The FY2027 Intelligence Authorization Act, reported this spring by the Senate Select Committee on Intelligence, is still moving through Congress. It is not law yet. But for counterintelligence leaders, the direction it sets is worth reading closely — because it widens the counterintelligence aperture in several places at once, and one of those places is the cyber domain.
Read from a CI perspective, the bill does several notable things: it establishes dedicated counterintelligence offices inside the Department of the Treasury and the Department of Commerce; it broadens the economic-espionage statute, extending jurisdiction over trade-secret theft that reaches U.S. victims or infrastructure and creating a new offense for transmitting trade secrets outside the country; and it removes the statute of limitations for the most serious espionage offenses. These are not housekeeping edits — they signal a Congress intent on treating counterintelligence as a broader, more accountable mission.
Section 607: Hostile Foreign Cyber Actors as a CI Priority
The provision most relevant to cyber CI is Section 607. It declares that the financial insecurity generated by foreign malicious cybercriminal organizations presents a counterintelligence threat to the intelligence community. It states the sense of Congress that these actors are valid targets for intelligence operations under existing authorities, and that the Director of National Intelligence should treat collection, analysis, and disruption of hostile foreign cyber actors as a national intelligence priority within the National Intelligence Priorities Framework, with a report due within 180 days.
The bill’s own findings frame the stakes:
- $7.5 billion. The FBI’s Internet Crime Complaint Center attributes at least this much in 2025 losses to these networks — a figure the Bureau itself calls conservative.
- $119 billion a year. The Consumer Federation of America’s estimate of what Americans lose annually to online scams.
- State-linked actors. The named targets are transnational cybercriminal and scam-center networks, several with documented ties to foreign governments and illicit-finance actors.
That last detail is the point for CI. Congress is recognizing that cyber-enabled threats, and the actors behind them, belong inside the counterintelligence mission. For a CI office, that is less a new mandate than a formal acknowledgment of something already true in the casework: cyber activity is increasingly entangled with the cases, sources, and assessments a CI program already owns.
Where Cyber CI Breaks Down Today
Most counterintelligence offices already do cyber CI. The problem is where it lives. Computer network defense telemetry sits in one system, digital forensics products in another, and cyber threat reporting arrives by email or in a threat-intelligence platform that was never designed to talk to a case management system. The CI cases those cyber threats bear on live somewhere else entirely.
So when a hostile cyber actor is named — by an overseer, by leadership, by a partner agency — the question that follows is almost always the same: how does this touch us? Which of our cases involve this actor or its infrastructure? Which sources or facilities are exposed? In too many programs, answering that means standing up a team to reconstruct the picture by hand, pulling threads from four tools and someone’s memory. It is slow, error-prone, and it erodes credibility at exactly the moment visibility matters most.
AxIS Cyber Module: Built to DoD 5240.23
AxIS Cyber Module is built to close that gap. Aligned to DoD 5240.23, the framework governing counterintelligence activities in cyberspace, it gives a CI office a single place to execute and record CI activities in cyberspace, computer network defense, and digital forensics. Every cyber CI action — a network defense event worked, a forensic examination completed, a threat indicator assessed — is captured as attributable data the moment it happens, in the same environment as the rest of the CI mission.
Correlation, Not a Separate Lane
Because cyber CI activity is recorded as structured case data rather than scattered across disconnected tools, it can be tied directly to the cases, collections, and analysis it relates to. AxIS Cyber Module correlates the cyber threat picture to the case portfolio continuously: which cyber threats touch which cases, which sources or assessments are affected, and how the cyber picture is reshaping the broader CI threat analysis. Cyber stops being a parallel workstream reconciled after the fact and becomes an integrated part of how the office sees its own operations.
Section 607 is a signal, not an isolated requirement. It reflects where counterintelligence is heading: cyber is now part of the mission, and programs will be measured on whether they can see it. AxIS Cyber Module is how a CI office keeps that picture connected to the cases, collections, and analysis it already owns.
See this capability in action.
Book a briefing with the AxIS team.