Skip to main content
CybersecurityIncident Response

FBI Warns of Cyber Info-Sharing Gap with Private Sector

Formal conference setting with podium, blurred audience, and law enforcement emblem, with daylight through tall windows.

"Our posture is, 'Share until it hurts,'" Brett Leatherman told an audience and reporters as he argued that private companies are not sharing enough cyber threat information with the FBI.

Leatherman, assistant director of the FBI’s cyber division, made the comments at the Billington CyberSecurity Summit and in a separate discussion with reporters. He said organizations often operate under misconceptions about how the bureau handles information — and those misconceptions, he warned, can slow down the FBI’s ability to help victims and to remove hostile actors from corporate environments.

Brett Leatherman on private-sector hesitancy

Leatherman framed the problem bluntly: “we’ve seen a hesitancy on some companies to engage [with] FBI.” He said that hesitancy is driven in part by a “key misconception” — that “the FBI is somehow sharing information with regulators for regulatory purposes, and that’s not the case.”

He described a more consequential concern: when “an organization is breached by a nation-state actor and believes that bringing law enforcement in might be more risky than handling it on their own,” it should worry everyone, because the bureau and its intelligence teams are in a position to act quickly against actors such as those from the People’s Republic of China (PRC). “Who is positioned to eradicate the PRC from their environments as quickly as when they might have law enforcement or the intelligence teams at FBI come in and actually help with that effort?” he asked.

FBI posture: "Share until it hurts" and adjusted standards

To address competing priorities — victim protection versus safeguarding law enforcement operations — Leatherman said the FBI has adjusted its standards for when to share information about threats. The guiding approach, he said, is to balance how much sharing will help victims now against whether it might jeopardize an operation later.

“What I always ask my team is, if the victim were sitting in this room right now … would they want this information, and what is the compelling justification we have to not share this now to stop the impact versus taking an operation 90 days from now?” Leatherman said. He emphasized that the bureau must “take that victim perspective because they can’t voice it in that moment.” Where intelligence can be shared without harming investigative equities, the FBI will do so; where sharing would protect “hundreds of pieces of critical infrastructure,” it should be done “quickly,” he said.

New FBI cyber strategy emphasizes aiding victims and blending response with investigation

The FBI published a new cyber strategy the same day Leatherman spoke, and he used that release to underline a conceptual shift. Historically, he said, remediation and incident response had been viewed as “mutually exclusive to investigation and threat pursuit.” The bureau now treats them as complementary: “If we can work with victims in a way that preserves investigative information, that allows us to move upstream against the actors,” Leatherman said.

In other words, helping a breached organization recover and protecting its systems can simultaneously preserve the forensic and intelligence traces needed to pursue the attackers.

Outside counsel summits and practical outreach to victims

Part of the FBI’s outreach has been practical: the bureau has held events such as outside counsel summits to walk attorneys through “what the FBI offers victims during a major breach,” Leatherman said. Those sessions are designed to correct misperceptions among legal advisers who counsel companies on whether to involve law enforcement.

Leatherman framed these efforts as a way to lower barriers to engagement so that victims, who cannot speak for themselves in a breach, will receive the information and assistance the FBI can provide without needless delay.

What this means for technologists, regulators, and affected enterprises

  • Technologists and security teams: If Leatherman’s account is accurate, teams responding to breaches should expect a more proactive FBI posture that seeks to share actionable intelligence quickly when doing so protects critical infrastructure and aids remediation.
  • Policymakers and regulators: Leatherman’s explicit denial that the FBI shares information with regulators “for regulatory purposes” is likely to shape how lawmakers and regulators evaluate claims from companies that fear regulatory exposure as a reason not to notify law enforcement.
  • Affected enterprises and their counsel: The FBI’s outside counsel summits are intended to change decision calculus inside companies and law firms by clarifying “what the FBI offers victims during a major breach” and by emphasizing the bureau’s victim-centered sharing posture.

Leatherman’s remarks put a practical tension at the center of current cyber policy: the desire to protect investigative operations versus the immediate need to stop active intrusions and protect critical infrastructure. The FBI’s stated remedy is twofold — adjust sharing standards to favor victim impact where possible, and educate the private sector through targeted outreach so that fear of regulatory or investigative consequences does not delay engagement. Whether that combination will persuade reluctant companies to change course remains a live question.

Read the original CyberScoop story: https://cyberscoop.com/fbi-cyber-division-private-sector-threat-sharing/