"We cannot build that trust if companies expect their risk calculus to change every 90 days," Doc McConnell, Head of Policy and Compliance at Finite State, warned after the House approved a short-term renewal.
House action: temporary extension through December 11, 2026
The House of Representatives approved a temporary extension of the Cybersecurity Information Sharing Act of 2015 (CISA 2015) that will remain in force until December 11, 2026. The measure leaves in place the statute’s liability protections and other provisions for the remainder of this calendar year but does not convert the law into a permanent or long-term authorization.
Doc McConnell, Finite State: voluntary sharing needs predictability
Doc McConnell framed the core debate around CISA 2015 as one of model and trust. He described the United States as having "placed a bet that voluntary information-sharing is the best model for collective security." McConnell argued that the law’s protections — which he said reduce risk by creating liability protections, exemptions from antitrust concerns, and prohibitions on using shared data for regulatory enforcement actions — are central to that voluntary system.
Against that, he contrasted other approaches: "Our voluntary approach stands in stark contrast to governments elsewhere, such as the European Union, that have strict mandatory reporting and disclosure requirements." McConnell’s bottom line was procedural: short-term renewals undercut the "long-term, predictable structure to build trust" that he says is necessary for companies to share threat data openly.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildDenis Calderone, Suzu Labs: near-lapses and operational disruptions
Denis Calderone, CTO of Suzu Labs, described repeated short-term renewals as inconsistent with declared priorities. He noted this was "the second near-lapse of CISA 2015 in a year," and recalled that "last year’s brief expiration during the shutdown sent legal teams scrambling." According to Calderone, some organizations paused their threat sharing programs entirely until protections were confirmed back in place.
Calderone also said the law has had "broad bipartisan support since it was enacted in 2015" and that "the White House has been pushing for a permanent reauthorization." His view was straightforward: if a broadly supported bill cannot be made permanent, that signals where cyber policy ranks on the Hill.
Seemant Sehgal (BreachLock) and Donald McFarlane (Xcape, Inc.): uncertainty erodes trust
Seemant Sehgal, Founder and CEO of BreachLock, described the recurring short-term renewals as a direct input into companies’ risk calculations: "Every few months, the industry has to wonder whether the legal framework that makes threat sharing possible will still exist by the end of the quarter." He said that while extending CISA 2015 to December 11 "buys time," it "still doesn’t fix what the recurring uncertainty is doing to the underlying trust."
Donald McFarlane, Advisory Board Member at Xcape, Inc., expressed disappointment that lawmakers have not delivered a durable framework. McFarlane said he shares "Senator Paul’s broader concerns about government overreach," but cautioned that "opening voluntarily-shared threat intelligence to FOIA, or stripping away the narrow good-faith liability protections that enable sharing, seems like solving the wrong problem." He added that a persistent inability by Washington to provide a durable framework will tend to make private-sector partnerships that are "less dependent on Washington" look more attractive.
John Strand, Black Hills Information Security: the cost of rolling short-term fixes
John Strand, owner of Black Hills Information Security, framed the statute’s value in historical terms: in the early years of computer security, he said, there was a "huge reticence to publicly share information about breaches or vulnerabilities" and "penetration testing was something that was largely done in the shadows." Laws like CISA 2015, Strand argued, "helped pull that information sharing out of the darkness," enabling researchers and security teams to exchange vulnerabilities, indicators, and techniques.
Strand welcomed the extension but lamented its brevity: "I’m just a little disappointed that this is another short-term extension that only buys us a few more months. This shouldn’t be something we have to keep revisiting every few months. It needs to be permanent." He cited the evolution of sharing over the "past seven or eight years" as the foundation that the statute helped create and preserve.
Where this leaves the system
The House-approved renewal keeps the liability protections and other CISA 2015 provisions alive through December 11, 2026, but the security leaders quoted here present a clear split on the sufficiency of a temporary fix. Several described operational disruption — paused sharing programs, legal teams scrambling, shifting organizational risk calculations — as direct consequences of repeated short-term extensions. Others warned that proposed incursions such as opening shared materials to FOIA or removing narrow good-faith protections would undercut the very incentives the law created.
The extension buys time. The voices in this reporting largely agree on two points: CISA 2015’s legal protections enable voluntary threat sharing, and short, recurring renewals undermine the trust and predictability that those protections were intended to foster. Whether Congress will translate that diagnosis into a permanent reauthorization remains the outstanding decision following the December 11, 2026 deadline.
Source: SecurityMagazine — Cybersecurity Information Sharing Act of 2015 Temporarily Extended




