CISA 2015: what it was and why it mattered
The Cybersecurity Information Sharing Act of 2015 (CISA 2015) was enacted to facilitate voluntary sharing of cyber-threat information between the private sector (companies, infrastructure operators) and the federal government (and among private parties).
Under CISA 2015:
- Private entities could share “cyber threat indicators” and “defensive measures” (for example, malware signatures, methods of exploitation, malicious IPs/domains) with federal agencies and other private entities, for a “cybersecurity purpose”.
- The law provided liability protections for entities that act in accordance with the statute, :[n]o cause of action shall lie or be maintained in any court against any private entity …” in relation to monitoring, sharing or receiving threat indicators as permitted under the Act.
- It ensured that the information voluntarily shared was exempt from certain disclosure obligations (state or federal) and that federal agencies could not use the shared indicators to regulate the lawful activities of the provider.
- It required that personally identifiable information (PII) not directly relevant to a cybersecurity threat be removed before sharing.
- The law included reporting and oversight requirements: e.g., reporting to Congress on how many threat indicators were shared, how they were used, and the privacy/civil-liberties impacts.
- It stipulated that participation was voluntary: the federal government could not mandate private entities to share threat indicators.
In short, CISA 2015 created an incentive and legal regime for information-sharing that many in the cybersecurity world treat as a core pillar of modern U.S. cyber-defence strategy: the private sector sees, blocks or mitigates attacks; sharing that intelligence with government and peers helps build collective awareness and response.
A recent Government Accountability Office (GAO) review concluded that the law “encourages the sharing of (1) cyber threat indicators … and (2) defensive measures … which can enhance federal and non-federal awareness of the extent and type of current cyber threats and attacks.”
The lapse and its implications
However, CISA 2015 included a sunset: it was set to expire on September 30, 2025 absent reauthorisation. On or about that date the legal protections expired. The expiration generated concern across industry, infrastructure operators and policy-makers for several reasons.
One key piece: the liability protections and safe-harbour that encouraged sharing are no longer guaranteed. Legal and cybersecurity professionals warn that without such protections, companies may become more reluctant to share threat indicators — because of fear of liability, antitrust exposure, regulatory or civil suits.
For example, a recent article noted: “CISA’s expiration wouldn’t just be a bureaucratic hiccup — it would trigger a cascade of consequences across our digital infrastructure … the act’s safe harbour provisions … form the legal backbone that allows private companies to share cyber threat indicators … Remove these protections, and organisations will retreat into information silos, leaving us blind to emerging threats.
This backdrop sets the stage for the new bill by Senators Peters and Rounds.
What the new proposal proposes
The bipartisan bill — currently referred to as the Protecting America from Cyber Threats Act (working title) — aims to restore and modernise the core CISA 2015 framework for voluntary cyber-threat information-sharing. Key features include:
- Reauthorisation of the statutory framework
The bill would restore the statutory regime that enables private entities to share cyber-threat indicators and defensive measures with the federal government and each other, with liability and antitrust protections.
Industry commentary indicates that the proposal seeks a 10-year reauthorisation of these protections. - Retroactive coverage of the lapse period
One of the features publicised is that the bill would aim to provide retroactive legal coverage to companies that shared threat information during the period of the lapse (i.e., after September 30, 2025) so as to avoid a chilling effect. - New language for AI-enabled threat-sharing
According to summary material, the proposed version explicitly adds language to allow the use of artificial-intelligence (AI) tools in threat-sharing contexts (i.e., shareable indicators generated or processed via AI). This reflects recognition of how threat-intelligence operations increasingly incorporate AI/ML. (Note: full text may still be draft/unreleased.) - Modernisation of definitions and scope
While anchored in the CISA 2015 framework, the bill reportedly considers updates around definitions of “cyber-threat indicator”, “defensive measure”, and what constitutes eligible entities for sharing. It would likely clarify which private entities (including small/rural critical-infrastructure operators) are eligible and clarify how sharing flows and oversight are managed. Industry commentary notes support for expanding to include rural/critical infrastructure operators. - Privacy and civil-liberties safeguards
The proposed bill emphasises that the sharing regime must include protections around how shared information is used, limits on regulatory or enforcement use of the shared data, and removal of personally identifiable information. For example, the bill is supported by industry groups in part because it includes “required privacy protections, limits on the use of shared information for regulatory purposes or enforcement actions … and clauses to ensure there is no lapse in legal protections.” - Renaming and clarity
The new bill reportedly renames the authority (i.e., moves away from “CISA” acronym which overlaps with the Cybersecurity and Infrastructure Security Agency) to avoid confusion.
