Calling the FBI. What Actually Happens.
The FBI field office number is in the incident response plan. It sits there, on page 11, next to the contact for the insurance broker and the external PR firm. During an actual incident, someone will ask whether to use it, and the room will go quiet, because nobody agreed on the answer in advance.
Most organizations default to one of two positions. They notify law enforcement reflexively, because "that's what you do," or they avoid it reflexively, because lawyers worry about loss of control and timelines. Neither position is wrong in every case. But neither is a strategy. The decision carries real consequences either way, and the organizations that handle it well made the call deliberately, early, and with a clear-eyed understanding of what they were getting and what they were giving up.
What Law Enforcement Actually Does
The FBI and CISA have different mandates and different value propositions.
CISA (the Cybersecurity and Infrastructure Security Agency) is oriented toward defense and information sharing. When you notify CISA about an incident, they can provide technical assistance, share indicators of compromise from other investigations, and connect you with resources. The relationship is more collaborative than investigative. CISA does not show up to build a criminal case. They show up to help you understand what happened and share what they know about the threat actor.
The FBI's primary interest is criminal investigation and prosecution. An FBI notification begins a legal process. Agents assigned to your case are building a file. They will want evidence preserved, they will have questions about attribution and scope, and their timelines are keyed to a prosecution calendar rather than your recovery calendar.
This distinction matters a great deal in practice. For most organizations navigating a ransomware event or a data breach, CISA is the more immediately useful call.
The Business Timeline Problem
Investigations move at investigation pace. Criminal prosecution can take years. Your incident response needs to move at business pace, and those two clocks do not synchronize naturally.
Law enforcement involvement creates legitimate constraints on remediation. Preserving forensic evidence and returning systems to production are sometimes in conflict. The FBI may ask you to leave systems up in ways that extend your exposure. They may ask you not to take certain remediation steps that would interfere with investigative leads they want to pursue. In a ransomware scenario where every hour of downtime is costing real money, this creates a genuine tension.
None of this means law enforcement involvement is the wrong call. It means the decision has a cost that organizations often do not price in when they make it.
When FBI Involvement Actually Helps
There are cases where federal law enforcement resources are genuinely your best option, and often your only one.
Suspected nation-state actors are the clearest example. If your incident has the hallmarks of an advanced persistent threat with government sponsorship, the FBI has capabilities no private sector firm can replicate: lawful intercepts, international contacts, classified threat intelligence. Attributing and responding to a nation-state intrusion without law enforcement is limiting in ways that matter.
Financial fraud with wire transfers has a narrow window where FBI involvement can result in recovery. The FBI's relationships with financial institutions mean that a quick notification within hours of a fraudulent transfer can sometimes result in a hold and reversal. That window closes fast, usually within 24 to 72 hours. If you have a BEC incident with a recent wire, notification is worth the call immediately.
Critical infrastructure sectors (energy, water, healthcare, financial services) have specific notification obligations under various federal frameworks. CISA reporting requirements for critical infrastructure operators have mandatory components that exist regardless of whether you want to involve law enforcement.
Ransomware has a complicated relationship with law enforcement. The FBI occasionally has decryption keys from prior operations against specific ransomware groups. Notification sometimes produces a usable key that eliminates the ransom decision entirely. This happens infrequently but often enough that it is worth a call to find out.
Making the Decision Before You Need To
The worst time to decide whether to involve law enforcement is at 3 AM, when the incident is active and someone is asking for a decision. The question should be settled in advance, as part of building your IR program.
Work through the scenarios with legal counsel before an incident. For each major incident category - ransomware, data exfiltration, financial fraud, nation-state intrusion - agree on what the notification decision looks like and who has authority to make it. Document the decision tree. Make it specific enough that the person holding the phone at midnight can execute it.
Understand your mandatory reporting obligations now. Critical infrastructure operators have CISA reporting timelines that start at discovery, not at investigation completion. Some industries have specific law enforcement notification requirements for particular incident types. If any of these apply to you, the decision is already made.
Include law enforcement considerations in your retainer conversations. If you have an external IR firm, ask them how they interface with FBI and CISA, what experience they have working alongside federal investigators, and what they recommend for your sector. Their guidance is worth more than your assumptions.
Running Both Tracks
If you do notify law enforcement, set up separate tracks from the start. The IR team focuses on technical investigation and recovery. A named point of contact handles law enforcement coordination and briefs them separately. The two tracks need to communicate with each other but should not have their workflows entangled.
Law enforcement coordination is a full-time job during an active investigation. Someone needs to own it. If that person is also trying to run the technical response, one or both efforts will suffer.
The organizations that feel good about their law enforcement experience afterward are the ones that went in knowing what they needed from the relationship and communicated that clearly. They used law enforcement as a resource rather than handing over control. They recovered at their own pace while cooperating with the investigation. That posture is deliberate, not lucky, and it starts with a conversation that happens well before the incident that requires it.