Financial & Investment

Cybersecurity Data Sharing Faces Liability Deadline

With CISA protections expiring Sept. 30, businesses face new liability risks. CFOs must weigh alternatives for cybersecurity data sharing. The post Cybersecurity Data Sharing Faces Liability Deadline appeared first on...

AAdmin
August 21, 2026
3 min read
Cybersecurity Data Sharing Faces Liability Deadline

Home Technology Cybersecurity Data Sharing Faces Liability Deadline

Author: Rob Daly | Photos: Shutterstock: QQMinh88

If not renewed, CISA 2015 protections end in the US on September 30.

This article appears in the September issue of Global Finance Magazine.

Companies that share cybersecurity information with their peers have until Sept. 30, 2026, before the limited liability granted by the Cybersecurity Information Sharing Act of 2015 runs out, exposing them to potential regulatory scrutiny and penalties.

Under the Act, non-federal entities may share anonymized cyberattack and response information with other non-federal entities and the federal government via the Automated Indicator Sharing (AIS) program operated by the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA).

In July, 23 industry associations that represented the financial services, energy, technology, transportation, healthcare, and retail sectors wrote to Speaker of the House Michael Johnson (R-LA) requesting an extension to the Act since it is “a foundational component of the nation’s cybersecurity.”

However, some view AIS as a relic of an earlier era of cyberdefense that provides machine-readable cyber threat indicators and defensive measures against malicious IP addresses, file hashes associated with malware distribution, and known malicious web links.

“It was a failure from the get-go, and it accomplishes nothing,” Milton Mueller, a professor of cybersecurity policy at Georgia Institute of Technology’s Jimmy and Rosalynn Carter School of Public Policy, told Global Finance . “No one will notice when it’s gone.”

A web post by Mueller earlier this year cited a DHS Office of Inspector General (OIG) report stating that non-federal participants using AIS fell to fewer than 90 in 2024 from a high of 304 in late 2022. The report also noted that alert volume on the platform dropped 93% between 2020 and 2022. Though there was a surge in alerts, to 10 million from 1 million, the OIG found that 89% of the data came from a single private-sector participant.

“The non-Federal participants we interviewed stated that they find AIS useful and an effective tool for protecting their systems from cyber threats,” wrote the report’s authors. “However, the number of non-Federal participants remained lower in 2023 and 2024 than in previous years. AIS now has 87 non-Federal participants compared to 252 in 2020.”

Nonetheless, the House of Representatives included an extension to the Act in part of the 2027 National Defense Authorization Act, which is waiting for Senate approval.

In July, the Trump administration sidestepped legislative concerns and created “Gold Eagle,” a clearinghouse to share cybersecurity vulnerability information and coordinate responses among private industry and federal agencies, including the U.S. Treasury Department, CISA, and the U.S. War Department, formerly the Defense Department. The new system will be powered by frontier artificial intelligence, which emulates and may surpass human-level intelligence.

Although CISA 2015’s renewal is up in the air and details regarding Gold Eagle are sparse, private industry has had formalized cybersecurity data-sharing programs since 1999.

“There is plenty of threat intelligence sharing going on,” said GeorgiaTech’s Mueller. “There are commercial services, sectoral nonprofit Information Sharing and Analysis Centers (ISACs) , and industry consort…