Cybersecurity Information Exchange of Critical Infrastructures in the United States
Copyright (c) 2026 Bordács Bálint

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Abstract
Cybersecurity information sharing for critical infrastructures has become a key challenge in modern cybersecurity governance. Timely information on cyber threats can help organizations strengthen their defenses, identify vulnerabilities and emerging threats, and mitigate the financial impact of cyber incidents. This study examines the current U.S. information-sharing framework and proposes measures to improve corporate participation as well as the quality and quantity of shared information. In this context, the paper outlines the potential reform of the ISAC system in line with the National Cybersecurity Strategy through the establishment of a mandatory critical infrastructure information-sharing model. The study seeks to identify the structural and regulatory factors that hinder the effective operation of the U.S. cybersecurity information-sharing system and to assess which reforms could improve its effectiveness. The research is based on document and literature analysis, with particular focus on the ISAC system and U.S. cybersecurity regulation. The findings suggest that the effectiveness of information sharing is primarily limited by low participation rates, lack of trust, interoperability challenges, and funding constraints, all of which undermine the cyber resilience of critical infrastructures if left unresolved.
Keywords:
References
ALAEIFAR, Poopak et al. (2024): Current Approaches and Future Directions for Cyber Threat Intelligence Sharing: A Survey. Journal of Information Security and Applications, 83, 103786. Online: https://doi.org/10.1016/j.jisa.2024.103786
ATKINS, Sean – LAWSON, Chapell (2021): Cooperation amidst Competition: Cybersecurity Partnership in the US Financial Services Sector. Journal of Cybersecurity, 7(1), tyab024. Online: https://doi.org/10.1093/cybsec/tyab024
BAKIS, Bruce J. – WANG, Edward D. (2017): Building a National Cyber Information-Sharing Ecosystem. [H. n.]: The MITRE Corporation. Online: https://www.mitre.org/sites/default/files/2021-09/building-national-cyber-information-sharing-ecosystem-pr-17-1125.pdf
BLAIR-FRASIER, Rachelle (2023): Experts Weigh in on CIRCIA One Year Later. Security Magazine, 2023. március 31. Online: https://www.securitymagazine.com/articles/99138-experts-weigh-in-on-circia-one-year-later
CARLSON, John et al. (2017): Cybersecurity in the Financial Services Sector. Online: https://www.jstor.org/stable/resrep20737
Center for Strategic and International Studies [é. n.]: Significant Cyber Events List. Online: https://www.csis.org/programs/strategic-technologies-program/significant-cyber-incidents
Cyber Incident Reporting for Critical Infrastructure Act of 2022 (2022). Online: https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia
Cybersecurity and Infrastructure Security Agency [é. n.]: Information Sharing. Online: https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing
Cybersecurity and Infrastructure Security Agency (2016): Critical Infrastructure Threat Information Sharing Framework. A Reference Guide for the Critical Infrastructure Community. Online: https://www.cisa.gov/sites/default/files/publications/ci-threat-information-sharing-framework-508.pdf
Cybersecurity and Infrastructure Security Agency (2022): Traffic Light Protocol (TLP) Definitions and Usage. Online: https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage
DYKSTRA, Josiah et al. (2023): Maximizing the Benefits from Sharing Cyber Threat Intelligence by Government Agencies and Department. Journal of Cybersecurity, 9(1), tyad003. Online: https://doi.org/10.1093/cybsec/tyad003
FLEMING, Mathew – GOLDSTEIN, Eric (2012): Metrics for Measuring the Efficacy of Critical-Infrastructure-Centric Cybersecurity Information Sharing Efforts. Online: http://dx.doi.org/10.2139/ssrn.2201033
FS-ISAC (2023): 2023 Year in Review. Online: https://www.fsisac.com/hubfs/EOY/23_YearInReview.pdf
