Site icon RedFort Tech

Rebuilding America’s Cyber Shield: Inside the Peters-Rounds Bill to Renew Threat-Information Sharing

CISA 2015: what it was and why it mattered

The Cybersecurity Information Sharing Act of 2015 (CISA 2015) was enacted to facilitate voluntary sharing of cyber-threat information between the private sector (companies, infrastructure operators) and the federal government (and among private parties). 

Under CISA 2015:

In short, CISA 2015 created an incentive and legal regime for information-sharing that many in the cybersecurity world treat as a core pillar of modern U.S. cyber-defence strategy: the private sector sees, blocks or mitigates attacks; sharing that intelligence with government and peers helps build collective awareness and response.

A recent Government Accountability Office (GAO) review concluded that the law “encourages the sharing of (1) cyber threat indicators … and (2) defensive measures … which can enhance federal and non-federal awareness of the extent and type of current cyber threats and attacks.” 

The lapse and its implications

However, CISA 2015 included a sunset: it was set to expire on September 30, 2025 absent reauthorisation. On or about that date the legal protections expired. The expiration generated concern across industry, infrastructure operators and policy-makers for several reasons.

One key piece: the liability protections and safe-harbour that encouraged sharing are no longer guaranteed. Legal and cybersecurity professionals warn that without such protections, companies may become more reluctant to share threat indicators — because of fear of liability, antitrust exposure, regulatory or civil suits. 

For example, a recent article noted: “CISA’s expiration wouldn’t just be a bureaucratic hiccup — it would trigger a cascade of consequences across our digital infrastructure … the act’s safe harbour provisions … form the legal backbone that allows private companies to share cyber threat indicators … Remove these protections, and organisations will retreat into information silos, leaving us blind to emerging threats. 

This backdrop sets the stage for the new bill by Senators Peters and Rounds.

What the new proposal proposes

The bipartisan bill — currently referred to as the Protecting America from Cyber Threats Act (working title) — aims to restore and modernise the core CISA 2015 framework for voluntary cyber-threat information-sharing. Key features include:

  1. Reauthorisation of the statutory framework
    The bill would restore the statutory regime that enables private entities to share cyber-threat indicators and defensive measures with the federal government and each other, with liability and antitrust protections.

    Industry commentary indicates that the proposal seeks a 10-year reauthorisation of these protections.
  2. Retroactive coverage of the lapse period
    One of the features publicised is that the bill would aim to provide retroactive legal coverage to companies that shared threat information during the period of the lapse (i.e., after September 30, 2025) so as to avoid a chilling effect.
  3. New language for AI-enabled threat-sharing
    According to summary material, the proposed version explicitly adds language to allow the use of artificial-intelligence (AI) tools in threat-sharing contexts (i.e., shareable indicators generated or processed via AI). This reflects recognition of how threat-intelligence operations increasingly incorporate AI/ML. (Note: full text may still be draft/unreleased.)
  4. Modernisation of definitions and scope
    While anchored in the CISA 2015 framework, the bill reportedly considers updates around definitions of “cyber-threat indicator”, “defensive measure”, and what constitutes eligible entities for sharing. It would likely clarify which private entities (including small/rural critical-infrastructure operators) are eligible and clarify how sharing flows and oversight are managed. Industry commentary notes support for expanding to include rural/critical infrastructure operators.
  5. Privacy and civil-liberties safeguards
    The proposed bill emphasises that the sharing regime must include protections around how shared information is used, limits on regulatory or enforcement use of the shared data, and removal of personally identifiable information. For example, the bill is supported by industry groups in part because it includes “required privacy protections, limits on the use of shared information for regulatory purposes or enforcement actions … and clauses to ensure there is no lapse in legal protections.” 
  6. Renaming and clarity
    The new bill reportedly renames the authority (i.e., moves away from “CISA” acronym which overlaps with the Cybersecurity and Infrastructure Security Agency) to avoid confusion.

In short: the bill is intended not merely to extend the previous statute but also bring it into alignment with present-day cyber-threat operations (including AI) and restore the continuity of legal protections.

