
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
The FBI’s cybersecurity strategy can play a role in increasing information sharing and collaboration between the government and the private sector, according to Tonya Ugoretz, a former FBI official with expertise in cyber threat intelligence analysis.
Summary
“A lot of the focus in current cyber policy is bringing together government and private industry,” Ugoretz told Inside Cybersecurity . Ugoretz spent more than twenty years at the FBI, leaving in 2025 when she was assistant director of the FBI Directorate of Intelligence. She now works a PricewaterhouseCoopers as co-leader of the Cyber and Risk Innovation Institute.
The FBI unveiled a cybersecurity strategy on Sept. 9 with four pillars. Increasing coordination with the private sector in cybersecurity operations is a main component of the strategy and in line with the Trump administration’s national cyber strategy , which emphasizes efforts for “unleashing the private sector.” “Obviously, that has to start with good information sharing,” Ugoretz said on the national cyber strategy, adding, “I would expect that it is only going to grow, because it has to.
There is no other way to address the threats that we see without that type of cooperation.” Ugoretz said the FBI strategy builds on previous work at the bureau on “working closely with victims of malicious cyber activity, other government partners and private industry.” “The main focus, then and now, is on joint sequenced operations to have the maximum impact on the adversaries that they're looking to disrupt,” Ugoretz said. Ugoretz spoke with Insid e Cybersecurity following the release of a PwC report , published on Sept. 30, examining how industry leaders are managing cybersecurity risks.
PwC surveyed 3,934 business and tech leaders from 71 countries. Among the findings in the survey, PwC reviewed how the private sector is responding to a heightened threat environment from increased geopolitical risks. The survey found 50 percent of respondents are diversifying their third-party and supply chain risk management decisions to mitigate cyber risks, while 49 percent are looking to bolster their defenses against geopolitical threats through investing in cyber insurance, incident response and crisis management.
“We see companies realizing that you don’t have to be a direct participant in a conflict, or even in a region where a conflict is occurring, to experience the consequences because there is so much use of common providers, vendors [and] reliance on common infrastructure,” Ugoretz said. On supply chain risks from geopolitical threats, Ugoretz said, “If a certain provider or infrastructure is targeted, it really ripples throughout companies.” Morgan Adamski, a former top U.S. Cyber Command official, also highlighted the heightened threat landscape for business executives due to geopolitical tensions as a key finding from the survey.
“Because companies rely on shared infrastructure, service providers, cloud environments and supply chains, cyber activity in one part of the world can create second- and third-order effects elsewhere,” Adamski said. “That is pushing companies to think more seriously about third-party risk, redundancy and concentration risk,” Adamski said.
KazaSec's take
Most public cloud incidents trace back to a misconfiguration, an overly permissive IAM role, a storage bucket left open, a default setting nobody revisited, rather than a flaw in the cloud provider itself. A cloud security review is built to catch exactly that class of mistake before it's found the hard way.
Coverage details
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.