Home Finance Cybersecurity Data Sharing Faces Liability Deadline
Finance

Cybersecurity Data Sharing Faces Liability Deadline

Share


If not renewed, CISA 2015 protections end in the US on September 30.

This article appears in the September issue of Global Finance Magazine.

Companies that share cybersecurity information with their peers have until Sept. 30, 2026, before the limited liability granted by the Cybersecurity Information Sharing Act of 2015 runs out, exposing them to potential regulatory scrutiny and penalties.

Under the Act, non-federal entities may share anonymized cyberattack and response information with other non-federal entities and the federal government via the Automated Indicator Sharing (AIS) program operated by the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA).

In July, 23 industry associations that represented the financial services, energy, technology, transportation, healthcare, and retail sectors wrote to Speaker of the House Michael Johnson (R-LA) requesting an extension to the Act since it is “a foundational component of the nation’s cybersecurity.”

However, some view AIS as a relic of an earlier era of cyberdefense that provides machine-readable cyber threat indicators and defensive measures against malicious IP addresses, file hashes associated with malware distribution, and known malicious web links.

“It was a failure from the get-go, and it accomplishes nothing,” Milton Mueller, a professor of cybersecurity policy at Georgia Institute of Technology’s Jimmy and Rosalynn Carter School of Public Policy, told Global Finance. “No one will notice when it’s gone.”

A web post by Mueller earlier this year cited a DHS Office of Inspector General (OIG) report stating that non-federal participants using AIS fell to fewer than 90 in 2024 from a high of 304 in late 2022. The report also noted that alert volume on the platform dropped 93% between 2020 and 2022. Though there was a surge in alerts, to 10 million from 1 million, the OIG found that 89% of the data came from a single private-sector participant.

“The non-Federal participants we interviewed stated that they find AIS useful and an effective tool for protecting their systems from cyber threats,” wrote the report’s authors. “However, the number of non-Federal participants remained lower in 2023 and 2024 than in previous years. AIS now has 87 non-Federal participants compared to 252 in 2020.”

Nonetheless, the House of Representatives included an extension to the Act in part of the 2027 National Defense Authorization Act, which is waiting for Senate approval.

In July, the Trump administration sidestepped legislative concerns and created “Gold Eagle,” a clearinghouse to share cybersecurity vulnerability information and coordinate responses among private industry and federal agencies, including the U.S. Treasury Department, CISA, and the U.S. War Department, formerly the Defense Department. The new system will be powered by frontier artificial intelligence, which emulates and may surpass human-level intelligence.

Private Data Sharing Alternatives

Although CISA 2015’s renewal is up in the air and details regarding Gold Eagle are sparse, private industry has had formalized cybersecurity data-sharing programs since 1999.

“There is plenty of threat intelligence sharing going on,” said GeorgiaTech’s Mueller. “There are commercial services, sectoral nonprofit Information Sharing and Analysis Centers (ISACs), and industry consortia like the Cyber Threat Alliance.”

The newly rebranded Alliance for Critical Infrastructure (formerly the Tri-Sector Executive Working Group) seeks to bring together critical infrastructure operators to strengthen national resilience and reduce systemic risk, while sustaining economic continuity.

The 501c(6) non-profit industry coalition started with nine founding members: American International Group Inc., AT&T Inc., Berkshire Hathaway Energy Co., Consolidated Edison Inc., JPMorgan Chase & Co., Lumen Technologies Inc., Mastercard Inc., The Southern Co., and Xcel Energy Inc.

Since its formation, the organization has been on a membership drive, with JPMorgan Chase CEO Jamie Dimon reportedly having private conversations with numerous companies across industry sectors to join the alliance.

Despite the benefits of sharing cybersecurity data, such as faster and broader threat detection and coordinated responses, sharing that data is not risk-free for a corporation.

“When information is shared, one should assume that information could be obtained by others, including regulators, litigants, and insurers, and that can inform the nature, contour, and context of the sharing,” said Mary Alexander Myers, lead of law firm Jones Day’s Cybersecurity, Privacy & Data Protection practice.

For chief financial officers, uncertainty around CISA’s liability shield adds another costly risk to the existing risk landscape. As cyber governance moves from the realm of IT to a board-level issue, CFOs and other C-level executives will have to determine if a reauthorized CISA 2015 or Gold Eagle provides them with enough confidence to continue to share cybersecurity information without the fear of regulatory penalties.

Rob Daly covers fintech and the economy. Contact him at rdaly@gfmag.com.



Source link

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Don't Miss

UK cities where families ‘losing significant cash in the bin due to food waste’

Families in Glasgow, Liverpool and Nottingham are particularly likely to be wasting high amounts of money on food that goes uneaten, a survey...

‘Equitable Mortgages’ Very Much Recognized In India As ‘Charge’ U/S 100 TP Act: Supreme Court

The Supreme Court held that ‘equitable mortgages’ are very much recognized in India under the nomenclature of ‘charge’ in terms of Section 100...

Related Articles

Understanding dynamic pricing: Why some companies charge you more based on your spending habits

If you've ever purchased a plane ticket, hotel room, or rideshare, you've...

Newbridge Securities names Basenese as managing director, investment banking, and chief market strategist

Lou Basenese. - via LinkedIn Newbridge Securities Corp. said Oct. 5 that...

Economic Secretary to the Treasury speech for UK Digital Assets Week

Thank you, and good morning everyone.  It is a real pleasure to...

NS&I boosts rates on eight savings accounts

NS&I has hiked rates on eight of its fixed-rate savings accounts for...