ZeroHour
CyberScooppublished ()ingested Tim Starks

FBI cyber chief worries private sector not sharing enough cyber threat information

infoPolicy & legalimportance 38
AI summary · glm-5.3-flash

FBI cyber chief Brett Leatherman urged companies to share breach information with the bureau as it publishes a victim-focused cyber strategy.

FBI Cyber Division assistant director Brett Leatherman said at the Billington CyberSecurity Summit that private-sector hesitancy to engage the FBI stems from misconceptions, including a belief that shared incident data is passed to regulators. He warned that organizations breached by PRC nation-state actors risk more by handling intrusions alone, since FBI involvement speeds eradication. The bureau published a new cyber strategy Wednesday emphasizing victim aid, adopting a 'share until it hurts' posture on releasing threat intelligence.

  • FBI cyber division head says firms wrongly fear shared data reaches regulators
  • New FBI cyber strategy prioritizes aiding breach victims and rapid threat sharing
  • Leatherman stresses law enforcement can help eradicate PRC actors from networks
  • FBI held outside counsel summits to explain victim services after major breaches
OrganizationsFBI
Full article711 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Brett Leatherman said that industry has the wrong idea about what the FBI does with the data it collects during incidents, which is used to help victims and investigations alike.

Listen to this article

0:00

Learn more.

(Getty Images)

The private sector still isn’t sharing enough cyber information with the FBI in part because organizations are operating on false assumptions about what the bureau will do with what it collects, the FBI’s top cyber official said Wednesday.

Brett Leatherman, assistant director of the FBI’s cyber division, said in remarks at the Billington CyberSecurity Summit and in a discussion with reporters that organizations stand to benefit from bringing in the bureau when it’s compromised by hackers from the People’s Republic of China (PRC) and others. But one of the “key misconceptions” is that “the FBI is somehow sharing information with regulators for regulatory purposes, and that’s not the case.”

“From my standpoint over the last few years, I think we’ve seen a hesitancy on some companies to engage [with the] FBI,” Leatherman said.

“It worries me when an organization is breached by a nation-state actor and believes that bringing law enforcement in might be more risky than handling it on their own,” he said. “That should worry all of us when that happens, because who is positioned to eradicate the PRC from their environments as quickly as when they might have law enforcement or the intelligence teams at FBI come in and actually help with that effort?”

In response, the bureau has held events like outside counsel summits to walk attorneys through what the FBI offers victims during a major breach, Leatherman said. The FBI also has adjusted its standards for when to share information about threats when weighing how much it might help victims versus whether it might jeopardize a law enforcement operation in the future.

“Our posture is, ‘Share until it hurts,’” he said. “What I always ask my team is, if the victim were sitting in this room right now … would they want this information, and what is the compelling justification we have to not share this now to stop the impact versus taking an operation 90 days from now?”

“We have to in every situation where we have intelligence, we have to take that victim perspective because they can’t voice it in that moment,” he said. “Where we can share in a way that will protect our equities in conducting those operations, we’ll do it. But [where] we can have an impact to hundreds of pieces of critical infrastructure, we should share that, and we should share it quickly.”

The FBI published a new cyber strategy Wednesday that places an emphasis on aiding victims of cyberattacks. Helping victims also helps investigations, Leatherman said.

“We used to look at remediation and incident response as mutually exclusive to investigation and threat pursuit,” he said. “And what we’ve shown over the last few years is that they are not mutually exclusive. … If we can work with victims in a way that preserves investigative information, that allows us to move upstream against the actors.”

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/fbi-cyber-division-private-sector-threat-sharing/