In Defense of Defensive Measures: Reauthorizing Cybersecurity Information Sharing Activities that Underpin U.S. National Cyber Defense

Environmental Permitting and Water InfrastructureHomeland Security Subcommittee on Cybersecurity and Infrastructure Protection · 2025-05-15 · 119th Congress
The Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held this hearing to examine the Cybersecurity Information Sharing Act of 2015 (CISA 2015), which provides liability and privacy protections for voluntary cyber threat information sharing between the private sector and government and is set to expire in September 2025. Begins at 0:08:42
Transcript
Highlights

Title

Reauthorizing the Cybersecurity Information Sharing Act of 2015

Purpose

The Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held this hearing to examine the Cybersecurity Information Sharing Act of 2015 (CISA 2015), which provides liability and privacy protections for voluntary cyber threat information sharing between the private sector and government and is set to expire in September 2025. Members and a panel of industry witnesses discussed the law's track record, potential targeted updates, and the effects of recent cuts to related advisory bodies and CISA's workforce and budget. Begins at0:08:42

Who spoke

Chairman Andrew Garbarino (R-NY)0:08:42: Opened the hearing on reauthorizing CISA 2015, noting a major organization shared 84 formal reports this year alone0:10:50, and said Secretary Noem voiced support for reauthorization the day before0:11:46; later pressed witnesses on why a lapse would matter and on private-to-private sharing gains1:03:081:24:11.

Ranking Member Eric Swalwell (D-CA)0:12:14: Recalled the 2015 debate and said the biggest current complaint is that JCDC information flow remains "a one-way relationship"0:13:19; urged codifying JCDC and restoring CIPAC0:15:50; later raised security-clearance mismatches between cleared executives and working engineers0:59:35 and asked about the loss of CIPAC's advisory function1:18:00.

John Miller, ITI General Counsel/SVP Policy0:19:20: Said any CISA 2015 lapse would be "an unforced error" benefiting China, Iran, and Russia0:20:58; proposed narrow updates such as covering supply-chain "suspect supplier" information under cyber threat indicator definitions0:24:10; testified he's aware of no privacy-related complaints in 10 years1:21:46.

Diane Rinaldo, private citizen, former House Intelligence staff0:24:58: Said the original bill underwent three major rewrites and over 100 stakeholder meetings before passage0:27:50; noted more than 90% of US networks are privately held0:56:05; said non-reauthorization would push decisions "from the CISO to the general counsel's office," slowing response1:05:16.

Karl Schimmeck, CISO, Northern Trust (for SIFMA)0:29:59: Said there have been zero known reports of improper PII sharing in 10 years0:32:04; warned a lapse would immediately increase vulnerability and disproportionately hurt small and medium firms unable to build bilateral arrangements1:05:47; said the automated indicator sharing (AIS) system, built roughly a decade ago, could use modernization1:14:30.

Kate Kuehn, CISO-in-Residence, National Technology Security Coalition0:34:14: Cited the termination of CIPAC, disbandment of the Cyber Safety Review Board, and dismissal of Cybersecurity Advisory Committee members as having created gaps in public-private cooperation0:37:38; described roughly 80% of critical infrastructure sitting with small and medium businesses1:16:43; recounted a small Dallas business owner forced to close after a $6 ransomware demand from a gang in Turkey0:50:26.

Rep. Carlos Gimenez (R-FL)0:40:00: Asked whether cybersecurity firms share information freely or guard it proprietarily0:41:48 and whether AI "swords" or "shields" are winning0:43:49; in a second round asked whether the US invests enough in AI defense and whether agencies pursue a unified strategy1:08:331:10:57.

Rep. Seth Magaziner (D-RI)0:45:40: Warned the administration's fiscal 2026 budget proposes cutting nearly half a billion dollars from CISA and reported plans to cut over 1,000 CISA jobs0:47:120:48:00; argued the administration should be investing in CISA, not cutting it0:46:56.

Rep. Andy Ogles (R-TN)0:51:44: Asked Miller how CISA 2015 could be strengthened, including JCDC's role0:52:090:54:12; asked Rinaldo about China-specific protections0:55:36; in a later round asked Schimmeck and Kuehn how smaller Tennessee communities can defend critical infrastructure with limited IT staff1:15:00.

A committee member (unidentified, questioning after Ogles)1:02:38: Entered eight stakeholder statements—including one signed by 52 organizations—into the record1:03:08 and asked witnesses to state on the record what would happen without reauthorization.

Key moments

Miller said if CISA 2015 lapses there would be an "immediate chilling effect" on information sharing and the legal status of DHS's automated indicator sharing program would become uncertain1:04:041:05:16.

Schimmeck said a lapse would make information sharing "a big firm only play," pushing smaller companies out and reviving pre-2015 bilateral, ad hoc arrangements1:05:47.

Magaziner cited a proposed cut of nearly $500 million from CISA's FY26 budget and over 1,000 job cuts, arguing this contradicts claims the administration takes cybersecurity seriously0:47:120:48:00.

Rinaldo said more than 90% of US networks are held by the private sector, framing why government-to-business information flow needs improvement via oversight rather than new legislation0:56:05.

Panel unanimously recommended a "clean" reauthorization without amendments, citing risk that reopening the bill could cause it to lapse entirely1:01:291:02:091:02:38.

Miller, Rinaldo, Schimmeck, and Kuehn each stated they are aware of zero confirmed privacy or PII-related breaches under CISA 2015 in its 10-year history, corroborated by an Inspector General report1:20:25.

Kuehn described three current AI-era threat categories — malicious, malfunction, and mistake — citing CrowdStrike as an example of malfunction risk0:48:290:48:57.

Kuehn recounted a small-business owner whose company closed after a $6 ransomware payment demand from a group in Turkey overwhelmed their ability to respond0:50:260:51:13.

Swalwell and Rinaldo both flagged a mismatch in security clearances: senior executives are cleared to receive threat briefings but often lack the technical skill to act, while the engineers who could act are not cleared0:59:351:00:01.

Miller proposed a narrow legislative fix: adding "derogatory information about a supplier" to the statutory definition of cyber threat indicator to address software supply-chain attacks like SolarWinds0:53:300:54:10.

Metadata

CommitteeHomeland Security Subcommittee on Cybersecurity and Infrastructure Protection
Chamber / CongressHouse · 119th Congress
Date2025-05-15
TypeHearing
Witnesses
Ms. Diane Rinaldo — Private Citizen
Mr. Karl Schimmeck — Chief Information Security Officer, Northern Trust
Mr. John Miller — General Counsel and Senior Vice President of Policy, Trust, Data, and Technology, Information Technology Industry Council
Ms. Kate Kuehn — Member and CISO-in-Residence, National Technology Security Coalition
Videoyoutube
Transcript181 caption blocks · 13,223 words · 1:26:23 runtime
EventCongress.gov 118149