← All posts

Your Threat Intelligence Legal Shield Runs on 90-Day Extensions

Last week, Congress did something it has now done four times in twelve months: it temporarily extended the legal framework that makes it safe for companies to share cyber threat intelligence. The Cybersecurity Information Sharing Act of 2015 — not to be confused with the Cybersecurity and Infrastructure Security Agency that shares its acronym — was hours from its September 30 expiration when the continuing resolution signed into law this month pushed the deadline to December 11.

If you are a board member or executive, the headline is not "crisis averted." The headline is that the legal foundation of America's threat-sharing infrastructure now runs on 90-day patches, and nobody in Washington seems to have the appetite to fix it.

What CISA 2015 Actually Protects

CISA 2015 created a voluntary legal framework that gives companies three critical protections when they share cyber threat indicators and defensive measures with peers and the federal government.

Liability protection. Companies sharing qualifying threat intelligence cannot be sued for doing so. That sounds academic until your general counsel explains that sharing details about an attack pattern with an industry peer could expose you to antitrust claims, breach-of-contract disputes, or privacy lawsuits.

Antitrust exemption. Competitors can exchange threat intelligence without violating competition laws. This is the legal backbone of every Information Sharing and Analysis Center and industry-specific threat-sharing consortium in the country.

Privacy safeguards. The law sets requirements for how shared information is handled by federal agencies, giving companies confidence that threat data will not become a backdoor for regulatory overreach.

Without these protections, every sharing decision becomes a legal judgment call. And legal judgment calls, in most organizations, default to "don't."

A Law That Has Lapsed Once and Been Extended Four Times

Here is the timeline that should concern you:

CISA 2015 was enacted in December 2015 with a ten-year sunset. On September 30, 2025, Congress missed the reauthorization deadline and the law expired. For six weeks, the statutory protections vanished. The Washington Post reported on October 2, 2025, that corporate legal departments were reconsidering their threat-sharing activity. Bloomberg Law noted the same day that while the Automated Indicator Sharing platform remained online, the legal shield companies relied on to contribute sensitive intelligence was gone.

The technical plumbing stayed on. The willingness to use it did not.

Congress then played catch-up: Public Law 119-37 restored protections through January 30, 2026. The Consolidated Appropriations Act, signed February 3, 2026, extended the deadline to September 30, 2026. And now the continuing resolution signed this month pushes it to December 11, 2026.

Meanwhile, the House passed a long-term renewal as part of its fiscal 2027 National Defense Authorization Act on July 22, 2026. The Senate's defense bill did not include an equivalent provision. The two chambers remain apart, and the continuing resolution's short extension bought time rather than resolution.

Four extensions in twelve months. One actual lapse. And a December 11 cliff already on the calendar.

The Three Questions Every Board Should Ask

In Cyber Risk Is Business Risk, I argue that boards need a repeatable framework for evaluating cyber issues — not a deep technical briefing, but a disciplined set of questions that separate noise from exposure. This situation is a textbook application.

Question One: What is our exposure? Does your organization share threat intelligence through ISACs, government channels, or peer consortia? If so, your legal team needs to understand whether those activities depend on CISA 2015's liability protections — and what happens if those protections disappear on December 12.

Question Two: What are we doing about it? Your CISO and general counsel should be coordinating now, not on December 11. The question is not whether threat sharing will technically stop. It is whether your lawyers will allow it to continue at the same pace and depth without statutory safe harbor. If your sharing agreements were drafted with CISA 2015's protections baked in, they may need revision regardless of what Congress does — because a law that has lapsed once and been extended four times in a year is not a stable legal foundation.

Question Three: How will we know if it is working? The board should expect a briefing on what threat intelligence the organization depends on, where it comes from, and what legal framework supports each source. Commercial threat feeds you pay for are contractual. Voluntary peer sharing is where the legal uncertainty bites.

Compliance vs. Security — The Gap That Keeps Widening

This situation illustrates a theme I return to throughout the book: the dangerous gap between compliance and actual security. CISA 2015 is a compliance mechanism — it creates legal guardrails for voluntary behavior. But the underlying need for threat intelligence sharing is a security imperative that exists whether the law does or not.

Too many organizations treat compliance frameworks as the ceiling rather than the floor. If your threat intelligence program depends entirely on one law's liability shield, you have built a security function on a legal foundation that Congress cannot keep stable for a full fiscal year.

The organizations that weather this well will be the ones that already treat threat sharing as a core security function and have diversified their legal basis for doing it — through bilateral agreements, contractual frameworks, and information-sharing arrangements that do not depend solely on CISA 2015.

What to Ask Your CISO This Week

If you are a board member or executive, here are three conversations worth starting before the December 11 deadline arrives faster than anyone expects:

  1. "Which ISACs and threat-sharing groups do we belong to, and what legal framework governs our participation?" If the answer begins and ends with CISA 2015, you need a contingency plan.
  2. "What happens to our threat intelligence feeds if the law lapses again?" Not the commercial feeds you pay for — the voluntary peer sharing that often surfaces the earliest indicators of targeted attacks against your sector.
  3. "Has our general counsel reviewed our information-sharing agreements for CISA 2015 dependency?" Many of these agreements were drafted when the law had a ten-year horizon. That horizon is now measured in weeks.

Cybersecurity is a team sport, but teams stop passing the ball when the referee leaves the field. Congress has spent the past year proving that the referee's schedule is unreliable. Build your game plan accordingly.