In short: the bill is intended not merely to extend the previous statute but also bring it into alignment with present-day cyber-threat operations (including AI) and restore the continuity of legal protections.
Why it matters: the strategic importance
1. Private-public coordination and critical infrastructure defence
In the U.S., much of the critical infrastructure (energy, utilities, telecommunications, transportation, finance) is privately owned or operated. The federal government, therefore, cannot defend it alone; timely and actionable threat information coming from the private sector is vital. When a company detects a new piece of malware or a novel exploitation method, sharing that indicator with appropriate peers and government agencies enables a collective defence posture. The reauthorisation of the sharing framework matters because it enables that dynamic to continue effectively.
Without legal protections, private entities may hesitate to share — slowing down detection, information dissemination, and mitigation efforts. That in turn may reduce the overall resiliency of national cyber-defence. Industry voices already warn that the lapse could degrade information-sharing.
2. Liability and safe-harbour: reducing barriers to sharing
One of the most tangible barriers for companies in sharing threat intelligence is fear of litigation or regulatory exposure. The original CISA 2015’s liability protections helped address that by giving firms a clearer legal incentive to share voluntarily. The proposed bill retains and extends that principle, which fosters more open sharing of indicators, quicker dissemination of intelligence, and potentially faster incident response across sectors.
3. Modern threats and technological change
Attackers today are more sophisticated and use tools like AI/ML, supply-chain compromise, zero-day vulnerabilities, cloud-native attacks, and OT/IT convergence. The threat landscape has evolved significantly since 2015. By explicitly adding AI-related language and modernising definitions, the new bill acknowledges that old frameworks must be adapted. This matters if the regime is to remain fit for purpose.
4. Continuity and certainty for industry
When liability protections expire without a replacement, companies face uncertainty. That uncertainty itself may deter sharing. By providing long-term (e.g., 10-year) reauthorisation, the new bill seeks to give continuity, reduce the “gap risk” and give firms more confidence in investing in threat-sharing programmes, participating in government-industry initiatives, and deploying defence tools.
5. National security and economic stability
Cyber-threats aren’t purely technical; they have national security and economic consequences (e.g., ransomware attacks on infrastructure, supply-chain compromises, espionage). Effective threat-sharing helps mitigate such risks. The loss or weakening of such a regime could increase vulnerability, potentially raising the cost of incidents, downtime, regulatory scrutiny, and reputational damage.
Key provisions and issues to watch
Below are core aspects of the bill and critical considerations for stakeholders.
A. Scope of eligible entities and coverage
Who can share? One question: which private entities are eligible for the protections under the new law? Under CISA 2015, “private entity” included private companies and state/local/tribal governments (when performing utility services) but excluded foreign powers under FISA.
In the new bill, watch whether:
- small businesses, rural utilities, and local providers are explicitly included or given incentives;
- critical infrastructure sectors (e.g., rural electric co-ops, small water utilities, small transport networks) are covered;
- There are carve-outs or limitations on which types of entities can participate.
Industry commentary indicates hope for inclusion of small/rural/critical infrastructure operators.
B. Definition of “cyber-threat indicator” and “defensive measure”
Precise definitions are key: what counts as a threat indicator? What qualifies as a defensive measure? Under CISA 2015, a “cyber threat indicator” included info such as malicious reconnaissance, a method of defeating a security control, a security vulnerability, malicious cyber command applied to a system, etc.
