Grant Gross
Senior Writer

Senate heads toward vote on CISA cyberthreat info sharing bill

News
Aug 4, 20153 mins

The U.S. Senate could take a preliminary vote as soon as Wednesday on a controversial bill intended to encourage businesses to share cyberthreat information with each other and with government agencies, despite concerns that the legislation would allow the widespread sharing of personal customer data.

Senate leaders are attempting to iron out compromise language to address privacy concerns in the Cybersecurity Information Sharing Act (CISA), but if no compromise is reached Senate Majority Leader Mitch McConnell will schedule a so-called cloture vote on Wednesday morning, said a spokesman for McConnell, a Kentucky Republican.

A cloture vote would limit debate on the bill and move the Senate toward final passage, potentially before the Senate leaves for a four-week summer recess this weekend.

CISA would protect from customer lawsuits businesses that share cyberthreat information, but privacy groups have opposed the bill, saying it would allow businesses to share customers’ personal information with the National Security Agency and other intelligence agencies.

CISA would be a “trigger” for the NSA to target U.S. residents for surveillance, Jonathan Mayer, a security researcher and lawyer at Stanford University, said last week.

In a letter sent last week, the Department of Homeland Security also raised privacy concerns.

CISA could “contribute to the compromise of personally identifiable information by spreading it further”, by mandating that DHS, the agency that would receive most of the shared cyberthreat information, share that information in real time without scrubbing out personal data, the agency said in its letter.

Privacy groups criticized the move toward a vote in the Senate after a recent campaign against the bill resulted in more than 6 million faxes sent to Congress.

Digital rights group Access is “deeply disappointed that Leader McConnell has chosen to ignore the will of the people and push ahead with consideration of this deeply flawed cybersurveillance bill before the August recess,” Amie Stepanovich, U.S. policy manager for the group, said by email. “Any senator who values privacy and security must reject this attempt to sacrifice both at the altar of increased surveillance and corporate liability protections.”

Supporters of CISA say the legislation is needed to stimulate a cyberthreat information sharing culture among U.S. businesses. Many businesses are reluctant to share information because of potential customer lawsuits, said former U.S. Representative Mike Rogers, sponsor of the controversial Cyber Intelligence Sharing and Protection Act (CISPA), a similar bill that failed to become law after President Barack Obama threatened to veto it.

CISA is the “one piece of legislation” that could help fix the U.S. cybersecurity weaknesses, Rogers said during a cybersecurity event Monday. “If we can share malicious source code in real time—machine to machine, zeroes and ones in light speed—we might be able to put a dent in this.”

The concerns from DHS over CISA means “our own government is going to work against itself over the details over how we come up with a cybersharing regime,” Rogers added.

Grant Gross

Grant Gross, a senior writer at CIO, is a long-time IT journalist who has focused on AI, enterprise technology, and tech policy. He previously served as Washington, D.C., correspondent and later senior editor at IDG News Service. Earlier in his career, he was managing editor at Linux.com and news editor at tech careers site Techies.com. As a tech policy expert, he has appeared on C-SPAN and the giant NTN24 Spanish-language cable news network. In the distant past, he worked as a reporter and editor at newspapers in Minnesota and the Dakotas. A finalist for Best Range of Work by a Single Author for both the Eddie Awards and the Neal Awards, Grant was recently recognized with an ASBPE Regional Silver award for his article “Agentic AI: Decisive, operational AI arrives in business.”

More from this author