The expiration of the Cybersecurity Information Sharing Act, or CISA, on September 30, 2025, has created a significant gap in U.S. cyber defense capabilities. Since the act’s lapse, there has been a reported decline of more than 70% in the sharing of threat indicators across formal channels, leading to increased delays in alert dissemination and a rise in cyber threats, particularly in sectors like healthcare and energy. Federal agencies and private companies are feeling the impact of this legal and operational vacuum, as organizations hesitate to report incidents without the liability protections that CISA provided. This has resulted in a fragmented response to threats, particularly as adversaries exploit vulnerabilities in critical infrastructure.
The Verge highlighted a recent incident in Arizona where an online portal for political candidates was hacked, replacing candidate images with those of Iranian Ayatollah Ruhollah Khomeini. This breach is believed to be linked to an Iranian government-affiliated group, raising alarm over the security of critical infrastructure. Since the beginning of Donald Trump’s presidency, the Cybersecurity and Infrastructure Security Agency (CISA) has experienced severe staffing cuts and a loss of trust among state officials, as Arizona Secretary of State Adrian Fontes noted. Once a vital resource for election security, CISA’s diminished capacity now leaves organizations wary of sharing sensitive information, which is crucial for national cybersecurity. With CISA’s budget potentially slashed by nearly half a billion dollars, experts warn that the agency’s reduced capabilities put America at greater risk of cyberattacks.
Legislation to end the federal government shutdown includes a provision to extend the Cybersecurity Information Sharing Act of 2015 through the end of January. This extension has been sought by industry groups since the law’s expiration at the end of September, as its legal protections are crucial for sharing threat data between businesses and government agencies.
Why do we care?
Here’s one that’s flying under the radar but has huge implications — the Cybersecurity Information Sharing Act expired back in September. That law made it safe for companies to share threat data with the government without getting sued. Since it lapsed, threat-sharing activity has dropped over 70%. That means slower alerts, less coordination, and more blind spots — especially in sectors like healthcare and energy.
And if that wasn’t bad enough, CISA — the agency that used to coordinate much of this — has been hit with budget cuts and staffing losses, and it’s the impacts that are the new story. It’s a warning sign that adversaries are testing weaknesses while our coordination is at its weakest.
Congress has tacked on a short-term extension through January, but that’s just kicking the can. For MSPs, this means less reliable government intel for now — so rely more on your vendor and private feeds. The bigger takeaway? The U.S. cyber defense ecosystem just lost one of its key connective tissues, and it’s up to private networks and MSPs to help fill the gap until.. and if…. Washington gets its act together.

