Recent Bills
- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
Committees
- AdministrationU.S. House
- AgricultureU.S. House
- Agriculture, Nutrition, And ForestryU.S. House
- AppropriationsU.S. House
- Armed ServicesU.S. House
- Banking, Housing, And Urban AffairsU.S. House
- BudgetU.S. House
- Commerce, Science, And TransportationU.S. House
- Education and WorkforceU.S. House
- Energy And CommerceU.S. House
- Energy And Natural ResourcesU.S. House
- Environment And Public WorksU.S. House
- EthicsU.S. House
- FinanceU.S. House
- Financial ServicesU.S. House
- Foreign AffairsU.S. House
- Foreign RelationsU.S. House
- Health, Education, Labor, And PensionsU.S. House
- Homeland SecurityU.S. House
- Homeland Security And Governmental Affa…U.S. House
- Indian AffairsU.S. House
- Indian and Insular AffairsU.S. House
- IntelligenceU.S. House
- JudiciaryU.S. House
- Natural ResourcesU.S. House
- Oversight And Government ReformU.S. House
- Permanent Select IntelligenceU.S. House
- RulesU.S. House
- Rules And AdministrationU.S. House
- Science, Space, And TechnologyU.S. House
- Select IntelligenceU.S. Senate
- Small BusinessU.S. House
- Small Business And EntrepreneurshipU.S. House
- Subcommittee on AviationU.S. House
- Subcommittee on Border Security and Enf…U.S. House
- Subcommittee on Coast Guard and Maritim…U.S. House
- Subcommittee on Commodity Markets, Digi…U.S. House
- Subcommittee on Conservation, Research,…U.S. House
- Subcommittee on Counterterrorism and In…U.S. House
- Subcommittee on Cybersecurity and Infra…U.S. House
- Subcommittee on Disability Assistance a…U.S. House
- Subcommittee on Economic Development, P…U.S. House
- Subcommittee on Economic OpportunityU.S. House
- Subcommittee on Emergency Management an…U.S. House
- Subcommittee on Energy and Mineral Reso…U.S. House
- Subcommittee on Federal LandsU.S. House
- Subcommittee on Forestry and Horticultu…U.S. House
- Subcommittee on General Farm Commoditie…U.S. House
- Subcommittee on HealthU.S. House
- Subcommittee on Highways and TransitU.S. House
- Subcommittee on Livestock, Dairy, and P…U.S. House
- Subcommittee on Nutrition and Foreign A…U.S. House
- Subcommittee on Oversight and Investiga…U.S. House
- Subcommittee on Oversight, Investigatio…U.S. House
- Subcommittee on Railroads, Pipelines, a…U.S. House
- Subcommittee on Transportation and Mari…U.S. House
- Subcommittee on Water Resources and Env…U.S. House
- Subcommittee on Water, Wildlife and Fis…U.S. House
- Transportation And InfrastructureU.S. House
- Veterans' AffairsU.S. House
- Ways And MeansU.S. House

“In Defense of Defensive Measures: Reauthorizing Cybersecurity Information Sharing Activities that Underpin U.S. National Cyber Defense”
Hearing•Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection•May 15, 2025 · 2:00 PM
Summary
Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held a hearing on May 15, 2025 at 2:00 PM in Cannon House Office Building, Room 310. 4 witnesses appeared.
Record
The meeting has its video, its transcript, witnesses and documents on the record.
Video
The proceedings, as the committee streamed them.
Transcript
The transcript runs to 4,574 lines and 269,635 characters, as the Government Publishing Office printed it.
house-hearing-61338.txt1[House Hearing, 119 Congress]2[From the U.S. Government Publishing Office]34 IN DEFENSE OF DEFENSIVE MEASURES:5 REAUTHORIZING CYBERSECURITY INFORMA-6 TION-SHARING ACTIVITIES THAT UNDERPIN U.S.7 NATIONAL CYBER DEFENSE89=======================================================================1011 HEARING1213 BEFORE THE1415 SUBCOMMITTEE ON16 CYBERSECURITY AND INFRASTRUCTURE17 PROTECTION1819 OF THE2021 COMMITTEE ON HOMELAND SECURITY22 HOUSE OF REPRESENTATIVES2324 ONE HUNDRED NINETEENTH CONGRESS2526 FIRST SESSION2728 __________2930 MAY 15, 20253132 __________3334 Serial No. 119-153536 __________3738 Printed for the use of the Committee on Homeland Security3940[GRAPHIC NOT AVAILABLE IN TIFF FORMAT]4142 Available via the World Wide Web: http://www.govinfo.gov4344 __________4546 U.S. GOVERNMENT PUBLISHING OFFICE4761-338 PDF WASHINGTON : 20254849-----------------------------------------------------------------------------------5051 COMMITTEE ON HOMELAND SECURITY5253 Mark E. Green, MD, Tennessee, Chairman54Michael T. McCaul, Texas, Vice Bennie G. Thompson, Mississippi,55 Chair Ranking Member56Clay Higgins, Louisiana Eric Swalwell, California57Michael Guest, Mississippi J. Luis Correa, California58Carlos A. Gimenez, Florida Shri Thanedar, Michigan59August Pfluger, Texas Seth Magaziner, Rhode Island60Andrew R. Garbarino, New York Daniel S. Goldman, New York61Marjorie Taylor Greene, Georgia Delia C. Ramirez, Illinois62Tony Gonzales, Texas Timothy M. Kennedy, New York63Morgan Luttrell, Texas LaMonica McIver, New Jersey64Dale W. Strong, Alabama Julie Johnson, Texas, Vice Ranking65Josh Brecheen, Oklahoma Member66Elijah Crane, Arizona Pablo Jose Hernandez, Puerto Rico67Andrew Ogles, Tennessee Nellie Pou, New Jersey68Sheri Biggs, South Carolina Troy A. Carter, Louisiana69Gabe Evans, Colorado Robert Garcia, California70Ryan Mackenzie, Pennsylvania Vacant71Brad Knott, North Carolina72 Eric Heighberger, Staff Director73 Hope Goins, Minority Staff Director74 Sean Corcoran, Chief Clerk75 ------7677 SUBCOMMITTEE ON CYBERSECURITY AND INFRASTRUCTURE PROTECTION7879 Andrew R. Garbarino, New York, Chairman80Clay Higgins, Louisiana Eric Swalwell, California, Ranking81Carlos A. Gimenez, Florida Member82Morgan Luttrell, Texas Seth Magaziner, Rhode Island83Andrew Ogles, Tennessee LaMonica McIver, New Jersey84Mark E. Green, MD, Tennessee (ex Vacant85 officio) Bennie G. Thompson, Mississippi86 (ex officio)87 Alexandra Seymour, Subcommittee Staff Director88 Moira Bergin, Minority Subcommittee Staff Director8990 C O N T E N T S9192 ----------93 Page9495 Statements9697The Honorable Andrew R. Garbarino, a Representative in Congress98 From the State of New York, and Chairman, Subcommittee on99 Cybersecurity and Infrastructure Protection:100 Oral Statement................................................. 1101 Prepared Statement............................................. 2102The Honorable Eric Swalwell, a Representative in Congress From103 the State of California, and Ranking Member, Subcommittee on104 Cybersecurity and Infrastructure Protection:105 Oral Statement................................................. 3106 Prepared Statement............................................. 4107The Honorable Bennie G. Thompson, a Representative in Congress108 From the State of Mississippi, and Ranking Member, Committee on109 Homeland Security:110 Prepared Statement............................................. 6111112 Witnesses113114Mr. John Miller, Senior Vice President of Policy for Trust, Data,115 and Technology, General Counsel, Information Technology116 Industry Council:117 Oral Statement................................................. 7118 Prepared Statement............................................. 9119Ms. Diane Rinaldo, Private Citizen:120 Oral Statement................................................. 17121 Prepared Statement............................................. 19122Mr. Karl Schimmeck, Executive Vice President and Chief123 Information Security Officer, Northern Trust:124 Oral Statement................................................. 21125 Prepared Statement............................................. 22126Mr. Katherine Kuehn, Member and CISO-in-Residence, National127 Technology Security Coalition:128 Oral Statement................................................. 26129 Prepared Statement............................................. 28130131 For the Record132133The Honorable Andrew R. Garbarino, a Representative in Congress134 From the State of New York, and Chairman, Subcommittee on135 Cybersecurity and Infrastructure Protection:136 Letter From Business Roundtable................................ 37137 Statement of the Protecting America's Cyber Networks Coalition. 38138 Letter From the Alliance for Automotive Innovation............. 40139 Joint Statement of Intrado Life & Safety, the National140 Association of State 9-1-1 Administrators, and NENA--The 9-1-141 1 Association................................................ 41142 Joint Letter From Multiple Associations........................ 42143 Statement of the Operational Technology Cybersecurity Coalition144 (OTCC)....................................................... 43145 Statement of the National Retail Federation.................... 44146 Letter From the Software & Information Industry Association147 (SIIA)....................................................... 47148149 Appendix150151Questions From Chairman Andrew R. Garbarino for John Miller...... 57152Questions From Chairman Andrew R. Garbarino for Diane Rinaldo.... 59153Questions From Chairman Andrew R. Garbarino for Karl Schimmeck... 60154Questions From Chairman Andrew R. Garbarino for Katherine Kuehn.. 61155156 IN DEFENSE OF DEFENSIVE MEASURES:157 REAUTHORIZING CYBERSECURITY INFORMATION-SHARING ACTIVITIES THAT158 UNDERPIN U.S. NATIONAL CYBER DEFENSE159160 ----------161162 Thursday, May 15, 2025163164 U.S. House of Representatives,165 Committee on Homeland Security,166 Subcommittee on Cybersecurity and167 Infrastructure Protection,168 Washington, DC.169 The subcommittee met, pursuant to notice, at 2:04 p.m., in170room 310, Cannon House Office Building, Hon. Andrew R.171Garbarino (Chairman of the subcommittee) presiding.172 Present: Representatives Garbarino, Gimenez, Luttrell,173Ogles, Swalwell, and Magaziner.174 Mr. Garbarino. The Committee on Homeland Security,175Subcommittee on Cybersecurity and Infrastructure Protection,176will come to order.177 Without objection, the Chair may declare the committee in178recess at any point.179 The purpose of this hearing is to examine the Cybersecurity180Information Sharing Act of 2015, or CISA 2015, which is up for181reauthorization this year. We will evaluate the voluntary182cybersecurity information-sharing framework established by this183legislation, assessing how it has influenced the way private184entities share information today.185 This hearing will highlight the need to continue186cybersecurity information sharing given an increasingly complex187threat environment, and we'll consider improvements to the188legislation.189 I now recognize myself for an opening statement.190 Information sharing is a critical component of our Nation's191defense against global cyber threats. From utility companies in192rural areas to major banks on Wall Street, the private sector193is on the front lines of the digital battlefield, frequently194defending itself from malicious cyber actors.195 Securing the United States in cyber space requires a whole-196of-society approach, strong partnerships, and close197coordination between industry and Government at all levels. Our198national resilience against cyber threats is reinforced by199sharing threat information and best practices amongst all200stakeholders.201 Nearly 10 years ago, Congress passed the Cybersecurity202Information Sharing Act of 2015, establishing a framework for203the voluntary exchange of cybersecurity information between204private entities and the Federal Government.205 By providing liability and privacy protections for206information shared in accordance with the statute, CISA 2015207removed long-standing barriers to public-private collaboration208in cybersecurity.209 Over the past decade, the threat landscape has evolved210significantly, with sophisticated nation-state and criminal211actors increasingly exploiting cyber space to target212infrastructure and individuals.213 As these threats continue to rise, CISA 2015 has become214more vital than ever. The law has fostered a foundation of215trust among cybersecurity stakeholders, making information216sharing the default rather than an exception.217 A significant volume of critical cyber threat intelligence218has been exchanged between industry and Government under this219law. For instance, just this year a major organization shared22084 formal reports, reaching thousands of partner organizations.221This doesn't include the numerous informal daily exchanges that222are also protected by the law.223 This September, CISA 2015 is set to expire unless Congress224reauthorizes it.225 As we've heard from many stakeholders, the liability and226privacy protections provided by the law have facilitated better227information sharing, helped secure networks, and improved our228overall cybersecurity posture.229 The Cybersecurity and Infrastructure Security Agency, which230this subcommittee oversees, has played a crucial role in231fostering these information-sharing partnerships, a mission I232look forward to continuing under the new administration.233 There are valid concerns that without these protections the234private sector would be less willing to share cybersecurity235information, either amongst themselves or with the Federal236Government. Without these safeguards, we can be certain that237our Nation would be more vulnerable to cyber threats.238 I strongly support reauthorizing CISA 2015. I've made it a239top priority this year. I am encouraged that just yesterday240Secretary Noem voiced similar support before the full241committee.242 This hearing is a crucial step forward in the243reauthorization process, and I look forward to incorporating244feedback into a reauthorization bill.245 I'd like to thank our expert panel for being here. Your246insights on how this law has been implemented across industry247are invaluable. Some of you have tracked or worked directly on248this law since its inception.249 I look forward to exploring ways to maintain and250potentially improve voluntary cybersecurity information sharing251between the public and private sectors.252 [The statement of Chairman Garbarino follows:]253 Statement of Chairman Andrew R. Garbarino254 May 15, 2025255 Information sharing serves as a critical component in our Nation's256defense against global cyber threats. Ranging from utility companies in257rural communities to large banks on Wall Street, the private sector258operates on the front lines of the digital battlefield and is259frequently defending itself from malicious cyber actors.260 Securing the United States in the cyber domain requires a whole-of-261society approach--partnerships and close coordination with industry as262well as State, local, Tribal, and territorial governments. Our national263resilience against cyber threats is strengthened by sharing threat264information and best practices among stakeholders.265 Almost 10 years ago, Congress enacted the Cybersecurity Information266Sharing Act of 2015--otherwise known as ``CISA 2015.'' This law created267a framework for the voluntary exchange of cybersecurity information268between private entities and with the Federal Government.269 By granting liability and privacy protections to information shared270in accordance with the statute, CISA 2015 removed significant and long-271standing barriers to public-private collaboration in cybersecurity.272 The threat landscape has evolved significantly in the past 10273years, with an emergence of sophisticated nation-state and criminal274actors who use cyber space to exploit infrastructure and individuals.275As threats continue to rise, CISA 2015 has become more important than276ever before. The law has built a bedrock of trust among cybersecurity277stakeholders to make information sharing the default, rather than the278decision point.279 Indeed, a high volume of critical cyber threat intelligence has280been shared between industry and Government under this statute. For281example, this year alone, a large organization has shared 84 formal282reports that have reached--in some cases--thousands of partner283organizations. This does not include the multiple, daily, informal284information-sharing engagements that the law also protects.285 This September, CISA 2015 will expire unless Congress acts now to286reauthorize this key authority. As we have heard from many287stakeholders, the liability and privacy protections have enhanced288information sharing, helped secure their networks, and improved overall289cyber defense posture of the United States. CISA the agency, which this290subcommittee oversees, has played a significant role in facilitating291information-sharing partnerships--something I look forward to seeing it292continue as it refocuses on its core mission.293 There are valid concerns that, without this framework and its294protections, the private sector would be less willing to share295cybersecurity information among itself or with the Federal Government.296 We can be certain that our Nation would be more vulnerable to cyber297threats if there were significant reductions in cybersecurity298intelligence sharing.299 I wholeheartedly support the reauthorization of CISA 2015, and have300made this bill a top priority this year. This hearing is a vital step301forward for the reauthorization process, and I look forward to302incorporating feedback from this hearing into a reauthorization bill303that I intend to introduce very soon.304 I want to thank our expert panel for being here today. You bring305valuable insights about how this law has been operationalized across306industries. Some of you have even tracked, or directly worked on, this307law from initial inception.308 I look forward to exploring ways in which we can maintain, and309potentially further improve, voluntary cybersecurity information310sharing between the public and private sectors.311312 Mr. Garbarino. I now recognize the Ranking Member, the313gentleman from California, Mr. Swalwell, for his opening314statement.315 Mr. Swalwell. Thank you, Chairman.316 I was a member of the Intelligence Committee back in 2015317when the CISA 2015 was enacted, and it was apparent to me then,318even in the midst of very intense, vigorous debate, that we319needed greater public-private cybersecurity collaboration.320 So I want to first just thank the witnesses for coming321today and sharing their perspective, their members' positions,322their industry's concerns, because we want to get this right323and we want to build on the success that we have.324 So we're hearing about new cybersecurity attacks every day,325yet the Federal Government at the time had very little326visibility into what was happening on private networks, and the327private sector was receiving very little information from the328Federal Government on cyber threats.329 I would say that is probably still happening today, and the330biggest complaint I hear from you all, especially on JCDC, is331it's a one-way relationship. I know we want to do more to332increase what is shared with you in the private sector.333 But I laid out in the 2015 debate that there was at the334time almost no cyber sharing between the public sector and the335private sector.336 CISA 2015 sought to change that, and it has changed that.337It's provided the legal framework to facilitate cyber338information sharing between the Federal Government and the339private sector. It gives companies the confidence that they'll340be legally protected if they voluntarily share cyber threat341information with the Department of Homeland Security or with342their competitors.343 It's rare that these days we see such a wide consensus on344any topic, but on the issue of reauthorizing CISA 2015 I've345received a very clear message from everyone I've talked to: Do346not let it lapse.347 Stakeholders have consistently stated that CISA 2015 has348drastically improved public-private collaboration, helping our349cyber defenders better do their job.350 Of particular importance to me was that in 2015 we351addressed privacy and civil liberty protections and352demonstrated that their effectiveness was in ensuring353information shared with the Government is protected and always354used properly.355 As CISA 2015 was developed, I advocated for strong privacy356protections, and I'm glad to see those statutory requirements357have achieved their outcomes.358 We must move quickly to reauthorize CISA 2015 before it359expires in September. Maybe we could change the name so it's360not so confusing with the other CISA that we're working on.361That is one change I think we would all welcome. Yeah, good362name change.363 While it's reasonable to discuss if there are ways to364strengthen the law going forward, we cannot allow such365discussions with such an imminent time line to delay366reauthorization.367 It's also important to remember there are steps that368Congress and the administration can take in the interim after369reauthorization.370 While establishing the legal regime to facilitate cyber371information sharing, the maturation of the Cybersecurity and372Infrastructure Security Agency--the original CISA--has provided373a central hub for public-private cyber collaboration across374critical infrastructure sectors.375 If CISA lacks the people and forms necessary to receive,376analyze, and share cyber threat information, CISA 2015's377provisions will be rendered meaningless.378 One important step for Congress that I have been working379with in this committee is to codify the Joint Cyber Defense380Collaborative and better define its mission and structure, and381I hope we get a vote on that again this Congress.382 The administration should restore the Critical383Infrastructure Partnership Advisory Council--also known as384CIPAC--or establish a similar new entity that provides a385mechanism for critical infrastructure collaboration.386 Finally, we must continue to support CISA's efforts to387improve Automated Indicator Sharing and implement its Threat388Intelligence Enterprise Services Program.389 Again, I thank the witnesses for participating in this. I390expect I will hear across the board the value of CISA, that391there are reforms that we can put in place.392 But if it's deciding between not authorizing and trying to393find better reforms and risking this lapsing or reauthorizing394something clean and then fighting and working together395collaboratively ultimately to get reforms in the future, I396think that you would choose the latter.397 With that, I yield back.398 [The statement of Ranking Member Swalwell follows:]399 Statement of Ranking Member Eric Swalwell400 May 15, 2025401 As a Member of the Intelligence Committee when the Cybersecurity402Information Sharing Act of 2015 (CISA 2015) was enacted, it was very403apparent to me then that there was a need for greater public-private404cybersecurity collaboration.405 We were hearing about new cyber attacks every day, yet the Federal406Government had little visibility into what was happening on private407networks, and the private sector was receiving little information from408the Federal Government on cyber threats. As I explained during the409debate leading up to the enactment of CISA 2015, there was, at the410time, ``virtually zero relationship between private industry and411Government'' when it came to cybersecurity.412 Thanks to CISA 2015, that has changed over the last decade. CISA4132015 has provided the legal framework to facilitate cyber information414sharing between the Federal Government and the private sector, as well415as between private-sector entities. It gives companies the confidence416that they will be legally protected if they voluntarily share cyber417threat information with the Department of Homeland Security or with418their competitors.419 It is rare these days that we see such a wide consensus on any420topic, but on the issue of reauthorizing CISA 2015, I have received a421very clear message from everyone I have talked to--we cannot let this422authority lapse. Stakeholders have consistently stated that CISA 2015423has drastically improved public-private collaboration, helping our424cyber defenders better do their job.425 Of particular importance to me, CISA 2015's privacy and civil426liberties protections have demonstrated their effectiveness in ensuring427information shared with the Government is protected and used properly.428As CISA 2015 was developed, I advocated for strong privacy protections,429and I am glad to see those statutory requirements have achieved their430desired outcomes. We must move quickly to reauthorize CISA 2015 before431it expires in September.432 While it is reasonable to discuss if there are ways to strengthen433the law going forward, we cannot allow such discussions to delay434reauthorization, which would risk CISA 2015 lapsing and undermine the435private sector's confidence in cooperating with the Federal Government.436 It is also important to remember that there are steps that Congress437and the administration can take to improve cybersecurity information438sharing beyond just reauthorizing CISA 2015. While CISA 2015439established the legal regime to facilitate cyber information sharing,440the maturation of the Cybersecurity and Infrastructure Security Agency441has provided a central hub for public-private cyber collaboration442across critical infrastructure sectors. Continued support and443resourcing for CISA will be essential to improved information sharing.444 If CISA lacks the people and forums necessary to receive, analyze,445and share cyber threat information, CISA 2015's provisions will be446meaningless. One important step for Congress to take would be to codify447the Joint Cyber Defense Collaborative and better define its mission and448structure. And the administration should restore the Critical449Infrastructure Partnership Advisory Council (CIPAC) or establish a450similar, new entity that provides a mechanism for critical451infrastructure collaboration.452 Additionally, we must continue to support CISA's efforts to improve453Automated Indicator Sharing and implement its Threat Intelligence454Enterprise Services program. It is critical that CISA has access to the455best technologies available to facilitate timely and useful cyber456threat information sharing, and Congress must ensure CISA has the457resources and capacity to modernize its systems and services so that458they become more useful to the private sector.459 I know there is bipartisan support for these efforts and am eager460to work together to get CISA 2015 reauthorized and to continue building461out the Federal Government's capacity for information sharing.462 I thank the witnesses for participating today and look forward to463hearing from them about how CISA 2015 has strengthened our national464security and how we can continue to better facilitate public-private465information sharing going forward.466467 Mr. Garbarino. The gentleman yields back.468 Other Members of the committee are reminded that opening469statements may be submitted for the record.470 [The statement of Ranking Member Thompson follows:]471 Statement of Ranking Member Bennie G. Thompson472 May 15, 2025473 Ten years ago, Congress enacted legislation that transformed how474the Government and private sector collaborate to defend the Nation475against cyber threats. The Cybersecurity Information Sharing Act of4762015 reflects a hard-fought compromise that took years and multiple477Congresses to accomplish.478 Many of the witnesses testifying today worked with Congress over479the multi-year authorization effort to ensure the bill included480protections for privacy and civil liberties and establish appropriate481mechanisms for information sharing. I'd like to thank you for your482efforts to get CISA 2015 enacted then and to get it reauthorized now.483Today, CISA 2015 serves as the foundational authority for critical484public-private collaboration programs--from CISA's Ransomware Task485Force and Notification Initiative to the Joint Cyber Defense486Collaborative--as well as private-sector information-sharing487organizations like information sharing and analysis centers (ISACs).488 More broadly, the Cybersecurity Information Sharing Act transformed489security culture, creating within the private sector a bias toward490sharing information with Government and each other through both formal491and informal mechanisms. As a result, Government has been able to work492with the private sector to more dynamically respond to a range of cyber493threats from our most sophisticated adversaries and cyber criminals.494 While I recognize that there is room to improve and modernize the495Cybersecurity Information Sharing Act, we cannot allow efforts to496rethink the bill to interfere with its timely reauthorization. This497critical authority expires in just 44 legislative days. If history is498any guide, changes to CISA 2015--however minor--will involve multiple499stakeholders and multiple rounds of careful negotiation. I recommend,500in the strongest terms, that this committee move a clean, 10-year501extension of CISA 2015 as soon as possible to ensure continuity of the502collaboration programs that both Government and the private sector rely503on.504 Doing so will send a strong message to the security community that505despite the current upheaval across Government, Congress remains506committed to ensuring the Federal Government is a strong security507partner. It will also make clear to our adversaries that our political508divisions will not distract us from our obligation to defend the509critical infrastructure Americans rely on every day from cyber attacks.510 I appreciate the Subcommittee Chair and Ranking Member's commitment511to reauthorizing the Cybersecurity Information Sharing Act of 2015, and512I look forward to working with them to get it across the finish line.513514 Mr. Garbarino. I am pleased to have a distinguished panel515of witnesses before us today. I ask that our witnesses please516rise and raise their right hand.517 [Witnesses sworn.]518 Mr. Garbarino. Let the record reflect that the witnesses519have answered in the affirmative.520 Thank you, and please be seated.521 I would now like to formally introduce our witnesses.522 Mr. John Miller currently serves as the senior vice523president of policy for trust, data, and technology and general524counsel for the Information Technology Industry Council.525 Mr. Miller is responsible for driving ITI's global strategy526and advocacy on cybersecurity, technology, and digital policy527issues while also serving as the organization's chief legal528officer.529 In addition to his work at ITI, his experience includes530serving as co-chair of CISA's ICT Supply Chain Risk Management531Task Force, 3 terms as chair of the IT Sector Coordinating532Council, and co-founder of the Council to Secure the Digital533Economy.534 Ms. Diane Rinaldo previously served on the House Permanent535Select Committee on Intelligence, where she had first-hand536experience working on CISA 2015. Ms. Rinaldo also held senior-537level roles in the Executive branch, serving as acting538administrator of the National Telecommunications and539Information Administration and as acting assistant secretary of540Commerce for communications and information. She currently541serves as the executive director of the Open RAN Policy542Coalition.543 Mr. Karl Schimmeck currently serves as executive vice544president and chief information security officer of Northern545Trust. He's also here on behalf of the Securities Industry and546Financial Markets Association, or SIFMA, where he previously547served as the managing director of cybersecurity, business548resiliency, and operational risk.549 At Northern Trust, he is responsible for designing and550managing the strategy and operations of the bank's information551security, cybersecurity, and data protection programs.552Additionally, he serves on the board of directors of both the553Financial Services Information Sharing and Analysis Center and554the Cyber Risk Institute.555 Ms. Kate Kuehn serves on the board of directors and is556CISO-in-residence at the National Technology Security557Coalition, where she brings experience leading and advising558cybersecurity, technology, innovative AI strategies, and teams559to help shape the industry with better business security and560risk decisions.561 In addition to her work at the NTSC, Ms. Kuehn serves on562the board of directors for HYAS and the Cybermaniacs.563 I thank the witnesses for being here today.564 I now recognize Mr. Miller for 5 minutes to summarize his565opening statement.566567 STATEMENT OF JOHN MILLER, SENIOR VICE PRESIDENT OF POLICY FOR568 TRUST, DATA, AND TECHNOLOGY, GENERAL COUNSEL, INFORMATION569 TECHNOLOGY INDUSTRY COUNCIL570571 Mr. Miller. Chairman Garbarino, Ranking Member Swalwell,572and distinguished Members of the subcommittee, on behalf of the573Information Technology Industry Council, or ITI, thank you for574the opportunity to testify today on the critical need for575Congress to reauthorize the Cybersecurity Information Sharing576Act of 2015, or CISA 15, before it is set to expire in just 4577months.578 ITI is a global trade association representing 80 of the579world's leading tech companies, and I lead ITI's Trust, Data,580and Technology policy team, including our work on581cybersecurity, AI, and privacy in the United States and582globally.583 I've worked on cyber policy issues for nearly 2 decades,584and I have extensive experience partnering with DHS, CISA, and585other Federal Government stakeholders to improve cyber and586critical infrastructure security, including currently serving587in the leadership of the IT Sector Coordinating Council and ICT588Supply Chain Risk Management Task Force.589 I've had the honor of testifying before this subcommittee590previously on the related topic of security incident591notification, so I know you appreciate that sharing cyber592threat information is vital to improving the Nation's cyber593resilience and security by increasing situational awareness594across Government and industry and driving more effective595operational collaboration to prevent and respond to cyber596threats.597 The same principles underlying CIRCIA motivated Congress to598pass CISA 15, and that law is as fundamental to our collective599cybersecurity today as it was back in 2015.600 I want to underscore that any lapse in CISA 15 authorities601would be an unfortunate step backward, an unforced error that602only stands to benefit cyber criminals, including sophisticated603nation-state threat actors, such as China, Iran, and Russia.604 The axiom that cybersecurity is a team sport is no more605self-evident than in the context of information sharing, which606dictates that those experiencing or observing an incident,607vulnerability, or other indicators that a network or device has608been compromised should share that information.609 Sharing these indicators of compromise and other threat610intelligence helps defenders team up to prevent potential611targets from becoming future victims.612 The goal of CISA 15 and a central thrust of U.S. cyber613policy over the years has been to foster cyber threat info614sharing to increase real-time situational awareness of the615threat landscape to improve threat prevention, response, and616mitigation efforts.617 CISA 15 sought to accomplish this goal by incentivizing and618making it easier for companies to share threat intelligence,619both with the Government and with each other, without fear of620lawsuits or liability, including as related to antitrust,621information disclosure, or regulatory uses, provided the622information shared adhered to privacy and civil liberties623guardrails. It also required DHS to establish an automated624process for sharing such information at scale.625 After nearly 5 years of debate and negotiation, the CISA 15626statute realized these goals. It included precisely-scoped627definitions of the information the bill authorized628organizations to share and carefully negotiated and calibrated629liability and privacy protections that balance the competing630and sometimes conflicting concerns of stakeholders, ranging631from the intelligence community to privacy advocates.632 As a cyber policy expert and lawyer working on this issue633at the time, I worked, along with fellow witnesses on this634panel and many others, to help Congress strike a winning635balance.636 While it was a messy and sometimes contentious process,637Congress ultimately reached an effective compromise, and we are638better off today from a cybersecurity standpoint than we were63910 years ago.640 The reality today is that organizations are benefiting more641from cyber threat info sharing than they were before CISA 15642became law, and they are sharing and receiving via automated643processes, not via spreadsheets.644 This is not to say that CISA 15 was perfectly designed or645has been perfectly implemented or that it cannot be improved.646But with a looming September deadline for CISA 15647reauthorization, we cannot allow the perfect to be the enemy of648the good.649 Please do not jeopardize the cybersecurity improvements and650partnerships that CISA 15 has catalyzed and that many now651likely take for granted by letting the law lapse if that is the652price of making changes.653 That said, the tech sector stands ready to work with654Congress to update and improve upon the cyber threat info-655sharing ecosystem in the United States at any time.656 Three targeted improvements worth considering include, No.6571, both the threat landscape and technology have changed over658the past decade. From ransomware and operational technology to659the explosion of generative AI, technologies and threats660continue to evolve well beyond 2015 and hackers continue to661adapt.662 One simple rubric Congress could use in considering changes663to CISA 15 is to evaluate whether the statute, as written,664effectively captures the sharing of information necessary to665combat cyber threats in 2025.666 No. 2, given the rise of software supply chain attacks, I667encourage Congress to examine whether definitions of terms such668as cyber threat indicator can be updated to promote the sharing669of information useful in preventing or mitigating threats to670the ICT supply chain, such as information related to suspect671suppliers.672 No. 3, Congress could consider including adjacent673authorities which also support public-private information674sharing and partnership, such as the currently suspended675Critical Infrastructure Partnership Advisory Council, or CIPAC,676in a future iteration of CISA 15.677 While the administration has indicated it plans to678reinstate CIPAC authorities in some form, Congress could679provide certainty by firmly codifying functionally equivalent680authorities in statute.681 Thank you for the opportunity to testify today. I look682forward to your questions.683 [The prepared statement of Mr. Miller follows:]684 Prepared Statement of John Miller685 May 15, 2025686 Chairman Garbarino, Ranking Member Swalwell, and distinguished687Members of the Subcommittee on Cybersecurity and Infrastructure688Protection, thank you for the opportunity to testify today. My name is689John Miller, senior vice president of policy and general counsel at the690Information Technology Industry Council (ITI).