FBI cyber chief worries private sector not sharing enough cyber threat information
FBI cyber chief worries private sector not sharing enough cyber threat information
The private sector still isnât sharing enough cyber information with the FBI in part because organizations are operating on false assumptions about what the bureau will do with what it collects, the FBIâs top cyber official said Wednesday.
Brett Leatherman, assistant director of the FBIâs cyber division, said in remarks at the Billington CyberSecurity Summit and in a discussion with reporters that organizations stand to benefit from bringing in the bureau when itâs compromised by hackers from the Peopleâs Republic of China (PRC) and others. But one of the âkey misconceptionsâ is that âthe FBI is somehow sharing information with regulators for regulatory purposes, and thatâs not the case.â
âFrom my standpoint over the last few years, I think weâve seen a hesitancy on some companies to engage [with the] FBI,â Leatherman said.
âIt worries me when an organization is breached by a nation-state actor and believes that bringing law enforcement in might be more risky than handling it on their own,â he said. âThat should worry all of us when that happens, because who is positioned to eradicate the PRC from their environments as quickly as when they might have law enforcement or the intelligence teams at FBI come in and actually help with that effort?â
In response, the bureau has held events like outside counsel summits to walk attorneys through what the FBI offers victims during a major breach, Leatherman said. The FBI also has adjusted its standards for when to share information about threats when weighing how much it might help victims versus whether it might jeopardize a law enforcement operation in the future.
âOur posture is, âShare until it hurts,ââ he said. âWhat I always ask my team is, if the victim were sitting in this room right now ⌠would they want this information, and what is the compelling justification we have to not share this now to stop the impact versus taking an operation 90 days from now?â
âWe have to in every situation where we have intelligence, we have to take that victim perspective because they canât voice it in that moment,â he said. âWhere we can share in a way that will protect our equities in conducting those operations, weâll do it. But [where] we can have an impact to hundreds of pieces of critical infrastructure, we should share that, and we should share it quickly.â
The FBI published a new cyber strategy Wednesday that places an emphasis on aiding victims of cyberattacks. Helping victims also helps investigations, Leatherman said.
âWe used to look at remediation and incident response as mutually exclusive to investigation and threat pursuit,â he said. âAnd what weâve shown over the last few years is that they are not mutually exclusive. ⌠If we can work with victims in a way that preserves investigative information, that allows us to move upstream against the actors.â
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.