Estimated reading time: 4 minutes · Last updated:
On 5 October 2026 the FBI published a bureau-wide public cyber strategy that reframes its approach from passive defence to proactive disruption: the bureau will seek to use private-sector telemetry and operational intelligence to identify and dismantle hostile cyber actors before they reach victims. James Turgal, vice president of global cyber risk at Optiv, described the shift as an effort to “systematically dismantle the organization” of attackers by targeting people, money and infrastructure. This account is based on an interview with James Turgal, as first reported by Federal News Network.
This is really taking a new look at how do you systematically dismantle the organization, dismantle, the actual threat actors out there,
James Turgal
Key takeaways
- New emphasis: The FBI’s strategy shifts focus from detection-and-response toward disrupting threat actors earlier using private-sector telemetry and operational intelligence.
- Victim support: The strategy gives roughly equal weight to victim support and partnerships as to disruption, promising more operational intelligence to affected companies.
- Private-sector scale: Optiv, represented by James Turgal in the interview, said the firm supports about 6,000 clients and is watching how CISOs react to the change.
- Historic perspective: Turgal, who began working cyber in 2002, said the shift departs from a decades-long model of detecting intruders and patching vulnerabilities.
Table of contents
How the FBI is shifting from defence to active disruption
The FBI’s new bureau-wide public cyber strategy reframes the bureau’s role from primarily detecting intrusions and remediating victims to taking operational steps intended to prevent repeat attacks. James Turgal said the previous model focused on finding intruders, removing them, repairing the exploited vulnerability and preparing for the next incident, and that the new approach aims to go further by identifying the people, the funding and the infrastructure that let attackers return.
That change rests on a practical trade: the government has investigative authorities and legal tools, while private companies hold the telemetry—logs, endpoint data and other visibility—needed to map attacker behaviours. Under the shift, the FBI plans to treat selected private-sector telemetry as the basis for disruption operations and for sharing actionable, operational intelligence back to potential victims so they can harden defences before breaches complete.
Turning private telemetry into operational intelligence
A central promise of the strategy is more two-way information flows: the FBI will move beyond threat intelligence and aim to deliver operational intelligence to network defenders. James Turgal distinguished the two by saying threat intelligence is descriptive while operational intelligence would include concrete indicators, models of an adversary’s methods and suggestions for immediate defensive steps.
Practically, that means companies that share telemetry could receive targeted indicators—IP ranges, malware signatures, attack patterns—and context that helps CISOs act quickly. Turgal said that historically the FBI often collected private-sector data without reciprocating, a complaint that impeded cooperation; the new posture emphasises giving back usable, co-ordinated guidance so victims can respond in real time.
The blast radius risk for unprepared organisations
Turgal warned the strategy carries a collateral risk he described as a “blast radius.” If disruption steps target nation-state proxies or criminal infrastructures, adversaries may retaliate against U.S. networks. He contrasted the FBI’s readiness with many private firms’ uneven cyber hygiene, saying retaliation could hit companies that are not prepared.
That observation frames the strategy’s practical test: will the FBI’s disruptions reduce successful intrusions overall, or will retaliatory activity increase harm among organisations that lack mature defences? Turgal expects stronger two-way ties between local FBI cyber squads and CISOs, and more engagement through groups he named such as InfraGar and DSAC, as part of the resilience response.
| Element | Old approach | New strategy |
|---|---|---|
| Primary goal | Detect and remediate intrusions | Disrupt adversary operations before incidents |
| Data flows | Private-sector telemetry -> FBI | Two-way sharing; operational intelligence returned to victims |
| Outcome for victims | Investigation and attribution | Advance warning and actionable indicators |
How the strategy could play out
The case for
- More operational intelligence shared with CISOs could reduce successful intrusions by enabling faster mitigation.
- Closer ties between local FBI cyber squads and private-sector CISOs may increase reporting and coordinated defence across sectors.
The case against
- Disruption actions could provoke retaliatory attacks that hit unprepared companies and third parties in the ‘blast radius’.
- Legal, privacy or classification limits on telemetry sharing could slow or constrain the operational detail the FBI can provide.
What to be careful about
- Retaliation against U.S. private-sector networks after FBI disruption operations, as warned by James Turgal.
- Incomplete or one-way information sharing if privacy or classified constraints remain, reducing operational usefulness for CISOs.
- Variation in corporate cyber maturity that leaves smaller or less-prepared firms exposed to collateral effects.
- Potential operational mistakes when translating telemetry into disruption targets that could cause unintended service impacts.
The bottom line
The FBI’s bureau-wide public cyber strategy represents a deliberate shift from incident response toward proactive disruption, built on tighter ties with private-sector telemetry holders and a promise of operational intelligence for victims. That change could materially reduce repeat intrusions if legal, classification and privacy constraints are managed and if CISOs forge stronger local ties to FBI cyber squads. At the same time, leaders should prepare for the risk of retaliatory activity and ensure their organisations are not left in the ‘blast radius’ by improving basic cyber hygiene and formalising channels with federal partners.
What to watch
- Watch for the FBI to publish implementation guidance or playbooks that clarify how it will share operational intelligence; no date has been set.
- Watch for an increase in formal CISO engagement with local FBI cyber squads, InfraGar and DSAC as companies adjust to two-way information sharing; no date has been set.
Frequently asked questions
What does the FBI mean by disruption in this strategy?
Disruption refers to active steps the FBI can take to impair adversaries’ ability to operate—targeting people, funding and infrastructure—rather than only investigating and prosecuting after an incident. James Turgal framed the goal as moving beyond attribution to “dismantle” attackers’ organisations.
How will private companies benefit from the change?
The strategy aims to provide companies with operational intelligence—specific indicators and models of attack methods—so defenders can act before breaches complete; Optiv’s James Turgal said that reciprocity addresses longstanding complaints that the FBI collected telemetry but returned little actionable data.
What is the main operational risk for the private sector?
Turgal warned of a potential ‘blast radius’: when the FBI disrupts adversary infrastructure, adversaries may retaliate against U.S. networks and organisations that lack mature cyber hygiene, increasing exposure for those firms.
Related reading