intelligence capability: it conducts cyber operations and provides cryptographic expertise. The FBI operates under the Department of Justice with law enforcement authority: it investigates, pursues indictments, and works with international partners. The September 2026 strategy integrates all three mandates under a unified US government cyber posture for the first time (CISA joint statement, September 2026; NSA statement, September 2026; FBI Cyber Strategy, September 10, 2026).
What organizations should expect
Organizations should expect more frequent FBI outreach, faster incident response coordination, and earlier threat intelligence sharing. The strategy creates new engagement channels for organizations of all sizes.
| Expectation | Frequency | Channel |
|---|---|---|
| Sector-specific threat briefings | Monthly | FBI field office, CISA regional office |
| Pre-incident threat notifications | As threats develop | FBI InfraGard, CISA alerts |
| Incident response coordination | When attacked | FBI Cyber Division, CISA incident response |
| Disruption operations affecting legitimate services | Several times per year | Public disruption announcements |
| FBI liaison outreach | Quarterly for critical infrastructure | FBI field office |
Source: FBI Cyber Strategy implementation section, September 10, 2026; InfraGard program guidance, September 2026.
FAQs
The questions above cover what the FBI cyber strategy is, what the four pillars are, how the Disrupt pillar changes the cyber landscape, what role CISA and NSA play, what the strategy means for ransomware operators, and what organizations should expect from implementation.
Photo: ajay_suresh, CC BY, via Wikimedia Commons (https://upload.wikimedia.org/wikipedia/commons/7/72/FBI_Headquarters_-_J._Edgar_Hoover_Building_%2853840035941%29.jpg?utm_source=commons.wikimedia.org&utm_campaign=imageinfo&utm_content=original)
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read moreShow less
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.








