Most of us have never heard of “ISACs,” but they have been around for over 25 years, quietly helping keep our country’s critical infrastructure – like railroads, hospitals, power plants and banks – safe from attacks and threats, both cyber and physical. Information Sharing and Analysis Centers, or ISACs, for short, are private sector organizations charged with helping protect our nation’s critical infrastructure – its customers, facilities and personnel – from cyber and physical security threats and other hazards. ISACs share information about threats and vulnerabilities by collecting, analyzing and disseminating threat information to their members and providing them with resources and tools to mitigate risks and enhance resiliency.
Created by Presidential Directive in 1998, ISACs cover all of the critical infrastructure segments in the U.S., including finance, energy, health, communications, defense and transportation.
Since their implementation, ISACs across all sectors have been essential in keeping our country’s critical systems safe and functioning, halting and overcoming thousands of threats and attacks every year. As technology and bad actors, including criminals and even adversarial countries, become more sophisticated and more motivated, voluntarily sharing information and collaboration among the private sector critical infrastructure operators is a crucial part of combating these threats. ISACs help focus on the most critical information and also act as a hub where companies can share attacks as they happen, allowing others to use that information to protect their own networks.
The Role of CISA 2015 in Fostering Trust and Collaboration
In the early 2000’s, as ISACs were in their nascency, it became evident that legal teams at many private organizations were hesitant to approve sharing of cyber incident and sensitive information with others in the larger community –and especially with the government – fearing that the information might end up in the wrong hands or it would subject the company to additional regulatory oversight and enforcement. In 2015, Congress passed the Cybersecurity Information Sharing Act of 2015 (CISA 2015). This Act eliminated potential sources of liability faced by companies for sharing data on security threats, and it created mechanisms for real-time sharing of data. (To be clear, CISA 2015, the law, should not be confused with CISA, the agency. CISA, the Cybersecurity and Infrastructure Security Agency, is an entirely different entity with a different mission.)
Since its inception, CISA 2015 has been very effective in improving and facilitating threat intelligence information sharing across all critical infrastructure sectors. The law alleviated some of the companies’ concerns about legal liability related to information being shared and also protected the organizations from claims of anticompetitive or collusive behavior. The law fostered trust, speed and collaboration among private and public entities, to help make each sector stronger against attacks. CISA 2015 shielded companies from lawsuits and liability if they were willing to share details about incidents, threats and vulnerabilities with each other and with federal agencies. That law and its immunity protection have encouraged industry to share threat intelligence for the last decade.
Meanwhile, the global cybersecurity threat landscape has become increasingly complex, with about 600 million cyberattacks happening every single day across the globe, according to Microsoft’s 2024 Digital Defense Report. The US was subject to more attacks than any other country, the report said. IT and cybersecurity professionals are going up against complex nation-state actors and well-financed criminal gangs, so it’s important to encourage the private sector to voluntarily share and collaborate not only between the firms but also with the federal government. Working together is the only way we can address the ever-evolving threats we face. CISA 2015 helped provide these legal protections and incentives.
What’s at Stake: The Expiring Protections
CISA 2015 and its immunity protections for collaboration are set to expire on September 30, 2025, unless Congress takes action. The expiration of CISA 2015 could discourage companies from contributing to information-sharing communities due to the absence of explicit liability protections.
Today, as the Chief Security Officer for Health-ISAC, I see the fallout of cyber attacks and incidents across the global health sector. Nearly every day, we’re reading about how ransomware has shut down a hospital, or new adversarial advances leveraging AI created a brand new attack no one ever saw coming. These attacks disrupt healthcare services – creating a real human toll when ambulances are diverted to other hospitals, surgeries are cancelled, lab results are delayed, oncology appointments are postponed and sensitive patient information is breached.
Nearly 26 years after the launch of the first ISAC, there are now at least 28 industry-focused ISACsin the US. Rest assured, ISACs will continue to serve their communities and promote information sharing, regardless of whether CISA 2015 is extended. Information sharing started long before CISA 2015 went into effect. While it is important to extend CISA 2015 to explicitly establish those legal protections and not lose the momentum we’ve gained in the past 10 years with corporate legal counsel and senior leaders supporting information sharing programs across the private sector, there are other protections and controls in place to limit liability.
Beyond CISA 2015: The Future of Information Sharing
To overcome the challenges to information sharing, a shift in perspective is needed, one that views the practice not as a legal risk but as a strategic business model. This shift must be driven from the top, with the C-suite playing a pivotal role in fostering a more secure, resilient, and collaborative cybersecurity environment. When members of the C-suite change the discussion around information sharing from a narrow focus on legal risks to a broader understanding of business benefits, organizations can unlock the full potential of collaborative cybersecurity efforts. The approach not only strengthens individual companies but also enhances the security and resilience of entire industries.
Some ISACs already offer members protection. The IT sector’s ISAC, for example, provides non-disclosure agreements and guarantees that information will only be shared anonymously. Health-ISAC has similar membership agreements and data handling requirements, while also providing members the ability to share information securely and anonymously.
Regardless of CISA 2015 being extended or not, Health-ISAC will continue to deter threats and attacks by leveraging information sharing and collaboration between our member organizations, using the trusted tools, infrastructure and relationships we have established in our 15-year history. Health-ISAC has many resources to address privacy and enforcement reservations and to protect information sharing and alleviate concerns. The biggest incentive to continue collaboration and information sharing is, of course, deterrence from attacks, mitigation of threats and rapid recovery from cyber incidents. We are all working together toward a common goal – to keep our nation’s critical infrastructure, including its customers and personnel, safe and secure. For us at Health-ISAC, that means helping to improve health and saving lives. That is the biggest incentive of all.
Comment on this article on LinkedIn. Click Here