FBI launches Secure 2027 to counter PRC pre-positioning
The clock on Taiwan is the organizing principle, not a generic counter-espionage posture, but a specific bet that 2027 is when pre-positioned access becomes destructive action.
TL;DR
FBI Cyber Division chief Brett Leatherman announced "Secure 2027" at the Billington Cybersecurity Summit, the bureau's first unclassified cyber strategy, built around four pillars: investigate and impose cost, support victims, expand partnerships, and strengthen FBI cyber capabilities. The initiative is a coordinated effort with DoD and critical infrastructure operators, framed explicitly around Chinese pre-positioning in U.S. critical infrastructure ahead of a potential Taiwan conflict. Leatherman said the Salt Typhoon unified coordination group (co-led with CISA and the CIA) remains active because PRC targeting continues with 2027 readiness as the stated intent.
The FBI is no longer treating PRC pre-positioning as a diffuse threat. It has a banner, a clock, and an interagency architecture that didn't dissolve after the Salt Typhoon headlines.
Leatherman's Secure 2027 announcement is less a strategy document and more an organizing framework, one that grafts the FBI's investigative and disruption authorities onto a DoD force-projection problem. "Understand how to preserve force projections when cyber targeting can impact us domestically" was how he framed the goal. That's a long way from the advisory-and-mitigate rhythm of 2024.
The 2027 clock isn't the FBI's invention
Xi Jinping has pointed to 2027 for military readiness on Taiwan, and CISA has been flagging the same timeline since at least the February 2024 Volt Typhoon advisory. What's new is the FBI naming it publicly as the operational horizon and building a branded initiative around it, a signal that the bureau believes the pre-positioning it has observed isn't speculative.
Leatherman confirmed the Salt Typhoon unified coordination group, stood up in 2024 and co-led with CISA and the CIA, is still running. The IC is "all involved," he said, because PRC targeting of critical infrastructure hasn't stopped and the intent around 2027 readiness hasn't changed.
The enabler ecosystem beneath the APT names
Leatherman also pointed at the private-sector supply chain that keeps the pre-positioning machinery running, companies working on behalf of nation-states, particularly in China and Russia. DOJ demonstrated the point in August with the QTFY infrastructure takedown. These aren't the APT groups themselves but the layer beneath: the firms that provision infrastructure, launder access, and make persistent intrusion possible at scale.
The continuity is the story. The Volt Typhoon advisory was February 2024. The CISA fact sheet telling critical infrastructure leaders to treat cyber risk as core business risk was March 2024. The Flax Typhoon botnet disruption was September 2024. Secure 2027 says none of those were the end of the drill.
Published ·Deep Fathom