Cybersecurity Information Exchange of Critical Infrastructures in the United States

doi: 10.32563/hsz.2026.3.2

Abstract

Cybersecurity information sharing for critical infrastructures has become a key challenge in modern cybersecurity governance. Timely information on cyber threats can help organizations strengthen their defenses, identify vulnerabilities and emerging threats, and mitigate the financial impact of cyber incidents. This study examines the current U.S. information-sharing framework and proposes measures to improve corporate participation as well as the quality and quantity of shared information. In this context, the paper outlines the potential reform of the ISAC system in line with the National Cybersecurity Strategy through the establishment of a mandatory critical infrastructure information-sharing model. The study seeks to identify the structural and regulatory factors that hinder the effective operation of the U.S. cybersecurity information-sharing system and to assess which reforms could improve its effectiveness. The research is based on document and literature analysis, with particular focus on the ISAC system and U.S. cybersecurity regulation. The findings suggest that the effectiveness of information sharing is primarily limited by low participation rates, lack of trust, interoperability challenges, and funding constraints, all of which undermine the cyber resilience of critical infrastructures if left unresolved.

Keywords:

cybersecurity critical infrastructure information exchange National Cybersecurity Strategy ISAC

References

ALAEIFAR, Poopak et al. (2024): Current Approaches and Future Directions for Cyber Threat Intelligence Sharing: A Survey. Journal of Information Security and Applications, 83, 103786. Online: https://doi.org/10.1016/j.jisa.2024.103786

ATKINS, Sean – LAWSON, Chapell (2021): Cooperation amidst Competition: Cybersecurity Partnership in the US Financial Services Sector. Journal of Cybersecurity, 7(1), tyab024. Online: https://doi.org/10.1093/cybsec/tyab024

BAKIS, Bruce J. – WANG, Edward D. (2017): Building a National Cyber Information-Sharing Ecosystem. [H. n.]: The MITRE Corporation. Online: https://www.mitre.org/sites/default/files/2021-09/building-national-cyber-information-sharing-ecosystem-pr-17-1125.pdf

BLAIR-FRASIER, Rachelle (2023): Experts Weigh in on CIRCIA One Year Later. Security Magazine, 2023. március 31. Online: https://www.securitymagazine.com/articles/99138-experts-weigh-in-on-circia-one-year-later

CARLSON, John et al. (2017): Cybersecurity in the Financial Services Sector. Online: https://www.jstor.org/stable/resrep20737

Center for Strategic and International Studies [é. n.]: Significant Cyber Events List. Online: https://www.csis.org/programs/strategic-technologies-program/significant-cyber-incidents

Cyber Incident Reporting for Critical Infrastructure Act of 2022 (2022). Online: https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia

Cybersecurity and Infrastructure Security Agency [é. n.]: Information Sharing. Online: https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing

Cybersecurity and Infrastructure Security Agency (2016): Critical Infrastructure Threat Information Sharing Framework. A Reference Guide for the Critical Infrastructure Community. Online: https://www.cisa.gov/sites/default/files/publications/ci-threat-information-sharing-framework-508.pdf

Cybersecurity and Infrastructure Security Agency (2022): Traffic Light Protocol (TLP) Definitions and Usage. Online: https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage

DYKSTRA, Josiah et al. (2023): Maximizing the Benefits from Sharing Cyber Threat Intelligence by Government Agencies and Department. Journal of Cybersecurity, 9(1), tyad003. Online: https://doi.org/10.1093/cybsec/tyad003

FLEMING, Mathew – GOLDSTEIN, Eric (2012): Metrics for Measuring the Efficacy of Critical-Infrastructure-Centric Cybersecurity Information Sharing Efforts. Online: http://dx.doi.org/10.2139/ssrn.2201033

FS-ISAC (2023): 2023 Year in Review. Online: https://www.fsisac.com/hubfs/EOY/23_YearInReview.pdf

Government Accountability Office (2004): Critical Infrastructure Protection: Improving Information Sharing with Infrastructure Sectors. Online: https://www.gao.gov/products/gao-04-780

Government Accountability Office (2023): National Cybersecurity Strategy Needs to Address Information Sharing Performance Measures and Methods. Online: https://www.gao.gov/assets/d23105468.pdf

GRIEGER, Gisela (2023): The US Cybersecurity Posture under Biden. European Parliamentary Research Service. Online: https://www.europarl.europa.eu/RegData/etudes/ATAG/2023/753929/EPRS_ATA(2023)753929_EN.pdf

HUMPHREYS, Brian E. (2024): The 2024 National Security Memorandum on Critical Infrastructure Security and Resilience. 2024. július 25. Congression Research Service. Online: https://www.congress.gov/crs-product/IF12716

