Current News

/

ArcaMax

Cyber information-sharing law stuck in Senate stalemate

Allison Mollenkamp, CQ-Roll Call on

Published in News & Features

WASHINGTON – More than a year has passed since permanent authority for cybersecurity information-sharing protections expired, and there’s little sign that a standoff in the Senate over the law will end this Congress.

A long-term extension of the law, titled the Cybersecurity Information Sharing Act of 2015, has bipartisan backing. If Democrats win control of the Senate – and the Homeland Security and Governmental Affairs Committee – lawmakers could negotiate a future-ready version of the law that responds to artificial intelligence’s impact on cybersecurity.

Commonly called CISA 2015, the law gives liability protections, including from antitrust law, to companies sharing indicators of a cyber threat with the federal government or with each other.

A long-term reauthorization remains the subject of a blockade by Senate Homeland Security Chairman Rand Paul, R-Ky.

Despite bipartisan, bicameral efforts to reauthorize those protections, the program expired at the end of fiscal 2025. It has been renewed on a short-term basis in continuing resolutions, leaving it subject to the politics of government funding fights and opening the possibility for further lapses.

Last week, Paul said in an interview he has had an amendment “for over two years” that would, if adopted, make him supportive of a long-term authorization for CISA 2015.

“The amendment would protect freedom of speech and prevent the government from trying to restrict speech by sending the FBI to Twitter headquarters or sending the FBI to Facebook and threatening them,” Paul said. “That would become illegal.”

Paul said that he’s had multiple conversations with ranking member Sen. Gary Peters, D-Mich., about the amendment, but that those conversations haven’t gone anywhere.

Also last week, Peters said in an interview that Paul “has not allowed any kind of long-term extension to be put forward.”

“He continues to be the impediment,” Peters said. “Unless he changes his mind, it’ll still be difficult.”

Proposals

Peters is the sponsor of two bipartisan bills that would extend CISA 2015 through fiscal 2035. The first would extend the program without changes. The second, introduced during the fall 2025 partial government shutdown, includes a provision that would have made the liability protections retroactive during the period they lapsed and changed the name of the program to the “Protecting America from Cyber Threats Act.”

Last year, Paul canceled a markup that Peters said was expected to include a re-up of the cybersecurity program. He also accused Paul of conflating CISA 2015 with the Homeland Security Department’s Cybersecurity and Infrastructure Security Agency.

Paul’s plans to regulate government contacts with social media platforms come as he has expressed outrage over efforts by the agency during the Biden administration to influence online content moderation, including of posts about COVID-19 and the 2020 election.

In the House, the Homeland Security Committee voted unanimously last year to advance a bill by Chairman Andrew Garbarino, R-N.Y., that would reauthorize CISA 2015 through 2035 with select changes. That bill, like Peters’ shutdown-era one, would also rename the program, dubbing it the “Widespread Information Management for the Welfare of Infrastructure and Government Act.”

 

The House bill has not been taken up on the floor, with no indication yet if it will get a vote before the end of the year.

Paul’s stipulations for renewing CISA 2015, coupled with a crowded calendar when Congress returns to Washington after the midterms, could mean action will be left to the incoming 120th Congress.

Outlook

Prospects next year could depend on the outcome of the midterm elections. If Republicans keep control of the Senate, Paul would not be term-limited out of the chair. However, he could also be a candidate to lead the Health, Education, Labor and Pensions Committee due to Sen. Bill Cassidy, R-La., departing in January.

If Democrats win a majority in the chamber, it’s similarly uncertain who would lead the Homeland Security Committee and take a leading role in CISA 2015’s fate, as Peters is retiring.

Sen. Maggie Hassan, D-N.H., is the second most senior Democrat on the committee and a co-sponsor on Peters’ original 10-year extension bill.

In the meantime, the cybersecurity community has been able to continue sharing information under the short-term extensions, though with some impacts.

Michael Daniel leads the Cyber Threat Alliance, a membership organization for companies to share cyber threat intelligence. He said that he hasn’t seen “too much change” in information sharing in the absence of a long-term CISA 2015 extension.

Instead, he said the “uncertain status” of the program has possibly discouraged new organizations from starting or ramping up their cybersecurity information sharing. He also said the ongoing fight has distracted from other cybersecurity policy discussions.

He urged a medium-term reauthorization of CISA 2015 in its current form to give lawmakers time to update the bill for the age of artificial intelligence, including adding new types of information that companies will need to share.

“Could I make a good argument that the definitions in the existing CISA statute could cover… a lot of what we need for AI? Yes,” Daniel said. “Do I think the statute would benefit from being updated, to include definitions related to things like distillation attacks? Absolutely.”

In the year since the law originally expired, Daniel said that cybersecurity has been impacted by fewer alerts coming from CISA at DHS, as well as a change at the National Institute of Standards and Technology to only enrich, or give context to, a subset of cybersecurity vulnerabilities. He attributed both changes to lower “staffing and dollars” for cybersecurity in the federal government.

During the second Trump administration, Congress and the executive branch have wrestled over funding for CISA. The White House has asked for deeper cuts to the agency, while Congress lowered the agency’s funding for fiscal 2026, but by a more modest amount. CISA has also been without a permanent director since Trump’s second inauguration.


©2026 CQ-Roll Call, Inc., All Rights Reserved. Visit cqrollcall.com. Distributed by Tribune Content Agency, LLC.

 

Comments

blog comments powered by Disqus