Chapter 27

Working With Law Enforcement

When to call the FBI and when not to, what law enforcement can offer that you can't get yourself, evidence sharing protocols, and how a law enforcement investigation changes your IR timeline.

Scenario

Your CISO asks: "Should we call the FBI?" The CFO says no — they're worried about bad press and losing control of the investigation timeline. The IR lead says yes — the attacker appears to be the same ransomware group that hit three other companies in the sector, and the FBI may already have intelligence on them. Legal says it depends. All three positions are defensible. This chapter explains what law enforcement involvement actually means — what they can do, what it costs you (in time and control), and how to make the decision with real information rather than assumptions.

When to Engage Law Enforcement

ScenarioLaw enforcement valueCaveat
Ransomware from a sanctioned groupFBI has intelligence on the group; may have decryption keys from prior seizures; can advise on payment sanctions riskFBI involvement doesn't speed up your recovery timeline directly
Nation-state attribution suspectedFBI CISA collaboration, attribution confirmation, potential offensive action on your behalfAttribution investigations take months; your immediate IR response proceeds independently
BEC / wire fraudFBI can submit SWIFT financial freeze request that private entities can't; IC3 complaint initiates financial fraud process72-hour window — if you wait too long, the financial recovery opportunity closes
Trade secret theft for a competitorFBI Cyber Division handles trade secret cases; criminal prosecution is possible under DTSA (Defend Trade Secrets Act)Criminal investigation timeline is years, not weeks; doesn't directly help your immediate business recovery
CSAM discovered on company systemsMandatory reporting under federal law (18 U.S.C. § 2258A) to NCMEC and law enforcement — this is not optionalNon-compliance is a federal offense regardless of the IR timeline

What the FBI Does (and Doesn't Do) During a Cyber Incident

  FBI Engagement: What to Expect
  ═══════════════════════════════════════════════════════════════════

  What the FBI WILL do:
    ├── Provide threat intelligence on the specific actor
    │     (if they have it — they may know more about this group than you do)
    ├── Take evidence for potential criminal prosecution
    ├── Issue legal process (subpoenas) on cloud providers for attacker data
    ├── Coordinate with CISA for ICS/OT incidents
    └── Submit financial fraud freeze requests (SWIFT network) for BEC

  What the FBI will NOT do:
    ├── Run your incident response for you
    ├── Tell you what to do with your systems
    ├── Speed up your investigation in any meaningful way
    ├── Keep your incident confidential (federal law enforcement
    │   operates under different disclosure rules — grand jury subpoenas
    │   and prosecution disclosures may make your incident public)
    └── Take over containment or recovery operations

  Your obligations if you engage FBI:
    ├── Preserve all evidence (don't eradicate before FBI review)
    │   → May delay your eradication timeline
    ├── Provide evidence copies on request (with your legal counsel present)
    └── May need to leave attacker infrastructure in place for monitoring
        (FBI may want to observe C2 activity for investigation purposes —
         this conflicts with your containment objectives and must be
         negotiated explicitly)

Evidence Sharing Protocol

When sharing evidence with law enforcement, follow these protocols to protect your organization's interests.

ProtocolWhy
Legal counsel present for all formal evidence requestsEnsures you understand what you're providing and can assert privilege over attorney-client communications in the evidence set
Provide copies, not originalsForensic copies with hash verification; original evidence stays in your chain of custody
Document every transfer with a receiptProtects you if the evidence is later challenged or goes missing in the investigation
Be factual, not interpretive, in any statementsStatements to law enforcement can be used in prosecution — your technical findings can become testimony. Stick to what you observed, not what you concluded.
Request a point of contact with direct communicationFBI investigations can go quiet for months; having a named AUSA (Assistant US Attorney) or special agent as a contact ensures you can get updates and plan around investigation constraints

IC3 and Reporting Mechanisms

OrganizationRoleHow to contact
FBI IC3 (Internet Crime Complaint Center)Initial intake for cybercrime reports; route to appropriate field office; BEC financial fraud alertsic3.gov — file complaint online
FBI Local Field Office — Cyber DivisionDirect engagement for significant incidents; more responsive than IC3 for active P1 incidentsfbi.gov/contact-us/field-offices — call directly
CISA (Cybersecurity and Infrastructure Security Agency)Critical infrastructure sectors; threat intelligence sharing; no law enforcement authority (CISA can't arrest anyone — good for information sharing without prosecution risk)cisa.gov/report — or call 888-282-0870
US-CERTTechnical assistance and coordination; now integrated into CISAcisa.gov/report
Secret Service ECTF (Electronic Crimes Task Force)Financial cybercrime — wire fraud, ransomware payments, cryptocurrency tracingSecret Service field office

Q & A

Q: The FBI asks you to delay eradication so they can monitor the attacker's C2 activity. This conflicts with your obligation to contain the incident. How do you resolve this?

This is a business decision requiring authorization from the CISO/CEO and outside counsel — not a unilateral IR team decision. Present the conflict explicitly to leadership: "The FBI has requested we maintain the attacker's C2 channel for X days for their investigation. This conflicts with our eradication timeline and means the attacker retains access to these systems for X more days. The business risk of continued access is [describe]. The benefit of cooperating is [criminal prosecution, intelligence, potential attribution]. I need a decision from [CISO/CEO] and outside counsel on whether to comply with the FBI's request." The FBI cannot legally compel you to delay eradication — they can ask and you can decline. If you choose to cooperate, document the business decision and the FBI's specific request in writing. The responsibility for any harm that occurs during the delay period is shared with the party that requested it.

Q: CISA reaches out proactively saying they've seen similar activity across multiple organizations and want to share IOCs. Should you share your IOCs back?

Generally yes — CISA's information sharing operates under the Cybersecurity Information Sharing Act (CISA 2015), which provides liability protections for private entities that share cyberthreat indicators with CISA in good faith. Sharing IOCs with CISA does not constitute disclosure of your incident publicly, and CISA is prohibited from using shared information for regulatory enforcement purposes. Confirm with outside counsel that the CISA protection applies in your situation before sharing, but the legal framework is designed specifically to enable exactly this kind of bi-directional information sharing during incidents. IOCs shared with CISA can be used to protect other organizations from the same attack — a pro-industry outcome that also builds goodwill with the agency that may be involved in any future regulatory interaction.