\1\691---------------------------------------------------------------------------692 \1\ The Information Technology Industry Council (ITI) is the693premier global advocate for technology, representing the world's most694innovative companies. Founded in 1916, ITI is an international trade695association with a team of professionals on 4 continents. We promote696public policies and industry standards that advance companies on and697innovation worldwide. Our diverse membership and expert staff provide698policy makers the broadest perspective and thought leadership from699technology, hardware, software, services, manufacturing, and related700industries. Visit https://www.itic.org/ to learn more.701---------------------------------------------------------------------------702 ITI represents 80 of the world's leading information and703communications technology (ICT) companies. We promote innovation704worldwide, serving as the ICT industry's premier advocate and thought705leader in the United States and around the globe. ITI's membership706comprises leading innovative companies from all corners of the707technology sector, including hardware, software, digital services,708semiconductor, network equipment, cloud, artificial intelligence (AI),709cybersecurity, and other internet and technology-enabled companies that710rely on ICT to evolve their businesses. Our companies service and711support the global ICT marketplace via complex supply chains in which712products are developed, made, and assembled in multiple countries, and713service customers across all levels of government and the full range of714global industry sectors, including financial services, health care, and715energy. We, thus, not only acutely understand the importance of716cybersecurity as a global priority for governments, companies, and717customers, and critical to our collective security, but our members can718also attest to the complexities of demonstrating compliance with719diverging or duplicative regulations in the United States and around720the world.721 I lead ITI's Trust, Data, and Technology policy team, including our722work on cybersecurity, supply chain resiliency, privacy, artificial723intelligence, data, and related policy issues in the United States724(U.S.) and globally. I have deep experience working on public-private725initiatives with the Department of Homeland Security (DHS), the726Cybersecurity and Infrastructure Security Agency (CISA), and other727Federal agencies. Currently, I serve as the co-chair of the CISA-728sponsored Information and Communications Technology729 Supply Chain Risk Management Task Force (ICT SCRM Task Force) and730on the Executive Committee of the Information Technology Sector731Coordinating Council (IT-SCC), the principal IT sector partner to CISA732on critical infrastructure protection and cybersecurity policy. I have733also previously served as an industry representative to the Enduring734Security Framework (ESF), and on multiple National Security and735Telecommunications Advisory Committee (NSTAC) subcommittees, most736recently as an appointee to the Subcommittee on Addressing the Misuse737of Domestic Infrastructure by Foreign Malicious Actors.738 introduction739 I am honored to testify before you today on an issue that is740critical to our collective national and cybersecurity, as well as an741issue of personal interest for me given my long-standing experience as742an industry representative to many public-private partnerships where743information sharing is a foundational, core goal. Like the other744cybersecurity policy and legal experts appearing on this witness panel745and many others, I spent several years discussing, debating, and746working with policy makers, as well as industry and civil society747representatives, on the statute that would ultimately become the748Cybersecurity Information Sharing Act of 2015 (hereinafter CISA 15). I749will recount some of those challenges later in my testimony in the750hopes of illustrating the progress gained from the hard-won compromises751that led CISA 15 to become a cornerstone of the modern cyber threat752information sharing ecosystem.753 Over the last decade, CISA 15 has strengthened America's cyber754defenses by incentivizing and facilitating the sharing of cyber threat755information. Any lapse of CISA 15 would create significant uncertainty,756weaken the U.S. cybersecurity posture, and undermine a decade of757progress in building trust between national security, law enforcement,758critical infrastructure owners and operators, and others in industry.759It is axiomatic that in cybersecurity, no single company or agency has760a complete picture of the threat; it is, thus, the real-time761aggregation of threat intelligence from many sources that allows us to762detect, counter, or mitigate new attacks before they spread.763 A failure to renew CISA 15 could be interpreted by malicious actors764as the United States ``dropping its guard'' and would be an unforced765error in a dangerous and evolving moment of cyber risk for the United766States. The lapse of CISA 15 would remove the legal protections767underlying the trust mechanisms and relationships that underpin the768cyber threat information sharing that is fundamental to our collective769cyber defense. The one guarantee of a lapse in the CISA 15 authority is770that attackers would be in a better position to capitalize on any771resulting confusion and uncertainty caused by a lapse in CISA 15.772 I urge Congress to act swiftly to reauthorize the Cybersecurity773Information Sharing Act of 2015 and preserve an authority that is774foundational to many collaborative cybersecurity activities in the775United States.776 how cisa 15 became law777 Prior to the passage of CISA 15, cyber threats were escalating at778an alarming rate. Meanwhile, legal uncertainty often constrained the779ability of incident responders to communicate with one another. Many780companies feared that sharing indictors of compromise, technical781information on vulnerabilities, defensive measures, or other782cybersecurity information could violate privacy laws, antitrust or783disclosure rules, or create regulatory exposure. In short, the legal784uncertainties surrounding private-sector cyber threat information785sharing created a chilling effect that constrained some companies from786sharing threat data and intelligence that could prevent or mitigate787potential targets from becoming victims.788 The pre-CISA 15 era was marked by strong consensus among789cybersecurity professionals, industry stakeholders, and policy makers790in both Congress and the Executive branch that something needed to be791done to improve the threat information-sharing ecosystem in the United792States. However, that shared recognition of the problem did not quickly793result in passage of the much-needed law. Finding agreement on cyber794threat information-sharing policy among national security, law795enforcement, and homeland security stakeholders was a challenge unto796itself. The challenge was only exacerbated when balancing those797equities against the interests of a wide array of stakeholders across798industry and the privacy and civil liberties communities.799A. CISPA and Privacy Concerns800 The push for cybersecurity information-sharing legislation began in801earnest around 2011.\2\ The first major legislative effort, the Cyber802Intelligence Sharing and Protection Act (CISPA), had broad bipartisan803support with 111 Republican and Democratic co-sponsors in the House.\3\804The bill stalled in the Senate after President Obama threatened to veto805the bill arguing that ``the law repeals important provisions of806electronic surveillance law without instituting corresponding privacy,807confidentiality, and civil liberties safeguards.''\4\808---------------------------------------------------------------------------809 \2\ In May 2011, the administration unveiled a legislative810proposal. The proposal contained problematic regulatory elements, which811the administration later abandoned when it issued EO 13636. However,812the commitment to incentivizing greater information sharing was a813bipartisan, public-private constant at this time, from all quarters--814admin, Congress, and industry. Howard A. Schmidt, The Administration815Unveils its Cybersecurity Legislative Proposal, The White House, posted816May 12, 2011, available at https://obamawhitehouse.archives.gov/blog/8172011/05/12/administration-unveils-its-cybersecurity-legislative-818proposal.819 \3\ Cyber Intelligence Sharing and Protection Act of 2011, H.R.8203523, H.Rept. 112-445. 112th Congress, available at https://821www.congress.gov/bill/112th-congress/house-bill/3523.822 \4\ Cybersecurity bill CISPA passes US House, bbc.com, posted April82327, 2012, available at https://www.bbc.com/news/world-us-canada-82417864539.825---------------------------------------------------------------------------826 The tech sector strongly supported the concept of voluntary827information sharing and argued it could and should be done in a way828that protected privacy. In April 2012, ITI helped organize a coalition829of major technology associations to urge Congress to move forward with830a ``balanced threat information-sharing system'' as part of a national831cybersecurity strategy.\5\ We emphasized that cybersecurity was not a832partisan issue and that ``from the perspective of America's major833innovators, there is no Republican cybersecurity or Democratic834cybersecurity. There is only American cybersecurity, where urgent835action is needed.''836---------------------------------------------------------------------------837 \5\ Tech Sector Unites Behind Cybersecurity Plan, ITI Press838Release, dated April 18, 2012, available at https://itic.genb.pro/news-839events/news-releases/tech-sector-unites-behind-cybersecurity-840plan#:?:text=WASHINGTON%2C%20D,balanced%20threat%20information%20'sharin841g%20'sys- tem.842---------------------------------------------------------------------------843 While proponents of CISPA argued that information sharing would844help stem the ``hemorrhaging'' of U.S. company data to China and845Russia, privacy and civil liberty groups raised legitimate concerns846that the new authorities could be used for ``nefarious purpose[s].''\6\847Civil liberties groups feared that information sharing might become a848back door for Government surveillance, funneling personal data to849intelligence agencies. ITI recognized early on that those concerns were850not without merit and advocated that trust had to be built into any851information-sharing framework by safeguarding privacy and civil852liberties. We actively engaged with privacy advocates to help find853common ground, and publicly lauded the efforts of CISPA's sponsors to854work with groups like the Center for Democracy and Technology (CDT) to855make sure that important privacy safeguards were included in any856information-sharing bill. When CDT announced it would not oppose857CISPA's progress after key changes, ITI praised the ``constructive858dialog between bill sponsors and privacy groups'' that improved the859bill and helped ``balance privacy concerns.''\7\860---------------------------------------------------------------------------861 \6\ Hayley Tsukayama, CISPA: Who's for it, who's against it and how862it could affect you, The Washington Post, dated April 27, 2012,863available at https://www.washingtonpost.com/business/technology/cispa-864whos-for-it-whos-against-it-and-how-it-could-affect-you/2012/04/27/865gIQA5- ur0lT_story.html.866 \7\ ITI Applauds Privacy Agreement between CISPA Sponsors and CDT,867ITI Press Release, dated April 24, 2012, available at https://868www.itic.org/news-events/news-releases/iti-applauds-privacy-agreement-869between-cispa-sponsors-and-cdt#:?:text=Dean%20Garfield%2C%20President-870%20and%20CEO,%E2%80%9D.871---------------------------------------------------------------------------872B. Cybersecurity Act of 2012 and Passage of CISA 15873 The House did pass an information-sharing bill in 2012 but the874leading comprehensive, bipartisan Senate bill, the Cybersecurity Act of8752012 (S. 3414) failed to overcome a filibuster.\8\ Opposition to the876Senate bill was due in part to a lack of consensus on how to craft a877balanced legal regime for information sharing. Nonetheless, information878sharing was the constant element with bipartisan support across879legislative efforts and proposals from the Obama administration.880---------------------------------------------------------------------------881 \8\ Michael S. Schmidt, Cybersecurity Bill Is Blocked in Senate by882G.O.P. Filibuster, The New York Times, dated August 2, 2012, available883at https://www.nytimes.com/2012/08/03/us/politics/cybersecurity-bill-884blocked-by-gop-filibuster.html.885---------------------------------------------------------------------------886 The next few years saw both progress and new challenges. Cyber887attacks on U.S. companies and Government agencies continued unabated,888keeping pressure on lawmakers to act. President Obama, via multiple889Executive Orders, encouraged voluntary information sharing.\9\ But890Congress needed to legislate to address removing the real and perceived891legal barriers so as to incentivize increased information sharing. By892mid-2013, revelations about U.S. Government surveillance programs had893come to light, eroding trust in sharing information with Government894more broadly. Many in the public and Congress became wary of any bill895that might inadvertently expand intelligence agencies' access to896private data.897---------------------------------------------------------------------------898 \9\ President Obama Signs Executive Order on Cybersecurity899Information Sharing, hunton.com, posted February 17 2015, available at900https://www.hunton.com/privacy-and-information-security-law/president-901obama-signs-executive-order-cybersecurity-information-sharing. See902Executive Order 13636, February 12, 2013, available at https://903obamawhitehouse.archives.gov/the-press-office/2013/02/12/executive-904order-improving-critical-infrastructure-cybersecurity and Executive905Order 13691, February 13, 2015, available at https://906obamawhitehouse.archives.gov/the-press-office/2015/02/13/executive-907order-promoting-private-sector-cybersecurity-information-shari.908---------------------------------------------------------------------------909 To address these concerns, one of the core principles ITI pushed910for was to channel information sharing through a civilian agency--911specifically, the Department of Homeland Security (DHS)--rather than912directly to intelligence agencies. In ITI's view, having DHS serve as913the ``civilian interface'' for the program would help reassure the914public that information was not simply feeding into a black box at the915National Security Agency (NSA). By 2014, this concept had gained916traction as the 113th Congress drew to a close. To further bolster the917privacy protections in the bill, ITI also pressed for provisions to918ensure that any shared data would be ``anonymized'' or stripped of919personal information to the extent possible prior to sharing. The goal920was to share threat indicators (like malicious IP addresses, signatures921of malware, etc.), not personal information about individuals.922 The 114th Congress took up the effort with fresh urgency, partly923spurred by high-profile breaches like the massive OPM Federal data924breach in mid-2015. Throughout 2015, as the bill advanced, ITI925advocated for key provisions that we believed would make the926information-sharing framework both effective and responsible--notably927voluntary participation, multi-directional sharing (private-to-928Government, Government-to-private, and private-to-private sharing), and929protecting privacy through data minimization.\10\930---------------------------------------------------------------------------931 \10\ Id.932---------------------------------------------------------------------------933 The result was a bill that addressed the private sector's needs to934incentivize greater sharing (by providing liability protections and935clarity that it was lawful for the private sector to share data) while936building in the privacy safeguards and civilian government oversight937that many stakeholders demanded. By late 2015, a bipartisan consensus938had finally coalesced around this balanced approach. CISA 15 was passed939by the Senate with strong bipartisan support and was ultimately enacted940in the year-end omnibus funding bill.941 One key takeaway relevant to today's hearing is this: even in the942face of an urgent need and rising threats, it took half a decade of943work to get to finally enact an information-sharing law. Along the way,944Congress and other stakeholders had to navigate legitimate concerns945about privacy and the role of intelligence agencies, amongst others.946Since its passage, CISA 15 has become a cornerstone legal authority947that underpins a multitude of information-sharing organizations,948forums, and activities both within the private sector and between the949private sector and the public sector.950 While privacy concerns were constantly at the forefront of the951cybersecurity information-sharing conversation in the years leading up952to CISA 15, looking back we can see that the carefully negotiated and953constructed privacy provisions \11\ have proven effective. DHS \12\ and954the intelligence communities \13\ Inspectors General both investigated955the CISA 15 program in 2023 and 2024 and found no evidence of adverse956privacy and civil liberty effects of the law. The fact is that zero957reported incidents regarding leakage of personal data over the course958of nearly 10 years provide convincing evidence to demonstrate the959effectiveness of the statute's privacy safeguards.960---------------------------------------------------------------------------961 \11\ U.S. Department of Homeland Security and U.S. Department of962Justice, Privacy and Civil Liberties Final Guidelines: Cybersecurity963Information Sharing Act of 2015, dated April 2025, available at https:/964/www.cisa.gov/sites/default/files/2025-04/CISA%202015%20PCL%20-965Final%20Guidelines%20Periodic%20Review%20%28April%202025%29%20Final-966508.pdf.967 \12\ U.S. Department of Homeland Security Office of Inspector968General, CISA Faces Challenges Sharing Cyber Threat Information as969Required by the Cybersecurity Act of 2015, dated September 25, 2024,970available at https://www.oig.dhs.gov/sites/default/files/assets/2024-97109/OIG-24-60-Sep24.pdf?utm_source.972 \13\ Office of the Inspector General of the Intelligence Community,973Joint Report on the Implementation of the Cybersecurity Information974Sharing Act of 2015, dated December 12, 2023, available at https://975www.oversight.gov/sites/default/files/documents/reports/2024-01/Joint-976Report-Implementation-Cybersecurity-Information-Sharing-Act-2015AUD-9772023-002Unclassified.pdf#:-978?:text=civil%20liberties%20of%20United%20States,adverse%20effects%20were979%20not%20neces- sary.980---------------------------------------------------------------------------981How CISA 15 Enables Information Sharing and What's at Stake if Congress982 Does Not Act983 Since its enactment, CISA 15 has meaningfully improved the capacity984and speed with which we can respond to cyber incidents while985establishing clear expectations for privacy and confidentiality. CISA98615 helped foster and expand a vast network of cyber information-sharing987organizations at the Federal, State, and local levels, in addition to98828 Information Sharing and Analysis Centers (ISACs) for specific989industry sectors.\14\ ISACs serve as trusted entities to exchange and990share cyber and physical threat information, allowing for sector-wide991situational awareness, 24/7 threat warnings, incident reporting, and992response.\15\ ISACs also share with each other, including through the993National Council of ISACs and directly with each other to facilitate994and coordinate cross-sector sharing and collaboration. The Multi-State995ISAC additionally facilitates sharing and collaboration amongst State,996local, Tribal, and territorial government entities. This network of997ISACs, and other Information Sharing and Analysis Organizations998(ISAOs), non-governmental organizations, and security operations999centers does more than improve visibility into hackers' activities.1000These networked entities enhance our ability to mitigate risks, conduct1001threat-hunting activities, and close technical vulnerabilities.1002---------------------------------------------------------------------------1003 \14\ National Council of ISACs website, last visited May 12, 2025,1004https://www.nationalisacs.org/. ``Formed in 2003, the [National Council1005of ISACs (NCIO)] today comprises 28 organizations. It is a coordinating1006body designed to maximize information flow across the private-sector1007critical infrastructures and with Government. Critical infrastructure1008sectors and subsectors that do not have ISACs are invited to contact1009the NCI to learn how they can participate in NCI activities.''1010 \15\ Id.1011---------------------------------------------------------------------------1012 Relatedly, I understand there has been criticism of the Automated1013Indicator Sharing (AIS) program authorized by CISA 15, specifically for1014the apparent decrease in participants and volume of threat indicators1015shared through the platform. However, such criticisms overlook the fact1016that back in 2015, wide-spread automated sharing of threat indicators1017at scale was an aspiration that CISA 2015 helped turn into a reality.1018As Scott Algeier, executive director of the IT-ISAC, recently argued,1019``While measuring the number of companies directly sharing is1020interesting, it doesn't necessarily reflect how the industry shares1021information. Thousands of companies belong to ISACs, including the IT-1022ISAC and many of our peers in the National Council of ISACs who1023participate in the DHS AIS program. Leveraging the ISACs and our1024collective member companies provides scale for DHS to share with1025thousands of companies. Any assessment of industry's participation1026should include the thousands of companies who participate through1027ISACs.''\16\ The fact is that AIS as envisioned by CISA 15 laid the1028groundwork for countless public and private organizations to share1029automated indicators at scale, and there now exist a multitude of1030forums and venues to conduct threat sharing that did not exist in 20151031and are reliant upon the protections and mechanisms established by CISA103215.\17\1033---------------------------------------------------------------------------1034 \16\ Scott Algeier, A Decade of CISA 2015: Reviewing its1035Effectiveness, IT-ISAC Blog, posted May 12, 2025, available at https://1036www.it-isac.org/post/a-decade-of-cisa-2015-reviewing-its-effectiveness.1037 \17\ Id.1038---------------------------------------------------------------------------1039 Equally important, the law's antitrust exemption and associated1040protections, such as protections from Freedom of Information Act (FOIA)1041disclosure and regulatory use have facilitated broader cyber1042information sharing between private-sector organizations and set the1043stage for expanding non-governmental cyber-threat-sharing1044organizations. As discussed above, legal ambiguities in privacy and1045antitrust law and potential regulatory exposure chilled the sharing of1046cyber threat information prior to the passage of CISA 15. These1047protections removed those legal barriers to incentivize increased1048sharing and spurred the modern information-sharing ecosystem to grow1049over the last 10 years.1050 A lapse in CISA 15 liability protections would remove the legal1051scaffolding that Federal, State, and local governments and private-1052sector entities rely on to conduct many of their day-to-day1053cybersecurity operations. Below, I outline 3 categories of consequences1054that such a lapse would have, both legally and operationally, for our1055Nation's cybersecurity.1056 Chilling of Threat Information Sharing.--Companies would1057 lose the liability protections and safe harbors from antitrust1058 rules and regulatory use that currently encourage them to share1059 cyber threat indicators and defensive measures. Without these1060 assurances and the business certainty, stability, and1061 predictability they provide, many organizations will likely,1062 and understandably, become more reluctant to share sensitive1063 threat information due to concerns regarding potential negative1064 legal and regulatory consequences.1065 Loss of Real-Time Visibility and Early Warnings for State,1066 Local, and Federal Government.--Government entities--including1067 DHS, law enforcement, and the intelligence community, as well1068 as State, local, Tribal, and territorial government entities--1069 would likely begin to lose access to a great volume of1070 voluntarily shared threat intelligence from private-sector1071 partners. Indeed, the CISA 15 framework is now fundamental to1072 how industry and agencies collaborate and work together when1073 cyber incidents arise. Key examples include critical1074 infrastructure sectors from finance to energy which have1075 expanded their role and reach since the passage of CISA 15. The1076 law also enabled the DHS/CISA to establish the Joint Cyber1077 Defense Collaborative (JCDC),\18\ which facilitates real-time1078 sharing of threat alerts and coordinated operational1079 collaboration and response planning among public and private1080 partners.1081---------------------------------------------------------------------------1082 \18\ CISA website, last visited May 13, 2025, https://www.cisa.gov/1083topics/partnerships-and-collaboration/joint-cyber-defense-1084collaborative/jcdc-faqs.1085---------------------------------------------------------------------------1086 Undermining Trust and Deterrence.--A lapse of CISA 15 would1087 signal a broader retreat from coordinated defense. This1088 includes the trust that non-Government entities have formed1089 with CISA as the responsible facilitator of cyber information1090 sharing activities in a way that protects privacy, focuses on1091 security over regulatory use, and advances the Government's1092 cybersecurity mission. Sending a message of retreat to threat1093 actors including foreign adversaries could have even more1094 troubling consequences.1095A. Other Cybersecurity Authorities and Activities Would Be Harmed by a1096 Lapse of CISA 151097 A lapse in CISA 15 would also undermine the effectiveness of1098multiple related laws and programs created since 2015. For example, the1099liability protections in CISA 15 were incorporated by reference into1100other significant cyber laws, such as the Cyber Incident Reporting for1101Critical Infrastructure Act (CIRCIA). Similarly, information sharing1102and operational programs and initiatives across various levels of1103government have relied on CISA 15 authorities as a basis on which to1104build out their own cybersecurity programs. Barring any successor1105agreements, these programs and initiatives might be weakened or forced1106to temporarily suspend operations if CISA 15 were allowed to lapse.1107 CISA 15 also covers information sharing with a ``non-Federal1108entity'' to include State, Tribal, or local governments, as well as1109their departments or components. This terminology means that State-run1110cybersecurity organizations, such as the New York Joint Security1111Operations Center (JSOC) or the California Cybersecurity Integration1112Center (Cal-CSIC), also rely upon the protections in CISA 15 and would1113likely lose information from their private-sector partners if CISA 151114were to lapse.1115 Finally, CISA 15 contributed to the sustained growth of additional1116platforms and automated information-sharing standards. Specifically,1117the Open Threat Exchange (OTX), a crowd-sourced cybersecurity platform1118initiated by AlienVault (now AT&T Cybersecurity), has seen substantial1119growth. According to the latest reports, OTX boasts over 180,0001120participants across 140 countries, sharing more than 19 million1121potential threats daily. CISA 15 provided a key impetus to help push1122the adoption of standardized formats for the automated sharing of such1123cyber threat information. Specifically, section 105(c)(1) of CISA 151124required DHS to develop a ``capability and process'' to share threat1125indicators in an automated manner, catalyzing the uptake of the1126Structured Threat Information Expression (STIX) and the Trusted1127Automated Exchange of Intelligence Information (TAXII). Studies have1128shown a steady increase in the volume of STIX data shared among1129organizations in recent years \19\ which suggests the continued1130utilization and need for automated information sharing.1131---------------------------------------------------------------------------1132 \19\ Jin et al., Sharing cyber threat intelligence: Does it really1133help? Network and Distributed System Security (NDSS) Symposium, January11342024, available at https://www.ndss-symposium.org/ndss-paper/sharing-1135cyber-threat-intelligence-does-it-really-help/.1136---------------------------------------------------------------------------1137 evolving threats and the technology landscape1138 Private-sector cyber defenders, including those from critical1139infrastructure entities, are regularly targeted by threat actors. Since1140the enactment of the CISA 15, the threat landscape has continued to1141evolve alongside significant technology innovation.1142 For example, AI has become a ubiquitous feature of IT applications,1143offerings, and services transforming various aspects of cybersecurity.1144AI is being used to enhance threat detection and response capabilities,1145but it is also being leveraged by malicious actors to conduct more1146sophisticated attacks. Experts note that with the advent of advanced AI1147models, we face novel risks like adversarial AI manipulation (tricking1148algorithms through malicious inputs), data poisoning (corrupting the1149training data of AI systems), and prompt injection exploits--challenges1150that our current cybersecurity approaches were not designed to1151handle.