Why it matters: the strategic importance

1. Private-public coordination and critical infrastructure defence

In the U.S., much of the critical infrastructure (energy, utilities, telecommunications, transportation, finance) is privately owned or operated. The federal government, therefore, cannot defend it alone; timely and actionable threat information coming from the private sector is vital. When a company detects a new piece of malware or a novel exploitation method, sharing that indicator with appropriate peers and government agencies enables a collective defence posture. The reauthorisation of the sharing framework matters because it enables that dynamic to continue effectively.

Without legal protections, private entities may hesitate to share — slowing down detection, information dissemination, and mitigation efforts. That in turn may reduce the overall resiliency of national cyber-defence. Industry voices already warn that the lapse could degrade information-sharing. 

2. Liability and safe-harbour: reducing barriers to sharing

One of the most tangible barriers for companies in sharing threat intelligence is fear of litigation or regulatory exposure. The original CISA 2015’s liability protections helped address that by giving firms a clearer legal incentive to share voluntarily. The proposed bill retains and extends that principle, which fosters more open sharing of indicators, quicker dissemination of intelligence, and potentially faster incident response across sectors.

3. Modern threats and technological change

Attackers today are more sophisticated and use tools like AI/ML, supply-chain compromise, zero-day vulnerabilities, cloud-native attacks, and OT/IT convergence. The threat landscape has evolved significantly since 2015. By explicitly adding AI-related language and modernising definitions, the new bill acknowledges that old frameworks must be adapted. This matters if the regime is to remain fit for purpose.

4. Continuity and certainty for industry

When liability protections expire without a replacement, companies face uncertainty. That uncertainty itself may deter sharing. By providing long-term (e.g., 10-year) reauthorisation, the new bill seeks to give continuity, reduce the “gap risk” and give firms more confidence in investing in threat-sharing programmes, participating in government-industry initiatives, and deploying defence tools.

5. National security and economic stability

Cyber-threats aren’t purely technical; they have national security and economic consequences (e.g., ransomware attacks on infrastructure, supply-chain compromises, espionage). Effective threat-sharing helps mitigate such risks. The loss or weakening of such a regime could increase vulnerability, potentially raising the cost of incidents, downtime, regulatory scrutiny, and reputational damage.

Key provisions and issues to watch

Below are core aspects of the bill and critical considerations for stakeholders.

A. Scope of eligible entities and coverage

Who can share? One question: which private entities are eligible for the protections under the new law? Under CISA 2015, “private entity” included private companies and state/local/tribal governments (when performing utility services) but excluded foreign powers under FISA. 

In the new bill, watch whether:

B. Definition of “cyber-threat indicator” and “defensive measure”

Precise definitions are key: what counts as a threat indicator? What qualifies as a defensive measure? Under CISA 2015, a “cyber threat indicator” included info such as malicious reconnaissance, a method of defeating a security control, a security vulnerability, malicious cyber command applied to a system, etc. 

For the new bill, watch how:

C. Liability protections and safe harbours

One of the hallmark features of the original law was liability protection: if you share indicators in accordance with the statute, you cannot be sued for doing so, or have private causes of action maintained. 

Key issues for the new bill:

D. Privacy, civil liberties and governance safeguards

Threat sharing must be balanced with the protection of personal privacy, civil liberties, and the prevention of misuse of data. Key issues:

E. Use of AI & modernisation of threat-sharing

A distinguishing feature of the new proposal is the explicit inclusion of AI in the threat-sharing framework. With threat-actors increasingly using AI/ML for automation, phishing campaigns, adversarial modelling, and defenders similarly turning to AI for detection, the law must reflect that reality.

Considerations include:

F. Oversight, transparency and governance

To maintain trust (both from the public and from private-sector participants), governance is key. The new bill should (and likely will) stipulate:

G. Alignment with broader regulatory environment

The new bill does not operate in a vacuum. Considerations include:

Potential Benefits and Risks

Benefits

  1. Enhanced situational awareness: With more threat indicators shared, both government and private actors gain faster visibility into emerging threats, enabling quicker response.
  2. Faster incident response: Shared intelligence can accelerate detection and mitigation across organisations, e.g., if Company A detects a novel ransomware variant and shares it, Company B can pre-emptively block it.
  3. Reduced duplication of effort: Private entities acting in silos may duplicate investigations; sharing allows collective defence, better prioritisation of resources.
  4. Stronger resilience for critical infrastructure: Given that many critical sectors are privately operated, the regime helps ensure that small/midsize operators can receive high-quality intelligence and defend accordingly.
  5. Legal clarity and reduced hesitation: With liability safe-harbours reinstated, companies may feel more comfortable participating in threat-sharing without fear of being sued for doing the “right thing”.
  6. Modernisation to reflect current threats: Inclusion of AI, clearer definitions, better flow of indicators equals a better fit for today’s threat environment.

