The expiration of the Cybersecurity Information Sharing Act of 2015 (CISA 2015) on September 30, 2025, ended a decade-long legal framework that enabled safe and consistent sharing of cyber-threat intelligence between the U.S. government and private sector. The lapse has led to a significant reduction in the volume and speed of threat data exchanged, with industry groups and federal agencies reporting over a 70% decline in shared indicators of compromise and delays in alert dissemination. Key sectors such as healthcare, energy, and finance have experienced increased risks, including a rise in ransomware activity and slower responses to nation-state threats, as organizations hesitate to share information without the law’s liability protections.
In response to the growing concerns, legislation to end the federal government shutdown includes a provision to temporarily extend CISA 2015 through January 30, 2026. The Senate has advanced this bill, which, if passed by the House and signed by the President, would restore the legal protections for information sharing, at least temporarily. Industry groups and cyber experts emphasize the urgent need for a more permanent solution, as the current extension is only a stopgap measure. Lawmakers are considering different approaches to amending and extending the law, with the Trump administration advocating for a 10-year extension without changes, while others propose significant reforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
President Trump signed the bill ending the shutdown, formally renewing both the 2015 cyber threat information-sharing law and the state and local cybersecurity grant program. The law restored staffing protections and temporary funding through January 2026.
Reporting revealed the funding package also reauthorized the State and Local Cybersecurity Grant Program, a $1 billion CISA-FEMA initiative supporting state and local cyber defenses.
Congressional action advanced to revive the expired information-sharing law and other cybersecurity authorities following the shutdown agreement, signaling broader efforts to restore lapsed cyber programs.
A bill to end the U.S. government shutdown was introduced with a short-term extension of the 2015 cyber information-sharing law through January 30, 2026. The measure still required House approval and the president's signature.
During the prolonged federal shutdown, CISA staffing fell sharply and key programs were disrupted, with reports indicating the agency was operating at about 35% of its earlier staffing level and under 900 employees.
The Cybersecurity Information Sharing Act of 2015 lapsed at the end of September 2025, ending its liability and antitrust protections for private-sector cyber threat sharing with the federal government.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetherecord.media
Open sourcescworld.com
Open sourcegovinfosecurity.com
Open sourcescworld.com
Open sourcecyberscoop.com
Open sourcetherecord.media
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.