\20\ While such AI-specific attacks are still emerging, their1152potential impact is serious and highlights how our defensive strategies1153(and the laws governing them) may need to adapt to keep pace with1154technological change.1155---------------------------------------------------------------------------1156 \20\ ITI's AI Security Policy Principles, dated October 2024,1157available at https://www.itic.org/documents/artificial-intelligence/1158ITI_AI-Security-Principles_102124_FINAL.pdf#:?:text=-1159However%2C%20threats%20unique%20to%20AI,systems%20has%20been%20'steadily1160%20increas- ing.1161---------------------------------------------------------------------------1162 Additionally, the convergence of Information Technology (IT) and1163Operational Technology (OT) systems has introduced new complexities and1164vulnerabilities. This integration aims to improve operational1165efficiency but also expands the attack surface, making it crucial to1166manage a broader landscape of cybersecurity risks effectively.1167 New categories of attacks have emerged since Congress passed CISA116815 as malicious actors continuously seek new attack vectors. Ransomware1169attacks have become increasingly prevalent, causing significant1170disruptions and financial losses. These attacks are striking ever more1171critical targets--governments, hospital systems, pipelines--with1172increasingly dire consequences.\21\ Software supply chain attacks such1173as SolarWinds have also gained prominence, targeting vulnerabilities in1174third-party software components to compromise entire systems.1175---------------------------------------------------------------------------1176 \21\ Threat Evaluation Working Group, Supplier, Products, and1177Services Threat Evaluation, Information and Communications, Technology1178Supply Chain Risk Management Task Force, July 2021, available at1179https://www.cisa.gov/sites/default/files/publications/ict-scrm-task-1180force-threat-scenarios-report-1181v3.pdf#:?:text=The%20impacts%20of%20ransomware%20attacks,-1182Another%20recently.1183---------------------------------------------------------------------------1184 While we have a better understanding of these new threats and1185patterns thanks to a combination of pre- and post-incident information1186sharing enabled by CISA 15. Defenders depend on threat indicator1187sharing to strengthen their defenses and protect their customers' data.1188Information sharing alone cannot be the solution, but it is undoubtedly1189a critical component of our collective response to the evolving threat1190landscape, and it is fair to ask whether CISA 15 adequately accounts1191for the sharing of threat information related to all of these1192technological advances.1193 recommendations1194 Given the importance of CISA 15 authorities to our national cyber1195defense, Congress' first and most important job this year is the1196reauthorization of the existing law before it lapses in September.1197Given recent cybersecurity incidents, notably the Salt Typhoon campaign1198against U.S. telecommunications companies, Congress should examine how1199to improve our Nation's digital defenses. The technology sector looks1200forward to partnering with policy makers to improve all areas of our1201cybersecurity posture, including improvements to CISA 15. The1202improvements cannot come at the expense of the existing cyber1203activities that rely on CISA 15 authorities. Any lapse to CISA 15's1204liability protections could have real and immediate negative1205consequences that put all American organizations at greater risk.1206 There are ways in which Congress could improve the information-1207sharing ecosystem spurred by CISA 15. These include updating the scope1208of covered cyber threat indicators to match the modern threat1209environment, exploring ways to support offensive cyber capabilities,1210and considering the intersection of CISA 15 authorities with other laws1211and authorities. I will cover each of these recommendations below.12121. Modernize Terms to Match Threats and Technology1213 Given the ever-improving and evolving nature of technology and of1214hacker behaviors and capabilities, Congress should consider updating1215the scope of CISA 15 to align with modern threats, indicators, and1216defensive measures. Specifically, Congress should consider whether and1217how to refine the definition of ``cyber threat indicator,''\22\ to1218ensure that CISA 15 is operative and applicable to cover the current1219landscape of threats, vulnerabilities, and malicious activities.1220Additional indicators may be appropriate to include, especially those1221related to supply chain exploits and risk information,\23\ ransomware,1222or fraud. Similarly, AI-related threats may be worth considering such1223as those related to training data anomalies, evasion logs, prompt1224ejections, or malicious prompt patterns.1225---------------------------------------------------------------------------1226 \22\ Sec. 102. Definitions. (6) available at https://www.cisa.gov/1227sites/default/files/publications/1228Cybersecurity%2520Information%2520Sharing%2520Act%2520of%25202015.pdf.1229 \23\ CISA website, last visited May 13, 2025, available at https://1230www.cisa.gov/resources-tools/groups/ict-supply-chain-risk-management-1231task-force.1232---------------------------------------------------------------------------1233 For example, CISA 15 defines a ``cybersecurity threat'' primarily1234as an action ``on or through an information system'' that may harm the1235security or data of that information system.\24\ This framing made1236sense at the time but might not explicitly encompass threats that1237exploit machine-learning models in the cloud, corrupt software1238components before they ever reach a victim's network, or target IoT and1239OT devices that fall outside the classic notion of an IT system.1240Updating the terminology of CISA 15 to encompass AI-driven exploits,1241ransomware operations, software supply chain compromises, and OT1242attacks, among other attack vectors, will remove doubt and friction in1243our information-sharing efforts.1244---------------------------------------------------------------------------1245 \24\ Megan Brown, Jacqueline Brow, and Sydney White, CSIA 151246Reauthorization--Are Changes on the Horizon? Wiley Connect Blog, posted1247March 3, 2025, available at https://www.wileyconnect.com/CISA-2015-1248Reauthorization-Are-Changes-on-the-Horizon#:?:text=%E2%-124980%9CCybersecurity%20threat%E2%80%9D%20is%20defined%20under,be%20'scoped1250%20- more%20broadly%20or.1251---------------------------------------------------------------------------12522. Information Sharing for Effect--Degrading Threat Actor1253 Infrastructure & the JCDC1254 It is important to underscore the limits of sharing information1255about cybersecurity vulnerabilities, threat actor behaviors, and other1256intelligence. If policy makers are concerned about how best to1257structure the Federal cybersecurity enterprise to degrade hackers'1258ability to conduct attacks, I recommend evaluating the current1259functions of the Joint Cyber Defense Collaborative (JCDC).1260 The best version, and stated intent, of the JCDC is to serve as a1261forum for real-time, joint cyber defense operational planning and1262response. A public-private collaborative approach is essential to1263countering advanced persistent threat (APT) actors which are backed by1264nation-state resources, access to talent, and technical capabilities.1265The work of the JCDC builds upon and evolves CISA 15, though the1266program remains only a few years old and could benefit from1267Congressional direction and oversight.1268 Combatting sophisticated APT level groups will require a different1269strategy than promoting basic cyber hygiene policies which, if1270effectively implemented, can combat the vast majority of cyber1271criminals but not the most sophisticated threat actors. A deeper1272public-private collaboration is needed to leverage the authorities and1273capabilities of a multitude of Federal agencies from Homeland Security1274and Law Enforcement in concert with the private-sector companies--1275including tech, telecom, and cybersecurity firms--who have visibility1276into the targets APTs are looking to compromise.1277 ITI appreciates committee Members' interest in JCDC legislation and1278provided feedback to the committee on Ranking Member Swalwell's1279legislative proposal last Congress. At a high level, additional1280governance structures and processes at the JCDC are important to make1281participants co-equal partners in the center's activities. A well-1282defined strategy for the JCDC, transparency through a charter for the1283JCDC, and regular reporting requirements would all benefit the JCDC's1284mission of evolving information sharing into a collaborative planning1285body.12863. Protect-Related Information-Sharing Partnerships and Forums for1287 Collaboration1288 The currently-suspended Critical Infrastructure Partnership1289Advisory Council (CIPAC) provided a protected forum and set of umbrella1290authorities enabling private-sector and Federal agencies to exchange1291threat intelligence, craft cybersecurity policies, and discuss and make1292recommendations to address risks to critical infrastructure. CIPAC1293created trust among numerous public-private partnerships by providing a1294protected channel controlling how shared information could be used and1295disseminated, exempt from the Federal Advisory Committee Act's1296requirements.1297 Examples of partnerships impacted by the suspension of CIPAC1298include the Sector Coordinating Councils (SCCs), the Enduring Security1299Framework (ESF) and the Information and Communications Technology1300Supply Chain Risk Management (ICT SCRM) Task Force. The SCCs are1301independent, self-governed bodies composed of private-sector entities1302that own, operate, and secure the Nation's critical infrastructure. The1303SCCs leveraged CIPAC to provide advice and guidance to collectively1304address the most pressing security challenges facing our country. ESF1305is a cross-sector working group that operates under the auspices of1306CIPAC to address threats and risks to the security and stability of1307U.S. National Security Systems and critical infrastructure by bringing1308together the public and private sectors to work on intelligence-driven1309cyber challenges. The ICT SCRM Task Force is a public-private1310partnership established by DHS in 2018 in concert with the IT and1311Communications SCCs as another cross-sector CIPAC-chartered working1312group whose work is becoming increasingly critical as adversaries scale1313efforts to disrupt the supply chains underpinning the digital economy.1314While Secretary Noem has publicly announced plans to reinstate CIPAC1315authorities in some form, Congress could provide greater certainty by1316firmly codifying functionally equivalent authorities in statute.1317 conclusion1318 The legal framework established by CISA 15 is a critical foundation1319for the effective functioning of cyber threat information sharing1320between the public and private sector, for Federal, State, and local1321governments and among industry sectors. Any lapse in these authorities1322will likely disrupt critical information-sharing activities nationwide,1323significantly weaken our cybersecurity defenses, and provide malicious1324actors with new opportunities to exploit vulnerabilities. It is1325imperative that Congress prioritize the reauthorization of CISA 151326ahead of its sunset date in September. We strongly recommend a clean1327extension to ensure continuity, with any improvements to the important1328protections in existing law to be addressed in future legislation.1329 Thank you for the opportunity to testify today. I look forward to1330your questions.13311332 Mr. Garbarino. Thank you, Mr. Miller.1333 I now recognize Ms. Rinaldo for 5 minutes to summarize her1334opening statement.13351336 STATEMENT OF DIANE RINALDO, PRIVATE CITIZEN13371338 Ms. Rinaldo. Thank you.1339 Chairman Garbarino, Ranking Member Swalwell, Members of the1340committee, thank you for the opportunity to appear before you1341today.1342 My name is Diane Rinaldo, and by way of background, I1343worked on the Cybersecurity Information Sharing Act from its1344inception to passage into law as a staff member on the House1345Permanent Select Committee on Intelligence. I am grateful to1346speak to the urgent need for its reauthorization.1347 This act remains a critical legislative framework that has1348enabled meaningful cooperation between the public and private1349sectors, yet the threat environment has grown dramatically more1350complex and our approach must evolve accordingly.1351 When the original legislation was drafted in 2012, growing1352concerns about the frequency and sophistication of cyber1353attacks were already taking shape. In hindsight, those early1354warnings significantly underestimated the scale and complexity1355of today's threat landscape.1356 Over the past decade, threat actors have become more1357capable and emboldened, outpacing both legislative safeguards1358and defensive technologies. High-profile attacks, such as Salt1359Typhoon and incursions on the U.S. Government, have made it1360abundantly clear: No sector, private or public, is immune.1361 At the heart of the legislation and what remains just as1362urgent today is China's unrelenting assault on the U.S. economy1363through cyber-enabled espionage. Chinese cyber hacking stands1364out as one of the most strategically dangerous and persistent1365threats to national security.1366 For over a decade, state-sponsored actors have conducted a1367sweeping and coordinated cyber espionage campaign targeting1368U.S. companies, research institutions, and Government agencies.1369These operations have resulted in the theft of massive troves1370of intellectual property and trade secrets.1371 This is not random or opportunistic. It's a deliberate1372strategy to fuel China's economic and military ambitions, with1373cyber capability serving as a core instrument of statecraft and1374industrial policy.1375 In this evolving threat environment, the need for real-time1376bidirectional information sharing between Government and1377industry has never been more critical.1378 The Cyber Information Sharing Act laid the foundation for1379improved collaboration between Government agencies and the1380private sector by creating a legal framework for voluntary1381information sharing. It offered liability protections to1382encourage private-sector companies to share threat indicators1383and defensive measures with the Federal Government and business1384to business.1385 Our thought was simple: See something, say something.1386 That framework helped normalize and destigmatize cyber1387threat information sharing across industry.1388 The Department of Homeland Security's Automated Indicator1389Sharing program and the role of ISACs is a direct result and1390outgrowth of this legislation.1391 This legislation was the product of 4 years of intensive1392effort, including more than 100 meetings with stakeholders,1393ranging from Fortune 100 companies to small and medium-sized1394businesses, privacy advocates, and academic institutions.1395 It also reflected countless consultations with Government1396agencies and underwent 3 major rewrites based on the feedback1397that we received.1398 From the outset, the committee recognized the critical need1399to strike the right balance between privacy and security. With1400so much at stake, we knew we had to get it right.1401 However, while the law was forward-thinking at the time,1402the pace of technological change and the growing complexity of1403cyber threats have outpaced some of its provisions. Despite1404progress, some gaps still remain: limited participation, speed1405and relevance of information, lack of bidirectional flow,1406inconsistent standards, and a trust deficit.1407 Reauthorizing information sharing gives Congress the1408opportunity to strengthen and scale its original vision. To1409strengthen national security, Congress should expand and1410clarify liability protections to encourage broader information1411sharing.1412 Additionally, Federal agencies, such as CISA, must be1413required, not merely allowed, to share timely, relevant, and1414declassified intelligence with the private sector. Trust and1415engagement improve significantly when companies see tangible1416reciprocity.1417 Cybersecurity is no longer a technical issue, it's a1418national security imperative that requires whole-of-nation1419coordination. No single company, agency, or State can defend1420against these threats alone. The adversaries we face, whether1421criminal networks or foreign governments, exploit our silos. We1422must instead leverage our strengths: diversity of talent,1423innovation, and democratic collaboration.1424 In closing, I urge the committee to quickly reauthorize1425this critical function. Let us affirm the importance of1426information sharing, strengthen the incentives and protections1427for participants, and build the trusted, interoperable, and1428actionable threat ecosystem our future demands.1429 Thank you, and I look forward to your questions.1430 [The prepared statement of Ms. Rinaldo follows:]1431 Prepared Statement of Diane Rinaldo1432 May 15, 20251433 Chairman Garbarino, Ranking Member Swalwell, and Members of the1434subcommittee: Thank you for the opportunity to appear before you today.1435As someone who was closely involved in the development and passage of1436the Cybersecurity Act of 2015, I am grateful to speak to the urgent1437need for its reauthorization and modernization. This Act, which1438included the Cybersecurity Information Sharing Act (CISA) remains a1439critical legislative framework that has enabled meaningful cooperation1440between the public and private sectors. Yet the threat environment has1441grown dramatically more complex--and our approach must evolve1442accordingly.1443 the growing cyber threat landscape1444 When the original legislation was drafted in 2012, growing concerns1445about the frequency and sophistication of cyber attacks were already1446taking shape. In hindsight, those early warnings significantly1447underestimated the scale and complexity of today's cyber threat1448landscape. Over the past decade, threat actors have become more capable1449and emboldened, exploiting zero-day vulnerabilities, bypassing multi-1450factor authentication, compromising third-party vendors, and outpacing1451both legislative safeguards and defensive technologies. High-profile1452attacks--from the SolarWinds breach to the Colonial Pipeline ransomware1453incident, from Salt Typhoon to incursions targeting the Office of the1454Comptroller of the Currency--have made it abundantly clear: no sector,1455public or private, is immune.1456 Today, cyber threats are not only more pervasive but also more1457destructive. Ransomware, state-sponsored espionage, supply chain1458infiltration, and AI-driven attack vectors now pose existential risks1459to critical infrastructure, national security, and economic stability.1460 The proliferation of artificial intelligence promises to1461supercharge this already volatile landscape. AI enables the creation of1462life-like audio and imagery, more convincing spear-phishing campaigns,1463and advanced social engineering tactics. Large language models allow1464adversaries to write malware and exploit code at unprecedented speed1465and scale, lowering the technical barriers for would-be attackers.1466State-backed intelligence and military units are now leveraging these1467tools to target critical infrastructure, enhance surveillance1468capabilities, and support offensive cyber operations.1469 At the heart of the legislation--and what remains just as urgent1470today--is China's unrelenting assault on the U.S. economy through1471cyber-enabled espionage. Chinese cyber hacking stands out as one of the1472most strategically dangerous and persistent threats to national1473security. For over a decade, state-sponsored actors tied to the1474People's Liberation Army and China's Ministry of State Security have1475conducted a sweeping and coordinated cyber-espionage campaign targeting1476U.S. companies, research institutions, and Government agencies. These1477operations have resulted in the theft of massive troves of intellectual1478property, trade secrets, source code, and sensitive defense1479technologies. This is not random or opportunistic--it is a deliberate1480strategy to fuel China's economic and military ambitions, with cyber1481capabilities serving as a core instrument of statecraft and industrial1482policy.1483 In this evolving threat environment, the need for real-time,1484bidirectional information sharing between Government and industry has1485never been more critical.1486 the legacy of the cybersecurity act of 20151487 The cyber information sharing laid the foundation for improved1488collaboration between Government agencies and private entities by1489creating a legal framework for voluntary information sharing. It1490offered liability protections to encourage private companies to share1491threat indicators and defensive measures with the Federal Government1492and, most importantly, business to business. Our thought was simple:1493see something, say something.1494 That framework helped normalize, and de-stigmatize, cyber threat1495information sharing across industries. The Department of Homeland1496Security's Automated Indicator Sharing (AIS) program and the role of1497Information Sharing and Analysis Centers (ISACs) and Organizations1498(ISAOs) are direct outgrowths of the Act.1499 The legislation was the product of 4 years of intensive effort,1500including over 100 meetings with stakeholders ranging from Fortune 1001501companies to small and medium-sized businesses, privacy advocates, and1502academic institutions. It also reflected countless consultations with1503Government agencies and underwent 3 major rewrites based on the1504feedback received. From the outset, the committee recognized the1505critical need to strike the right balance between privacy and security.1506With so much at stake, we knew we had to get it right.1507 However, while the law was forward-thinking at the time, the pace1508of technological change and the growing complexity of cyber threats1509have outpaced some of its provisions.1510 Despite progress, several key gaps remain:1511 1. Limited Participation.--Many private-sector entities,1512 particularly small and mid-sized businesses, still hesitate to1513 share information due to uncertainty about liability1514 protections and limited resources.1515 2. Speed and Relevance.--The timeliness and utility of shared data1516 can be inconsistent. Automated platforms are underutilized, and1517 actionable intelligence does not always flow quickly enough to1518 prevent or mitigate attacks.1519 3. Lack of Bidirectional Flow.--While private entities are1520 encouraged to share data with the Government, the feedback loop1521 is often one-way. Companies need useful, contextualized threat1522 intelligence in return.1523 4. Inconsistent Standards.--Threat data is not always shared in a1524 standardized, machine-readable format, limiting its utility at1525 scale.1526 5. Trust Deficit.--Public trust in Government handling of sensitive1527 data--particularly in sectors like finance and health care--1528 remains a concern. Transparency, oversight, and accountability1529 must be strengthened.1530 Reauthorizing the Cybersecurity Information Sharing Act gives1531Congress the opportunity to strengthen and scale its original vision.1532To strengthen national cybersecurity, Congress should expand and1533clarify liability protections to encourage broader information sharing.1534Businesses, particularly those outside of traditionally-designated1535``critical infrastructure'' sectors, need clear legal assurances that1536they will be shielded when acting in good faith. The scope of protected1537activities must be explicitly defined to eliminate ambiguity and foster1538participation. Small and medium enterprises, which often lack dedicated1539personnel or technical expertise, should be supported for training,1540tool kits, and access to threat-sharing ecosystems like Information1541Sharing and Analysis Centers (ISACs). Additionally, Federal agencies1542such as CISA must be required--not merely allowed--to share timely,1543relevant, and declassified intelligence with the private sector. Trust1544and engagement improve significantly when companies see tangible1545reciprocity.1546 Cybersecurity is no longer a technical issue; it is a national1547security imperative that requires whole-of-Nation coordination. No1548single company, agency, or State can defend against these threats1549alone. The adversaries we face--whether criminal networks or foreign1550governments--exploit our silos. We must instead leverage our strengths:1551diversity of talent, innovation, and democratic collaboration.1552 The reauthorization of information sharing presents a generational1553opportunity. We can reinforce our values, secure our systems, and1554create a more resilient digital economy by recommitting to a1555collaborative model built on transparency, accountability, and mutual1556support.1557 In closing, I urge this committee to quickly modernize and1558reauthorize this critical function. Let us affirm the importance of1559information sharing, strengthen the incentives and protections for1560participants, and build the trusted, interoperable, and actionable1561threat-sharing ecosystem our future demands.1562 Thank you again for the opportunity to testify.15631564 Mr. Garbarino. Thank you, Ms. Rinaldo.1565 I now recognize Mr. Schimmeck for 5 minutes to summarize1566his opening statement.15671568STATEMENT OF KARL SCHIMMECK, EXECUTIVE VICE PRESIDENT AND CHIEF1569 INFORMATION SECURITY OFFICER, NORTHERN TRUST15701571 Mr. Schimmeck. Chairman Garbarino, Ranking Member Swalwell,1572and distinguished Members of the committee, thank you for the1573opportunity to testify today on a matter of critical national1574importance: the urgent need to reauthorize the Cybersecurity1575Information Sharing Act of 2015.1576 My name is Karl Schimmeck. I serve as the chief information1577security officer at Northern Trust and serve on the board of1578directors of the Financial Services Information Sharing and1579Analysis Center, or the FS-ISAC.1580 I'm here today on behalf of the Securities Industry and1581Financial Markets Association, or SIFMA, where I sit on the1582Cybersecurity Committee.1583 SIFMA is the leading trade association for broker-dealers,1584investment banks, and asset managers operating in the United1585States. SIFMA advocates on legislation, regulation, and1586business policy affecting financial markets.1587 I've spent much of my career focused on cybersecurity in1588the financial sector, and I was directly involved in the1589advocacy that helped shape CISA 2015. That law was a bipartisan1590achievement, and it remains one of the most important1591cybersecurity tools that we have and a cornerstone of our1592Nation's cyber defense strategy.1593 The threats we face today are not hypothetical. They are1594real, growing, and increasingly dangerous. Nation-state actors1595are conducting relentless cyber operations against our critical1596infrastructure--banking systems, communication networks, energy1597grids, and Government agencies.1598 These attacks are not just attempts to steal data. They are1599designed to disrupt, destabilize, and undermine confidence in1600our institutions.1601 Put simply, cyber is now a national security domain, and1602the private sector is on the front lines.1603 CISA 2015 provides the legal foundation that enables1604companies like mine to share threat intelligence quickly and1605confidently with the Federal Government and with one another.1606It creates the trust, structure, and legal protections required1607for real-time collaboration.1608 Without the protections in the act--protections against1609civil liability, regulatory action, and antitrust exposure--1610companies would hesitate. They would share less and they would1611share more slowly. That hesitation would be a gift to our1612adversaries.1613 When CISA passed, there were concerns about protecting the1614privacy of individuals. After 10 years of activity, there have1615been no known reports that PII not directly related to a1616cybersecurity incident has been shared.1617 The participants in this system have a responsibility to1618ensure that the only information submitted is directly related1619to a cybersecurity threat. We take this responsibility1620seriously, and the unblemished track record demonstrates that1621commitment.1622 Let me be clear: If the act lapses, our Nation will be more1623vulnerable to cyber attacks the very next day. Threat sharing1624saves time, and in cybersecurity time is everything. It's the1625difference between stopping an attack at the perimeter or1626watching it spread across the system. It's the difference1627between a minor disruption and a systemic crisis.1628 We often say that cybersecurity is a team sport, but that's1629only true if the rules allow us to play together. CISA 20151630makes teamwork possible. Recent events, including SolarWinds1631and CrowdStrike, clearly evidence the value of rapid1632information sharing, which helped to minimize the damage of1633these events.1634 That's why we are calling on this subcommittee and the full1635Congress to act swiftly and decisively to reauthorize the act1636without delay, without changes. We cannot afford a gap in our1637defenses, not now, not with the threat landscape evolving by1638the day.1639 We are not asking for new authorities. We are asking to1640preserve what already works--a proven framework that enables1641trust, protects privacy, and makes us all stronger.1642 The act is not just a legal mechanism, it's a force1643multiplier. It has created a trusted architecture for cyber1644collaboration. To let it expire would be to knowingly dismantle1645the critical defense layer at a precise moment when we need it1646most.1647 In closing, I'll leave you with this: Cyber threats don't1648take breaks and they don't wait for legislative calendars. If1649we hesitate, we expose ourselves. If we act, we protect the1650Nation.1651 Thank you for the opportunity to speak today, and I look1652forward to any questions.1653 [The prepared statement of Mr. Schimmeck follows:]1654 Prepared Statement of Karl Schimmeck1655 May 15, 20251656 introduction1657 Chairman Garbarino, Ranking Member Swalwell, and distinguished1658Members of the subcommittee, thank you for the opportunity to testify1659today in favor of the reauthorization of the Cybersecurity Information1660Sharing Act of 2015 (``CISA 2015'' or the ``Act'').\1\ My name is Karl1661Schimmeck. I am an executive vice president and chief information1662security officer of Northern Trust, responsible for the design and1663management of the bank's information security, cybersecurity, and data1664protection programs. I am here today as a representative of the1665Securities Industry and Financial Markets Association (``SIFMA'') where1666I am a member of the Cybersecurity Committee. I am also on the board of1667directors of the Financial Services Information Sharing and Analysis1668Center (``FS-ISAC'').1669---------------------------------------------------------------------------1670 \1\ Consolidated Appropriations Act, 2016, Pub. L. No. 114-113,1671Div. N, Title I--Cybersecurity Information Sharing Act of 2015, 1291672Stat. 2935 (2015), 6 U.S.C. 1501; S. Rep. No. 114-32, at 2 (2015).1673---------------------------------------------------------------------------1674 Prior to my current position at Northern Trust, I served as chief1675information security officer and head of technology risk and resilience1676for Morgan Stanley's U.S. banks. Prior to that, I was managing director1677of cybersecurity, business resiliency & operational risk at SIFMA from16782011 to 2016, during which I was involved in the advocacy efforts for1679CISA 2015. During that time, I was also on the executive committee of1680the Financial Services Sector Coordinating Council (``FSSCC'').1681 SIFMA is the leading trade association for broker-dealers,1682investment banks, and asset managers operating in the United States and1683global capital markets. SIFMA advocates on legislation, regulation, and1684business policy affecting financial markets and serves as an industry1685coordinating body to promote fair and orderly markets, informed1686regulatory compliance, and efficient market operations and resiliency.1687 As part of its critical role as a coordinating body and as it1688relates to this hearing, SIFMA hosts an bi-annual cybersecurity1689exercise known as Quantum Dawn which brings together public and1690private-sector participants for a series of exercises that simulate the1691operational impacts that a systemic cyber attack could have on1692financial firms, critical third parties, and the global financial1693ecosystem due to a large-scale attack. Last year's exercise included1694more than 1,000 participants from 20 countries. The goal of the1695exercise is to improve response and recovery plans and strengthen1696global coordination and information-sharing mechanisms which are1697necessary for quickly responding to significant operational outages,1698including cyber events.