For the new bill, watch how:
- The definitions may be updated (e.g., to include AI-derived indicators, anomaly-detection results, threat-actor profiles, cloud/OT indicators)
- The delimitation between what must be removed (PII) vs what may be shared is clarified
- The scope of “defensive measure” is re-examined — e.g., whether proactive blocking, threat-hunting, cyber-insurance data qualifies
The clarity (or lack thereof) of these definitions will impact how confidently private entities share under the statute.
C. Liability protections and safe harbours
One of the hallmark features of the original law was liability protection: if you share indicators in accordance with the statute, you cannot be sued for doing so, or have private causes of action maintained.
Key issues for the new bill:
- whether the protections cover both “monitoring” and “sharing” (CISA 2015 covered both).
- whether the protections are contingent on compliance with certain rules (e.g., removal of PII, use of the Government-designated sharing channels).
- how “sharing” is defined (who shares with whom) and whether private-to-private sharing is covered.
- whether the statute explicitly prohibits the shared information from being used for regulatory enforcement or as basis for liability/regulation of the provider. The original law did so: e.g., indicators shared could not be used by federal agencies to regulate the lawful activities of the provider.
- how retroactive coverage is handled (for the lapse period) and whether safe-harbour is fully retrospective or limited.
- how antitrust exposure is handled: if multiple competitors share intelligence, does that raise antitrust or collusion concerns? The new bill may provide explicit antitrust safe-harbours.
D. Privacy, civil liberties and governance safeguards
Threat sharing must be balanced with the protection of personal privacy, civil liberties, and the prevention of misuse of data. Key issues:
- Removal of PII: Under CISA 2015, private entities were required to remove “identifying information about a specific person that is not directly related to a cybersecurity threat” before sharing.
- Use limitations: The new bill emphasises that information shared should not be used for regulatory enforcement of the providing entity’s lawful business activities. Industry commentary highlights this as a feature.
- Oversight and reporting: Will the bill include strong requirements for transparency, audits, reporting to Congress, IG reviews, privacy and civil-liberties boards? The original had reporting obligations.
- Restrictions on sharing: Will the new law limit how the shared information flows among private parties, or from government back to private parties? Will there be classification controls or sensitive-use restrictions?
- Integration of AI: Given the addition of AI language, how will the law ensure that AI-derived threat intelligence respects privacy safeguards and is not overly broad or misused?
- Accountability: What happens if an entity misuses the information shared (e.g., for competitive advantage or regulatory avoidance)? Are there enforcement penalties or disqualifications from protection?
E. Use of AI & modernisation of threat-sharing
A distinguishing feature of the new proposal is the explicit inclusion of AI in the threat-sharing framework. With threat-actors increasingly using AI/ML for automation, phishing campaigns, adversarial modelling, and defenders similarly turning to AI for detection, the law must reflect that reality.
Considerations include:
- Does the statute clarify that threat indicators generated via AI/ML (for example, anomalous traffic flagged by AI) count as valid “cyber-threat indicators”?
- Does it allow sharing of aggregated/derived intelligence (e.g., behavioural analytics results) as opposed to just raw signatures or domains?
- How does the law treat AI-augmented sharing systems with respect to the removal of PII and accuracy/false positive risk?
- Are there special oversight provisions for AI use (e.g., accountability for algorithmic bias, false positives, misuse) when threat indicators are generated and shared via AI tools?
F. Oversight, transparency and governance
To maintain trust (both from the public and from private-sector participants), governance is key. The new bill should (and likely will) stipulate:
- which federal agencies receive/share indicators (e.g., DHS, FBI, sector-specific agencies) and how quickly the sharing must happen.
- automated real-time sharing channels, building on the original law’s Automated Indicator Sharing (AIS) framework.
- reporting to Congress: number of indicators shared, distribution, removal of PII, use of info by government, effect on privacy/civil-liberties. The original law required periodic reports.
- Auditing and inspectors-general oversight: Did the government misuse the information? Did private entities violate rules?
