Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
    • House Debates Stopgap Funding Bill That Would Revive Cyber Threat Info-Sharing Law
    • Democratic Governors Urged to Block Data-Sharing With ICE
    • EU Privacy Advocates Decry Proposed Changes to GDPR
    • Overview of Data Broker Opt-Out System Provided by California Privacy Agency
    • Recommendations for Data Processing Agreements Offered in Netherlands
    • U.K. Parliament Readies Bill to Update Cybersecurity Law
    • U.K.’s Information Commissioner Aims to Raise Public Sector Data Protection Standards
    • Warnings Issued to Dutch Websites With Noncompliant Cookie Banners
  • Articles
  • Articles

    Cybersecurity Policy Report, House Debates Stopgap Funding Bill That Would Revive Cyber Threat Info-Sharing Law, (Nov 12, 2025)

    By Tom Leithauser

    An expired law that enabled private-sector entities to report cyber attacks without fear of legal repercussions would be resurrected until Jan. 30, 2026, under a stopgap spending bill that was under consideration today in the House.

    A final House vote ...

    By Tom Leithauser

    An expired law that enabled private-sector entities to report cyber attacks without fear of legal repercussions would be resurrected until Jan. 30, 2026, under a stopgap spending bill that was under consideration today in the House.

    A final House vote on the Continuing Appropriations and Extensions Act, 2026 (HR 5371) was expected this evening after CPR’s afternoon deadline.

    The bill’s main purpose is to end the ongoing federal government shutdown by providing full-year appropriations for some agencies and stopgap funding for the rest (CPR, Nov. 10). The Senate passed the bill Monday by a vote of 60-40.

    But the bill also would revive the Cybersecurity Information Sharing Act of 2015 (CISA 2015), which sunset on Sept. 30, through Jan. 30, 2026.

    CISA 2015 is widely regarded as a foundational cybersecurity law. It encouraged private sector entities to share cyber threat information among themselves and with the federal government. Its expiration has led to uncertainty by some businesses about whether they might face legal repercussions if they continue sharing information about cyber attacks (CPR, Oct. 17).

    Another provision of HR 5371 would reinstate a cybersecurity grant program for state and local governments. The State and Local Cyber Security Grant Program (SLCGP), originally authorized by the 2021 Infrastructure Investment and Jobs Act, expired Sept. 30.

    The SLCGP provided $1 billion over four years to help state and local governments assess their cybersecurity needs and develop programs to address those needs.

    The National Association of State Chief Information Officers (NASCIO) said it was “encouraged” by the inclusion of CISA 2015 and the SLCGP in the agreement to reopen the federal government.

    “SLCGP has been instrumental in helping state and local governments strengthen their cybersecurity defenses and the inclusion of both demonstrates that Congress is indeed taking this issue seriously,” NASCIO said in a news release.

    “However, this extension of both laws is only a temporary solution to a significant and pressing problem,” NASCIO added. “Congress should act swiftly to provide certainty and stability for state governments by passing a long-term extension of both programs, combined with adequate levels of funding, that will allow stakeholders to strengthen their cyber defenses and meet the challenges of the future.”

    MainStory: TopStory FederalLegislation DataSecurity

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use