\2\1699---------------------------------------------------------------------------1700 \2\ Press release, SIFMA Cybersecurity Exercise, Quantum Dawn VII1701After-Action Report (May 1, 2024), https://www.sifma.org/resources/1702general/cybersecurity-exercise-quantum-dawn-vii/.1703---------------------------------------------------------------------------1704 Certain key provisions of CISA 2015 are set to expire in September1705if Congress does not reauthorize them. SIFMA is calling for a clean1706reauthorization of the expiring provisions of CISA 2015 as soon as1707possible so that participating institutions will have the necessary1708assurances that the existing protections will continue. These expiring1709provisions include liability protections for private companies when1710sharing information pursuant to the Act--protections that are essential1711to the collective protection of the United States via the enhanced1712situational awareness that information sharing provides. It is critical1713that Congress reauthorize these provisions to preserve information1714sharing before they expire.1715 cisa 2015 background and reauthorization1716 Since its bipartisan passage 10 years ago, CISA 2015 has become a1717vital part of cyber defense by providing a robust legal and operational1718framework for voluntarily sharing information between the public and1719private sector in the United States. The financial services industry1720has since become reliant on the Act's legal framework and protections,1721which have proven necessary on many occasions. In the decade since its1722enactment, the law has meaningfully improved the capacity and speed1723with which we can respond to large-scale cyber incidents while1724establishing clear expectations for privacy and confidentiality. This1725includes building the structures used by private-sector cyber defenders1726to inform Government partners of on-going cyber threats from malicious1727actors.1728 The Act provides a formalized foundation for firms to voluntarily1729collaborate with both the Federal Government and other institutions to1730share necessary information to protect investors and the financial1731markets from cyber criminals seeking financial gain and nation-states1732seeking to disrupt orderly markets and critical infrastructure. This1733foundation is largely based on legal and liability protections granted1734to the private sector to further promote voluntary sharing of cyber1735threat indicators and defensive measures to help prevent imminent cyber1736threats. Public and private-sector participants primarily share this1737information through the Cybersecurity and Infrastructure Security1738Agency's (``CISA'') Automated Indicator Sharing Program (``AIS'') which1739operates a server that allows public and private participants to share1740cyber threat indicators.\3\ Once that information is analyzed and1741appropriately sanitized including the removal of personally1742identifiable information (``PII''), AIS shares indicators or defensive1743measures submitted by Government agencies and private-sector entities1744with all AIS participants. This information may also be compared and1745used in conjunction with post-incident information reporting required1746under the Cyber Incident Reporting for Critical Infrastructure Act of17472022 (``CIRCIA'') to prevent future incidents.\4\ Further, information1748sharing under CISA 2015 benefits financial institutions of all sizes1749and business models, not just large firms.1750---------------------------------------------------------------------------1751 \3\ Cong. Rsch. Serv., The Cybersecurity Information Sharing Act of17522015: Expiring Provisions (Apr. 8, 2025), https://www.congress.gov/1753crs_external_products/IF/PDF/IF12959/IF12959.4.pdf.1754 \4\ 6 U.S.C. 681a-681b.1755---------------------------------------------------------------------------1756 At the time of passage, there were some concerns about protecting1757the privacy of individuals when cyber threats were reported under CISA17582015. After 10 years of activity, no AIS participants (public or1759private) have been known to report PII that was not directly related to1760a cybersecurity incident pursuant to CISA 2015.\5\ The participants in1761this system have a responsibility to ensure that the only information1762submitted to AIS is directly related to a cybersecurity threat. All AIS1763participants are responsible for scrubbing any PII not directly related1764to cybersecurity threats prior to submission. Further, CISA has1765additional automated controls to identify potential PII in reports1766prior to dissemination through the AIS. Flagged information is reviewed1767and approved by designated CISA staff before it is sent out through1768AIS.1769---------------------------------------------------------------------------1770 \5\ Dep't of Homeland Sec. Off. of the Inspector Gen., CISA Faces1771Challenges Sharing Cyber Threat Information as Required by the1772Cybersecurity Act of 2015, OIG 24-60 (Sept. 25, 2024), https://1773www.oig.dhs.gov/sites/default/files/assets/2024-09/OIG-24-60-Sep24.pdf.1774---------------------------------------------------------------------------1775 The U.S. Government and the private sector face daily cyber threats1776that require cross-sector information sharing to capably combat.1777 The reality of the on-going threats to financial institutions,1778Federal and State governments, and the general public cannot be1779overstated. Nation-state hackers have launched numerous attacks on U.S.1780critical infrastructure \6\ including our communications systems--1781signaling they are positioning for bigger, more disruptive attacks.1782Federal agencies have similarly been targeted--most recently the1783Treasury Department in the BeyondTrust breach,\7\ the SolarWinds1784incident in which 9 agencies were compromised,\8\ and the Office of the1785Comptroller of the Currency email breach this year.\9\ Unfortunately,1786foreign cyber criminals continue to target U.S. companies through1787various tactics, such as phishing and ransomware, making information1788sharing essential to defending our critical infrastructure against such1789threats.\10\ Further, a recent report found that two-thirds of1790financial institutions faced cyber attacks in 2024.\11\ The threat is1791real, its increasing in volume, speed, and sophistication; effective1792information sharing is one of the best ways we can work together1793against this growing risk.1794---------------------------------------------------------------------------1795 \6\ Dustin Volz et al., How Chinese Hackers Graduated From Clumsy1796Corporate Thieves to Military Weapons, WALL ST. J. (Jan. 4, 2025),1797https://www.wsj.com/tech/cybersecurity/typhoon-china-hackers-military-1798weapons-97d4ef95; Nat'l Counterintelligence and Sec. Ctr. & Off. of1799Cybersecurity Exec, SolarWinds Orion Software Supply Chain Attack (Aug.180019, 2021), https://www.dni.gov/files/NCSC/documents/1801SafeguardingOurFuture/1802SolarWinds%20Orion%20Software%20Supply%20Chain%20Attack.pdf.1803 \7\ Arielle Waldman, CISA: BeyondTrust breach affected Treasury1804Department only, TECHTARGET (Jan. 7, 2025), https://www.techtarget.com/1805searchsecurity/news/366617777/CISA-BeyondTrust-breach-impacted-1806Treasury-Department-only.1807 \8\ Nat'l Counterintelligence and Sec. Ctr. & Off. of Cybersecurity1808Exec., SolarWinds Orion Software Supply Chain Attack (Aug. 19, 2021),1809https://www.dni.gov/files/NCSC/documents/SafeguardingOurFuture/1810SolarWinds%20Orion%20Software%20Supply%20Chain%20Attack.pdf.1811 \9\ Office of the Comptroller of the Currency, OCC Notifies1812Congress of Incident Involving Email System, News Rel. 2025-30 (April18138, 2025), https://occ.gov/news-issuances/news-releases/2025/nr-occ-18142025-30.html.1815 \10\ Office of the Dir. Of Nat'l Intelligence, Annual Threat1816Assessment of the U.S. Intelligence Community, (March 18, 2025).1817https://www.dni.gov/files/ODNI/documents/assessments/ATA-2025-1818Unclassified-Report.pdf.1819 \11\ Tom Kellerman, Modern Bank Heists Report 2025: Executive1820Summary, at 4 (Contrast Sec. 2025).1821---------------------------------------------------------------------------1822 Legal protections under CISA 2015 are necessary to facilitate1823information sharing by and among private companies.1824 CISA 2015 provides legal and liability protection for entities that1825share cyber threat indicators pursuant to the Act. Prior to CISA 2015,1826existing laws did not clearly shield private entities from regulatory1827enforcement actions, civil actions, or antitrust enforcement actions1828when sharing cyber threat information. Likewise, the law did not1829explicitly preserve legal protections, like attorney-client privilege,1830or safeguards for trade secrets and proprietary information shared with1831the Government or with other private entities for the purpose of1832preventing cyber attacks. CISA 2015 provided a clearer legal framework,1833outlining what information can be shared and how that information1834should be shared to retain these legal protections. Such protections1835encourage voluntary information sharing, which has become necessary for1836defending against cyber threats.1837 1. Protection from Civil Liability1838 Under the Act, if a private entity shares a cyber threat indicator1839or a defensive measure in accordance with CISA's procedures, it is1840protected from civil lawsuits that might otherwise arise from such1841sharing.\12\ The conditions for civil liability protections include1842sharing information in compliance with the Act's privacy and data-1843handling requirements and when sharing information with the Federal1844Government, doing so only through CISA's prescribed process. As a1845result, if a financial institution sends an IP address associated with1846malware to AIS in compliance with the Act, the firm cannot be held1847liable for a breach of privacy or other civil right of action in1848connection with that information sharing.1849---------------------------------------------------------------------------1850 \12\ 6 U.S.C. 1505.1851---------------------------------------------------------------------------1852 2. Protection from Antitrust Liability1853 CISA 2015 provides critical protection from antitrust liability for1854private entities that share covered information with the Federal1855Government or other private entities in accordance with the Act.\13\ As1856with the other legal protections provided under the Act, the1857information must be shared only in accordance with CISA 2015 and only1858used for the purpose of cybersecurity. In particular, the Act's1859antitrust exemption and associated protections have provided important1860assurances and therefore also facilitated broader cyber information1861sharing between private companies.1862---------------------------------------------------------------------------1863 \13\ 6 U.S.C. 1503(e)(1).1864---------------------------------------------------------------------------1865 3. Protection from Regulatory Enforcement Action1866 CISA 2015 provides that sharing cyber threat information or1867defensive mechanisms shall not be used by Federal regulators to take1868enforcement action against the sharing entity. This protection1869encourages financial institutions to share information voluntarily by1870providing assurance that such information will not be used against them1871in an enforcement proceeding brought by the Securities and Exchange1872Commission or other prudential regulators so long as that information1873is shared within the Act's stated parameters.1874 4. No Waiver of Privileges or Protections1875 Sharing cyber threat information under CISA does not waive any1876applicable privilege or legal protection, including attorney-client1877privilege and protections for trade secrets and proprietary business1878information. These provisions ensure that institutions can share1879indicators without fearing loss of legal protections over that1880information.1881 5. Controlled Government Use1882 Information shared under the Act may be retained and used by the1883Federal Government only for limited purposes including for1884cybersecurity, investigating, or prosecuting certain crimes (e.g.,1885cyber crime, identity theft, or serious violent crimes), and certain1886national security matters. This provision provides assurances to the1887private sector that the information they share voluntarily will not be1888used for purposes other than what was intended when disclosed.1889Public-private information sharing has been beneficial to the financial1890 services industry.1891 There are many examples where public-private information sharing1892has helped to mitigate significant cybersecurity threats impacting1893financial institutions. For example, during the SolarWinds incident1894SIFMA, FSSCC, and other organizations were able to quickly identify the1895impact areas thanks to information sharing among members but also with1896CISA and other Federal agencies. Even risks posed by non-malicious1897events in the CrowdStrike software update which caused a wide-spread1898outage in the financial services industry. This event demonstrated how1899well CISA's sharing and notification systems helped to improve1900resilience in the financial services industry and beyond.\14\ The1901ability to fend off imminent cyber threats through information sharing1902cannot be emphasized enough and these are just 2 examples of such1903events.1904---------------------------------------------------------------------------1905 \14\ Kapko, Mike, CrowdStrike snafu was a `dress rehearsal' for1906critical infrastructure disruptions, CISA director says, Cybersecurity1907Dive (Aug. 8, 2024), https://www.cybersecuritydive.com/news/1908crowdstrike-critical-infrastructure-resiliency-cisa/723712/.1909---------------------------------------------------------------------------1910A lapse in the legal framework provided in the Act could discourage1911 essential information sharing.1912 A lapse in the legal framework provided in the Act could limit1913cyber threat information sharing. These communication channels1914formalized under CISA 2015 are essential for enhancing overall1915awareness of national security threats and quickly responding to1916incidents.1917 Without these legal safeguards, the flow of information would slow1918significantly, leaving critical vulnerabilities and awareness of1919malicious activity unreported. Because information shared under the Act1920is related to cyber threats, that information may help prevent imminent1921cyber events before they happen, preserving time and resources that1922would be expended on the resolution of the event. While post-incident1923reporting also helps to prevent future attacks, such information may1924not be as useful for protecting against an impending threat.1925 In addition, these statutory provisions have been incorporated by1926reference to other significant cyber laws like CIRCIA--making1927reauthorization all the more critical.\15\1928---------------------------------------------------------------------------1929 \15\ See 6 U.S.C. 681a.1930---------------------------------------------------------------------------1931 conclusion1932 In closing, SIFMA and the financial services industry remain1933committed to strengthening the cybersecurity of our Nation's critical1934infrastructure. CISA 2015 has been a vital tool in building the trust,1935structure, and legal certainty needed for effective, real-time1936collaboration between the private sector and Government. It has made1937our institutions more resilient, our responses more coordinated, and1938our defenses more adaptive.1939 Allowing the Act to lapse would weaken one of the most constructive1940public-private partnerships in cybersecurity policy to date. We1941respectfully urge this subcommittee and Congress to act swiftly to1942reauthorize CISA 2015.19431944 Mr. Garbarino. Thank you, Mr. Schimmeck.1945 I now recognize Ms. Kuehn for 5 minutes to summarize her1946opening statement.19471948 STATEMENT OF KATHERINE KUEHN, MEMBER AND CISO-IN-RESIDENCE,1949 NATIONAL TECHNOLOGY SECURITY COALITION19501951 Ms. Kuehn. Chairman Garbarino, Ranking Member Swalwell, and1952Members of the committee, thank you for the opportunity to1953testify today in support of reauthorizing the Cybersecurity1954Information Sharing Act of 2015 and the importance of public-1955private partnerships in protecting our national security.1956 My name is Katherine Kuehn, and I am a board member of the1957National Technology Security Coalition and serve as their CISO-1958in-residence.1959 Established in 2016, the NTSC is a nonprofit, nonpartisan1960organization that advocates for the chief information security1961officers, chief privacy officers, and senior security1962technology executives.1963 NTSC's mission is to advance cybersecurity policies that1964protect critical national infrastructure and foster strong1965collaboration between the public and private sectors to secure1966our digital landscape.1967 As a part of this mission, we have been deeply involved in1968shaping the national conversation on cybersecurity, including1969advocacy for the creation of the Cybersecurity Advisory1970Committee.1971 The Cybersecurity Information Sharing Act of 2015 has long1972been a cornerstone of our national cybersecurity strategy.1973Since its inception, this law has fostered collaboration1974between industry leaders and Federal agencies, enabling the1975identification and mitigation of cybersecurity threats.1976 The legal protections offered by CISA encourage private1977organizations to share information without fear of1978repercussions, enhancing the Nation's ability to respond to1979cyber attacks. It facilities the exchange of critical cyber1980information threats between private-sector companies and the1981Federal Government.1982 CISA provides incentives for companies to share1983cybersecurity threat indicators, such as software1984vulnerabilities and malware, with the Department of Homeland1985Security, DHS. This collaboration is crucial for preventing1986data breaches and attacks from cyber criminals and foreign1987adversaries.1988 This law has been pivotal in addressing some of the most1989significant cyber threats over the past decade, including high-1990profile incidents like the SolarWinds breach and, more recent,1991the Volt Typhoon and Salt Typhoon campaigns. These attacks1992underscore the growing sophistication and scale of cyber1993threats we face today.1994 As noted by Senators Gary Peters and Mike Rounds, allowing1995CISA 15 to lapse would significantly weaken our cybersecurity1996ecosystem and undermine the ability to address these1997sophisticated threats. Moreover, a lapse would remove essential1998liability protections and hinder defensive operations across1999critical sectors.2000 The protections under CISA 15 have provided legal certainty2001for companies that might otherwise hesitate to share critical2002data threats.2003 This safe harbor provision has been crucial in fostering a2004culture of trust and collaboration. Without this legal2005protection, the flow of vital threat intelligence would slow,2006hindering both proactive and reactive cyber defense efforts.2007 Cybersecurity is a team sport, one that requires2008collaboration between Government and private sector.2009Information sharing is essential for national security as cyber2010threats become increasingly sophisticated.2011 The current global cyber threat environment demands2012constant information exchange between these sectors to protect2013the Nation's critical infrastructure.2014 CISA 15 has been instrumental in supporting this2015collaboration, particularly through initiatives like the Joint2016Cyber Defense Collaborative, which unites Federal agencies and2017leading private-sector companies.2018 Unfortunately, the recent termination of the Critical2019Infrastructure Partnership Advisory Council, the disbandment of2020the Cyber Safety Review Board, and the dismissal of members of2021the Cybersecurity Advisory Committee have undermined public-2022private cooperation in cybersecurity. These advisory bodies2023have played crucial roles in fostering dialog and sharing best2024practices between Government and industry. Their loss has2025created a gap that must be addressed.2026 The importance of public-private partnerships is further2027emphasized by the fact that critical infrastructure sectors,2028such as energy, finance, and health care, are predominantly2029managed by private companies. These industries rely on timely2030and accurate information to protect themselves against attacks2031from nation-state actors and cyber criminals.2032 Information sharing is crucial for defending against2033complex state-sponsored attacks, such as those originating from2034Russia, China, and North Korea.2035 The NTSC was directly involved in creating the2036Cybersecurity Advisory Committee, which was introduced in 20192037through bipartisan legislation, a bill aimed at establishing an2038advisory committee composed of highly-skilled cybersecurity2039professionals responsible for protecting enterprises across all2040primary business sectors.2041 The Advisory Committee would serve as a valuable cyber2042resource, providing unparalleled insight and expertise to the2043director of the Cybersecurity and Infrastructure Security2044Agency and Homeland Security.2045 The NTSC, in collaboration with these Members of Congress2046and this committee, proposed the idea for the Advisory2047Committee and played a central role in the establishment.2048 In conclusion, the reauthorization of CISA 15 is crucial2049for maintaining the Nation's cybersecurity and strengthening2050public-private partnerships in cybersecurity. The law has2051fostered a collaborative environment that enables real-time2052sharing of cyber intelligence and defends against attacks from2053sophisticated adversaries.2054 We urge Congress to prioritize a clean reauthorization of2055CISA 15 and to ensure that we continue to look at areas we can2056focus on joint public-private cybersecurity collaboration.2057 I thank you for your attention to this critical issue, and2058I look forward to addressing your questions.2059 [The prepared statement of Ms. Kuehn follows:]2060 Prepared Statement of Katherine Kuehn2061 Wednesday, May 15, 20252062 The National Technology Security Coalition (NTSC) is a nonprofit,2063nonpartisan organization that serves as the preeminent advocacy voice2064for the chief information security officer (CISO) and senior security2065technology executives. Through dialog, education, and Government2066relations, we unite both public and private-sector stakeholders around2067policies that improve national cybersecurity standards and awareness.2068 Chairman Garbarino, Ranking Member Swalwell, and Members of the2069committee, thank you for the opportunity to testify today in support of2070reauthorizing the Cybersecurity Information Sharing Act of 2015 (CISA20712015) and the importance of public-private partnerships in protecting2072our national security. My name is Katherine Kuehn, and I am a board2073member of the National Technology Security Coalition (NTSC), serving as2074the CISO-in-residence.2075 Established in 2016, the NTSC is a nonprofit, nonpartisan2076organization that advocates for chief information security officers,2077chief privacy officers, and senior security technology executives.2078NTSC's mission is to advance cybersecurity policies that protect2079critical infrastructure and foster strong collaboration between the2080public and private sectors to secure our digital landscape. As part of2081this mission, we have been deeply involved in shaping the national2082conversation on cybersecurity, including advocacy for the creation of2083the Cybersecurity Advisory Committee.2084 The Cybersecurity Information Sharing Act of 2015 has been a2085cornerstone of our national cybersecurity strategy. Since its2086inception, this law has fostered collaboration between industry leaders2087and Federal agencies, enabling the identification and mitigation of2088cybersecurity threats. The legal protections offered by CISA encourage2089private organizations to share information without fear of legal2090repercussions, enhancing the Nation's ability to respond to cyber2091attacks. It facilitates the exchange of critical cyber threat2092information between private-sector companies and the Federal2093Government. Through CISA 2015, companies can share indicators of cyber2094threats, such as software vulnerabilities, malware, and malicious IP2095addresses, without fearing liability or legal repercussions. This2096collaborative approach has been instrumental in enhancing the Federal2097Government's ability to respond to cyber attacks quickly and2098effectively.2099 CISA provides incentives for companies to share cybersecurity2100threat indicators, such as software vulnerabilities and malware, with2101the Department of Homeland Security (DHS). This collaboration is2102crucial for preventing data breaches and attacks from cyber criminals2103and foreign adversaries. This law has been pivotal in addressing some2104of the most significant cybersecurity threats over the past decade,2105including high-profile incidents like the SolarWinds breach and the2106more recent Volt Typhoon and Salt Typhoon campaigns. These attacks2107underscore the growing sophistication and scale of cyber threats we2108face today. As noted by Senators Gary Peters and Mike Rounds, allowing2109CISA 2015 to lapse would ``significantly weaken our cybersecurity2110ecosystem'' and undermine the ability to address these sophisticated2111threats.2112 Moreover, a lapse would remove essential liability protections and2113hinder defensive operations across critical sectors. The protections2114under CISA 2015 have provided legal certainty for companies that might2115otherwise hesitate to share critical threat data. This ``safe harbor''2116provision has been crucial in fostering a culture of trust and2117collaboration. Without this legal protection, the flow of vital threat2118intelligence would slow, hindering both proactive and reactive cyber2119defense efforts.2120 Cybersecurity is a team effort--one that requires collaboration2121between the Government and the private sector. Information sharing is2122essential for national security as cyber threats become increasingly2123sophisticated. The current global cyber threat environment demands2124constant information exchange between these sectors to protect the2125Nation's critical infrastructure. CISA 2015 has been instrumental in2126supporting this collaboration, particularly through initiatives like2127the Joint Cyber Defense Collaborative, which unites Federal agencies2128and leading private-sector cybersecurity firms.2129 Unfortunately, the recent termination of the Critical2130Infrastructure Partnership Advisory Council, the disbandment of the2131Cyber Safety Review Board, and the dismissal of members of the2132Cybersecurity Advisory Committee have undermined public-private2133cooperation in cybersecurity. These advisory bodies played a crucial2134role in fostering dialog and sharing best practices between the2135Government and industry. Their loss has created a gap in collaboration2136that must be addressed.2137 The importance of these public-private partnerships is further2138emphasized by the fact that critical infrastructure sectors--such as2139energy, finance, and health care--are predominantly managed by private2140companies. These industries rely on timely and accurate information to2141protect themselves against attacks from nation-state actors and cyber2142criminals. Information sharing is crucial for defending against2143complex, state-sponsored cyber attacks, such as those originating from2144Russia, China, and North Korea.2145 The NTSC was directly involved in creating the Cybersecurity2146Advisory Committee, which was introduced in 2019 through bipartisan2147legislation. In the 116th Congress, Representatives John Katko, Dan2148Newhouse, Brian Fitzpatrick, and Dan Lipinski introduced H.R. 1975, the2149Cybersecurity Advisory Committee Act of 2019, a bill aimed at2150establishing an advisory committee composed of highly-skilled2151cybersecurity professionals responsible for protecting enterprises2152across all primary business sectors. The advisory committee would serve2153as a valuable cyber resource, providing unparalleled insight and2154expertise to the director of the Cybersecurity and Infrastructure2155Security Agency and the Secretary of Homeland Security. The NTSC, in2156collaboration with these Members of Congress and this committee,2157proposed the idea for the advisory committee and played a central role2158in its establishment.2159 The advisory committee was established to provide expert guidance2160on cybersecurity policy and offer actionable recommendations to enhance2161the Nation's defenses. Its work has been invaluable in shaping2162cybersecurity policy and ensuring the Government remains in close2163contact with industry leaders. Reinstating this advisory body is2164essential for ensuring that our cybersecurity policies continue to2165evolve in response to new threats.2166 Given the urgency of the current cyber threat landscape, Congress2167must proceed with a clean reauthorization of CISA 2015. While there2168will be opportunities to adjust the law in the future, now is not the2169time for complicated negotiations that could delay reauthorization. A2170clean reauthorization would preserve the practical framework that2171facilitates public-private collaboration and provides legal protections2172for information sharing.2173 In conclusion, the reauthorization of CISA 2015 is crucial for2174maintaining the Nation's security and strengthening public-private2175partnerships in cybersecurity. The law has fostered a collaborative2176environment that enables the real-time sharing of cyber threat2177intelligence, helping to defend against attacks from sophisticated2178adversaries.2179 We urge Congress to prioritize a clean reauthorization of CISA 20152180to ensure the continued effectiveness of these public-private2181partnerships and the legal protections they provide. Furthermore, we2182urge Congress and the administration to reinstate advisory bodies, such2183as CIPAC, CSRB, and CSAC, to strengthen public-private cybersecurity2184collaborations.2185 Thank you for your attention to this critical issue. I look forward2186to addressing any questions you may have.21872188 Mr. Garbarino. Thank you, Ms. Kuehn.2189 Members will be recognized by order of seniority for their21905 minutes of questioning. I want to remind everyone to please2191keep their questioning to 5 minutes. Sometimes we go over. It's2192OK. An additional round of questioning may be called after all2193Members have been recognized.2194 I now recognize the gentleman from Florida, Mr. Gimenez,2195for 5 minutes of questioning.2196 Mr. Gimenez. Thank you, Mr. Chairman.2197 I understand the importance of reauthorizing that bill, but2198what is the state of the cyber threat today compared to what it2199was 10 years ago?2200 Mr. Miller.2201 Mr. Miller. Thank you for the question, Congressman.2202 I think by any account, the state of the cyber threat today2203is that there are far more threats. We have a different2204technology environment, including threats such as ransomware,2205which we weren't really talking about 10 years ago, threats to2206operational technology, and artificial intelligence, which is2207clearly on everyone's minds. Artificial intelligence can be2208used both as a sword and a shield, as it were.2209 Also, I think it's fair to say that we have much more--even2210more sophisticated nation-state threat actors, the usual2211suspects, of course, China, Russia, North Korea, Iran.2212 So, I mean, I think when we look at it and we look at the2213cyber threat ecosystem in particular, there are a lot more2214threats. But the good news is, in large part because of CISA221515, we're able to share much more information at scale to keep2216pace with the various different changes in technology today2217than we were 10 years ago. That's why I think you hear2218unanimity on this panel that we need to----2219 Mr. Gimenez. There are a number of cybersecurity companies2220that are contracted by different companies, et cetera, right?2221So do you find that they share information freely or do they2222try to keep their stuff proprietary and try to shield2223themselves from competition?2224 Mr. Miller. Well, I mean, I don't know that I can talk2225about individual companies' business practices. But I will say,2226generally speaking, that when we think about Automated2227Indicator Sharing in particular we have--yes, there are some2228very large, excellent cyber threat companies who are sharing2229information with their customers at scale. They're plugged into2230the AIS system.2231 Mr. Gimenez. But that's not--I'm not talking about their2232customers. I'm talking about sharing it throughout the Nation.2233In other words, not just their customers. I'm talking about2234sharing information with other entities that may not be using2235the same company for cybersecurity.2236 How is that? Is there still a barrier there? Are there2237barriers there? Or are they freely sharing information across2238different companies and different platforms?2239 Mr. Miller. I think when we look at the Information Sharing2240and Analysis Centers, the ISACs--and I can most speak to the2241IT-ISAC, but there are ISACs for all 16 critical infrastructure2242sectors--there are thousands of companies participating in2243those ISACs and sharing information, including the2244cybersecurity companies.2245 I mean, as far as I know, there are not barriers to sharing2246there. Actually, the fact that we are able to share at scale2247amongst all these different entities is certainly a very good2248thing, because the cyber companies do participate in those2249sorts of sharing activities.2250 There are others, other groups, like the Cyber Threat2251Alliance for instance, there are various other information and2252sharing and analysis organizations out there, and there's a lot2253of sharing going on, much, much more sharing than there was2254pre-CISA 15.2255 Mr. Gimenez. Thank you.2256 You talked about artificial intelligence, that it could be2257a sword or it could be a shield. Who's winning?2258 Mr. Miller. I mean, I'd certainly like to think that the2259good guys are winning. Right now, it's probably----2260 Mr. Gimenez. That's a matter of perspective. When we're2261trying to hack into somebody else, we're the good guys. So2262that's a sword.2263 So who's winning, the sword or the shield? Who is keeping2264pace with who? Is the shield keeping pace with the sword?2265 Mr. Miller. I think it's hard to generalize, but, I mean, I2266think that the way in which artificial intelligence technology2267is being used by defenders is proving quite effective today.2268But we really can't let our guard down, because, again, the2269good guys are innovating and so are the bad guys. So we really2270need to keep pace.2271 Mr. Gimenez. Do you think that it would be a wise move for2272Congress, for the Government, to invest in artificial2273intelligence as a shield? Because we're never going to match2274our adversaries in terms of the manpower that they pour into2275this effort. The only way that we can match that is through2276automation.2277 Do you agree with