Fortune | FORTUNE 08月18日
Former FBI cyber leader: The cybersecurity law that’s quietly keeping America safe is about to expire
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

美国一项至关重要的网络安全保护法案《2015年网络安全信息共享法案》(CISA 2015)将于2025年9月30日到期,除非国会采取行动。该法案十年来已成为国家网络防御的基石,促进了政府与企业间威胁情报的快速共享,有效阻止了无数网络攻击,尤其为小微企业提供了关键的早期预警系统。若该法案失效,特别是对缺乏足够财力和应对能力的小微企业将是毁灭性的打击,可能导致其倒闭。此外,在医疗等关键领域,网络攻击威胁生命安全,法案的失效将削弱对医院等关键基础设施的保护。该法案的续期不仅关系到企业生存和民众生命安全,更对美国的经济稳定和全球技术领导地位至关重要,目前两党对此已有共识,呼吁国会尽快通过。

🛡️ **CISA 2015是美国网络安全防御的核心支柱**:该法案自2015年起,通过促进政府与企业之间以及企业之间的威胁情报快速共享,有效构筑了国家网络防御体系。它为信息共享提供了关键的法律豁免和反垄断保护,鼓励了广泛的合作,极大地提升了美国网络空间的安全性,并已成为许多组织应对网络威胁的早期预警系统。

📉 **小微企业面临巨大风险**:法案到期将对占美国企业绝大多数的小微企业造成不成比例的严重影响。这些企业通常缺乏应对网络攻击(如勒索软件)所需的财力和运营韧性,一次攻击可能导致其数周的停业,最终面临永久关闭。CISA 2015提供的早期预警机制对它们尤为重要,其失效将使它们成为网络犯罪分子的主要目标。

🏥 **医疗行业生命安全面临威胁**:在医疗领域,网络攻击的后果是致命的。研究表明,勒索软件攻击已导致患者死亡。一旦CISA 2015失效,关键基础设施(如医院)将失去获取新攻击方法和勒索软件变种的关键早期预警,这可能延误应对措施,在紧急医疗情况下造成灾难性后果。

🌐 **影响美国经济和全球竞争力**:小微企业不仅是经济的基石,也是就业的主要提供者,其大规模失败将对美国GDP产生严重冲击。此外,CISA 2015支持的全面威胁情报共享是美国在网络安全领域保持全球领先地位的关键因素。其他国家借鉴美国模式,若该框架崩溃,将削弱美国的竞争优势和全球影响力。

✅ **续期是当务之急**:目前,跨党派均认识到CISA 2015的重要性,并呼吁其续期。最直接的途径是进行一次简单的续期,以便在未来进行必要的技术性改进。该法案已在过去十年中证明了其价值,促进了数十亿美元损失的避免,并已在行业内建立了信息共享的良好文化。国会必须在9月30日截止日期前采取行动,以避免不可挽回的损失。

The clock is ticking toward September 30, 2025, when one of America’s most vital cybersecurity protections will expire unless Congress acts. The Cybersecurity Information Sharing Act of 2015 (CISA 2015) has quietly become the backbone of our nation’s cyber defense. Without creating any additional regulations, it enabled the rapid sharing of threat intelligence between government and businesses that has prevented countless cyber attacks over the past decade. The Act’s protections have facilitated threat warnings to thousands of organizations just this year.  Its potential sunset threatens to unleash a wave of cyberattacks that will devastate the small and medium-sized businesses (SMBs) that form a foundational part of our economy.

As someone who has worked on both sides—first leading public-private partnerships at the FBI and now facilitating industry collaboration—I’ve witnessed firsthand how CISA 2015 transformed our cybersecurity landscape. The law provides crucial liability protections that encourage companies to share threat indicators with the government and each other, while offering antitrust protection for industry-to-industry collaboration. Without these safeguards, the robust information sharing that has made American networks more secure simply stops.

