Working With Law Enforcement
When to call the FBI and when not to, what law enforcement can offer that you can't get yourself, evidence sharing protocols, and how a law enforcement investigation changes your IR timeline.
Your CISO asks: "Should we call the FBI?" The CFO says no — they're worried about bad press and losing control of the investigation timeline. The IR lead says yes — the attacker appears to be the same ransomware group that hit three other companies in the sector, and the FBI may already have intelligence on them. Legal says it depends. All three positions are defensible. This chapter explains what law enforcement involvement actually means — what they can do, what it costs you (in time and control), and how to make the decision with real information rather than assumptions.
When to Engage Law Enforcement
| Scenario | Law enforcement value | Caveat |
|---|---|---|
| Ransomware from a sanctioned group | FBI has intelligence on the group; may have decryption keys from prior seizures; can advise on payment sanctions risk | FBI involvement doesn't speed up your recovery timeline directly |
| Nation-state attribution suspected | FBI CISA collaboration, attribution confirmation, potential offensive action on your behalf | Attribution investigations take months; your immediate IR response proceeds independently |
| BEC / wire fraud | FBI can submit SWIFT financial freeze request that private entities can't; IC3 complaint initiates financial fraud process | 72-hour window — if you wait too long, the financial recovery opportunity closes |
| Trade secret theft for a competitor | FBI Cyber Division handles trade secret cases; criminal prosecution is possible under DTSA (Defend Trade Secrets Act) | Criminal investigation timeline is years, not weeks; doesn't directly help your immediate business recovery |
| CSAM discovered on company systems | Mandatory reporting under federal law (18 U.S.C. § 2258A) to NCMEC and law enforcement — this is not optional | Non-compliance is a federal offense regardless of the IR timeline |
What the FBI Does (and Doesn't Do) During a Cyber Incident
FBI Engagement: What to Expect
═══════════════════════════════════════════════════════════════════
What the FBI WILL do:
├── Provide threat intelligence on the specific actor
│ (if they have it — they may know more about this group than you do)
├── Take evidence for potential criminal prosecution
├── Issue legal process (subpoenas) on cloud providers for attacker data
├── Coordinate with CISA for ICS/OT incidents
└── Submit financial fraud freeze requests (SWIFT network) for BEC
What the FBI will NOT do:
├── Run your incident response for you
├── Tell you what to do with your systems
├── Speed up your investigation in any meaningful way
├── Keep your incident confidential (federal law enforcement
│ operates under different disclosure rules — grand jury subpoenas
│ and prosecution disclosures may make your incident public)
└── Take over containment or recovery operations
Your obligations if you engage FBI:
├── Preserve all evidence (don't eradicate before FBI review)
│ → May delay your eradication timeline
├── Provide evidence copies on request (with your legal counsel present)
└── May need to leave attacker infrastructure in place for monitoring
(FBI may want to observe C2 activity for investigation purposes —
this conflicts with your containment objectives and must be
negotiated explicitly)
Evidence Sharing Protocol
When sharing evidence with law enforcement, follow these protocols to protect your organization's interests.
| Protocol | Why |
|---|---|
| Legal counsel present for all formal evidence requests | Ensures you understand what you're providing and can assert privilege over attorney-client communications in the evidence set |
| Provide copies, not originals | Forensic copies with hash verification; original evidence stays in your chain of custody |
| Document every transfer with a receipt | Protects you if the evidence is later challenged or goes missing in the investigation |
| Be factual, not interpretive, in any statements | Statements to law enforcement can be used in prosecution — your technical findings can become testimony. Stick to what you observed, not what you concluded. |
| Request a point of contact with direct communication | FBI investigations can go quiet for months; having a named AUSA (Assistant US Attorney) or special agent as a contact ensures you can get updates and plan around investigation constraints |
IC3 and Reporting Mechanisms
| Organization | Role | How to contact |
|---|---|---|
| FBI IC3 (Internet Crime Complaint Center) | Initial intake for cybercrime reports; route to appropriate field office; BEC financial fraud alerts | ic3.gov — file complaint online |
| FBI Local Field Office — Cyber Division | Direct engagement for significant incidents; more responsive than IC3 for active P1 incidents | fbi.gov/contact-us/field-offices — call directly |
| CISA (Cybersecurity and Infrastructure Security Agency) | Critical infrastructure sectors; threat intelligence sharing; no law enforcement authority (CISA can't arrest anyone — good for information sharing without prosecution risk) | cisa.gov/report — or call 888-282-0870 |
| US-CERT | Technical assistance and coordination; now integrated into CISA | cisa.gov/report |
| Secret Service ECTF (Electronic Crimes Task Force) | Financial cybercrime — wire fraud, ransomware payments, cryptocurrency tracing | Secret Service field office |
Q & A
Q: The FBI asks you to delay eradication so they can monitor the attacker's C2 activity. This conflicts with your obligation to contain the incident. How do you resolve this?
This is a business decision requiring authorization from the CISO/CEO and outside counsel — not a unilateral IR team decision. Present the conflict explicitly to leadership: "The FBI has requested we maintain the attacker's C2 channel for X days for their investigation. This conflicts with our eradication timeline and means the attacker retains access to these systems for X more days. The business risk of continued access is [describe]. The benefit of cooperating is [criminal prosecution, intelligence, potential attribution]. I need a decision from [CISO/CEO] and outside counsel on whether to comply with the FBI's request." The FBI cannot legally compel you to delay eradication — they can ask and you can decline. If you choose to cooperate, document the business decision and the FBI's specific request in writing. The responsibility for any harm that occurs during the delay period is shared with the party that requested it.
Q: CISA reaches out proactively saying they've seen similar activity across multiple organizations and want to share IOCs. Should you share your IOCs back?
Generally yes — CISA's information sharing operates under the Cybersecurity Information Sharing Act (CISA 2015), which provides liability protections for private entities that share cyberthreat indicators with CISA in good faith. Sharing IOCs with CISA does not constitute disclosure of your incident publicly, and CISA is prohibited from using shared information for regulatory enforcement purposes. Confirm with outside counsel that the CISA protection applies in your situation before sharing, but the legal framework is designed specifically to enable exactly this kind of bi-directional information sharing during incidents. IOCs shared with CISA can be used to protect other organizations from the same attack — a pro-industry outcome that also builds goodwill with the agency that may be involved in any future regulatory interaction.