- Sunset or periodic review provisions: although this new bill seeks long reauthorisation (10 years), there may still be mandated reviews.
- Government must “not require” private entities to share (voluntary nature preserved) to avoid compulsory mandates. This remains a key trust factor. The original law preserved voluntariness.
G. Alignment with broader regulatory environment
The new bill does not operate in a vacuum. Considerations include:
- Interplay with sector-specific cybersecurity regulation (e.g., for finance, energy, health, telecom). Will indicators shared under this statute be used by regulators in those sectors? The industry commentary highlights concern about not using shared information for regulatory enforcement.
- Relationship with privacy laws and data-protection regimes (e.g., GDPR in Europe, state privacy laws). The act must respect limitations under other applicable laws and define how remediation of PII is handled.
- Global information-sharing and trans-border issues: threat-actors operate globally; will sharing frameworks cover cross-border sharing? Will foreign private entities be included or excluded?
- Emerging technology issues: IoT, OT/ICS (operational technology / industrial control systems), supply-chain threats — how comprehensively will the sharing regime cover these?
- Incentives and cost-sharing: Will the act include incentives for smaller entities to participate (grants, cost-sharing, federated sharing mechanisms)?
- Public-private trust: Private firms must trust that their shared data won’t be misused by government or competitors; conversely, government must trust private data. The statute must foster that trust.
Potential Benefits and Risks
Benefits
- Enhanced situational awareness: With more threat indicators shared, both government and private actors gain faster visibility into emerging threats, enabling quicker response.
- Faster incident response: Shared intelligence can accelerate detection and mitigation across organisations, e.g., if Company A detects a novel ransomware variant and shares it, Company B can pre-emptively block it.
- Reduced duplication of effort: Private entities acting in silos may duplicate investigations; sharing allows collective defence, better prioritisation of resources.
- Stronger resilience for critical infrastructure: Given that many critical sectors are privately operated, the regime helps ensure that small/midsize operators can receive high-quality intelligence and defend accordingly.
- Legal clarity and reduced hesitation: With liability safe-harbours reinstated, companies may feel more comfortable participating in threat-sharing without fear of being sued for doing the “right thing”.
- Modernisation to reflect current threats: Inclusion of AI, clearer definitions, better flow of indicators equals a better fit for today’s threat environment.
Risks and concerns
- Privacy and civil liberties: Even with PII removal requirements, threat indicators may still carry fragments of personal data (for example, endpoint telemetry). How rigorously is “PII removal” applied? Could sharing inadvertently reveal private individuals?
- Over-broad definitions / mission creep: If “cyber-threat indicator” is defined too broadly, there is a risk that very generic data (or legitimate business information) gets swept in, raising concerns about misuse or regulatory leverage.
- Use of shared data for enforcement/regulation: Private firms may worry that the government will use the data they share to regulate or penalise them rather than solely for threat-mitigation. The statute must sustain clear walls.
- Information-asymmetry/trust issues: If smaller firms feel they receive fewer benefits than larger ones, or worry that sharing may expose them to competitive disadvantage, participation may drop.
- False positives / bad intelligence: AI-derived indicators or shared data might result in false positives, wasteful blocks, or worse, interruption of critical services. Oversight must mitigate that.
- Lapse/continuity risk: The current gap (post-September 30, 2025) may have already weakened sharing; if the reauthorisation is delayed further, the weakened regime may cause lasting damage to sharing culture.
- Dependence on voluntary regime: Because participation is voluntary, if firms choose not to share, coverage may be uneven; adversaries may exploit the weakest links.
- Complexity for small operators: The burden of compliance (legal reviews, PII removal, sharing mechanisms) may be harder for small rural utilities or small businesses, creating “information deserts”.
What to watch going forward
As the legislative process unfolds, here are key questions and indicators to track:
- Timeline for passage: Will the Senate and House move quickly? Delays risk further erosion of sharing incentives. Recent commentary suggests there is urgency, but also obstacles.
- Length and terms of reauthorisation: Is the bill indeed for 10 years? Is it a “clean” extension or are major amendments attached (e.g., mandates, new oversight, sector-specific carve-outs)?
