The four pillars of the FBI’s new cyber roadmap
The FBI has published a new cyber strategy it calls “a roadmap for defending the American people and the nation's critical infrastructure in cyberspace.” The document centers on four named pillars of activity:
- Investigate, disrupt and impose cost on cyber adversaries
- Support victims
- Increase impact via partnerships
- Enhance the agencies cyber capabilities
Those four pillars frame the Bureau’s move toward a more interventionist posture in cyberspace, according to the strategy language cited by an FBI veteran now in the private sector.
James Turgal’s reading: from “investigate, attribute, and indict” to active disruption
James Turgal, vice president of Cyber Risk & Board Relations at Optiv and a former Executive Assistant Director for the FBI’s Information and Technology Branch, described the strategy as a decisive shift. “For years, the playbook was ‘investigate, attribute, and indict,’” he said. “But you can’t arrest your way out of a nation-state cyber threat when the perpetrators sit safely behind non-extradition borders in Moscow, Beijing, or Tehran.”
Turgal framed the change as an operational evolution: “As a former FBI agent, I see this strategy as a necessary evolution: taking down adversary infrastructure, seizing criminal servers, and burning zero-day exploits before they hit critical infrastructure.” Those phrases capture the strategy’s emphasis on offensive measures — actions that go beyond traditional evidence collection and prosecution.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramblePrivate-sector fallout and the “blast radius” of offensive operations
Alongside endorsement of disruption, Turgal warned of consequences for private networks. “However, as a former CIO, my immediate focus is on the private sector fallout. The blast radius from this strategy will be extensive, as offensive cyber operations inevitably invite retaliation,” he said. The warning locates potential collateral effects squarely on domestic enterprises, not only on the adversaries targeted.
He pointed to specific categories of private enterprise that, in his view, must prepare for impact when the Bureau dismantles a major threat: “private enterprises — particularly critical infrastructure, healthcare, and finance — must brace for impact.”
Coordination with CIOs and CISOs as the measure of success
Turgal argued the strategy’s success should be evaluated less by the number of servers taken offline and more by downstream protection of networks. “The success of this strategy won’t be measured just by the servers the FBI takes offline, but by how effectively they coordinate with private sector CIOs and CISOs to shield corporate networks from the inevitable blowback.”
That formulation reframes operational success metrics: disruption performed by the Bureau becomes one input; the other is operational resilience among the private defenders who share cyber terrain with the FBI’s targets.
What this means for CIOs and CISOs, and for critical infrastructure, healthcare, and finance
- CIOs and CISOs: Turgal’s comments signal an elevated expectation of close coordination with the FBI during offensive operations; the Bureau will likely require practical arrangements to protect corporate networks from retaliation and collateral damage.
- Critical infrastructure, healthcare, and finance: These sectors are called out specifically as ones that “must brace for impact” when major ransomware groups or nation-state proxies are disrupted, implying an elevated risk profile tied to offensive actions.
Implication: operational ambition paired with coordination challenges
The new FBI roadmap, as described by Turgal, combines clear operational ambition — taking down infrastructure, seizing servers, burning zero-days — with an explicit caveat: offensive cyber operations invite retaliation. That admission places heavy weight on the “Increase impact via partnerships” and “Support victims” pillars; if offensive measures provoke blowback, the Bureau’s ability to shield private networks and support affected organizations will define whether the strategy reduces or redistributes risk.
For now, the record in the published account is straightforward: the FBI has adopted a strategy built around disruption and partnership, and a former senior Bureau official now in the private sector warns the practical test will be in protecting the entities most exposed to retaliation.




