Skip to main content

Historic Cybersecurity Law Is Up for Renewal

Graphic featuring a CXOTech article, Historic Cybersecurity Law Is Up for Renewal, with a health sector quote bubble.
By Matthew Eggers, Vice President, Cybersecurity Policy, U.S. Chamber of Commerce 

While Popular, CISA 2015 Needs Its Advocates 

Before it expires on September 30, 2025, the U.S. Congress must reauthorize the Cybersecurity Information Sharing Act of 2015 (CISA 2015). A key cornerstone of American cybersecurity efforts is CISA 2015, which improves companies’ capacity to address cybersecurity threats at scale and react quickly to modern cyberthreats. If CISA 2015 lapses, the U.S. will face a more complex and hazardous security environment. 

CISA 2015 Increases Collaboration and Imposes Costs on Criminals 

An economist may say that CISA 2015 aims to reduce businesses’ opportunity costs and impose them on malicious actors (e.g., criminal organizations and foreign nation-states). Indeed,  since the implementation of CISA 2015, collaborations in cybersecurity have improved significantly in several ways, including encouraging the development and expansion of information sharing and analysis centers (ISACs) across multiple sectors. These centers act as focal points for exchanging cybersecurity information within particular industries, which improves the ability to detect and respond to threats specific to those sectors. 

For example, CISA 2015 enabled the Health-ISAC to deliver substantial value to the healthcare and public health (HPH) sector by fostering a trusted environment for sharing timely,  relevant, and actionable threat intelligence and best practices. A prime example of this value in action occurred during the 2017 NotPetya cyberattack. The malware spread rapidly, impacting thousands of organizations around the globe and in every critical infrastructure sector. In the  HPH sector, NotPetya caused major disruptions to hospital systems, pharmaceutical manufacturing, and healthcare supply chain vendors. Within hours, the Health-ISAC facilitated crucial real-time information sharing among its members.

The collaboration led to a swift understanding of the attack, the mechanisms of the malware’s propagation, and the development of mitigation strategies, including a “vaccine,” to prevent the malware from spreading. The Health-ISAC became a force multiplier in defending against widespread cyber threats as this information was rapidly disseminated across the health sector, enabling even small and rural hospitals to halt the attack and prevent significant disruption to healthcare in local communities. This type of information-sharing partnership is just one example of the various partnerships that occur across critical infrastructure and government on a minute-by-minute basis. 

Other points covered in the article include:

  • Our Adversaries Want CISA to Expire’
  • U.S. Cybersecurity Relies on Trust 

 

Read the article in CXO Tech Magazine. Click Here