Risks and concerns

  1. Privacy and civil liberties: Even with PII removal requirements, threat indicators may still carry fragments of personal data (for example, endpoint telemetry). How rigorously is “PII removal” applied? Could sharing inadvertently reveal private individuals?
  2. Over-broad definitions / mission creep: If “cyber-threat indicator” is defined too broadly, there is a risk that very generic data (or legitimate business information) gets swept in, raising concerns about misuse or regulatory leverage.
  3. Use of shared data for enforcement/regulation: Private firms may worry that the government will use the data they share to regulate or penalise them rather than solely for threat-mitigation. The statute must sustain clear walls.
  4. Information-asymmetry/trust issues: If smaller firms feel they receive fewer benefits than larger ones, or worry that sharing may expose them to competitive disadvantage, participation may drop.
  5. False positives / bad intelligence: AI-derived indicators or shared data might result in false positives, wasteful blocks, or worse, interruption of critical services. Oversight must mitigate that.
  6. Lapse/continuity risk: The current gap (post-September 30, 2025) may have already weakened sharing; if the reauthorisation is delayed further, the weakened regime may cause lasting damage to sharing culture.
  7. Dependence on voluntary regime: Because participation is voluntary, if firms choose not to share, coverage may be uneven; adversaries may exploit the weakest links.
  8. Complexity for small operators: The burden of compliance (legal reviews, PII removal, sharing mechanisms) may be harder for small rural utilities or small businesses, creating “information deserts”.

What to watch going forward

As the legislative process unfolds, here are key questions and indicators to track:

Implications for stakeholders

Private sector (industry, operators, cyber-defence firms)

Companies across sectors should pay attention and take proactive steps:

Government & regulators

Civil-liberties/community/academic stakeholders

Challenges and open questions

Contact RedFort Technologies

For partnership inquiries or federal technology support, reach us at info@redforttech.com or visit www.redforttech.com.

Conclusion

The proposed “Protecting America from Cyber Threats Act” is a timely and important legislative initiative. It seeks to restore and modernise a fundamental building block of U.S. cyber-defence: the voluntary sharing of cyber-threat indicators between private entities and the federal government, underpinned by clear liability protections, privacy safeguards and modernised definitions (including AI).

Given the lapse of the prior regime on September 30, 2025, the need is acute: without clear protections and sharing incentives, companies may withhold threat intelligence, slowing collective response to dynamic cyber threats. For critical infrastructure, the stakes are high—not merely technical but economic and national-security related.

At the same time, the success of the new law will depend on the details: how inclusive it is of smaller/rural operators, how definitions are drawn, how AI is integrated and governed, how oversight and privacy are balanced, and how effectively the sharing infrastructure is funded and executed. Stakeholders from industry, government, academia and civil society all have roles to play: to ensure the regime is not only extended on paper, but works in practice.

For businesses, this is a wake-up call: evaluate current threat-sharing practices, document your sharing (especially during the lapse period), prepare your legal and compliance posture, and consider how you might leverage a re-authorised regime to strengthen your cyber-resilience.

For policymakers and regulators, the bill offers a chance to set a long-term (potentially decade-long) framework for information-sharing at a time when cyber-threats are rapidly evolving (AI-enabled attacks, supply-chain intrusions, OT/ICS risks). But it also imposes responsibilities: oversight, transparency, equity among participants, and the safeguarding of civil liberties.

Ultimately, from a national cyber-resilience perspective, the hope is that this bill will prevent a retreat into information silos, bolster collective visibility of threats, accelerate incident response, and sustain the public-private partnerships upon which much of cyber-defence rests. The legislative window — and the urgency around closing the gap — are now.

Exit mobile version