Implementating CIRCIA’s Reporting Requirement (2022). Online: https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia

JOHNSON, Chris et al. (2016): Guide to Cyber Threat Information Sharing. Gaithersberg: National Institute of Standards and Technology. Online: http://dx.doi.org/10.6028/NIST.SP.800-150

LABBÉ, Rob (2017): Building a Successful ISAC/ISAO – Don’t Forget the Community. LinkedIn, 2017. október 2. Online: https://www.linkedin.com/pulse/building-successful-isacisao-dont-forget-community-rob-labbé/

National Council of ISACs (2016): Information Sharing and Analysis Centers (ISACs) and Their Role in Critical Infrastructure Protection. Online: https://1d74b95c-e5fa-4920-9b2e-254ec35a1c46.filesusr.com/ugd/416668_2e3fd9c55185490abcf2d7828abfc4ca.pdf

National Council of ISACs (2021a): National Council of ISACs Congressional Update. Critical Infrastructure Information Sharing Successes and Opportunities. Online: https://www.nationalisacs.org/_files/ugd/b8fa6c_4add9893be20400a925ca4868ec1e975.pdf

National Council of ISACs (2021b): NCI Principles on Mandatory Reporting. Online: https://www.nationalisacs.org/_files/ugd/b8fa6c_deb4d9982b3a42a4b0d77992d1e75b73.pdf

NOLAN, Andrew (2015): Cybersecurity and Information Sharing: Legal Challenges and Solutions. Congressional Research Service. Online: https://sgp.fas.org/crs/intel/R43941.pdf

NWEKE, Livinus O. – WOLTHUSEN, Stephen (2020): Legal Issues Related to Cyber Threat Information Sharing Among Private Entities for Critical Infrastructure. In 2020 12th International Conference on Cyber Conflict. Tallinn: NATO CCDCOE Publications, 63–78. Online: https://doi.org/10.23919/CyCon49761.2020.9131721

President Trump’s Cyber Strategy for America. 2026. március. Washington: The White House. Online: https://www.whitehouse.gov/wp-content/uploads/2026/03/President-Trumps-Cyber-Strategy-for-America.pdf

Presidential Decision Directive 63. 1998. május 22. Washington D.C.: The White House. Online: https://irp.fas.org/offdocs/pdd/pdd-63.htm

Presidential Policy Directive 21. 2013. február 12. Washington D.C.: The White House. Online: https://www.cisa.gov/sites/default/files/2023-01/ppd-21-critical-infrastructure-and-resilience-508_0.pdf

SEFFERS, George I. (2023): CISA Views Critical Infrastructure and Cybersecurity Through Global Lens. The CyberEdge by Signal, 2023. október 1. Online: https://www.afcea.org/signal-media/cyber-edge/cisa-views-critical-infrastructure-and-cybersecurity-through-global-lens

Statement on the National Cybersecurity Strategy. DCPD-202300176. 2023. március 1. Online: https://bidenwhitehouse.archives.gov/wp-content/uploads/2023/03/National-Cybersecurity-Strategy-2023.pdf

The MITRE Corporation (2012): Cyber Information-Sharing Models. An Overview. Elérhető: https://www.mitre.org/sites/default/files/pdf/cyber_info_sharing.pdf

TOSH, Deepak K. et al. (2015): Cyber-Investment and Cyberinformation Exchange Decision Modeling. In 17th IEEE International Conference on High Performance Computing and Communications, HPCC 2015, 7th IEEE International Symposium on Cyberspace Safety and Security, CSS 2015, and 12th IEEE International Conference on Embedded Software and Systems, ICESS 2015, New York, NY, USA, August 24–26, 2015. 1219–1224. Online: https://www.cse.unr.edu/~shamik/research/papers/CSS-2015-CyberInfoSharingGame-accepted.pdf

TURETSKY, David – NUSSBAUM, Brian – TATAR, Unul (2020): Cybersecurity Information Sharing Success Stories. Lawfare, 2020. július 15. Online: https://www.lawfaremedia.org/article/cybersecurity-information-sharing-success-stories

WEISS, Errol (2025): Why a Government-Led AI-ISAC Is a Missed Opportunity. LinkedIn, 2025. július 24. Online: https://www.linkedin.com/pulse/why-government-led-ai-isac-missed-opportunity-errol-weiss-2wake/

World Economic Forum (2023): Response to the White House’s Request on Harmonizing Cybersecurity Regulations. Online: https://www3.weforum.org/docs/WEF_Response_to_the_White_House’s_Request_on_Harmonizing_Cybersecurity_Regulations_2023.pdf

Downloads

Download data is not yet available.