- Retroactive protection details: How broad is retroactive coverage for companies that shared during the lapse period? Are there conditions (e.g., proof of sharing) or exclusions?
- Definition of eligible entities: Are small/medium-sized operators, rural utilities, non-traditional critical sectors (e.g., health-tech, cloud service providers) covered?
- Requirements/triggers for sharing: Are there incentives or minimum standards? Is sharing purely voluntary, or will some entities be required (either by statute or via sector-regulator) to share certain classes of data?
- Privacy safeguards and use limitations: How strictly will the new law require PII removal? How are “defensive measures” defined? Will the statute impose audit/penalty regimes if governments misuse shared data?
- AI-related language and risk management: How is AI explicitly treated? Does the law address algorithmic transparency, bias, reliability, and governance of AI-derived threat indicators?
- Government back-flow and dissemination: When the government receives indicators, how quickly are they shared with other entities? Are there standards for timeliness and distribution?
- Reporting, oversight, transparency: Will the bill require robust periodic reporting (number of indicators shared, use by government, resulting actions, privacy/civil-liberties impact)? Will independent oversight bodies have access?
- Budget and resources: Will the federal government (e.g., via DHS) allocate resources to build/operate the sharing infrastructure for the next decade? Sharing mechanisms (automation, real-time feeds) need investment.
- Alignment with other laws: How will the statute align with sector-specific regulatory regimes (e.g., energy, finance, healthcare), with state privacy/data-protection laws, and with international sharing frameworks?
- Impact on industry behaviour: Once passed, will the bill actually re-incentivise sharing? Will we see an uptick in participation? How will smaller firms engage?
- Gap consequences: Because the protections lapsed as of September 30, 2025, what is the interim impact? Are firms already withholding from sharing? Will the new law include mitigation for this gap (retroactivity)? Industry commentary indicates concern.
Implications for stakeholders
Private sector (industry, operators, cyber-defence firms)
Companies across sectors should pay attention and take proactive steps:
- Re-evaluate whether they currently participate in threat-sharing programmes (e.g., AIS, ISACs, ISAO) and whether they rely on liability protections.
- If the law reauthorises protections and expands scope, consider expanding sharing programmes (e.g., into OT/ICS, cloud, supply-chain).
- Ensure internal legal/compliance teams are aware of the lapse period, and if the new law includes retroactive coverage, ensure documentation of past sharing is preserved.
- Assess data-sharing workflows: Are mechanisms robust, is PII removal systematic, is sharing meaningful (i.e., high-quality indicators)?
- Review partnerships with industry ISACs/ISAOs, government sharing programmes and vendors. Consider how AI-derived indicators can be fed into sharing channels.
- Incorporate the reauthorised regime into cyber-risk assessments and cyber-insurance underwriting; insurers will likely adjust their view of sharing behaviour in light of legal changes.
Government & regulators
- Federal agencies (especially DHS, CISA, FBI, sector-specific regulators) need to plan for the reauthorised regime: build the infrastructure, real-time automated sharing capability, ensure capacity for ingesting, sanitising, analysing, and distributing indicators.
- Federal oversight bodies (IGs, Privacy & Civil-Liberties Oversight Board) must update audit/monitoring frameworks for the new law.
- Ensure clear guidance to private-sector participants on the new sharing processes, liability protections, and expectations (including AI-derived sharing).
- Federal budget and resource planning must account for the operational costs of the sharing mechanism for the next decade.
- Regulators of sectors (e.g., energy, finance, healthcare) should coordinate with the sharing regime to ensure that sector-specific frameworks align, and there is no unintended adverse overlap (e.g., regulatory use of shared data).
Civil-liberties/community/academic stakeholders
- Privacy advocates should scrutinise the new definitions and ensure robust safeguards against misuse or mission creep. For instance, will AI-derived indicators carry the risk of over-collection of personal data?
