
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
USTelecom is continuing to push for a long-term reauthorization of the Cybersecurity Information Sharing Act of 2015, which provides critical protections for sharing threat indicators with the government and among industry players, in the context of increased threats posed by artificial intelligence.
Summary
“We’ve all seen the headlines and read the threads -- warnings that the next generation of AI systems may be able to find and exploit vulnerabilities autonomously, at machine speed and with little human direction. The Trump Administration has even noted that it’s open to sharing information about emerging threats posed by AI with other governments. But that effort will only be as strong as the information-sharing framework we maintain here at home,” according to a Sept.
25 USTelecom post from Robert Mayer and Brandon Heiner. CISA 2015 was set to lapse on Sept. 30 but received a short-term extension to Dec.
11 as part of a continuing resolution to avoid another government shutdown ahead of the midterm elections. The CR funds the federal government through Dec. 11, pushing the deadline to pass legislation for full fiscal 2027 spending to the lame duck session.
Mayer and Heiner argue the Dec. 11 extension “provides valuable continuity and reflects the broad recognition on both sides of the aisle that real-time cyber threat sharing is essential to confronting fast-moving threats, including those increasingly enabled by AI.” They emphasize, “Now Congress has an opportunity to build on that common-sense momentum and provide the long-term certainty this successful framework needs.” CISA 2015 provides liability and antitrust protections for industry to share threat information with the Department of Homeland Security and also extends those protections to sharing between industry players. The law was originally set to expire on Sept.
30, 2025 but has received three short-term extensions since then which kicks the can down the road for a long-term authorization to Dec. 11. Lawmakers included legislation led by House Homeland Security Chairman Andrew Garbarino (R-NY) and cyber subcommittee Chair Andy Ogles (R-TN) to extend CISA 2015 through fiscal 2035 as part of the House version of the fiscal 2027 National Defense Authorization Act.
The House NDAA was passed July 22 in a 216-212 vote. The Garbarino bill, the Widespread Information Management for the Welfare of Infrastructure and Government Act , makes some tweaks to the law that have been well received by industry players. In the Senate, Homeland Security ranking member Gary Peters (D-MI) has proposed an amendment to reauthorize CISA 2015 through fiscal 2036.
The Senate Armed Services Committee advanced its version of the fiscal 2027 at a June 10 closed-door markup. Senate leadership has yet to bring the fiscal 2027 NDAA to the floor. At this point, it is possible House and Senate leadership could reach an agreement on the major defense policy bill without a floor vote for the Senate version.
Mayer and Heiner emphasize that the CISA 2015 framework “helps make the public-private partnership at the heart of America’s cyber defense work at the necessary speed and scale.” They write, “Internet service providers, equipment vendors, financial institutions, and federal agencies all rely on the confidence CISA 2015 provides to share what they are seeing on their networks quickly and candidly.” “And the timing matters,” Mayer and Heiner argue on the 10-year extension. They write, “The threat landscape has only accelerated. Nation-state actors, ransomware syndicates, and increasingly sophisticated AI-enabled attacks are probing critical infrastructure, including the communications networks that everything else depends on, on a near-constant basis.” “The faster these threats move, the more important it becomes for defenders to be able to share what they are seeing quickly and confidently,” the post says.
Passing a long-term reauthorization will provide “stability” to cybersecurity partnerships, Mayer and Heiner argue, “while allowing government and industry to focus their attention where it belongs: identifying threats, sharing actionable information and strengthening America’s collective cyber defenses.” The post was published to coincide with USTelecom’s Sept. 29 cybersecurity leadership summit , which features a fireside chat between National Cyber Director Sean Cairncross and USTelecom president and CEO Jonathan Spalter. Cairncross has made a long-term authorization of CISA 2015 one of his priorities on Capitol Hill, since he was confirmed by the Senate in 2025.
The post concludes, “Congress has already demonstrated that CISA 2015 can bring lawmakers together around a shared goal.
KazaSec's take
Incidents like this rarely start with the headline event itself — they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
Related security advisories
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.