that, Mr. Schimmeck?2278 Mr. Schimmeck. Similar to private-sector companies, the2279U.S. Government should be investing in artificial intelligence,2280improving its capabilities. We rely on the U.S. Government and2281its capabilities, both offensive and defensive in nature, to2282support us and protect us. So the more effective you can be,2283the better protected we're going to be in the end.2284 Mr. Gimenez. Thank you so much.2285 I yield back.2286 Mr. Garbarino. The gentleman yields back.2287 I always love when you ask questions. I never know where2288you're going to go.2289 [Laughter.]2290 Mr. Gimenez. I don't either until I get here.2291 Mr. Garbarino. I love it.2292 I now recognize the gentleman from Rhode Island, Mr.2293Magaziner, for 5 minutes of questions.2294 Mr. Magaziner. Thank you, Chairman.2295 The Cybersecurity and Infrastructure Security Agency, CISA,2296leads our Nation in securing businesses' critical2297infrastructure and the Government from cyber criminals,2298hackers, and adversarial countries.2299 When U.S. businesses are attacked, CISA provides vital2300response and recovery. When there's an emerging cyber threat or2301a breach, CISA warns private industry about the threat and also2302provides training and education to the private sector, critical2303information operators, educational partners, and the general2304public.2305 The absolutely vital work done at CISA makes our country2306safer from the growing threats on cyber space, in cyber space.2307I am glad that there is bipartisan interest in reauthorizing2308the Cyber Information Sharing Act of 2015 so that this work can2309continue.2310 In part, though, the continued success of CISA and the2311hopefully growing success of CISA depends not just on this2312legislation being reauthorized but in making sure that CISA is2313adequately resourced. We need to ensure that the Trump and Musk2314administration doesn't cut CISA to the extent that they have2315announced they intend to do so. We should be investing in this2316space, not cutting back, because our adversaries are not2317cutting back.2318 If we're going to believe that the administration takes2319cybersecurity seriously, then we're going to need to see from2320them a reversal in their plan to cut nearly half a billion2321dollars from CISA's budget, which is what was proposed in the2322administration's fiscal 2026 budget. If the administration took2323cybersecurity seriously, they would be investing in CISA, not2324cutting it.2325 So we need to talk about that. Then we need to talk about2326the alternative. How do we build CISA up to continue to be2327successful going forward in the context of an ever-more complex2328and hostile threat environment targeting the United States?2329 So I'll start with Ms. Kuehn.2330 So in April it was reported that the administration, the2331Trump administration, plans to cut over a thousand jobs at2332CISA, which is expected to impact a myriad of programs across2333the agency.2334 Can you discuss what the impact of those kinds of work2335force cuts would be and whether they are a good idea or not?2336 Ms. Kuehn. So I think when you talk about the threats--if2337we talk about the threats that we're facing right now--you were2338asking about adversaries earlier.2339 One of the critical roles that CISA is playing right now is2340that we really have, with the advent of AI, and specifically2341generative and agentic AI, 3 types of threats right now. We2342have malicious, which we all understand, nation-state2343adversaries and criminals.2344 We also have malfunction and mistake. So if we think about2345what happened this summer with CrowdStrike from a software2346incident perspective, and then also with AI when all of a2347sudden an LM decides to go poorly.2348 So CISA is playing a critical role, No. 1, the public2349partnership groups that I discussed before, like JCDC and the2350Advisory Council, of helping share information between the2351companies that are on the front lines in the private sector2352developing technologies and the Government when things happen2353from a threat perspective.2354 The other thing that's really critical is we talk a lot2355about the private sector, but the reality is, is that a huge2356amount of our critical national infrastructure sits within2357medium and small businesses, and they rely on CISA for things2358like the small company guidances that came out in the last few2359years with cyber.2360 Mr. Magaziner. Yes. I think that's such an important point.2361I mean, one of the things that I think the general member of2362the public doesn't fully appreciate unless they're deep in this2363stuff is that when our adversaries, particularly the state2364actors, China, Iran, North Korea, others, are trying to hack2365into U.S. systems, it's not just the big Government agencies2366like the Pentagon or the big companies like Northern Trust, but2367small and medium-sized businesses, and also all of these local2368utilities and local governments all across the country.2369 We hear about these cases in Classified settings, but there2370are also plenty of cases that have been publicly reported of2371local water systems, local airports, et cetera.2372 So, again, just getting back to the issue of resources and2373work force, CISA has, I mean, thousands and thousands of2374customers that it needs to interface with, small businesses,2375small localities.2376 So, again, how important is it that we maintain a strong2377work force at CISA in that light?2378 Ms. Kuehn. So I'll give an example. You talk about the2379small businesses and the importance of CISA.2380 Not long ago I was on a plane chatting with a woman next to2381me. She was on her way to Florida because she was meeting her2382husband and her grandkids, and her husband was retiring from2383his job.2384 What did he do? Well, he was a concrete distributor in2385Dallas. She explained to me that they were selling the company.2386 The company was going out of business, basically, because,2387she literally went, ``There was one of those ransomware attack2388things. He borrowed my phone and did something for business on2389my phone, and we had a ransomware thing. And something, there2390was a gang in Turkiye''--and this is her explaining this to2391me--``who charged us $6 million. And it was just too hard to2392clean up. We don't have the ability of understanding the2393cybersecurity. And so we just gave up and we're closing the2394business and he's going to retire.''2395 That's the issue we're facing here, is that while we can2396represent large organizations that can spend millions and2397millions and millions on cybersecurity, there are exponentially2398more organizations out there--critical national infrastructure,2399small banks, grocery stores, you name it--that don't have the2400ability and need organizations like the program CISA provides2401in order to ensure that we have mature cybersecurity.2402 Mr. Magaziner. Thank you.2403 Mr. Garbarino. The gentleman yields back.2404 I now recognize the gentleman from Tennessee, Mr. Ogles,2405for 5 minutes of questions.2406 Mr. Ogles. Thank you, Mr. Chairman.2407 Thank you to the witnesses.2408 I think, by and large, we all agree that CISA should be2409reauthorized. So then the question becomes: How do we make it2410better? I know there have been some calls, let's do a clean re-2411auth and just get it out the door quickly.2412 But as we look at the landscape as we go forward, obviously2413in battlefield terms, as warfare has changed, I would argue2414that one of those battlefields is in the cyber realm.2415 So, Mr. Miller, I know you've had some suggestions in2416particular, some of the definitions as it pertains to CISA. Any2417thoughts on how we can improve as we go into reauthorization to2418make it better, stronger, more robust?2419 Mr. Miller. Thank you for that question, Congressman.2420 Yes, I did include some recommendations in my statement. I2421mean, I do think, in general, the approach that we should be2422taking if we're looking at changes is to just ask a pretty2423simple question: Hey, what's changed in the past 10 years from2424a threat standpoint, from a technology standpoint?2425 Are the very technical definitions that we have of cyber2426threat indicator and defensive measures in the bill, do they2427really account for all the different types of attacks that2428companies are experiencing today? Are we sharing the types of2429threat information that we need to counteract those threats?2430 I think one example of a relatively novel type of attack2431that's grown to prominence--I mean, someone mentioned2432SolarWinds earlier--supply chain attacks, software supply chain2433attacks.2434 Right now, if a company knows that there is a suspect2435supplier in its supply chain, it doesn't get the type of2436liability protections that CISA provides to share that sort of2437information.2438 So if you were thinking about making surgical, precise2439edits or changes to the bill, again, I would not open it up2440entirely, but you could look at things like the definition of2441cyber threat indicator, which has, I don't know, 7 or 82442subparts, and you could perhaps add something like derogatory2443information about a supplier in your supply chain or something2444like that.2445 That's just an example. But, I mean, that's like the2446general type of approach I would take rather than making2447wholesale changes to update the law.2448 Mr. Ogles. Well, kind-of going back to Mr. Gimenez's point,2449I think one of the things we need to look at is better2450information sharing, broadening the scope of who might be2451included. But then, with that, you probably need, to your2452point, the liability protections to protect someone as they're2453sharing information that otherwise might be.2454 So what about the JCDC? What role might they play as we go2455forward?2456 Mr. Miller. Yes. I mean, as others have testified to, the2457JCDC is a very valuable newer partnership that CISA has led,2458obviously.2459 It's really focused on operational collaboration as opposed2460to simply sharing information, and that's really what this is2461all about.2462 I will say, it is my understanding that you really could2463not have JCDC still without the liability protections that2464exist in CISA 15, though.2465 I mean, there are MOUs that companies that participate in2466JCDC sign, but that really deals more with information2467dissemination and adhering to pretty strict traffic light2468protocols. It doesn't have anything to do with the fundamental2469liability protections and authorizations that CISA provides for2470sharing the threat information in the first place, which at the2471end of the day is what underpins JCDC.2472 Mr. Ogles. Ms. Rinaldo, you touched on China in rather2473stark terms. Do you just want to give us a quick brief of are2474we adequately protecting ourselves with CISA and the2475reauthorization in terms of China and obviously their bad2476actions?2477 Ms. Rinaldo. Absolutely. When we were doing our fact-2478finding mission as we were drafting the legislation, one thing2479that was very abundantly clear is that more than 90 percent of2480our networks are held by the private sector. So what can we do2481as a Government to help protect the private sector?2482 So the idea of information sharing and the importance of2483Government to business. I think, to your question to John, how2484do we improve the transport of information from the Government2485to business? I would say that was one part that's lacking2486today. Not necessarily need--you don't need a Congressional2487change to make that happen, just oversight. How could we stay2488on top of the agencies to make sure that they are pushing out2489information?2490 Then I would also say security clearances is a big issue.2491You may have people that can get a clearance, go into a room,2492hear the information, but do you have the engineers that can2493actually act on it? So that's an important aspect as well.2494 Mr. Ogles. Mr. Chairman, I know I'm out of time. But I2495would just say to all the witnesses, if you have any2496suggestions or recommendations that might be specific as to how2497we make it better, now would be the time to provide that input.2498So if you would like to send that to my office or, of course,2499to anyone on the committee, the Chairman, happy to take a look2500at that, incorporate it, because, obviously, again, as we look2501to the future, as we look to the future of warfare, this is one2502of those battlefronts. We need to be ready. We need to be2503proactive. We need to be ahead of the AI curve.2504 Mr. Chairman, I yield back. Thank you for your2505graciousness.2506 Mr. Garbarino. The gentleman yields back.2507 I second that thought. So that's great.2508 I now recognize the Ranking Member, the gentleman from2509California, Mr. Swalwell, for 5 minutes of questions.2510 Mr. Swalwell. Thank you.2511 To follow what Ms. Rinaldo was saying about JCDC, Ms.2512Kuehn, can you discuss how JCDC facilitates information2513sharing? To Ms. Rinaldo's point, how important is it for CISA25142015 to be effective that we have a mechanism like JCDC that2515facilitates cross-sector information sharing?2516 Ms. Kuehn. I think how JCDC disseminates today and the2517critical importance of it and, to your point, that it's a2518relatively new program, one of the things about it is it allows2519for rapid distribution when threat happens between industry and2520Government so that we have, in essence, a real-time channel of2521things that are going on.2522 From an industry perspective it's really important that we2523even broaden the scope of it to work closer with the ISACs and2524to think about how we can distribute not just to the top level2525of industry but actually pull it down.2526 From a JCDC perspective, I think it's one of the best2527things we've seen come out of CISA so far, and it's still2528evolving.2529 But that ability to have information sharing without2530repercussion I think is one of the areas that we really need to2531focus on. So that's why looking at the, in essence,2532reauthorization of this act is so important, because we're just2533at the beginning of where JCDC could go.2534 As we start to think about--we mentioned China, but if we2535think about the Chinese threats that have come in from Volt2536Typhoon, Salt Typhoon, Flax Typhoon, Nylon Typhoon--there's a2537lot of typhoons right now--we're going to see, in essence,2538cross-pollination of those critical vulnerabilities' exploits,2539and JCDC is going to be incredibly important to ensure we2540disseminate rapidly through that.2541 Mr. Swalwell. To Ms. Rinaldo's point about security2542clearances, it's a frustration I share as well. My district is2543high tech and biotech, two nuclear labs. Often I hear what Ms.2544Rinaldo is saying, which is, yes, the CEO is cleared, but he's2545not the engineer. He doesn't understand. No. 1, his time is2546limited, or her time is limited; and, No. 2, he or she doesn't2547have the skill set to receive and understand the threat. But2548the problem on the Government side is they're not really2549willing to clear that many individuals.2550 I just welcome your feedback on if you're seeing that.2551Because if you remember like 2 years ago, it was a 19-year-old2552who was caught leaking Ukraine war plans, and it was a military2553service member. You're like, wait, we have a 19-year-old like2554basically the war plans for Ukraine, but we have like 20-year2555professionals who we could give 1-day passes or more2556information to better protect critical infrastructure and we're2557cautious about that?2558 So it just seems like we've got the priorities crosswise.2559But I'd welcome feedback from you, Ms. Kuehn, on that.2560 Ms. Kuehn. It's interesting. I've been in cybersecurity for2561over 25 years, and some of the first attacks or hacks I dealt2562with were nation-state-level attacks going around the financial2563services network. You can imagine, I was 23 years old walking2564rooms with Scotland Yard and looking at data center break-ins.2565Then some of the first financial services attacks.2566 I have never held a security clearance in the United States2567and I've been a risk executive of 2 Fortune 25 companies.2568 The reality is that we do need to reexamine how we look at2569clearance. But we also have to think about the fact that2570cybersecurity is to some degree--and we talked about it--a team2571sport. I've known 15-year-olds who have had inventions become2572state secrets and housed in the NSA, and I've known 90-year-2573olds who still sit on boards and talk about cybersecurity.2574 The reality of today's risk is that cyber risk is now2575business risk. It's a question of how we look at protecting all2576the different areas. Companies look at risk from a financial,2577operational, resilience perspective, everything.2578 So from a clearance perspective, it's getting the right2579individuals in an organization cleared to ensure they2580understand, but also to make it more of a common language so we2581understand the impact risk has on our organizations.2582 Mr. Swalwell. Just as Mr. Ogles said, I welcome ideas,2583feedback. I am a little hesitant to want to amend this at all2584at this point, at this late hour, risking that opening this up2585would not see it reauthorized.2586 But I do agree with Mr. Ogles that we need your feedback.2587Just because we reauthorize it, if we do it in a clean way,2588that doesn't mean we can't down the road, even right after2589reauthorization, have hearings and mark-ups to make it even2590better.2591 But avoiding a lapse is my priority, and it sounds like,2592Ms. Kuehn, you agree.2593 Ms. Kuehn. That would actually be my recommendation. I2594think that a reauthorization cleanly and then look at how we2595optimize and look at things down the road for a couple reasons.2596 We're at the beginning of AI. We're still trying to figure2597out some things regarding different types of attacks. Like I2598said, we have malicious, mistake, and malfunction. I think2599there's a way we can strengthen public-private on the back of2600it. But I would recommend a clean authorization.2601 Mr. Swalwell. Thank you. I yield back.2602 Mr. Garbarino. The gentleman yields back.2603 I now recognize myself for 5 minutes of questions.2604 I just want to say, since the beginning of Congress we have2605been approached by countless stakeholders about the need to2606reauthorize CISA 2015. In fact, we have 8 statements that we2607will be submitting for the record, one of which has 522608organizations as signatories.2609 So I would like to, without objection, add these to the2610record.2611 So done. OK, wonderful. So ordered.2612 That's great. I can do this by myself. Wonderful.2613 [The information follows:]2614 Letter From Business Roundtable2615 May 15, 2025.2616The Honorable Mark Green,2617Chairman, Committee on Homeland Security, U.S. House of2618 Representatives, Washington, DC 20515.2619The Honorable Bennie Thompson,2620Ranking Member, Committee on Homeland Security, U.S. House of2621 Representatives, Washington, DC 20515.2622The Honorable Andrew Garbarino,2623Chairman, Subcommittee on Cybersecurity and Infrastructure Protection,2624 Committee on Homeland Security, U.S. House of Representatives,2625 Washington, DC 20515.2626The Honorable Eric Swalwell,2627Ranking Member, Subcommittee on Cybersecurity and Infrastructure2628 Protection, Committee on Homeland Security, U.S. House of2629 Representatives, Washington, DC 20515.2630 Dear Chairman Green, Ranking Member Thompson, Subcommittee Chairman2631Garbarino, and Subcommittee Ranking Member Swalwell: Business2632Roundtable urges the Committee on Homeland Security to swiftly consider2633legislation to reauthorize the Cybersecurity Information Sharing Act of26342015 to ensure there is no disruption in the critical information-2635sharing activities on which the public and private sectors depend to2636defend against escalating cyber threats. A lapse in the Cybersecurity2637Information Sharing Act of 2015 authorities would hamstring both2638Federal and private-sector preparedness for and response to cyber2639threats. It would signal to malicious threat actors that, after2640September 30, 2025, the United States' cybersecurity posture will2641weaken, potentially encouraging future attacks on our critical2642infrastructure.2643 Since enactment, the Cybersecurity Information Sharing Act of 20152644has played a crucial role in facilitating information sharing on2645cybersecurity threats in the United States. By providing liability2646protections and exemptions from Federal antitrust law, Freedom of2647Information Act disclosure, and State disclosure laws, the law2648incentivizes voluntary sharing of cyber threat indicators and defensive2649measures. This law ultimately simplifies the process for sharing2650information, reducing regulatory burden and accelerating the response2651to cybersecurity incidents within and across sectors. The collective2652defense of private-sector networks is more important than ever as the2653cyber threat landscape grows increasingly perilous.2654 As the Federal Government and private sector have worked to2655collaboratively improve cybersecurity, the Cybersecurity Information2656Sharing Act of 2015's framework has served as the foundation. For2657example, the law underpins not only Cybersecurity and Infrastructure2658Security Agency's (CISA) Joint Cyber Defense Collaborative but also2659serves to drive greater information sharing between the various2660critical infrastructure sectors through Information Sharing and2661Analysis Centers. Moreover, the Cyber Incident Reporting for Critical2662Infrastructure Act explicitly builds on Cybersecurity Information2663Sharing Act of 2015 by directing CISA to use consistent procedures for2664incident reporting.2665 Thank you for holding today's hearing entitled ``In Defense of2666Defensive Measures: Reauthorizing Cybersecurity Information Sharing2667Activities that Underpin U.S. National Cyber Defense.'' Business2668Roundtable appreciates the Committee on Homeland Security's commitment2669to strengthening the Nation's cybersecurity defenses. Reauthorization2670of the Cybersecurity Information Sharing Act of 2015 is critical for2671the public and private sectors to defend against escalating cyber2672threats. We look forward to continued collaboration with you and your2673staff to ensure this essential authority is renewed.2674 Amy Shuart,2675 Vice President, Technology & Innovation, Business Roundtable.2676 ______26772678 Statement of the Protecting America's Cyber Networks Coalition2679 May 13, 20252680 TO THE MEMBERS OF THE U.S. CONGRESS: The Protecting America's Cyber2681Networks Coalition (the Coalition) urges Congress to reauthorize the2682Cybersecurity Information Sharing Act of 2015 (CISA 2015) before it2683expires on September 30, 2025.2684 Reauthorizing CISA 2015 is a top policy priority for the Coalition,2685a partnership of leading business associations representing nearly2686every sector of the U.S. economy. If CISA 2015 lapses, the United2687States will encounter a more complex and dangerous security2688environment. A variety of foreign cyber criminals are targeting our2689advanced commercial capabilities, critical infrastructure, and economic2690well-being through various tactics, such as phishing and ransomware.\1\2691Malicious hackers target both large national corporations and local2692branches, offices, and warehouses. Their attacks impact individual2693businesses, people, and their surrounding communities.2694---------------------------------------------------------------------------2695 \1\ Annual Threat Assessment of the U.S. Intelligence Community,2696Office of the Director of National Intelligence, March 18, 2025.2697https://www.dni.gov/files/ODNI/documents/assessments/ATA-2025-2698Unclassified-Report.pdf.2699---------------------------------------------------------------------------2700 Sharing information about cyber threats and incidents complicates2701attackers' operations because defenders learn what to monitor and2702prioritize. Consequently, attackers are forced to invest more in new2703tools or target different victims. CISA 2015 helps defenders improve2704their security measures while raising costs for attackers.2705 Congress passed CISA 2015 with bipartisan support from both parties2706and the administration.\2\ This important cybersecurity law enables2707private entities to increase their protection of data, devices, and2708computer systems while promoting the sharing of cyber threat2709information with industry and Government partners within a secure2710policy and legal framework. CISA 2015 also provides protections for2711businesses related to public disclosure, regulatory issues, and2712antitrust matters to promote the timely exchange of information between2713public and private entities. Industry and Government have a strong2714record of safeguarding privacy and civil liberties under this2715legislation.\3\2716---------------------------------------------------------------------------2717 \2\ Consolidated Appropriations Act, 2016 (Pub. L. 114-113),2718December 18, 2015 (see division N, title I). https://www.congress.gov/2719114/statute/STATUTE-129/STATUTE-129-Pg2242.pdf.2720 \3\ ``Recent Inspector General reviews have not found that2721[personally identifiable information] has been shared in violation of2722the act.'' Congressional Research Service, The Cybersecurity2723Information Sharing Act of 2015: Expiring Provisions, April 8, 2025.2724https://www.congress.gov/crs-product/IF12959.2725---------------------------------------------------------------------------2726 CISA 2015 is a cornerstone of American cybersecurity. It enhances2727businesses' ability to respond swiftly to today's cyber threats,2728including tackling cybersecurity issues and addressing them at scale.2729Lawmakers must send the CISA 2015 reauthorization legislation to the2730president to continue ensuring that businesses have legal certainty and2731protection against frivolous lawsuits when voluntarily sharing and2732receiving threat indicators and taking steps to mitigate cyber attacks.2733 Since the implementation of CISA 2015, collaboration in2734cybersecurity has improved significantly in several ways, including2735encouraging the development and/or the expansion of information sharing2736and analysis centers, or ISACs, across multiple sectors. These centers2737serve as hubs for sharing cybersecurity information within specific2738industries, thereby boosting sector-specific threat detection and2739response capabilities.2740 Cyber incidents underscore the need for legislation that helps2741businesses augment their understanding of cybersecurity threats and2742strengthen their protection and response capabilities in collaboration2743with Government entities.\4\ It is encouraging that leading members of2744the House and Senate Homeland Security and Intelligence committees2745advocated for the renewal of CISA 2015.\5\2746---------------------------------------------------------------------------2747 \4\ Cybersecurity: Selected Cyberattacks, 2012-2024, Congressional2748Research Service, January 8, 2025. https://www.congress.gov/crs-2749product/R46974.2750 \5\ ``A major cybersecurity law is expiring soon--and advocates are2751prepping to push Congress for renewal,'' CyberScoop, February 26, 2025.2752https://cyberscoop.com/cybersecurity-information-sharing-law-expiring-2753congress-renewal.2754---------------------------------------------------------------------------2755 The Coalition is dedicated to collaborating with the Trump2756administration and lawmakers to swiftly reauthorize CISA, thus2757enhancing national security and bolstering the resilience and2758protection of the U.S. business community.\6\ Congressional action is2759urgently needed.2760---------------------------------------------------------------------------2761 \6\ In April 2025, Secretary of Homeland Security Kristi Noem2762called for CISA 2015 to be reauthorized. ``Homeland Security Secretary2763Noem urges partnerships to guide future of CISA, backs secure by2764design'' Inside Cybersecurity, April 29, 2025. https://2765insidecybersecurity.com/daily-news/homeland-security-secretary-noem-2766urges-partnerships-guide-future-cisa-backs-secure-design.2767---------------------------------------------------------------------------2768 Sincerely,2769 ACT/The App Association2770 Airlines for America (A4A)2771 Alliance for Automotive Innovation2772 Alliance for Chemical Distribution (ACD)2773 American Chemistry Council (ACC)2774 American Council of Life Insurers (ACLI)2775 American Fuel & Petrochemical Manufacturers (AFPM)2776 American Gaming Association2777 American Gas Association (AGA)2778 American Institute of CPAs2779 American Petroleum Institute (API)2780 American Property Casualty Insurance Association (APCIA)2781 American Public Power Association (APPA)2782 American Short Line and Regional Railroad Association2783 (ASLRRA)2784 American Water Works Association (AWWA)2785 ASIS International2786 Association of American Railroads (AAR)2787 Association of Metropolitan Water Agencies (AMWA)2788 Business Software Alliance (BSA)2789 College of Healthcare Information Management Executives2790 (CHIME)2791 Connected Health Initiative (CHI)2792 CTIA2793 CyberAcuView2794 The Cybersecurity Coalition2795 Edison Electric Institute (EEI)2796 Electric Power Supply Association (EPSA)2797 The Fertilizer Institute (TFI)2798 The Financial Services Information-Sharing and Analysis2799 Center (FS-ISAC)2800 The GridWise Alliance2801 Healthcare Information and Management Systems Society2802 (HIMSS)2803 Healthcare Leadership Council (HLC)2804 Health-ISAC2805 Internet Security Alliance (ISA)2806 InterState Natural Gas Association of America (INGAA)2807 Large Public Power Council (LPPC)2808 National Association of Water Companies (NAWC)2809 National Defense Industrial Association (NDIA)2810 National Electrical Manufacturers Association (NEMA)2811 National Propane Gas Association (NPGA)2812 National Retail Federation (NRF)2813 NCTA--The Internet & Television Association2814 NTCA--The Rural Broadband Association2815 Open RAN Policy Coalition2816 Plumbing Manufacturers International (PMI)2817 Reinsurance Association of America (RAA)2818 Security Industry Association (SIA)2819 The Software & Information Industry Association (SIIA)2820 The Sulphur Institute2821 TIC Council2822 U.S. Chamber of Commerce2823 USTelecom--The Broadband Association2824 Utilities Technology Council (UTC).2825 Letter From the Alliance for Automotive Innovation2826 May 15, 2025.2827The Honorable Andrew Garbarino,2828Chairman, Subcommittee on Cybersecurity and Infrastructure Protection,2829 Committee on Homeland Security, U.S. House of Representatives,2830 2344 Rayburn House Office Building, Washington, DC 20515.2831The Honorable Eric Swalwell,2832Ranking Member, Subcommittee on Cybersecurity and Infrastructure2833 Protection, Committee on Homeland Security, U.S. House of2834 Representatives, 174 Cannon House Office Building, Washington,2835 DC 20515.2836 Dear Chairman Garbarino and Ranking Member Swalwell: The Alliance2837for Automotive Innovation (``Auto Innovators'') appreciates the2838opportunity to share its support for the reauthorization of the2839Cybersecurity Information Sharing Act of 2015 (``CISA 2015''). The U.S.2840automotive industry strongly urges Congress to prevent the September284130, 2025, expiration of this critical law, which is integral to the2842cybersecurity posture of the automotive ecosystem. We respectfully2843submit this letter for the hearing record.2844 Auto Innovators represents the full automotive industry, including2845the manufacturers producing most vehicles sold today in the U.S., major2846equipment suppliers, battery manufacturers, semiconductor makers,2847technology companies, and autonomous vehicle developers. The automotive2848industry is America's largest manufacturing sector and underpins our2849nation's industrial base. The sector employs ten million Americans in2850all fifty States and drives $1.2 trillion into the economy each year--2851nearly 5 percent of GDP.2852 Nimbleness and agility in response to a dynamic cybersecurity2853threat environment--particularly as the modern vehicle fleet becomes2854more automated, connected, and electrified--remains a top priority for2855the U.S. automotive industry. Automotive companies rely upon the2856exchange of cybersecurity threat intelligence, defensive measures, and2857shared experiences across industry sectors to counter cybersecurity2858threats and the ever-evolving tactics and capabilities of malicious2859threat actors. Congress enacted CISA 2015 to enable such cooperation2860and collaboration with broad bipartisan support.2861 Key provisions of CISA 2015 include:2862 Clear authorization for information sharing of cybersecurity2863 threat indicators, defensive measures, cybersecurity incidents,2864 and significant cybersecurity concerns;2865 Exemptions that safeguard shared intelligence and security2866 information from disclosure under the Freedom of Information2867 Act and State open records laws;2868 Assurances that threat indicator and defensive measure2869 sharing in accordance with the law do not waive applicable2870 privileges or other protections provided by law, including2871 trade secret protection;2872 Designation of threat indicators and defensive measures2873 shared by a private-sector entity with Federal entities as2874 their commercial, financial, and proprietary information; and2875 Protections against claims of antitrust violations or civil2876 liability for entities when sharing information in accordance2877 with the provisions of the law.2878 The Automotive Information Sharing and Analysis Center (``Auto-2879ISAC'') launched the same year as CISA 2015's enactment. Established to2880serve as the trusted cybersecurity community for automotive companies,2881the Auto-ISAC facilitates the sharing of cybersecurity threat2882intelligence and insights gained from public and private-sector2883sources. CISA 2015 fostered confidence among the initial Auto-ISAC2884members that their unified, community approach to cybersecurity risk2885mitigation was lawful. In the intervening decade, Auto-ISAC membership2886has grown over 500 percent, including original equipment manufacturers,2887suppliers, autonomous vehicle developers, and technology companies,2888highlighting the value that participants see in this trusted framework.2889In addition