The SMB Crisis Waiting to Happen

The consequences of letting CISA 2015 lapse will fall most heavily on America’s small and medium-sized businesses. Recent data from NetDiligence’s 2024 Cyber Claims Study shows that ransomware cost SMBs an average of $432,000 per attack. These businesses don’t have the cash reserves to weather extended downtime. At most, many can only survive three to four weeks of operational disruption before facing permanent closure.

According to industry analysis, small and medium enterprises represent 98% of cyber insurance claims while accounting for $1.9 billion in total losses, underscoring their vulnerability in today’s threat landscape. CISA 2015’s expiration will significantly weaken the early warning system that has helped businesses stay ahead of emerging threats. Without the government’s ability to share robust intelligence about new attack methods, SMBs become sitting ducks for cybercriminals who specifically target organizations that can’t afford to lose days or weeks.

Healthcare: Where Cybersecurity Becomes Life and Death

The stakes become particularly dire in healthcare, where ransomware attacks don’t just threaten profits—they threaten lives. The University of Minnesota School of Public Health’s experts estimate that ransomware attacks killed 42 to 67 Medicare patients between 2016 and 2021. These numbers represent a horrifying trend: threat actors deliberately target hospitals because they know healthcare systems will pay quickly to avoid putting patients at risk.

If information sharing degrades after CISA 2015’s sunset, hospitals–and all other critical infrastructure–very likely will lose crucial early warnings about ransomware variants and other attack methods. When a hospital’s systems are threatened, rapid information sharing matters. Minutes count in medical emergencies, and delays can be fatal.

Economic Ripple Effects 

The economic impact extends far beyond individual companies. SMBs make up the vast majority of (99%) businesses in the U.S., and employ nearly half of the private sector’s workforce. According to  the U.S. Chamber of Commerce, they’re responsible for 43.5% of our GDP, so their widespread failure would create devastating ripple effects throughout the economy. 

More concerning, America’s technological leadership depends on the robust threat intelligence sharing that CISA 2015 enables. Our cybersecurity companies lead the world precisely because they have access to comprehensive threat data that helps them develop superior products and services.

Other countries modeled its cybersecurity information sharing after our system, recognizing that America’s approach gives us a competitive advantage. If we allow this framework to collapse, we’re not just making individual businesses more vulnerable—we’re undermining the foundation of American cybersecurity leadership that other nations seek to emulate.

The Path Forward: Clean Reauthorization Now

There’s bipartisan agreement that CISA 2015 should be reauthorized, with experts from across the political spectrum recognizing its vital importance. DHS Secretary Kristi Noem has urgently called for reauthorization, emphasizing that public-private partnerships have grown stronger because of the information-sharing guidelines established in CISA 2015.

The cleanest path forward is a straightforward reauthorization while Congress works through any technical improvements. The core framework has proven its worth over a decade of operation, facilitating billions of dollars in prevented losses and creating a culture where information sharing is the default rather than the exception.

Beyond Politics: A National Security Imperative

In an era of political division, cybersecurity remains one of the few areas where Americans across the political spectrum can find common ground. We need to defend against constant attacks coming from the likes of Chinese actors using ransomware during SharePoint vulnerabilities to Iranian groups deploying ransomware as a political weapon to hundreds of criminal ransomware groups operating at any given time.

The solution isn’t more regulation or government overreach. It’s the collaborative approach that CISA 2015 has fostered. As I used to tell businesses when I was  at the FBI: we can’t help you if we don’t hear from others, and we can’t help others if we don’t hear from you. This principle of mutual aid and shared defense has made America stronger, and we cannot afford to abandon it now.

Congress must act before September 30. If we allow our cybersecurity information sharing framework to collapse it will devastate small businesses, endanger the sick, and undermine America’s position as the global leader in cybersecurity. The time for action is now, before the attacks that could have been prevented become the disasters we failed to stop.

The opinions expressed in Fortune.com commentary pieces are solely the views of their authors and do not necessarily reflect the opinions and beliefs of Fortune.

Introducing the 2025 Fortune Global 500

, the definitive ranking of the biggest companies in the world.

Explore this year's list.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

网络安全 CISA 2015 信息共享 小微企业 国家安全
相关文章