Senator Gary Peters has introduced new legislation aimed at extending and renaming the expired Cybersecurity Information Sharing Act of 2015 (CISA), which lapsed following a government shutdown on October 1, 2025. The expiration of CISA has left a gap in liability protections for private sector organizations that share cyber threat information with the federal government, a key feature that had encouraged robust information exchange since the law's enactment in 2015. Peters' new bill, the Protecting America from Cyber Threats (PACT) Act, seeks to extend these protections for another ten years and includes retroactive provisions to cover the period during which the law was inactive. Industry groups and cybersecurity professionals have emphasized the critical importance of these liability protections, often citing CISA as one of the most effective pieces of cyber legislation ever passed. The lapse in CISA's authority has created uncertainty for organizations that continue to share threat data, raising concerns about potential legal exposure. The legislative process to renew CISA has been complicated by political gridlock, with both the Senate and House advancing competing funding bills and short-term extensions that ultimately failed, leading to the shutdown. Peters has engaged in direct discussions with Senate leadership, including Majority Leader John Thune, to advocate for a swift renewal. The new bill also addresses confusion among lawmakers who conflate the CISA law with the Cybersecurity and Infrastructure Security Agency, clarifying that the legislation pertains to information sharing, not agency reauthorization. The expiration of CISA has also impacted related programs, such as the State and Local Cybersecurity Grant Program, which similarly lost authorization during the shutdown. The Department of Homeland Security's Automated Indicator Sharing (AIS) system, which had served as the central hub for threat intelligence exchange under CISA, now operates without the legal framework that previously governed its activities. Peters and his colleagues have repeatedly sought unanimous consent in the Senate to pass a clean extension of the law, but partisan disagreements have stalled progress. The proposed PACT Act aims to reassure private entities that any information shared during the lapse will be protected from liability, thereby maintaining the flow of critical threat intelligence. The ongoing debate underscores the importance of real-time cyber threat information sharing in defending against persistent and evolving cyberattacks. As Congress continues to negotiate, the cybersecurity community remains concerned about the potential chilling effect on information sharing and the broader implications for national cyber defense. The outcome of these legislative efforts will determine whether the United States can sustain the collaborative public-private partnerships that have become central to its cybersecurity strategy.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Industry stakeholders publicly raised concerns that the lapse in liability protections could discourage cyber threat sharing and called for long-term legislative certainty rather than temporary fixes. Their comments underscored the operational impact of the expiration.
Renewal legislation faced repeated procedural obstacles in the Senate, particularly from Homeland Security Committee Chairman Rand Paul, who sought additional free speech protections. The impasse prevented quick restoration of the expired liability shield.
Sen. Gary Peters introduced the Protecting America from Cyber Threats Act to extend the expired law for another decade. The bill also sought retroactive liability protection for companies that shared cyber threat data during the lapse.
Attempts to attach short-term extensions of the cyber information-sharing law to government funding measures failed in the Senate. The setbacks left the statute expired and its future unresolved.
The House Homeland Security Committee advanced bills to renew the 2015 cyber information-sharing law and the State and Local Cybersecurity Grant Program. This marked a congressional effort to restore the expired authorities, though the measures had not yet cleared the Senate.
The Cybersecurity Information Sharing Act's liability protections lapsed when the statute expired amid a government shutdown tied to congressional gridlock. The expiration created uncertainty for companies continuing to share cyber threat data with the government.
The Cybersecurity Information Sharing Act of 2015 established a framework for companies to share cyber threat indicators with the U.S. government while receiving liability protections. The law became a foundational federal mechanism for public-private cyber threat information sharing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcenextgov.com
Open sourcetherecord.media
Open sourcecyberscoop.com
Open sourceguidepointsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.