to the exchange of invaluable information, other key2890initiatives of the Auto-ISAC include table-top exercises, cybersecurity2891training, development of best practice guides and informational reports2892on important cybersecurity topics, and the creation of a common threat2893taxonomy related to automotive cybersecurity governance.2894 The Auto-ISAC's initiatives, proactive engagement efforts, threat2895and incident analyses, and dissemination of cybersecurity awareness and2896preparedness information depend on the statutory provisions of CISA28972015. These various cybersecurity risk mitigation efforts would not be2898possible without the authorizations and protections provided by the2899law.2900 As a result, Auto Innovators strongly supports Congress'2901reauthorization of CISA 2015. Such action is necessary to sustain the2902U.S. automotive industry's efforts that counter the unrelenting dangers2903posed by malicious threat actors. These efforts are crucial to ensuring2904the safe operations and resilience of the nation's largest2905manufacturing sector, and a predictable and durable policy environment2906related to cybersecurity information sharing is critical to these2907efforts. Auto Innovators looks forward to partnering with Congress on2908the reauthorization of CISA 2015, and we are grateful to the2909subcommittee for holding this hearing on such an important topic.2910 Sincerely,2911 Jennica Sims,2912 Director, Federal Affairs.2913 ______29142915 Joint Statement of Intrado Life & Safety, the National Association of2916 State 9-1-1 Administrators, and NENA--The 9-1-1 Association2917 May 15, 20252918 Intrado Life & Safety, the National Association of State 9-1-12919Administrators, and NENA--The 9-1-1 Association thank you and the2920Members of the House Homeland Security Subcommittee on Cybersecurity2921and Infrastructure Protection for holding this critical hearing,2922titled, ``In Defense of Defensive Measures: Reauthorizing Cybersecurity2923Information Sharing Activities that Underpin U.S. National Cyber2924Defense.''2925 Two hundred forty million calls are made to 9-1-1 every year.2926Together, as public safety advocates and industry leaders we proudly2927represent those who serve others in times of crisis. The networks that2928support our 9-1-1 infrastructure are the backbone of our national and2929public safety systems.2930 But these networks are also under constant threat. Bad actors2931seeking to cause harm are attempting to infiltrate America's public2932safety networks on a daily basis. To combat these attempts, we must use2933every private and public sector tool at our disposal.2934 That is why we have come together to voice our support for the2935reauthorization of the Cybersecurity Information Sharing Act, which2936sunsets on September 30, 2025. This legislation was enacted 10 years2937ago with the bipartisan vision of incentivizing and protecting2938information sharing between industry and Government to reduce2939cybersecurity threats to our Nation. It is working.2940 As current members of information sharing and analysis centers, we2941can speak to the invaluable impact the bill has had as we work to2942defend our network and protect 9-1-1 professionals, first responders,2943and the communities they serve. Information sharing in these forums2944provides us with key insights, data, and analysis that allows for2945quick, decisive action necessary to deploy our cyber defenses.2946 Nation-state actors and cyber criminals target critical 9-1-12947infrastructure daily. If CISA's authority is not extended, we fear we2948will lose our ability to be one step ahead of those who attack our2949critical infrastructure and seek to harm our national security. In2950short, the United States will encounter a more complex and dangerous2951security environment.2952 When we share information about cyber threats and incidents, we2953learn what to monitor and prioritize. This makes attack operations more2954difficult and requires bad actors to acquire new tools or target2955different victims, which raises their cost and gives us time to act.2956 Information sharing is a cornerstone of cybersecurity best2957practice, and the public-private sharing that this legislation has2958encouraged is central to protecting our national security and defending2959our homeland.2960 We are grateful to you and the subcommittee for holding this2961important hearing on the future of this legislation. We are hopeful it2962will lead to reauthorizing this legislation and needed support our2963Nation's continued efforts to defend our 9-1-1 systems.2964 ______29652966 Joint Letter From Multiple Associations2967 April 28, 2025.2968The Honorable Rand Paul,2969Chairman, Homeland Security & Governmental Affairs Committee, 2952970 Russell Senate Office Building, Washington, DC 20510.2971The Honorable Gary Peters,2972Ranking Member, Homeland Security & Governmental Affairs Committee, 7242973 Hart Senate Office Building, Washington, DC 20510.2974 Dear Chairman Paul and Ranking Member Peters: The undersigned trade2975associations (collectively, ``the associations'') urge Congress to2976extend, for at least 10 years, the Cybersecurity Information Sharing2977Act (CISA 2015), which is scheduled to expire at the end of September29782025.2979 Originally enacted in 2015 with broad bipartisan support, CISA 20152980established the voluntary information network to enable ``public and2981private-sector entities to share cyber threat information, removing2982legal barriers and the threat of unnecessary litigation.''\1\ The law2983remains foundational to strengthening our collective defense against2984cybersecurity threats, facilitating trust in the public-private2985partnership, and serving as the backbone of essential programs across2986the Federal Government--programs that have measurably improved the2987security posture of critical infrastructure in the United States and2988strengthened the Federal Governments' security awareness.2989---------------------------------------------------------------------------2990 \1\ Consolidated Appropriations Act, Pub. L. No. 114-113, Div. N,2991Title I--Cybersecurity Information Sharing Act, 129 Stat. 2935 (2015),29926 U.S.C. 1501; S. REP. NO. 114-32, at 2 (2015).2993---------------------------------------------------------------------------2994 Of paramount importance, the law's antitrust exemption and2995liability protections enables private-sector sharing of sensitive cyber2996information. Our Nation's critical infrastructure operators depend on2997threat indicator sharing from one another and from the Federal2998Government to strengthen their overall defenses. A lapse in CISA 20152999authorities will curb this sharing, which is fundamental for enhancing3000overall awareness of national security threats.3001 CISA 2015 continues to improve the capacity and speed of3002information sharing between the private sector and the Federal3003Government, while most critically providing necessary protections for3004privacy and confidentiality. Illustrative of this success is the joint3005effort of the Cybersecurity and Infrastructure Security Agency (CISA),3006the National Security Agency (NSA), and the Federal Bureau of3007Investigation (FBI) to identify the People's Republic of China (PRC)3008cyber actor, Volt Typhoon, in United States energy systems. This3009collaboration, fostered by CISA 2015, contributed to one of the most3010comprehensive, actionable, declassified cyber information sharing3011reporting in our Nation's history and continues to lead to further3012discoveries of this advanced persistent threat actor in other critical3013infrastructure sectors.3014 Extending CISA 2015 is also pivotal for supporting the3015effectiveness of Federal programs, like CyberSentry \2\ and ``Section30169''\3\ support, that mutually benefit the Federal Government as well as3017the infrastructure operator. In addition, CISA 2015 plays an essential3018role in the functions of CISA's Joint Cyber Defense Collaborative3019(JCDC), which reduces cyber risk by unifying the cyber defense3020capabilities and actions of Government and industry partners, including3021the associations' members. Furthermore, these statutory provisions are3022so undeniably indispensable that they are incorporated by reference in3023other significant cyber laws, including the Cyber Incident Reporting3024for Critical Infrastructure Act.\4\ Within the legal framework of the3025industry's Cyber Mutual Assistance (CMA) Program, CISA 2015 provides3026CMA Program participants additional protections when sharing certain3027sensitive cybersecurity information with one another. These additional3028protections strengthen the program and enhance security for the3029industry by encouraging and protecting greater sharing of cybersecurity3030information between private entities.3031---------------------------------------------------------------------------3032 \2\ Participating entities share threat information with CISA in3033real time for analysis and further dissemination to critical3034infrastructure operators across the Nation. CyberSentry also provides3035valuable insights into the nature and scope of potential cyber attacks,3036and facilitates proactive mitigation as well as swift and effective3037incident response planning.3038 \3\ See Executive Order--Improving Critical Infrastructure3039Cybersecurity 9 (February 12, 2013). https://3040obamawhitehouse.archives.gov/the-press-office/2013/02/12/executive-3041order-improving-critical-infrastructure-cybersecurity.3042 \4\ See 6 U.S.C. 681e.3043---------------------------------------------------------------------------3044 For these reasons, an expiration of these protections risks leaving3045our infrastructure more vulnerable to cyber incidents that could impact3046operational integrity and resilience. The associations and the3047companies we represent thank you for your leadership on this issue and3048stand ready to engage with Congress to ensure CISA 2015 remains3049prioritized in reinforcing our national and energy security goals.3050 Sincerely,3051 American Fuel & Petrochemical Manufacturers Association3052 American Gas Association3053 American Petroleum Institute3054 American Public Gas Association3055 Edison Electric Institute3056 GPA Midstream3057 InterState Natural Gas Association of America3058 Liquid Energy Pipeline Association.3059CC: The Honorable Mark Green, Chairman, House Homeland Security3060Committee; The Honorable Bennie Thompson, Ranking Member, House3061Homeland Security Committee; The Honorable Tom Cotton, Chairman, Senate3062Select Committee on Intelligence; The Honorable Mark Warner, Ranking3063Member, Senate Select Committee on Intelligence; The Honorable Rick3064Crawford, Chairman, House Permanent Select Committee on Intelligence;3065The Honorable Jim Himes, Ranking Member, House Permanent Select3066Committee on Intelligence.3067 ______30683069 Statement of the Operational Technology Cybersecurity Coalition (OTCC)3070 May 15, 20253071 The Operational Technology Cybersecurity Coalition, a dedicated3072group of cybersecurity vendors committed to safeguarding our Nation's3073critical infrastructure, writes to urge the reauthorization of the3074Cybersecurity Information Sharing Act of 2015 (CISA 2015).3075 Since its enactment following the Office of Personnel (OPM) data3076breach, CISA 2015 has provided a vital framework for voluntary public-3077private cyber threat information sharing, thereby strengthening our3078collective national cyber defenses. On November 12, 2024, your full3079House Committee on Homeland Security released a cyber threat snapshot3080that detailed a 30 percent increase in cyber attacks targeting critical3081infrastructure since 2023. The report also cited the Cybersecurity and3082Information Security Agency's findings that ransomware reports across3083all sectors increased over 70 percent from 2022 to 2023. The escalating3084sophistication of cyber threats, underscored by recent attacks on3085critical infrastructure including Volt Typhoon and Salt Typhoon, and on3086Federal agencies in incidents like SolarWinds, Storm 0558, and MOVEit,3087highlight the persistent and critical need for this legislation.3088 CISA 2015 has successfully facilitated collaboration by providing3089legal protections, including antitrust exemptions, necessary for3090companies to confidently share threat indicators and defensive measures3091with both governmental partners and other private entities. This3092collaborative environment has demonstrably improved the speed and3093capacity with which our Nation can respond to large-scale cyber3094incidents such as the Log4j JNDI attack and the CrowdStrike/Microsoft3095incident of 2024. In 2022, the latest year for which there is published3096data, 413,834 cyber threat indicators were shared with the3097Cybersecurity and Information Security Agency. For operational3098technology assets of critical infrastructure, this speed is essential3099to effectively mitigate cyber attacks, which is the core mission of our3100Coalition.3101 We firmly believe that a lapse in the CISA 2015 framework would3102inevitably and immediately reduce the crucial flow of information,3103leaving the United States--civilian, military, commercial, et al--more3104vulnerable to the malicious activities of nation-state actors and cyber3105criminals. These established communication channels are essential for3106maintaining situational awareness and enabling rapid, effective3107responses to security incidents which are crucial to protecting3108operational technology. Furthermore, the provisions of CISA 2015 are3109foundational to other significant cyber laws, including the Cyber3110Incident Reporting for Critical Infrastructure Act (CIRCIA), making its3111reauthorization essential for the stability of our broader3112cybersecurity legislative landscape.3113 The Operational Technology Cybersecurity Coalition champions an3114open, vendor-neutral approach to cybersecurity, a principle that is3115bolstered by voluntary information-sharing frameworks like the one3116established by CISA 2015. Echoing our formal communication sent to3117Congress on March 21, 2025, we reiterate the urgent call for the3118extension of the Cybersecurity Information Sharing Act of 2015.3119Preserving this framework is paramount to maintaining and enhancing the3120crucial information-sharing capabilities that protect our Nation's3121critical infrastructure and ensure our national security against ever-3122evolving cyber threats.3123 We thank the subcommittee for your leadership on this important3124matter and remain committed to working alongside you.3125 ______31263127 Statement of the National Retail Federation3128 May 15, 20253129 The National Retail Federation (``NRF'') submits this statement to3130the committee for its hearing entitled ``In Defense of Defensive3131Measures: Reauthorizing Cybersecurity Information Sharing Activities3132that Underpin U.S. National Cyber Defense'' and in support of the3133extension and reauthorization of the Cybersecurity Information Sharing3134Act of 2015 (``CISA 2015''). The framework established by CISA 2015,3135including its liability protections, has facilitated increased3136collaboration and information sharing both within the retail sector and3137between related stakeholders and partners over the past decade. It is3138critical that Congress reauthorizes the law before September 30, 2025.3139 NRF passionately advocates for the people, brands, policies, and3140ideas that help retail succeed. From its headquarters in Washington,3141DC, NRF empowers the industry that powers the economy. Retail is the3142Nation's largest private-sector employer, contributing $3.9 trillion to3143annual GDP and supporting 1 in 4 U.S. jobs--52 million working3144Americans. For over a century, NRF has been a voice for every retailer3145and every retail job, educating, inspiring and communicating the3146powerful impact retail has on local communities and global economies.3147 For more than a decade, NRF has worked to increase collaboration3148among retailers on cybersecurity. In 2014, NRF established its IT3149Security Council, a forum for retail Chief Information Security3150Officers (CISOs) and other senior members of their teams to engage with3151each other; share best practices; and participate in workshops,3152benchmarking surveys, and sector-specific cyber exercises.\1\ In early31532023, NRF established a formal partnership with the Retail and3154Hospitality Information Sharing and Analysis Center (``RH-ISAC'') and3155today works closely with them to increase sector-wide cybersecurity3156engagement.\2\ NRF has also worked to build ties with key Governmental3157partners on cybersecurity issues, including the Federal Bureau of3158Investigation (FBI), U.S. Secret Service, National Institute for3159Standards and Technology (NIST), and the Cybersecurity and3160Infrastructure Security Agency (CISA).3161---------------------------------------------------------------------------3162 \1\ NRF IT Security Council webpage. https://nrf.com/membership/3163committees-and-councils/it-security-council.3164 \2\ NRF press release, January 9, 2023. https://nrf.com/media-3165center/press-releases/retail-hospitality-isac-and-national-retail-3166federation-partner-enhance.3167---------------------------------------------------------------------------3168 Over the past decade, we have seen a gradual increase in the3169willingness of retailers to share cyber threat indicators that they3170have uncovered and collected, both via the RH-ISAC and directly with3171Government and industry partners. While the number of retailers that3172shared their own cyber threats indicators in the years immediately3173after CISA 2015 was limited, this engagement has increased over time,3174such that the RH-ISAC reported that 60 percent of its 300+ member3175companies had contributed cyber intelligence within the ISAC in 2024,3176including over 51,000 indicators of compromise and nearly 2,0003177responses to requests for information.\3\3178---------------------------------------------------------------------------3179 \3\ RH-ISAC, 2024 Year in Review Report. https://rhisac.org/wp-3180content/uploads/2024_RH-ISACYearinReview.pdf.3181---------------------------------------------------------------------------3182 Several factors explain this increase in information sharing over3183the past decade. Many large and medium-sized retailers have3184significantly increased the size and capability of their cybersecurity3185teams, which has strengthened efforts to detect and share information3186on threats. Retail legal teams have also gradually become more3187comfortable with allowing their cyber teams to share threat3188information, in large part due to the liability protections provided by3189CISA 2015. In the years immediately after CISA 2015 was enacted, NRF3190regularly heard from retail CISOs that their legal teams were reluctant3191to allow cyber threat information sharing. But over time, this3192reluctance has waned, and more teams are able to proactively share3193cyber threat information. We are concerned that this progress will3194stall or reverse if CISA 2015 lapses later this year.3195 Given the urgency of this reauthorization, NRF's priority request3196is for a clean extension of CISA 2015, consistent the language in3197Senate legislation introduced last month by Senators Gary Peters (D-MI)3198and Mike Rounds (R-SD).\4\ If there are opportunities to further amend3199the law as part of reauthorization, or in subsequent legislation, we3200would also support modest changes to the definitions of ``cybersecurity3201threat,'' ``cyber threat indicator'' and ``defensive measure'' that3202would clarify that CISA 2015 also applies to threat information related3203to cyber crime and on-line fraud, given the significant growth in3204threats in these domains over the past several years and the3205convergence of cyber and fraud threat actor tactics.3206---------------------------------------------------------------------------3207 \4\ S. 1337, Cybersecurity Information Sharing Extension Act.3208https://www.congress.gov/bill/119th-congress/senate-bill/1337.3209---------------------------------------------------------------------------3210 In support of the extension and reauthorization of CISA 2015,3211cybersecurity leaders at NRF and RH-ISAC member companies have provided3212examples of how cybersecurity information sharing has helped them3213prevent, disrupt, or respond to relevant cyber threats. The following3214quotes are relevant excerpts from these comments, anonymizing the3215company names by their general retail category:3216CISO of National Grocery Chain3217 ``We've found great success in information sharing both across3218industry and with our Government partners. We engage regularly with our3219Secret Service partners regarding intelligence we've gathered targeting3220retail skimming rings in several large markets across the industry.3221This work has DIRECTLY resulted in convictions of criminals attempting3222to place skimmers across various retailers in markets across the3223country.3224 ``We were warned by an ISAC partner that a prolific threat group3225was spinning up a campaign against us. This advanced warning gave us3226time to prepare for the incoming attack.3227 ``Recently, we were able to leverage the ISAC to anonymously share3228information regarding a potential breach of a third-party service3229provider. Our sharing allowed other ISAC members to make better3230decisions at a time when public information was scarce and fear,3231uncertainty, and doubt were circulating everywhere.''3232CISO of National Sporting Goods Chain3233 ``Within the first month of starting my new CISO role at a new3234company, I saw a post on the Retail & Hospitality ISAC portal from a3235cyber threat intel analyst that provided indicators of compromise (IOC)3236that contained over 600 known email addresses associated with the3237Democratic People's Republic of Korea (DPRK, aka North Korea) threat3238actor known as FAMOUS CHOLLIMA. This group impersonates U.S.-based tech3239workers applying for remote jobs, and when hired, will syphon the3240salaries to the DPRK government, steal sensitive data, and cause harm3241(e.g., ransomware) when discovered or when they have achieved their3242objectives.3243 ``I forwarded the link to my Security Operations Center (SOC)3244Manager, who also leads our Cyber Threat Intelligence (CTI) function,3245and asked if they had seen these IOCs yet, and if not, to please add3246them to our tooling for detection, blocking, and alerting. The3247following day we had 3 hits where the threat actor had applied for3248multiple jobs with the company, and one had already completed their3249interviews and was about to receive an offer. We were able to3250immediately stop the hiring process, which prevented an unknown but3251likely significant event, and we now have a process that continues to3252update these IOCs to prevent future risks with this and similar3253threats.''3254CISO of Footwear Company3255 ``RH-ISAC has been essential in helping protect our organization3256from modern cyber threats. There is no other place we get the quality3257of intelligence at the pace we need to action on it before adversaries3258take advantage of us. The recent major outages in the U.K. commercial3259sector attributed to Scattered Spider highlight what happens when3260threat actors use the same tactics against organizations that aren't3261sharing intelligence. Using intelligence from RH-ISAC partners, we have3262been able to detect and prevent these exact types of attacks and keep3263our business running and customer data secure.3264 ``Having access to verified community intelligence has allowed us3265to prevent malware infections, identify critical vulnerabilities,3266mitigate supply chain attacks, and respond to incidents more quickly3267than we otherwise would have been able to. This intelligence is a vital3268part of our information security practice.''3269IT Leader at Book Retailer3270 ``Our company uses the CISA portal to monitor cybersecurity and3271strengthen our threat awareness and incident response education--both3272of which are critical to our cybersecurity program. These capabilities3273help safeguard our systems, protect customer data and reduce3274operational risk. CISA 2015 was established to enable secure3275information sharing between the Government and private sector, helping3276organizations like ours stay ahead of emerging threats and coordinate3277timely responses. Eliminating this framework would reduce visibility3278into nationwide cyber risks and weaken our ability to respond quickly,3279increasing the likelihood of financial loss, service disruptions, and3280reputational damage.''3281CISO of National General Merchandise Retailer3282 ``We have numerous examples of successful cyber information sharing3283within retail to address and defend against threats.3284 ``As one example, Atlas Lion is a cyber criminal group targeting3285retail, hospitality, and gift card organizations that has been active3286since at least 2021. They manipulate victims into providing log-in3287information through SMS phishing and phishing, and once inside a3288network, they quickly identify and exploit gift card systems to3289facilitate gift card fraud and theft. As part of their Threat3290Intelligence processes, one of the larger retail cybersecurity teams3291identified phishing and credential harvesting infrastructure3292proactively and notified companies of likely phishing attempts before3293they happened. Together with other mature retail cyber programs, they3294shared infrastructure tracking for this threat actor with the RH-ISAC,3295enabling other retailers to proactively defend their infrastructure3296before the cyber criminals send phishing campaigns.3297 ``As a second example, Payroll Pirates is a cyber criminal group3298that uses phishing and fake log-in sites to steal victims' log-in3299information for human resources and payroll systems. This group sends3300phishing emails and sets up malicious advertisements on search engines.3301Once a victim enters their credentials, Payroll Pirates uses that3302information to redirect salaries and payroll to bank accounts3303controlled by the cybercriminal group. One of the mature retail3304cybersecurity programs proactively monitored this group's3305infrastructure and alerted multiple RH-ISAC organizations of3306infrastructure targeting these companies, helping them and their3307employees defend against fraud.''3308CISO of Fashion Retailer3309 ``As a member of the RH-ISAC, I can confidently state that our3310participation has been transformative for our security posture. Prior3311to joining the RH-ISAC in 2019, our company experienced a credit card3312breach. Based on the intelligence sharing and collaborative security3313resources we've accessed through RH-ISAC membership since then, I am3314100 percent certain that had we been members beforehand, we would have3315prevented that breach entirely.3316 ``Our membership has enabled us to advance our security program3317much more rapidly and in a targeted way compared to attempting to build3318our defenses independently. The threat intelligence and best practices3319shared through the RH-ISAC have directly contributed to protecting our3320customers' data and our business operations.''3321CISO of Footwear Manufacturer and Retailer3322 ``Information sharing fosters a culture of trust and collaboration3323within the cybersecurity community--specifically sharing of Indicators3324of Compromise and having that level of information to help reduce3325impact of known attacks. There isn't a need to `suffer' as individual3326companies but rather pooling resources and knowledge, we can develop3327stronger defenses.''3328CISO of a Regional Grocery Chain3329 ``Due to the sharing provisions of CISA 2015, our organization--a3330retail grocery chain--has been well prepared to prevent, detect, and3331respond to threats that would otherwise be unknown to us. One such3332example is recent activity from North Korean nation-state threat actors3333targeting retailers in fake remote work schemes. Intelligence like this3334comes from a complex blend of Classified, unclassified, and private3335sources. CISA 2015 removes the friction of collecting and compiling3336these sources for CISA and facilitates their ability to distribute a3337threat intelligence product that is easily digestible and rapidly3338actionable by us. Our organization, and many others like us, lack the3339resources to achieve this outcome on our own. We urge you to3340reauthorize CISA 2015 to maintain this essential public-private3341cybersecurity partnership.''3342CISO of Consumer Goods Product Manufacturer3343 ``In previous roles in the Defense and Aerospace sectors, I3344experienced first-hand the value of threat intelligence sharing between3345companies that were essentially competitors and the direct impact on3346national defense. In my current role, and with a much smaller3347cybersecurity team, we rely heavily on the intelligence and peer3348sharing within the ISAC to protect the company and maintain operations.3349It is almost impossible for companies smaller than $20 billion to3350effectively self-fund and manage their own threat intelligence teams/3351process/reporting.''3352Cyber Leader for Truck Stop Company3353 ``Information sharing between private companies, Government3354agencies, and law enforcement has been critical in furthering our3355cybersecurity posture. In several instances, information provided to3356law enforcement, under the security of the Cybersecurity Information3357Sharing Act of 2015, has been fruitful in thwarting fraud, breaches,3358and other potentially harmful events.''33593360 * * * * *3361 NRF is available to provide additional context on these comments3362with the committee upon request, including opportunities for direct3363dialog between retail cybersecurity leaders and committee Members and/3364or committee staff.3365 Thank you for focusing on this important issue. We encourage you to3366continue to work over the next 4 months to ensure that CISA 2015 is3367reauthorized and extended before the September 2025 expiration date.3368 ______33693370 Letter From the Software & Information Industry Association (SIIA)3371 May 15, 2025.3372The Honorable Andrew Garbarino,3373Chair, Subcommittee on Cybersecurity and Infrastructure Protection,3374 U.S. House of Representatives, Committee on Homeland Security,3375 H2-176 Ford House Office Building, Washington, DC 20515-6480.3376The Honorable Eric Swalwell,3377Ranking Member, Subcommittee on Cybersecurity and Infrastructure3378 Protection, U.S. House of Representatives, Committee on3379 Homeland Security, H2-176 Ford House Office Building,3380 Washington, DC 20515-6480.33813382Re: ``In Defense of Defensive Measures: Reauthorizing Cybersecurity3383Information Sharing Activities that Underpin U.S. National Cyber3384Defense''33853386 Dear Chair Garbarino and Ranking Member Swalwell: On behalf of the3387Software & Information Industry Association (SIIA), I write to urge the3388subcommittee to consider reauthorization of the Cybersecurity3389Information Sharing Act of 2015 (CISA 2015) during its May 15 hearing,3390``In Defense of Defensive Measures: Reauthorizing Cybersecurity3391Information Sharing Activities that Underpin U.S. National Cyber3392Defense.'' We would appreciate your including our views in the record3393of the hearing.3394 SIIA is the principal trade association for those in the business3395of information, including its aggregation, dissemination, and3396productive use. Our members include roughly 380 companies reflecting3397the broad and diverse landscape of digital content providers and users3398in academic publishing, education technology, and financial3399information, along with creators of software and platforms used3400worldwide, and companies specializing in data analytics and information3401services.3402 SIIA supports reauthorizing CISA 2015, which is scheduled to expire3403on September 30, 2025.\1\ Cybersecurity is a critical legislative3404priority, and one essential to the safety and security of a functioning3405democracy and a robust private sector. Information sharing between the3406Government and the private sector--as well as among private-sector3407entities--helps to harmonize meaningful cybersecurity safeguards with3408appropriate business compliance, and smooth implementation of joint3409cybersecurity efforts.3410---------------------------------------------------------------------------3411 \1\ The bipartisan Cybersecurity Information Sharing Extension Act,3412introduced in the Senate at S. 1337, provides for a clean extension. No3413such legislation has been introduced in the House this session.3414---------------------------------------------------------------------------3415 CISA 2015's protections for private-sector cyber defenders,3416including its antitrust exemption, has led to increased public-private3417collaboration and cyber threat information sharing, and has also3418improved information sharing within the private sector. This foundation3419has enabled American businesses to address and respond to cybersecurity3420threats and has raised the level of cyber resilience in critical3421infrastructure sectors and beyond. By improving cybersecurity3422resilience, CISA 2015 has also helped to advance consumer privacy and3423mitigate the impact of breaches. This has also benefited consumer3424privacy interests, since information sharing among private-sector3425entities, especially around threat indicators, has been foundational3426for responsibly stewarding customer data in the face of these threats.3427 Permitting CISA 2015 to lapse would be detrimental to the United3428States' cybersecurity posture at a time when cybersecurity risks are3429intensifying in intensity and scope. Recent incidents, including the3430Salt Typhoon attack and the BeyondTrust incident, underscore the3431importance of strengthening domestic cooperative efforts to counter3432these threats.3433 Reauthorizing CISA 2015 is an essential first step, but more should3434be done. We also encourage the subcommittee to examine ways to further3435incentivize information sharing with the public sector, which has3436lagged private-to-private sharing in recent years.