Key Takeaways
- The Cybersecurity Information Sharing Act of 2015 (CISA 2015) provides limited liability for companies that share anonymized cyber‑threat data via the Automated Indicator Sharing (AIS) platform, but this protection expires on September 30, 2026 unless renewed.
- Industry groups representing finance, energy, technology, transportation, health care, and retail have urged Congress to extend the act, calling it a foundational element of national cybersecurity.
- Critics, including cybersecurity policy professor Milton Mueller, argue that AIS has delivered minimal value, citing declining participation and low alert diversity.
- A DHS Office of Inspector General report shows non‑federal AIS users fell from 304 in late 2022 to fewer than 90 by 2024, with alert volume dropping 93 % between 2020 and 2022; a brief surge in 2023 was driven largely by a single private contributor.
- The Trump administration launched “Gold Eagle” in July 2024, an AI‑powered clearinghouse intended to replace or supplement AIS by enabling real‑time vulnerability sharing among private firms, Treasury, CISA, and the Department of Defense.
- Private‑sector sharing mechanisms—commercial threat‑intelligence feeds, ISACs, the Cyber Threat Alliance, and the newly formed Alliance for Critical Infrastructure—already provide robust alternatives, though data sharing always carries regulatory, litigation, and reputational risks that CFOs must weigh.
Background of the Cybersecurity Information Sharing Act (CISA) 2015
The Cybersecurity Information Sharing Act of 2015 was enacted to promote voluntary exchange of cyber threat information between private companies and the federal government while shielding participants from certain liabilities. Under the statute, non‑federal entities may submit anonymized indicators—such as malicious IP addresses, file hashes tied to malware, and known hostile web domains—through the Automated Indicator Sharing (AIS) platform managed by the Cybersecurity and Infrastructure Security Agency (CISA). The goal was to create a rapid‑response network that improves situational awareness and enables coordinated defenses across critical sectors.
Current Status and Impending Expiration
The liability shield granted by CISA 2015 is set to lapse on September 30, 2026, unless Congress takes action to renew the provision. After that date, firms that continue to share cyber‑threat data via AIS could lose the statutory protection that insulates them from civil lawsuits and regulatory penalties stemming from the disclosed information. The approaching deadline has prompted stakeholders to evaluate whether the existing framework still meets the nation’s cybersecurity needs or whether a replacement mechanism is necessary.
Industry Associations’ Call for Extension
In July 2024, twenty‑three trade associations representing finance, energy, technology, transportation, health care, and retail sent a letter to House Speaker Michael Johnson (R‑LA) urging an extension of CISA 2015. They characterized the act as a “foundational component of the nation’s cybersecurity” and argued that its liability protections are essential for sustaining the voluntary sharing model that has become integral to threat‑intelligence ecosystems across multiple industries.
Criticisms of the Automated Indicator Sharing (AIS) Program
Not all observers view the AIS program favorably. Milton Mueller, a cybersecurity policy professor at Georgia Institute of Technology, described the initiative as a “failure from the get‑go” that delivers little practical value. He contends that the machine‑readable indicators exchanged through AIS are largely redundant and that the program does not meaningfully improve defensive capabilities for most participants, questioning its continued relevance.
Federal Oversight and Performance Data
Supporting Mueller’s skepticism, a Department of Homeland Security Office of Inspector General report revealed declining participation in AIS. The number of non‑federal users fell from a peak of 304 in late 2022 to fewer than 90 by 2024, while overall alert volume dropped 93 % between 2020 and 2022. Although a brief spike to 10 million alerts occurred in 2023, the OIG found that 89 % of that surge originated from a single private‑sector contributor, suggesting limited breadth of engagement across the broader community.
Administration’s Alternative: Gold Eagle Initiative
Seeking to bypass legislative delays, the Trump administration unveiled “Gold Eagle” in July 2024 as a new clearinghouse for cybersecurity vulnerability information. The platform aims to facilitate real‑time sharing of threat data and coordinated responses among private industry, the Treasury Department, CISA, and the Department of Defense, leveraging frontier artificial intelligence that purportedly matches or exceeds human‑level analytical capabilities. Details remain sparse, but the initiative is positioned as a potential successor to AIS.
Existing Private‑Sector Sharing Mechanisms
Even if CISA 2015 lapses, private‑sector cybersecurity information sharing is not a novel concept. Since 1999, firms have participated in commercial threat‑intelligence feeds, sector‑specific Information Sharing and Analysis Centers (ISACs), and consortia such as the Cyber Threat Alliance. Mueller notes that these alternatives already provide robust intelligence exchange, reducing reliance on a federal program and offering firms flexibility in how they obtain and disseminate threat data.
Alliance for Critical Infrastructure and Its Goals
A recent effort to consolidate cross‑sector collaboration is the Alliance for Critical Infrastructure, formerly the Tri‑Sector Executive Working Group, now rebranded as a 501(c)(6) nonprofit. Founding members include AIG, AT&T, Berkshire Hathaway Energy, Consolidated Edison, JPMorgan Chase, Lumen Technologies, Mastercard, Southern Company, and Xcel Energy. The alliance aims to bolster national resilience, mitigate systemic risk, and maintain economic continuity through joint threat‑intelligence and incident‑response initiatives that span multiple critical‑infrastructure sectors.
Legal and Operational Risks of Sharing Cyber Data
Sharing cybersecurity data carries inherent risks. Mary Alexander Myers, head of Jones Day’s Cybersecurity, Privacy & Data Protection practice, warns that once information is disclosed, it may be accessed by regulators, litigants, or insurers, potentially shaping the nature and scope of subsequent legal or regulatory actions. Companies must therefore weigh the defensive benefits of sharing against possible exposure to liability, reputational harm, and the costs associated with defending against claims that arise from shared indicators.
Strategic Considerations for CFOs and Board‑Level Governance
For chief financial officers, the uncertainty surrounding CISA’s liability shield adds another layer of risk to an already complex risk landscape. As cyber governance migrates from IT departments to board‑level agendas, CFOs and other C‑suite executives must decide whether a reauthorized CISA 2015, the Gold Eagle system, or existing private‑sector channels provide sufficient confidence to continue sharing threat intelligence without fearing regulatory penalties or costly litigation. Their analysis will influence budgeting, insurance decisions, and the overall cyber‑risk posture of the organization.
Conclusion and Outlook
The fate of CISA 2015 hinges on congressional action before the September 30, 2026 deadline. While industry leaders advocate for renewal, critics argue the program is obsolete and point to emerging alternatives like Gold Eagle and established private sharing networks. Ultimately, organizations will need to assess the effectiveness, legal safeguards, and strategic alignment of any sharing mechanism they adopt to ensure a resilient cybersecurity posture in an evolving threat environment.

