The United States faces the simultaneous risk of a federal government shutdown and the expiration of the 2015 Cybersecurity Information Sharing Act (CISA), a law considered vital for public-private cyber threat intelligence exchange. The CISA Act of 2015, distinct from the agency of the same name, is set to lapse at 12:01 am ET on October 1 unless Congress passes a continuing resolution to extend federal funding and the law itself. The House of Representatives previously passed a resolution that would have extended CISA and other bills until November 21, but the Senate rejected it, leaving the law’s future uncertain. The CISA law enables companies to share cyber threat indicators with the federal government, provided they remove personal information not directly related to the threat, and grants legal immunity to those who participate. Supporters argue that this pipeline of information is critical for national cyber defense, while detractors raise privacy concerns. Law firms are advising clients to prepare for the possibility that the law will lapse, though the precise impact on information sharing remains unclear. The looming shutdown has heightened anxiety among federal cyber defenders, as the expiration of CISA could disrupt established channels for sharing threat intelligence between the government and private sector. Historically, national security staff, including cyber personnel, have continued working during funding lapses, but contingency plans suggest that only about a third of the Cybersecurity and Infrastructure Security Agency’s staff would remain during a shutdown. The White House has removed public contingency documents, making it difficult to assess the full impact on the Department of Homeland Security and its cyber components. CISA has already experienced significant workforce reductions, and further cuts could undermine its ability to monitor threats, respond to incidents, and conduct security assessments. The deadlock in funding negotiations, exacerbated by the cancellation of meetings between the White House and Congressional leaders, has left the fate of both the government’s operations and the CISA law in jeopardy. The uncertainty has prompted concern across the cybersecurity community, as the loss of the legal framework for information sharing could hinder the nation’s ability to respond to evolving cyber threats. The situation underscores the interconnectedness of legislative action, government funding, and national cybersecurity posture. If the law is allowed to expire, companies may become more reluctant to share threat data, potentially reducing the government’s visibility into emerging threats. The outcome of the ongoing political negotiations will have significant implications for both public and private sector cybersecurity operations in the United States.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
By 2025-10-28, the White House was seeking congressional renewal of the key cyber threat-information-sharing law for a decade after the Cybersecurity Information Sharing Act of 2015 had expired. The move marked a formal administration effort to restore longer-term legal protections for voluntary cyber intelligence sharing.
Following the shutdown and CISA 2015 expiration, reporting highlighted that the State and Local Cybersecurity Grant Program could also be paused, disrupting contracts and multi-year security projects. Commentators warned that smaller communities and critical infrastructure operators such as utilities, hospitals, schools, and emergency services could face increased exposure.
On or around October 1, 2025, the federal government shutdown coincided with the expiration of CISA 2015, leaving cyber information sharing in legal and operational limbo. The lapse raised concerns about fragmented threat-intelligence exchange and weaker national cyber defense during ongoing nation-state and ransomware threats.
On 2025-09-26, the DHS Office of Inspector General reported that CISA had not finalized plans for continuing automated cyber threat information sharing beyond the Cybersecurity Act of 2015's expiration. The finding highlighted preparedness gaps ahead of the expected lapse in legal authorities supporting voluntary cyber information exchange.
By late September 2025, multiple reports said the Cybersecurity Information Sharing Act of 2015 was likely to expire because Congress had not reauthorized it while a federal government shutdown also loomed. Experts warned that the lapse would remove liability and information-sharing protections relied on for voluntary public-private cyber threat sharing.
On 2025-04-16, reporting said lawmakers advanced legislation to extend the legal framework supporting cyber threat information sharing between the public and private sectors. The bill represented an earlier congressional effort to preserve the authorities later described as nearing expiration in September 2025.
18 references tracked. Mallory keeps watching after this page renders.
axios.com
Open sourcedarkreading.com
Open sourcescworld.com
Open sourcescworld.com
Open sourcegovinfosecurity.com
Open sourceoig.dhs.gov
Open sourcebankinfosecurity.com
Open sourcecybersecuritydive.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.