\2\ This may include3437expanding CISA 2015's definitions of ``cyber threat indicators,''3438``defensive measures,'' ``cybersecurity purpose,'' and ``cybersecurity3439threat'' to expand liability protections and further encourage sharing3440in a wider variety of contexts. Congress may also wish to consider3441extending liability protections to direct sharing with agencies beyond3442DHS and its automated indicator sharing system.3443---------------------------------------------------------------------------3444 \2\ See, e.g., Megan L. Brown, et al., ``CISA 20153445Reauthorization--Are Changes on the Horizon?,'' Wiley Connect (Mar. 3,34462025), https://www.wileyconnect.com/CISA-2015-Reauthorization-Are-3447Changes-on-the-Horizon; see also Sean Lyngaas, ``Private Sector Isn't3448Sharing Data with DHS's Threat Portal,'' CyberScoop (Jun. 28, 2018),3449https://cyberscoop.com/dhs-ais-cisa-isnt-used-jim-langevin/.3450---------------------------------------------------------------------------3451 Although undoubtedly helpful to enforcers, CISA 2015's exception3452permitting Government use of shared information to inform regulation3453and enforcement may have unintentionally chilled public-private3454sharing. Last, greater information sharing from the Government to the3455private sector--especially in the context of incidents targeting3456critical infrastructure--would be a boon to private-sector cyber3457defenders. Congress can address this by providing statutory guidance3458and direction to the Cybersecurity and Infrastructure Security Agency.3459 Thank you for considering our views and for the subcommittee's3460attention to this important matter. SIIA looks forward to continuing to3461engage with the subcommittee as its work continues.3462 Sincerely,3463 Paul N. Lekas,3464Senior Vice President, Global Public Policy Software & Information3465 Industry Association (SIIA).34663467 Mr. Garbarino. I know you all have said re-auth has to3468happen, so I'm not even going to start with that question.3469Everybody is saying that it has to happen. It sounds like clean3470re-auth, everybody thinks, is the best way to do it just to3471make sure it's done.3472 What would happen if this did not get reauthorized? You can3473all jump in. I want to hear from everybody. I feel like we need3474to get on the record why it's so important this has to be3475reauthorized. What would happen if it wasn't reauthorized?3476 Want to start, Mr. Miller?3477 Mr. Miller. Yes. Thank you for the question, Chairman.3478 I mean, I think if it was not reauthorized there would be3479an immediate chilling effect, at least for some organizations3480on their willingness and ability to share, because those3481express authorizations in the bill and those attendant3482liability protections would go away.3483 I mean, this is not to say that information sharing itself3484would completely stop. Information sharing did occur before3485CISA 15, but a lot more of it is occurring after CISA 15.3486 In particular, automated sharing at scale, again, as I3487understand it as a lawyer, not as a cybersecurity operator,3488didn't really exist in nearly the same way that it does today,3489and the bill should be credited for that.3490 I personally think it's an open question given what exactly3491the fate of, for instance, the Automated Indicator Sharing3492program at CISA would be if the bill went away, because their3493authorization to run it would go away. It doesn't mean they3494would necessarily stop doing it. We don't have Homeland3495authorizations every year, as you know. But it would put things3496into question.3497 So I think this would undermine a lot of certainty across3498industry and Government and, thus, undermine the certainty that3499we have with the trusted sharing partnerships that have been3500built since CISA 15.3501 Mr. Garbarino. Ms. Rinaldo.3502 Ms. Rinaldo. You are taking the decision from the CISO to3503the general counsel's office, and that is going to slow3504everything.3505 Mr. Garbarino. Us attorneys are the worst.3506 [Laughter.]3507 Ms. Rinaldo. I wasn't going to say that.3508 Mr. Garbarino. I can say it. It's OK.3509 Mr. Schimmeck.3510 Mr. Schimmeck. Yes. Reiterate that. Basically, firms would3511immediately hesitate. There would be uncertainty in what would3512be shared. Things would slow down.3513 The other thing is, you would very much be locking out the3514small and medium-sized businesses and companies and vendors.3515This would be a big-firm-only play, because we would be the3516only ones willing to try it, willing to evaluate it.3517 Then you'd also, I think, you'd start to see what we saw3518previously, which is every firm building bilateral gratis with3519the U.S. Government instead of going through this framework.3520 Mr. Garbarino. It's a very key point. Thank you for making3521that.3522 Ms. Kuehn.3523 Ms. Kuehn. Just to reaffirm everything that everyone else3524has said. But you're right, there was information sharing3525before 2015. We did have it. But it was picking up the phone3526and kind-of chatting behind closed doors.3527 That's going to hinder from both a proactive and a reactive3528cyber defense strategy if we don't have those safe harbors. To3529my fellow committee Member's point, it puts it in the hands of3530the lawyers.3531 The reality is, is that with AI coming in, with what we're3532seeing with the rapid spread of threats, we don't have time for3533it to go to the lawyers at this point. We have to be able to3534share information quickly.3535 Mr. Garbarino. The slower we are, the more exposed we are.3536 Ms. Kuehn. Hundred percent.3537 Mr. Garbarino. That information sharing is very important.3538 Mr. Schimmeck, I want to ask you both--you worked at--you3539worked with SIFMA for a while. I wanted to know if you could3540specifically share some information or some anecdotal3541information about how your companies or other companies you've3542worked with have shared information under this law.3543 Mr. Schimmeck. Sure. So what we'll use this for typically3544is we will provide the information via AIS. So we have that3545path of sharing information with DHS when we need to. We also3546use other mechanisms, phone calls, email.3547 DHS provides multiple ways for us to submit information. So3548it provides maximum flexibility for firms to go do that. But3549then it also enables us to go peer-to-peer.3550 There is probably not a day that goes by that I'm not3551talking to a peer CISO out there on some issue that's going on,3552either emerging or on an active threat that we're dealing with.3553 This just provides us that flexibility to make sure that3554anything we're sharing we're protected, we're doing it under3555the best intentions. So it really allows us to, as we say in3556financial services, this is a noncompetitive topic for us.3557 We want to make sure that the entire system is protected,3558because if there's an attack against one bank, it calls into3559question the entire system. Financial services, more than3560anything else, is built on trust.3561 Mr. Garbarino. I appreciate that. My time has expired.3562 We're going to start a second round of questioning, and I'm3563now going to recognize for a second round of questioning the3564gentleman from Florida, Mr. Gimenez, 5 minutes.3565 Mr. Gimenez. I'm trying to figure out where I'm going to3566go.3567 Mr. Swalwell. Uh-oh. Watch out.3568 Mr. Gimenez. I'm not so sure I share the Ranking Member's3569problems with a 19-year-old. In ``Ender's Game'' the guy was3570like 12 years old, and he defeated an entire alien race. So3571maybe the Ukrainians are onto something. So there, that's where3572I was going.3573 So my question is, and anybody can answer this, are we as a3574country spending enough?3575 Because I do believe that at the end the solution is not3576going to be--yes, we need a number of people--but with3577artificial intelligence I can see the day that you're going to3578be both on the offense and defensive side.3579 You will have literally millions of attacks per minute3580being launched and counter-launched and defended against. Then3581the systems learning from each other and probing and defending,3582probing, probing, and then basically, almost at the speed of3583light.3584 No, we can't have--there's no way we can ever fund that3585many people.3586 So are we investing enough as a country in artificial3587intelligence in order to protect us from what we know is going3588to be the threat, which is really artificial intelligence-3589launched cyber attacks on our country and our infrastructure3590and everything? Are we investing enough in artificial3591intelligence that will counter that?3592 Ms. Kuehn. I think, first of all, from the investment3593question, my other role is I'm head of global advocacy for--3594cyber advocacy for a privately-held company. From an AI3595perspective, we've invested over a half-billion dollars and a3596billion in labs just to look at all the different technologies3597that are coming in right now, both from a proactive and3598reactive AI perspective.3599 What I would say is, I think that we do need to invest3600more, but I think one of the critical areas is in public-3601private partnership, is getting closer with the organizations3602like NVIDIA and others that are on the front lines of creating3603AI, and also then the companies that are defending AI, which3604many of them are early stage organizations.3605 So the more we can strengthen the public-private3606partnership from Government and industry to approach how we3607look at AI, how we look at, like I said, malicious,3608malfunction, mistake going in the future, it's going to have3609benefit across all areas of industry.3610 Mr. Gimenez. Are we unified in an approach, or is everybody3611just doing their own thing as individual companies? Is CISA3612doing its own thing? Is DOD doing its own thing? Is Oracle3613doing its own thing? Or would it be beneficial to maybe have3614some other different kind of legislation that kind-of starts to3615focus it all? Because it's a mutual defense system that we3616really have to build here, not just, gee, OK, DOD is protected,3617but, gee, it's too bad that our critical infrastructure wasn't.3618 So are we there? Where are we with that? Is everybody just3619developing their own, or do we have some kind of a strategy to3620kind-of focus in on that to develop--instead of the golden3621shield, this will be the cyber shield, which is it's going to3622be artificial intelligence. That's the way it's going to be.3623Where are we on that?3624 Ms. Rinaldo. So I would say that different agencies are3625focusing on it for their specific needs. There is not one3626holistic approach to it but more of a buckshot, if you will. I3627think there is more of a holistic approach to how we manage AI3628moving forward, but I think there's a lot of exciting3629applications.3630 In my day job I run a telecom trade association, and we're3631really focusing on 6G and how AI is going to shape sensing3632communications moving forward, so you're able to detect3633anomalies in a network, whether it be security, whether it be3634weather-related. You could tell a certain portion of the3635network is down. That's all going to be done by AI.3636 So there are a lot of great aspects of it, and I think it's3637really important for the different agencies to kind-of focus3638and really hone in on their particular function.3639 Mr. Gimenez. Do you think our adversaries are somewhat3640scattered like we are, or do you think they're more focused on3641their goals?3642 Ms. Rinaldo. I think China remains an existential threat to3643us on these issues.3644 Mr. Gimenez. Are they focused, or do they have a3645scattershot kind of approach to their development of AI?3646 Ms. Rinaldo. So what we've seen, and from my work at the3647House Intel Committee on Huawei, is that China is especially3648focused on certain individual companies as opposed to we3649support sectors. So they will want to see one individual3650company succeed globally while we push a sector. So in that3651instance, they are honed in.3652 Mr. Gimenez. Should we match that?3653 Ms. Rinaldo. No.3654 Mr. Gimenez. No? OK.3655 My time is up. I wish I could go further, but I'm done.3656Thank you.3657 Ms. Rinaldo. True innovation happens when you have multiple3658different companies competing.3659 Mr. Garbarino. The gentleman yields back.3660 With the consent of the Ranking Member, I now recognize the3661gentleman from Tennessee, Mr. Ogles, for 5 minutes.3662 Mr. Ogles. Thank you again, Mr. Chairman.3663 I also sit on the Financial Services Committee, and, Mr.3664Schimmeck, I'd love to hear from you as one of the things that3665concerns me is the sophistication of AI and how we're seeing3666that play out in the financial sector and just the risks that3667are involved there.3668 So, what are the next phases? Does this go far enough?3669Again, if we're going to come back and do a clean-up or3670revision of this at some later date, what needs to be included?3671 Mr. Schimmeck. Yes. So AI, obviously, it's an area of3672investment for financial services both on the business side but3673also on the security side as well.3674 Very much still early days in regards to how we're going to3675embed that within our operations, but pretty much every firm3676has got a strategy around this and are making significant3677investments, to Mr. Gimenez's point.3678 In regards to how this is going to affect CISA, I think3679we're not really sure how this is going to play out and how3680we're going to want to share information, whether it's going to3681be in agentic AI within a financial services firm sharing with3682another agentic AI within DHS or within another agency. So I3683think that's something we'll have to work at.3684 I think it goes to maybe some of the improvements we can3685have on the AIS systems. The AIS system was probably designed368610 years ago. It's operational. It accomplishes the mission.3687But it's definitely something that could be modernized both3688with AI or even other opportunities to just improve the level3689of detail and to just make it more consumable for us as both a3690submitter and a consumer of that information.3691 Mr. Ogles. Ms. Kuehn, you mentioned the typhoon attacks. As3692a former county executive one of the things that concerns me3693across our landscape isn't the larger companies. Obviously,3694they're a target and there's risk associated with it, but it's3695that critical infrastructure in rural Tennessee that supports3696hundreds of thousands if not millions of people across this3697network.3698 What's the end game there? How do we help these smaller3699communities that, quite frankly--so I'll give you an example.3700In metro Nashville or Memphis or even the suburb, Williamson3701County, which is a very affluent county, they have the3702resources to have an IT department.3703 If you go a little further south, east, or west, the IT guy3704is probably also the H.R. guy, and they're not equipped to3705defend a county--the water system, the electrical grid--from3706these types of attacks. So what do we do going forward?3707 Ms. Kuehn. I think part of it is, again, and I sound like a3708broken record, it's public-private partnership.3709 So the 2 attacks you just mentioned, so I'll use Salt and3710Flax, both of them are exploiting critical vulnerability3711exploits that were back from, like, 2018, 2021 on known,3712basically antiquated network and technology gear.3713 So it's, again, educating smaller and mid-sized businesses.3714To your point, I saw a statistic recently that 80 percent of3715critical national infrastructure is sitting in small and medium3716business.3717 So working with those organizations to create modernization3718plans, working with organizations that have the CVEs to help3719with creating, in essence, modernization, technology upgrade,3720helping small to medium businesses and critical national3721infrastructure organizations upgrade to technology that is not3722vulnerable anymore and putting action plans together to do so.3723 The typhoons are--they're not going to care whether you're3724a large or a small organization. They're going to care about3725the disruption that it causes to critical national3726infrastructure. So it's going to take a shoulder-to-shoulder3727proactive measure between public and private to ensure that we3728don't have disruptive behavior from them.3729 Mr. Ogles. Not that I want to be one of the Members of3730Congress that authorizes Skynet, but it's almost like we need a3731cyber shield that better equips our private and public partners3732in this space. But, again, proceed with caution.3733 I yield back.3734 Mr. Garbarino. The gentleman yields back.3735 I now recognize the Ranking Member, Mr. Swalwell from3736California, for a second 5 minutes of questions.3737 Mr. Swalwell. Great. Thank you, Chair.3738 Ms. Kuehn, how has the loss of CIPAC impacted information3739sharing?3740 Ms. Kuehn. I think when you look at the loss of CIPAC3741there's kind-of 2 things, whether you're talking about CIPAC or3742any of the councils, so from the advisory council perspective3743and then the safety review board. The work that it does is the3744education that we need.3745 So from a CIPAC perspective, having that collaboration of3746experts both from public and private and being able to look and3747give advice on things like we've talked about, the typhoons,3748about agentic AI, about even quants that are going on, where3749should we be pointing our arrows. That's incredibly important3750for us to rely on.3751 If we talk about the safety board getting the revisions and3752understanding what happened on critical attacks, like the work3753that was being done on Salt Typhoon, there was the Microsoft3754vulnerabilities, there were others, it's a question of those3755type of information sharing allows us to go a step further than3756JCDC and really disseminate critical information about where we3757want to focus our attentions from public and private and then3758also how we better protect ourselves.3759 Mr. Swalwell. Are you aware as to whether DHS has provided3760a time line for when a CIPAC replacement will be established or3761a process for how the private sector can provide feedback?3762 Ms. Kuehn. I am not aware at this point.3763 Mr. Swalwell. How would you structure a new CIPAC?3764 Ms. Kuehn. From a CIPAC perspective I think that you have3765to look at--there's practitioners and operators in3766cybersecurity and in AI. As we think about it, we need a blend3767of Government, former Government, the practitioner side, like3768the CISOs and the risk executives sitting here today, and then3769also operators, who are the business risk side, from boards and3770CEOs and understanding the cyber perspective from the business3771side.3772 Because we're seeing we're in the middle of a digital3773revolution. Cyber touches every area. Traditional technology,3774everything we do has technology in it, and there's a cyber3775component.3776 So as we look at the new CIPAC, we have to take into3777consideration that we're no longer just looking from an3778adversarial perspective, it's a business, operational,3779resiliency perspective, and we need to adjust accordingly.3780 Mr. Swalwell. Great. Yield back.3781 Mr. Garbarino. The gentleman yields back.3782 I now recognize myself for my second 5 minutes of3783questions.3784 When the original CISA 2015 law was negotiated significant3785privacy concerns were raised. As far as I'm aware, these3786concerns did not come to fruition.3787 Ms. Rinaldo, you were there. Will you please walk us3788through the initial debates and how they were resolved dealing3789with privacy?3790 Ms. Rinaldo. Absolutely.3791 So during the 4 years we had 3 different bills that were3792introduced, and from the first bill, which was a couple of3793pages, to the one that was signed into law, which was much,3794much bigger, we took a lot of the feedback from privacy groups3795and industry--John was instrumental in a lot of this work that3796we did--and we made changes.3797 The information has to be anonymized. We want to make sure3798that what is actually being shared is the zeros and ones of it.3799 I know that the inspector general has done a report3800recently and has determined that no privacy issues have arisen3801in the past 10 years. So the language and all the protections3802that we put in have been working.3803 Mr. Garbarino. That's great, because I'll tell you, other3804than the name, privacy concerns, it might be the biggest3805obstacle to getting this reauthorized. So the fact that you3806have--that report has zero reports of privacy breaches is3807great.3808 Mr. Miller, you were also instrumental, as we all just3809heard Ms. Rinaldo say. Have you heard of any privacy-related3810concerns over the last 10 years the law has been in effect?3811 Mr. Miller. No, and I think that's pretty compelling3812evidence that the bill itself and the structure and the3813protections that were put in place to protect privacy and civil3814liberties worked.3815 If I could add one other protection that I think was very3816important to what Diane said. Actually having DHS serve as the3817central hub, what we kind-of called the civilian interface at3818the time, was very important.3819 If you think about what else was going on during this time,3820there was a lot of suspicion about sharing, and in particular3821about surveillance agencies, in light of the Snowden3822disclosures, for instance.3823 So I think that the protections that Diane mentioned,3824requiring the stripping out of PII, was very important. But3825also sharing through DHS and then having DHS share across the3826Federal Government was a good innovation, I think, of the time3827as well.3828 Mr. Garbarino. Mr. Schimmeck, anything to add there3829regarding privacy?3830 Mr. Schimmeck. Just the only thing I would add to it is,3831No. 1, as I made in my statement, we have not had anything3832realized in regards to any disclosures.3833 Also, from a financial services industry standpoint, we3834take privacy extremely seriously. It's something that's core to3835how our business operates.3836 So having those protections in there and really to focus on3837it in the act, in the bill, was really important.3838 Mr. Garbarino. Ms. Kuehn.3839 Ms. Kuehn. I would agree. I think that they've summed it3840up. There really have not been any, to my knowledge, concerns3841from a privacy perspective. I think that that's one of the3842reasons that a clean authorization of it from a renewal3843standpoint is just critical. We can change what we need to3844change later, but what's working right now from a fundamental3845perspective is working.3846 Mr. Garbarino. That was my follow-up question. You said3847clean re-auth, which means you would all agree that there is no3848need to change the language when it comes to privacy, correct?3849 Ms. Kuehn. Yes.3850 Mr. Schimmeck. Yes.3851 Mr. Miller. Yes.3852 Mr. Garbarino. They all said yes, for the record.3853 Thank you very much for that.3854 I do want to get to one more, because we're talking about3855information sharing with the Government, private to Government.3856 But can you all talk about some reflections on how this3857legislation changed information sharing amongst private-to-3858private entities and how it fostered that information sharing?3859Feel free to jump in, whoever wants.3860 Mr. Miller. I mean, I'll jump in.3861 Talking to, for instance, the executive director of the IT-3862ISAC recently, it does seem like--and talking about some of the3863types of things that CISA 15 really has allowed the private3864sector to do, I mean, I think there are criticisms of whether3865the private-Government sharing can be better. I mean, we've3866heard some of those already today.3867 But the private-private, private-to-private sharing, is a3868really critical and maybe sometimes overlooked aspect of what3869CISA 15 really enabled.3870 Again, if you look at the ISACs, again, some of the ISACs3871have less than a hundred people, some of them have thousands of3872companies involved, you look at the National Council of ISACs,3873the State and local, Tribal, and territorial ISAC, all of these3874ISACs are--allow--it's kind-of a concept of the few protecting3875the many.3876 They're very important in particular for those small and3877medium-sized businesses who can perhaps participate through3878ISACs because they don't have million-dollar budgets to spend3879on cybersecurity.3880 So I think there's really been a pretty dramatic increase3881in private-to-private sharing that has been enabled because of3882CISA 15.3883 Mr. Garbarino. Wonderful.3884 All right. Well, I'm now out of time.3885 I really want to thank you all for being here. I think you3886can tell by the fact that we all stayed for our second round3887and we have such a big crowd in the back that this is a very3888important hearing and people understand its importance.3889 Again, I said it was wonderful that the Secretary mentioned3890it yesterday, that she wants to see reauthorization. That's the3891second time I've heard her publicly say that, which is great.3892 So I want to thank you all for your valuable testimony and3893for the Members for their questions.3894 Members of the committee may have some additional questions3895for you all, and we would ask you to respond to these in3896writing.3897 Pursuant to committee rule VII(E), the hearing record will3898be held open for 7 days.3899 Without objection, the committee stands adjourned.3900 [Whereupon, at 3:22 p.m., the subcommittee was adjourned.]39013902 A P P E N D I X39033904 ----------39053906 Questions From Chairman Andrew R. Garbarino for John Miller3907 Question 1. Do barriers still exist to cybersecurity information3908sharing, such as private-sector companies' reluctance to share with law3909enforcement or quality concerns regarding redundant cyber threat3910indicators and defensive measures? What actions have been taken, if3911any, to overcome these barriers?3912 Answer. While certain barriers to information sharing may persist,3913CISA 15 removed or lowered the vast majority of barriers to information3914sharing by providing clear liability protections to companies for3915voluntarily sharing or receiving cyber threat indicators (CTIs) or3916defensive measures (DMs), for authorized monitoring activities, by3917exempting these sharing activities from disclosure under FOIA and from3918antitrust laws, and providing limited protections against regulatory3919use. A lapse of CISA 15 would immediately reintroduce those barriers.3920 It is important to note that while the intention behind CISA 15 was3921to incentivize voluntary sharing by removing these above-listed3922barriers, some private-sector entities have remained reluctant to share3923with DHS/CISA or other Government agencies due to lingering concerns3924over regulatory exposure, or other issues such as reputational risk or3925uncertainty around the onward use or dissemination of shared data.3926 Additionally, I believe it would be prudent to review and update3927the list of cyber threat indicators (CTIs) in CISA 2015, not for3928redundancy but for completeness. Adversaries are constantly developing3929new tactics, techniques, and procedures to advance their nefarious3930objectives. Defenders need to have the ability to share updated CTIs on3931the entire dynamic threat landscape. The CTI definition is framed to3932encompass much of the threat landscape without risking redundancy.3933Accordingly, any update to the list of CTIs should focus on adding3934additional CTIs to reflect developments in the threat landscape. For3935example, CTIs related to supply chain attacks or AI-enabled TTPs may be3936appropriate to include. Notably, DHS/CISA has already worked to improve3937the technical utility of shared data and to facilitate anonymization3938and contextual enrichment of threat indicators to enhance their value.3939Evolving the list of CTIs alongside continued stakeholder engagement,3940transparency, and advancements in automated sharing standards may help3941to mitigate persistent concerns.3942 Question 2. What can the Cybersecurity and Infrastructure Security3943Agency (CISA) do to increase participation in the Automated Indicator3944Sharing (AIS) program?3945 Answer. One way for DHS/CISA to increase participation in AIS would3946be to better emphasize the value proposition behind bi-directional3947information sharing, particularly from Government to industry.3948Currently, much information sharing happens industry-to-industry,3949industry-to-Government, or Government-to-Government. Increasing3950Government-to-industry sharing of information could incentivize more3951private-sector entities to participate in AIS. Additionally, DHS/CISA3952can also broaden industry engagement by continuing efforts to improve3953the relevance, accuracy, and timeliness of shared indicators and3954provide metrics demonstrating operational impact and actionable3955intelligence to further improve the value proposition for reluctant3956companies. Moreover, enhancing integration with threat intelligence3957platforms used by private-sector entities and expanding training and3958onboarding support for small and mid-sized enterprises can make3959participation more accessible.3960 While incentivizing greater participation is a worthwhile goal, it3961is also worth noting that the raw numbers of entities participating in3962AIS do not tell the whole story. Many companies including SMBs3963participate indirectly in and gain the benefits of the AIS program by3964virtue of their participation in the various sector ISACs representing3965critical infrastructure as well as other Information Sharing and3966Analysis Organizations (ISAOs).3967 Question 3. Do you believe that the Cybersecurity Information3968Sharing Act of 2015 (CISA 2015), if reauthorized, should still exclude3969protections from sharing with the Department of Defense (DoD),3970including the National Security Agency (NSA)? Why or why not?3971 Answer. The original decision to limit certain liability3972protections for sharing directly with the Department of Defense and NSA3973reflected a conscious effort to preserve public trust by emphasizing3974civilian-led cybersecurity collaboration. Removing those protections3975would resurface the same privacy concerns from a decade ago that took3976years to resolve. The intentional decision to establish DHS/CISA as a3977civilian intermediary was intended to mitigate these concerns, and3978based on available evidence--including no documented privacy incidents3979or instances of information leakage that I am aware of--the current3980structure establishing DHS/CISA as the central information sharing hub3981for the Federal Government has proven a success. There is no compelling3982reason to reassign these intermediary responsibilities to law3983enforcement or national security entities, and any effort to do so3984would raise the same privacy concerns from a decade ago. Resurfacing3985those concerns now would jeopardize the timely reauthorization of CISA398615.3987 Question 4. How important is the antitrust exemption in CISA 2015?3988Please explain and provide any examples that would help illustrate your3989point.3990 Answer. The antitrust exemption in CISA 2015 is essential to3991fostering collaborative defense across sectors. It reassures companies3992that sharing cyber threat indicators and defensive measures with3993competitors in good faith will not expose them to antitrust liability.3994For example, in the financial and energy sectors, where competitors3995often face similar threats, the exemption has enabled proactive3996collaboration through the information sharing Information Sharing and3997Analysis Centers (ISACs) and Information Sharing and Analysis3998Organizations (ISAOs). Without it, firms may hesitate to engage in3999joint threat analysis or response coordination. This legal assurance4000has enabled trusted sharing ecosystems that enhance collective4001resilience.4002 Question 5. How does CISA 2015 allow for small and rural critical4003infrastructure sector organizations to effectively share cyber threat4004information with Government entities?4005 Answer. CISA 2015 facilitates participation by small and rural4006critical infrastructure organizations primarily through sectoral or4007(multi-)regional Information Sharing and Analysis Centers (ISACs).4008These intermediaries allow smaller entities to receive relevant threat4009information and share indicators through a trusted network. Moreover,4010DHS/CISA's support for automated tools and templates, as well as its4011outreach to under-resourced entities, helps reduce technical and4012operational barriers to participation. Liability protections further4013assure these organizations that sharing information will not result in4014undue risk.4015 Question 6. Do liability protections under the existing statute4016sufficiently address threat actors' new and emerging tactics,4017techniques, and procedures (TTPs)? If they do not, please provide some4018recommendations to ensure the law upholds its relevancy as the threat4019landscape evolves.4020 Answer. The existing liability protections have proven effective in4021encouraging information sharing across a range of threats. However, as4022TTPs evolve, including those involving AI-enabled exploits, supply4023chain compromises, and manipulation of operational technology systems,4024there may be ambiguity about whether certain cyber threat indicators or4025defensive measures are covered. To maintain the law's relevance,4026Congress should consider modernizing the definitions within the statute4027to explicitly account for emerging threats, including indicators4028related to ransomware campaigns, AI anomalies, and software component4029tampering. Clarifying these elements would reduce hesitation and4030further incentivize more robust sharing.4031 Question 7. What changes, if any, can Congress make to CISA 2015 to4032ensure there are no delays or roadblocks to information sharing,4033especially when dealing with a campaign from an advanced persistent4034threat (APT) actor?4035 Answer. It is imperative that Congress reauthorize the existing law4036before it lapses in September. Improvements should not come at the4037expense of the existing cyber information sharing activities that rely4038on CISA 2015 authorities. Any lapse to CISA 2015's liability4039protections could have real and immediate negative consequences that4040put all American organizations at greater risk.4041 That said, Congress can take several actions to minimize delays in4042high-stakes scenarios involving APT