If not renewed, CISA 2015 protections end in the US on September 30.

This article appears in the September issue of Global Finance Magazine.

Companies that share cybersecurity information with their peers have until Sept. 30, 2026, before the limited liability granted by the Cybersecurity Information Sharing Act of 2015 runs out, exposing them to potential regulatory scrutiny and penalties.

Under the Act, non-federal entities may share anonymized cyberattack and response information with other non-federal entities and the federal government via the Automated Indicator Sharing (AIS) program operated by the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA).

In July, 23 industry associations that represented the financial services, energy, technology, transportation, healthcare, and retail sectors wrote to Speaker of the House Michael Johnson (R-LA) requesting an extension to the Act since it is “a foundational component of the nation’s cybersecurity.”

However, some view AIS as a relic of an earlier era of cyberdefense that provides machine-readable cyber threat indicators and defensive measures against malicious IP addresses, file hashes associated with malware distribution, and known malicious web links.

“It was a failure from the get-go, and it accomplishes nothing,” Milton Mueller, a professor of cybersecurity policy at Georgia Institute of Technology’s Jimmy and Rosalynn Carter School of Public Policy, told Global Finance. “No one will notice when it’s gone.”

A web post by Mueller earlier this year cited a DHS Office of Inspector General (OIG) report stating that non-federal participants using AIS fell to fewer than 90 in 2024 from a high of 304 in late 2022. The report also noted that alert volume on the platform dropped 93% between 2020 and 2022. Though there was a surge in alerts, to 10 million from 1 million, the OIG found that 89% of the data came from a single private-sector participant.

“The non-Federal participants we interviewed stated that they find AIS useful and an effective tool for protecting their systems from cyber threats,” wrote the report’s authors. “However, the number of non-Federal participants remained lower in 2023 and 2024 than in previous years. AIS now has 87 non-Federal participants compared to 252 in 2020.”

Nonetheless, the House of Representatives included an extension to the Act in part of the 2027 National Defense Authorization Act, which is waiting for Senate approval.

In July, the Trump administration sidestepped legislative concerns and created “Gold Eagle,” a clearinghouse to share cybersecurity vulnerability information and coordinate responses among private industry and federal agencies, including the U.S. Treasury Department, CISA, and the U.S. War Department, formerly the Defense Department. The new system will be powered by frontier artificial intelligence, which emulates and may surpass human-level intelligence.

Private Data Sharing Alternatives

Although CISA 2015’s renewal is up in the air and details regarding Gold Eagle are sparse, private industry has had formalized cybersecurity data-sharing programs since 1999.

“There is plenty of threat intelligence sharing going on,” said GeorgiaTech’s Mueller. “There are commercial services, sectoral nonprofit Information Sharing and Analysis Centers (ISACs), and industry consortia like the Cyber Threat Alliance.”

The newly rebranded Alliance for Critical Infrastructure (formerly the Tri-Sector Executive Working Group) seeks to bring together critical infrastructure operators to strengthen national resilience and reduce systemic risk, while sustaining economic continuity.

The 501c(6) non-profit industry coalition started with nine founding members: American International Group Inc., AT&T Inc., Berkshire Hathaway Energy Co., Consolidated Edison Inc., JPMorgan Chase & Co., Lumen Technologies Inc., Mastercard Inc., The Southern Co., and Xcel Energy Inc.

Since its formation, the organization has been on a membership drive, with JPMorgan Chase CEO Jamie Dimon reportedly having private conversations with numerous companies across industry sectors to join the alliance.

Despite the benefits of sharing cybersecurity data, such as faster and broader threat detection and coordinated responses, sharing that data is not risk-free for a corporation.

“When information is shared, one should assume that information could be obtained by others, including regulators, litigants, and insurers, and that can inform the nature, contour, and context of the sharing,” said Mary Alexander Myers, lead of law firm Jones Day’s Cybersecurity, Privacy & Data Protection practice.

For chief financial officers, uncertainty around CISA’s liability shield adds another costly risk to the existing risk landscape. As cyber governance moves from the realm of IT to a board-level issue, CFOs and other C-level executives will have to determine if a reauthorized CISA 2015 or Gold Eagle provides them with enough confidence to continue to share cybersecurity information without the fear of regulatory penalties.

Rob Daly covers fintech and the economy. Contact him at rdaly@gfmag.com.

Source link

Leave a Reply

Discover more from Occasional Digest

Subscribe now to keep reading and get access to the full archive.

Continue reading