Cybersecurity Policy Report, Sen. Paul Opposes ‘Clean’ Reauthorization of Cyber Threat Info-Sharing Law, (Jul 25, 2025)

Hopes for a “clean” reauthorization of a key cyber threat information-sharing law face a new roadblock—Sen. Rand Paul (R., Ky.), chairman of the Senate Homeland Security and Governmental Affairs Committee.
At the close of a hearing yesterday to consider the nomination of Sean Plankey to be director of the Cybersecurity and Infrastructure Security Agency, Sen. Paul suggested he wouldn’t support the reauthorization of the Cybersecurity Information Sharing Act of 2015 (CISA 2015), which is due to expire in September, unless the reauthorization bill includes language barring the Department of Homeland Security from identifying mis- and disinformation.
“I want everybody to know that we’re going to reauthorize CISA [2015], but we’re going to put language in there—and I hope it can be bipartisan language—that is going to protect speech,” Sen. Paul said.
Sen. Paul has long complained about past DHS efforts to flag potential falsehoods being circulated in the media or on the Internet. Those efforts reached their zenith in 2022 when DHS established what it called the Disinformation Governance Board, which quickly became so politically toxic that it was disbanded.
It was unclear whether supporters of a clean CISA 2015 reauthorization—which include Sen. Gary Peters (D., Mich.), ranking member of Sen. Paul’s committee, and Rep. Andrew Garbarino (R., N.Y.), the new chairman of the House Homeland Security Committee—would accept Sen. Paul’s demand for the addition of language addressing DHS “censorship.”
Sen. Peters has introduced the Cybersecurity Information Sharing Extension Act (S 1337), which would provide for a clean reauthorization of CISA 2015 through 2035. That bill is co-sponsored by Sen. Mike Rounds (R., S.D.), chairman of the Senate Armed Services Committee’s cybersecurity subcommittee (CPR, April 16).
A clean reauthorization of CISA 2015 was also included in the Senate version of the Intelligence Authorization Act for Fiscal Year 2026 (S 2342), which recently cleared the Senate Intelligence Committee by a vote of 15-2.
Sen. Paul was never a fan of CISA 2015. He didn’t register a vote when it finally cleared the Senate by a vote of 74-21 in October 2015, but he voted “no” on procedural moves to advance the bill, and—citing privacy concerns—he unsuccessfully offered an amendment that would have weakened the legal protections the law gave to private-sector entities that engage in cyber threat information-sharing.
His concerns about privacy were widely shared at the time by privacy advocates who feared that a broad grant of legal immunity to companies that exchanged cyber threat information with federal agencies would lead to more government surveillance of Americans.
The push for a clean reauthorization reflects concerns that negotiations over new language in CISA 2015 would take too long, leading to the law’s expiration on Sept. 30 and a sharp reduction in the amount of cyber threat information-sharing.
“We have known for ten years that CISA 2015 would expire this September,” Rep. Bennie Thompson (D., Miss.), ranking member of the House Homeland Security Committee, told CPR in an e-mailed statement.
“Those of us who were involved in the initial enactment of CISA 2015 remember all too well how difficult—and time consuming—it was to negotiate language that would satisfy the wide range of interested parties,” Rep. Thompson said. “The time to begin discussing and circulating potential changes to CISA 2015 was six months ago—if not earlier.”
MainStory: TopStory FederalLegislation DataSecurity