actors. First, cross-checking, and4043updating as necessary, the definitions of covered threat indicators and4044defensive measures to make certain they sufficiently capture advanced4045and emerging attack vectors related to APTs would reduce ambiguity and4046make sure actionable information necessary to counter them is shared.4047Second, reinforcing the role of the Joint Cyber Defense Collaborative4048(JCDC) as a central hub for coordinated operational planning can4049streamline real-time sharing and response. Finally, codifying4050governance mechanisms like charter requirements, stakeholder roles, and4051reporting standards would strengthen trust and agility. Ensuring that4052liability protections clearly extend to fast-moving collaborative,4053operational responses is vital to enabling timely and decisive action4054during APT campaigns.4055 Questions From Chairman Andrew R. Garbarino for Diane Rinaldo4056 Question 1. Do barriers still exist to cybersecurity information4057sharing, such as private-sector companies' reluctance to share with law4058enforcement or quality concerns regarding redundant cyber threat4059indicators and defensive measures? What actions have been taken, if4060any, to overcome these barriers?4061 Answer. Yes, barriers absolutely remain. Many companies still4062hesitate to share because they're uncertain about liability protections4063or they simply lack the resources to participate. Others worry about4064whether the information they share will be useful, or if they'll get4065meaningful intelligence back (is the juice worth the squeeze scenario).4066We've certainly made progress: DHS's Automated Indicator Sharing4067program, the growth of ISACs, and more streamlined declassification of4068intelligence have all helped. But the flow is still too often one-way,4069and the quality and timeliness of information aren't always what4070industry needs in the middle of an attack. What's required now is to4071strengthen reciprocity, provide clearer safe harbors, and make4072participation easier for small and mid-sized companies.4073 Question 2. What can the Cybersecurity and Infrastructure Security4074Agency (CISA) do to increase participation in the Automated Indicator4075Sharing (AIS) program?4076 Answer. CISA needs to make participation valuable in real time.4077When a company shares an indicator, they should get timely, actionable4078intelligence back but within hours. The data also needs to be delivered4079in formats that companies can use immediately in their security tools.4080Reducing noise, providing context, and integrating with the platforms4081companies already rely on would go a long way. Finally, CISA can make4082participation more attractive by offering incentives such as priority4083access to threat briefings or incident support for organizations that4084actively contribute.4085 Question 3. Is there any ambiguity in CISA 2015's definitions, such4086as for cyber threat indicators or defensive measures, that Congress4087should revisit? If so, please explain.4088 Answer. Yes, there are ambiguities. The term ``cyber threat4089indicator'' was written before today's realities like AI-driven4090attacks, identity-based threats, and large-scale abuse of cloud4091services. The definition should be broadened to clearly include4092behavioral analytics, AI detection artifacts, and identity signals like4093multifactor bypasses. Similarly, ``defensive measures'' should reflect4094the automated blocking and orchestration tools that are commonplace4095today. Clarifying these terms would remove uncertainty and give4096companies more confidence that their actions fall under the law's4097protections.4098 Question 4. Do you believe that CISA 2015, if reauthorized, should4099still exclude protections from sharing with the Department of Defense4100(DoD), including the National Security Agency (NSA)? Why or why not?4101 Answer. There needs to be a more balanced approach. The original4102exclusion was meant to build trust and avoid concerns about4103surveillance. The last 10 years have proven that the U.S. Government is4104able to adhere to the strict minimization standards and protect4105personally identifiable information (PII). The threat has certainly4106advanced beyond what we envisioned 10 years ago. When an advanced4107persistent threat is in play especially from a nation-state actor, it4108makes sense for DoD or NSA to be part of the picture. My view is that4109Congress should allow carefully-scoped sharing with these agencies,4110with guardrails: CISA should remain the front door, minimization and4111transparency should apply, and use of the data must be limited strictly4112to cybersecurity defense. That way, we preserve trust while ensuring we4113can act at the speed of the threat.4114 Question 5. Do liability protections under the existing statute4115sufficiently address threat actors' new and emerging tactics,4116techniques, and procedures (TTPs)? If they do not, please provide some4117recommendations to ensure the law upholds its relevancy as the threat4118landscape evolves.4119 Answer. Protections need to be enhanced to encourage greater4120participation. The statute was written before AI, before the explosion4121of ransomware-as-a-service, before the identity and supply chain4122attacks we see now. Companies need assurance that if they act in good4123faith, whether by sharing new types of indicators, deploying automated4124defensive measures, or collaborating internationally, they are4125protected. Congress should expand liability protections to explicitly4126cover these evolving tactics and tools. A good rule of thumb is: if a4127company follows best practices, uses recognized sharing standards, and4128acts to defend its network, they should be protected.4129 Question 6. How does CISA 2015 allow for small and rural critical4130infrastructure sector organizations to effectively share cyber threat4131information with Government entities?4132 Answer. In theory, the law applies equally to everyone. In4133practice, smaller organizations often don't have the staff, budget, or4134legal support to participate. Some benefit through ISACs, fusion4135centers, or State-based programs, but it's patchy. To make this law4136truly work for them, Congress should consider subsidizing membership in4137ISACs, and simplified legal frameworks so smaller players can4138participate without fear or cost barriers.4139 Question 7. What changes, if any, can Congress make to CISA 2015 to4140ensure there are no delays or roadblocks to information sharing,4141especially when dealing with a campaign from an advanced persistent4142threat (APT) actor?4143 Answer. Speed is everything in an advanced persistent threat4144scenario. Congress can help by requiring reciprocity: when companies4145provide indicators, CISA must push back sanitized, actionable4146intelligence quickly. Clear statutory time lines would help. Congress4147should also support ``default to declassify'' processes so that4148critical information isn't held up unnecessarily by classification. And4149we should empower joint operations cells with the relevant agencies4150such as CISA, FBI, DoD, NSA so the Government can act as one team and4151provide a single, timely stream of information to the private sector.4152 Questions From Chairman Andrew R. Garbarino for Karl Schimmeck4153 Question 1. Do barriers still exist to cybersecurity information4154sharing, such as private-sector companies' reluctance to share with law4155enforcement or quality concerns regarding redundant cyber threat4156indicators and defensive measures? What actions have been taken, if4157any, to overcome these barriers?4158 Answer. Large financial institutions do not have significant4159barriers to cybersecurity information sharing but there may be4160reluctance among smaller companies that are not aware of the4161protections that are provided under CISA 2015. Although there has been4162outreach to such firms at various points a more concerted effort to4163raise awareness about the necessity of information sharing and the4164protections provided would be helpful. The financial services industry4165views the Federal Government (including CISA and Federal financial4166regulators) and law enforcement as valuable partners in defending4167against cybersecurity threats, but having information shared from4168companies of all sizes will further improve that value of the4169information shared. CISA 2015 provides significant protections against4170regulatory and antitrust enforcement actions and antitrust which are4171critical.4172 Over the past few years U.S. Treasury has removed many barriers4173around sending Classified threat indicators (e.g., IOCs) to the private4174sector. Treasury now declassifies threat indicators more quickly to4175provide the sector with leading indicators they can use to prevent4176cyber attacks. And during crises, the public/private sector incident4177management mechanisms have improved to allow rapid sharing of ground4178truth during attacks in progress.4179 Question 2. What can the Cybersecurity and Infrastructure Security4180Agency (CISA) do to increase participation in the Automated Indicator4181Sharing (AIS) program?4182 Answer. CISA should make an affirmative effort to educate companies4183about the benefits of sharing through the AIS program. The program4184should also demonstrate its own valuable by using current technology as4185well as providing timely and accurate threat information shared in the4186system.4187 CISA should explore alternative approaches to its automated threat4188intelligence and information-sharing capabilities, including4189implementing a long-term vision for information sharing, building on4190existing capabilities, and aligning with reporting programs at other4191Government agencies including financial regulators.4192 Question 3. How important is the antitrust exemption in CISA 2015?4193Please explain and provide any examples that would help illustrate your4194point.4195 Answer. The antitrust exemption is critical to information sharing4196between private entities as well as with the Government as that4197information is also shared indirectly with private companies. Antitrust4198compliance is time-consuming and costly. The exemption limits the4199necessity of lengthy internal or external reviews of information to be4200shared for antitrust compliance thus decreasing response times for4201sharing critical information with the Government or with other private4202entities. For example, if a private company has information about a4203cyber threat stemming from its use of a vendor, that company may share4204that information with the Government or other private entities who may4205also use that vendor including what services the company receives from4206the vendor which may be related to the cyber threat without risk of4207that behavior being deemed anti-competitive under U.S. law.4208 Question 4. Is there any ambiguity in CISA 2015's definitions, such4209as for cyber threat indicators or defensive measures, that Congress4210should revisit?4211 Answer. The definitions are generally well-understood and do not4212require additional changes to meet the needs of the financial services4213industry. For the most part, these definitions have been harmonized4214across the public and private sector to provide for better4215communication during cyber events. As a result, changing these4216definitions may cause additional challenges since they are already4217generally accepted.4218 Question 5. What changes, if any, can Congress make to CISA 2015 to4219ensure there are no delays or roadblocks to information sharing,4220especially when dealing with a campaign from an advanced persistent4221threat (APT) actor?4222 Answer. CISA 2015 already contains the necessary framework for4223information cyber threat information sharing between public and private4224entities. The Department of Homeland Security should have the necessary4225financial resources and technology necessary to both share information4226and provide detailed instructions on defensive strategies wherever4227possible.4228 Question 6. Do you believe that CISA 2015, if reauthorized, should4229still exclude protections from sharing with the Department of Defense4230(DoD), including the National Security Agency (NSA)? Why or why not?4231 Answer. CISA 2015 if reauthorized should include the broadest4232protections possible for sharing with any Federal Government entity4233which may play a part in the protection of our critical infrastructure.4234There should be the same protections regardless of which agency the4235entity shares cyber threat information with.4236 Question 7. The existing statute states that the Federal Government4237must share ``timely'' information. Do you believe that the Federal4238Government is succeeding in this role, and does this extend to both4239Classified and unclassified information?4240 Answer. Response times for information sharing from the Federal4241Government to the private sector are critical for the system to work.4242Stale information is not valuable in defending against an impending4243cyber threat, so it is important that this information be shared as4244soon as possible while still ensuring the necessary privacy and other4245confidential information is not shared if it's not necessary to the4246prevention efforts.4247 Questions From Chairman Andrew R. Garbarino for Katherine Kuehn4248 Question 1. Do barriers still exist to cybersecurity information4249sharing, such as private-sector companies' reluctance to share with law4250enforcement or quality concerns regarding redundant cyber threat4251indicators and defensive measures? What actions have been taken, if4252any, to overcome these barriers?4253 Yes, barriers to cybersecurity information sharing persist, despite4254years of focus on public-private partnerships, and the private sector4255remains hesitant to share cyber threat information with the Federal4256Government. In addition, there are concerns that CISA doesn't protect4257its sensitive equities. According to information originating from the4258Cybersecurity and Infrastructure Security Agency (CISA), concerns have4259been raised regarding accuracy and timeliness. For example, Yara rules4260shared on threats have frequently contained inaccurate or poorly-4261crafted alerts.4262 Major barriers include:4263 Lack of Trust.--Organizations may be reluctant to share4264 information due to concerns about data misuse or leaks,4265 especially when sharing with competitors or Government4266 entities. Building trust through transparent policies and4267 fostering a collaborative culture is crucial.4268 Legal and Regulatory Challenges.--Different jurisdictions4269 have varied data-sharing laws, and regulations like GDPR can4270 pose challenges for cross-border sharing. Navigating these4271 legal frameworks and ensuring compliance can be complex,4272 potentially hindering collaboration. Concerns about potential4273 liability if shared information is inaccurate or misleading can4274 also deter organizations from sharing.4275 Organizational Barriers.--Issues such as resource4276 constraints, a lack of technical expertise, and internal silos4277 within organizations can impede effective information sharing.4278 Technical Challenges.--Difficulties in integrating systems4279 and establishing a common language for sharing can hinder4280 automated information exchange. The amount of data can also4281 overwhelm resources, making it difficult to deliver information4282 to the right place at the right time.4283 Concerns about Disclosure.--Companies worry about revealing4284 sensitive company information, potential non-compliance with4285 regulations, customer privacy violations, and reputational4286 damage from sharing details of cyber attacks.4287 Actions taken to overcome these barriers:4288 Efforts have been made to address these concerns, including4289updating the Automated Indicator Sharing (AIS) platform and launching4290programs such as the Joint Cyber Defense Collaborative (JCDC). However,4291these steps have not meaningfully changed the landscape. The private4292sector still overwhelmingly relies on peer-to-peer exchanges,4293commercial threat intelligence providers, and industry-specific4294Information Sharing and Analysis Centers (ISACs), all of which are4295connected to the foundation laid by CISA 2015, which provides the4296liability protections and other legal assurances necessary for these4297programs to exist. Even with these assurances, trust issues and4298inefficiencies continue to dominate the information-sharing environment4299and will persist without the safeguards established in CISA 2015. A4300clean renewal is necessary to continue the programs that are working,4301and as we look toward the future, additional actions could include:4302 Additional Legislation and Policy4303 More Collaborative Government/Industry Initiatives4304 Incorporation of Technological Advancements4305 Focus on Trust and Communication.4306 Following the clean renewal of the Cybersecurity Information4307Sharing Act of 2015 (CISA 2015), we can examine other ways of sharing4308information that should be considered for dissemination and building4309more trust between public-private partnerships. One suggestion would be4310to continue the Office of the National Cyber Director (ONCD) roundtable4311efforts or expand JCDC or AIS, which would enable coordinated cross-4312functional cyber information dissemination points that could act in a4313central and controlled way with the ability to engage with Industry in4314a functional and approved manner.4315 A potential framework for this type of partnership could be4316replicated by either the ONCD or the JCDC/AIS, which could be derived4317from the incomplete one currently found on the U.S. Cyber Command4318website. https://www.cybercom.mil/Partnerships-and-Outreach/Private-4319Sector-Partnerships/4320 private-sector partnerships the mission4321 The mission of our unclassified private-sector partnership program4322and forum, otherwise known as UNDER ADVISEMENT, is to engage with4323industry partners, agilely sharing critical information that enables4324both U.S. Cyber Command missions and private-sector partner priorities.4325Who We Are4326 UNDER ADVISEMENT is U.S. Cyber Command's front door regarding4327information sharing to and from private-sector partners. The immediate4328cyber crises information shared supports U.S. Cyber Command's entire4329mission set while providing vital information to our partners so they4330can further protect and defend their networks from adversary threats.4331How We Do It4332 U.S. Cyber Command enters into two-way information-sharing4333agreements with partners from across all aspects of the public and4334private sectors. These agreements are designed to enhance and expand4335trust and dialog between our partners and CYBERCOM. Once an agreement4336is in place, members of the UNDER ADVISEMENT program work with our4337partners to facilitate sharing of critical information across multiple4338agreed outlets.4339 Question 2. What can the Cybersecurity and Infrastructure Security4340Agency (CISA) do to increase participation in the Automated Indicator4341Sharing (AIS) program?4342 Answer. The Cybersecurity and Infrastructure Security Agency's4343Automated Indicator Sharing (AIS) program aims to facilitate the real-4344time sharing of cyber threat information among organizations, thereby4345enhancing cybersecurity and preventing attacks. However, recent reports4346from the Department of Homeland Security's Office of Inspector General4347(OIG) have raised concerns about the program's effectiveness and its4348usefulness to participants. Post a clean renewal of CISA 2015, a review4349of the program should be considered as a longer-term goal.4350 Current Benefits of CISA AIS are:4351 Real-time threat intelligence sharing.--Participants can4352 share and receive machine-readable cyber threat indicators4353 (CTIs) and defensive measures (DMs) in real time to proactively4354 defend their networks.4355 Collective knowledge.--Organizations benefit from the4356 collective knowledge of participants, gaining insights into4357 observed threats and vulnerabilities.4358 Liability and privacy protections.--The Cybersecurity4359 Information Sharing Act of 2015 (CISA 2015) provides certain4360 legal protections to encourage sharing, including liability4361 protection, privacy protections, and exemption from specific4362 disclosure laws.4363 Challenges and Criticisms:4364 1. Declining participation.--The number of participants actively4365 sharing information through AIS has decreased significantly in4366 recent years.4367 2. Insufficient shared indicators.--The volume of shared CTIs has4368 also declined considerably, raising concerns about the4369 program's ability to facilitate effective real-time threat4370 sharing.4371 3. Lack of context.--Some reports indicate that the quality of4372 shared information is not always sufficient, lacking the4373 contextual details necessary for effective threat mitigation.4374 4. Outreach and funding issues.--The OIG attributed the decline in4375 participation to CISA's inadequate outreach strategy and4376 difficulties in identifying specific program costs and auditing4377 expenditures.4378 Overall Usefulness:4379 Despite the reported challenges, the CISA AIS program is a valuable4380tool for enhancing cybersecurity by promoting information sharing and4381collective defense. However, the program's current effectiveness is4382under scrutiny due to the decline in participation and shared threat4383indicators. CISA has acknowledged the issues and is working to address4384them, including the development of a new threat intelligence strategy4385and evaluation of the AIS program's effectiveness. The agency is also4386exploring alternative information-sharing systems, potential technical4387enhancements, and feedback from participants to improve the program.4388 From a technical enhancement perspective, the platform needs more4389than technical compliance with STIX and TAXII standards. It should4390offer meaningful metrics, such as scores for timeliness, uniqueness,4391and detection effectiveness. The system must also reduce integration4392friction. Many companies already support the necessary formats but do4393not use AIS due to the additional burden involved.4394 One recommendation would be for CISA to offer hosted pilots for4395smaller organizations, provide direct feedback about how shared data is4396used, and build tools that demonstrate how one company's input protects4397others. Perhaps most importantly, AIS should be repositioned as a core4398element of national cyber defense, rather than merely serving as a data4399repository.4400 In conclusion, while the CISA AIS program offers potential benefits4401for cybersecurity, its usefulness may currently be limited by the4402reported challenges with participation and information sharing. It4403needs to be revamped if we are to achieve stronger collaboration.4404Still, the work necessary cannot be fully executed before the4405expiration of CISA 2015 and should not be considered in a clean renewal4406strategy.4407 Question 3. How has the Cybersecurity Information Sharing Act of44082015 (CISA 2015) changed the information-sharing environment among4409private-sector entities?4410 Answer. The Cybersecurity Information Sharing Act of 20154411significantly altered private-sector cybersecurity information sharing4412by creating a legal framework that encourages voluntary sharing of4413cyber threat indicators and defensive measures with both the Government4414and other private entities. This framework provides protections and4415incentives for companies to share information, including antitrust4416exemptions and immunity from specific disclosure laws.4417 Protections Include:4418 Legal Protection for Sharing.--CISA 2015 provides4419 protections from legal liability when organizations voluntarily4420 share cyber threat information with both the Federal4421 Government, through the Department of Homeland Security (DHS),4422 and other entities in the private sector.4423 Antitrust Exemptions.--The act permits companies to4424 collaborate and share information without the risk of antitrust4425 scrutiny by providing exemptions from antitrust laws.4426 Immunity from Disclosure Laws.--CISA 2015 shields shared4427 information from specific disclosure laws, such as open4428 Government and Freedom of Information Act requests, to4429 encourage more open sharing.4430 Non-Waiver of Protections.--Sharing information under the4431 guidance of CISA 2015 does not waive any other applicable4432 protections or privileges.4433 Centralized Sharing.--CISA 2015 established a centralized4434 mechanism for sharing information with DHS as the primary point4435 of contact through the AIS Initiative.4436 Focus on Cyber Threat Indicators and Defensive Measures.--4437 CISA 2015 encourages the sharing of cyber threat indicators,4438 such as malicious IP addresses, and defensive measures,4439 including security patches.4440 Ex Parte Communications Waiver.--The sharing of cyber threat4441 information with the Federal Government, under CISA 2015, is4442 not considered ex parte communication.4443 No Mandate for Sharing.--While CISA 2015 encourages sharing,4444 it does not require private entities to share information,4445 which is a key point of the act. Sharing is voluntary and helps4446 establish the trust necessary for transparent communications.4447 CISA 2015 marked a turning point in public-private cybersecurity4448collaboration. In summary, it provides the critical legal protections4449outlined, which encourage the private sector to share threat indicators4450more confidently, primarily through ISACs and coordinated efforts with4451CISA. By addressing liability, privacy, and antitrust concerns, the act4452helps shift cybersecurity from a siloed effort to a more collective4453defense model.4454 The act also promotes the use of standardized data formats, which4455improved technical compatibility and laid the groundwork for broader4456sharing across sectors. Over time, even this has led to stronger4457partnerships and faster threat awareness. While there have been4458challenges and developments that must be addressed, a clean renewal of4459CISA 2015 is the most effective way to maintain information sharing and4460the partnership in the future.4461 Question 4. Is there any ambiguity in CISA 2015's definitions, such4462as for cyber threat indicators or defensive measures? If so, please4463explain.4464 Answer. Yes, there are acknowledged ambiguities in the definitions4465within the Cybersecurity Information Sharing Act of 2015 (CISA 2015),4466particularly regarding its scope and application. These ambiguities,4467however, can be addressed in subsequent modifications to CISA 20154468after a clean renewal of the current act, modernization of the current4469public/private sharing organizations, and a potential revamp of CISA.4470The main examples of ambiguities are:4471 Substantial Cyber Incidents.--While CISA's approach to4472 covered cyber incidents is limited to ``substantial''4473 incidents, the definition of ``substantial'' has been4474 interpreted broadly, leading to ambiguities regarding which4475 incidents fall under the reporting requirements.4476 Third-Party Incidents.--The definition of ``third-party''4477 incidents, encompassing incidents involving vendors and4478 suppliers of covered entities, has been read broadly.4479 Cybersecurity Threat.--While the act defines ``cybersecurity4480 threat'' as an action on or through an information system that4481 may result in an unauthorized effort to impact its security or4482 data adversely, it also includes exemptions for activities that4483 are solely violations of consumer agreements and authorized4484 activities that incidentally cause adverse effects.4485 Definition of ``Cyber Threat Indicator''.--Since CISA 2015,4486 the recommendation has been made to expand the definition of4487 ``cyber threat indicator'' to address emerging threats such as4488 AI-related issues and supply chain vulnerabilities.4489 These ambiguities can raise operational questions in addition to4490concerns around legal risk, and impact how entities implement and4491comply with CISA 2015, particularly concerning information sharing and4492incident reporting. Companies often worry about crossing legal lines,4493especially when using sinkholing, beaconing, or deception techniques.4494The statute prohibits anything that causes ``damage,'' but it does not4495clearly outline what counts as damage in a cyber context. Even the4496phrase ``timely removal of personal information'' lacks a specific time4497frame, which leads to differing interpretations and inconsistent4498application.4499 These ambiguities create risk for legal teams and discourage4500organizations from sharing data that may otherwise be valuable and have4501led to discussions surrounding the CISA 2015 reauthorization,4502suggesting a need to address these ambiguities, possibly by amending4503definitions or expanding liability protections to encourage greater4504sharing of information now. This can, though, be accomplished post a4505clean renewal of CISA 2015 and would still enable the desired outcome4506of on-going efforts to refine the law and address potential issues4507related to its interpretation and effectiveness as new technologies.4508One short-term solution suggestion would be for CISA to continue to4509release more guidance to help clarify aspects of the law and assist4510non-Federal entities in sharing cyber threat information.4511 Question 5. How important is the antitrust exemption in CISA 2015?4512Please explain and provide any examples that would help illustrate your4513point.4514 Answer. The antitrust exemption in CISA 2015 is considered crucial4515for promoting cybersecurity information sharing, particularly within4516the private sector. It encourages collaboration, facilitates broader4517information sharing, enhances collective defense, and minimizes legal4518risks for companies. In essence, the antitrust exemption, alongside4519other legal protections provided by CISA 2015, plays a crucial role in4520enabling and encouraging the voluntary sharing of cyber threat4521information, which is considered vital for defending against modern4522cyber threats and strengthening national cybersecurity.4523 While the antitrust exemption is critically important, it is4524underutilized. In a few high-profile incidents, such as the response to4525Log4Shell, the exemption enabled competitors to coordinate quickly and4526share detection signatures. But these examples remain rare and could be4527examined post a clean renewal of CISA 2015 as an area for improvement.4528Legal departments often remain cautious because the statutory language4529is narrow and unfamiliar. Without more clarity or precedent, many4530companies still avoid open collaboration.4531 To make the exemption more effective, the Government, via either4532the ONCD or CISA, should publicize success stories and clarify4533boundaries. Clear guidance about what is and is not permitted would go4534a long way toward increasing confidence and use of this vital4535provision. Trying to address this improvement now, however, may4536jeopardize the renewal of the act, and is not recommended; it may,4537however, be an area for consideration in the future.4538 Question 6. The existing statute states that the Federal Government4539must share ``timely'' information. Do you believe that the Federal4540Government is succeeding in this role, and does this extend to both4541Classified and unclassified information? Please explain.4542 Answer. Consistency is critical, and while there has been4543improvement in the release of public joint advisories across CISA, NSA,4544and FBI, there has been little consistency. Without CISA 2015, there is4545a significant concern about ``timely'' sharing that needs to be4546addressed. The perception is that it often falls to the private sector4547to provide anchor points for further industry examination from the4548information provided by the Federal Government. If we were to lose the4549protections of information sharing that CISA 2015 provides, there would4550be significant concerns about how these critical anchor points would be4551disseminated.4552 In addition, as we highlighted, without a revamp of the AIS4553program, which could not be accomplished before the CISA 2015 renewal4554deadline, the current AIS feeds continue to deliver data with variable4555delays. The quality of that information is inconsistent, as noted with4556the incorrect Yara rules in many reports.4557 In cybersecurity, time matters. In discussions with the broader4558private-sector community, the primary concern is that our critical4559national infrastructure is increasingly becoming a target for non-state4560aggressors. Only through enhanced information sharing, such as that4561established in CISA 2015, will we be able to ensure its longevity. A4562clean renewal of CISA 2015 is one of the key ways we can start to take4563the steps necessary to enhance and improve a ``timely'' response from4564the Federal Government on cybersecurity, build more trust with the4565private sector, and address the rapidly-changing threat landscape.4566 In addition, from a ``timely'' information-sharing perspective, the4567goal of the Federal Government should be to shorten distribution cycles4568and modernize its communication methods, like the AIS program, to4569facilitate stronger and more accurate reporting of critical4570cybersecurity incidents, whether Malicious, Malfunction, or Mistake-4571driven that may impact the private sector. The sharing facilitated by4572CISA 2015 is crucial to achieving this goal.45734574 [all]Witnesses
4 witnesses appeared, with 8 papers on file.
| Name | Position | Papers |
|---|---|---|
| Ms. Diane Rinaldo | Private Citizen | Truth in Testimony · Testimony |
| Mr. Karl Schimmeck | Chief Information Security Officer, Northern Trust | Truth in Testimony · Testimony |
| Mr. John Miller | General Counsel and Senior Vice President of Policy, Trust, Data, and Technology, Information Technology Industry Council | Truth in Testimony · Testimony |
| Ms. Kate Kuehn | Member and CISO-in-Residence, National Technology Security Coalition | Truth in Testimony · Testimony |
Documents
The committee filed 2 documents for the meeting.
| Document | Kind | Format |
|---|---|---|
| Hearing: Witness List | Hearing: Witness List | |
| Hearing Notice | Support Document |