- Researchers and academia can pursue studies of how effective threat-sharing programmes are in practice (e.g., number of incidents prevented, speed of incident response improved) and whether transparency and oversight are adequate.
- Civil-society groups should monitor whether shared data is protected appropriately (e.g., anonymised, not used for non-cybersecurity enforcement) and whether smaller organisations (non-profits, local governments) are adequately included.
Challenges and open questions
- Will Congress pass the bill in time? Given the lapse of the prior protections, there is a risk that the new statute is delayed, leaving companies without clear safe-harbours and potentially reducing information-sharing in the interim. Some industry commentary already warns that companies may be slowing down sharing.
- Will the new regime meaningfully increase sharing? Having legal protections is necessary but not sufficient. Companies still need capability, incentives, and trust to share high-quality indicators. If the burden (legal, cost, compliance) remains high, participation may remain limited.
- Balance between speed and oversight: Threat intelligence often benefits from real-time sharing—but oversight and privacy checks slow things down. The regime must strike a challenging balance.
- Inclusion of smaller entities: Large firms may already have sharing programmes; smaller firms (and especially rural or less resourced operators) may not. Unless the law and its implementation include support (financial, technical), these “weaker links” may reduce the overall benefit.
- Effect of AI integration: While inclusion of AI in the law is forward-looking, it raises questions: how will accuracy be ensured, how will false positives be managed, and could AI-derived sharing lead to over-block or unintended consequences?
- Measurement of effectiveness: How will success be measured? Number of indicators shared? Time to respond? Number of incidents prevented? Without metrics, it’s hard to demonstrate return on investment.
- Global coordination and cross-border sharing: Cyber threats often span borders; will the U.S. regime align with or recognise foreign sharing frameworks? Will foreign entities be included? How will data-localisation or export-control issues play out?
- Interaction with compliance/regulation: Some sectors (finance, health) already have stringent cybersecurity regulations. Does threat-sharing under this statute overlap or conflict with those frameworks? Will regulated entities be reluctant to share unless regulatory consequences are clear?
- Trust and culture: Sharing culture remains a human/organisational challenge. Legal regime is one piece; trust, reward/incentive structures, cross-sector collaboration, and technical standards all play a role.
Contact RedFort Technologies
For partnership inquiries or federal technology support, reach us at info@redforttech.com or visit www.redforttech.com.
Conclusion
The proposed “Protecting America from Cyber Threats Act” is a timely and important legislative initiative. It seeks to restore and modernise a fundamental building block of U.S. cyber-defence: the voluntary sharing of cyber-threat indicators between private entities and the federal government, underpinned by clear liability protections, privacy safeguards and modernised definitions (including AI).
Given the lapse of the prior regime on September 30, 2025, the need is acute: without clear protections and sharing incentives, companies may withhold threat intelligence, slowing collective response to dynamic cyber threats. For critical infrastructure, the stakes are high—not merely technical but economic and national-security related.
At the same time, the success of the new law will depend on the details: how inclusive it is of smaller/rural operators, how definitions are drawn, how AI is integrated and governed, how oversight and privacy are balanced, and how effectively the sharing infrastructure is funded and executed. Stakeholders from industry, government, academia and civil society all have roles to play: to ensure the regime is not only extended on paper, but works in practice.
For businesses, this is a wake-up call: evaluate current threat-sharing practices, document your sharing (especially during the lapse period), prepare your legal and compliance posture, and consider how you might leverage a re-authorised regime to strengthen your cyber-resilience.
For policymakers and regulators, the bill offers a chance to set a long-term (potentially decade-long) framework for information-sharing at a time when cyber-threats are rapidly evolving (AI-enabled attacks, supply-chain intrusions, OT/ICS risks). But it also imposes responsibilities: oversight, transparency, equity among participants, and the safeguarding of civil liberties.
Ultimately, from a national cyber-resilience perspective, the hope is that this bill will prevent a retreat into information silos, bolster collective visibility of threats, accelerate incident response, and sustain the public-private partnerships upon which much of cyber-defence rests. The legislative window — and the urgency around closing the gap — are now.