Government Accountability Office (2004): Critical Infrastructure Protection: Improving Information Sharing with Infrastructure Sectors. Online: https://www.gao.gov/products/gao-04-780
Government Accountability Office (2023): National Cybersecurity Strategy Needs to Address Information Sharing Performance Measures and Methods. Online: https://www.gao.gov/assets/d23105468.pdf
GRIEGER, Gisela (2023): The US Cybersecurity Posture under Biden. European Parliamentary Research Service. Online: https://www.europarl.europa.eu/RegData/etudes/ATAG/2023/753929/EPRS_ATA(2023)753929_EN.pdf
HUMPHREYS, Brian E. (2024): The 2024 National Security Memorandum on Critical Infrastructure Security and Resilience. 2024. július 25. Congression Research Service. Online: https://www.congress.gov/crs-product/IF12716
Implementating CIRCIA’s Reporting Requirement (2022). Online: https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia
JOHNSON, Chris et al. (2016): Guide to Cyber Threat Information Sharing. Gaithersberg: National Institute of Standards and Technology. Online: http://dx.doi.org/10.6028/NIST.SP.800-150
LABBÉ, Rob (2017): Building a Successful ISAC/ISAO – Don’t Forget the Community. LinkedIn, 2017. október 2. Online: https://www.linkedin.com/pulse/building-successful-isacisao-dont-forget-community-rob-labbé/
National Council of ISACs (2016): Information Sharing and Analysis Centers (ISACs) and Their Role in Critical Infrastructure Protection. Online: https://1d74b95c-e5fa-4920-9b2e-254ec35a1c46.filesusr.com/ugd/416668_2e3fd9c55185490abcf2d7828abfc4ca.pdf
National Council of ISACs (2021a): National Council of ISACs Congressional Update. Critical Infrastructure Information Sharing Successes and Opportunities. Online: https://www.nationalisacs.org/_files/ugd/b8fa6c_4add9893be20400a925ca4868ec1e975.pdf
National Council of ISACs (2021b): NCI Principles on Mandatory Reporting. Online: https://www.nationalisacs.org/_files/ugd/b8fa6c_deb4d9982b3a42a4b0d77992d1e75b73.pdf
NOLAN, Andrew (2015): Cybersecurity and Information Sharing: Legal Challenges and Solutions. Congressional Research Service. Online: https://sgp.fas.org/crs/intel/R43941.pdf
NWEKE, Livinus O. – WOLTHUSEN, Stephen (2020): Legal Issues Related to Cyber Threat Information Sharing Among Private Entities for Critical Infrastructure. In 2020 12th International Conference on Cyber Conflict. Tallinn: NATO CCDCOE Publications, 63–78. Online: https://doi.org/10.23919/CyCon49761.2020.9131721
President Trump’s Cyber Strategy for America. 2026. március. Washington: The White House. Online: https://www.whitehouse.gov/wp-content/uploads/2026/03/President-Trumps-Cyber-Strategy-for-America.pdf
Presidential Decision Directive 63. 1998. május 22. Washington D.C.: The White House. Online: https://irp.fas.org/offdocs/pdd/pdd-63.htm
Presidential Policy Directive 21. 2013. február 12. Washington D.C.: The White House. Online: https://www.cisa.gov/sites/default/files/2023-01/ppd-21-critical-infrastructure-and-resilience-508_0.pdf
SEFFERS, George I. (2023): CISA Views Critical Infrastructure and Cybersecurity Through Global Lens. The CyberEdge by Signal, 2023. október 1. Online: https://www.afcea.org/signal-media/cyber-edge/cisa-views-critical-infrastructure-and-cybersecurity-through-global-lens
Statement on the National Cybersecurity Strategy. DCPD-202300176. 2023. március 1. Online: https://bidenwhitehouse.archives.gov/wp-content/uploads/2023/03/National-Cybersecurity-Strategy-2023.pdf
The MITRE Corporation (2012): Cyber Information-Sharing Models. An Overview. Elérhető: https://www.mitre.org/sites/default/files/pdf/cyber_info_sharing.pdf
TOSH, Deepak K. et al. (2015): Cyber-Investment and Cyberinformation Exchange Decision Modeling. In 17th IEEE International Conference on High Performance Computing and Communications, HPCC 2015, 7th IEEE International Symposium on Cyberspace Safety and Security, CSS 2015, and 12th IEEE International Conference on Embedded Software and Systems, ICESS 2015, New York, NY, USA, August 24–26, 2015. 1219–1224. Online: https://www.cse.unr.edu/~shamik/research/papers/CSS-2015-CyberInfoSharingGame-accepted.pdf
TURETSKY, David – NUSSBAUM, Brian – TATAR, Unul (2020): Cybersecurity Information Sharing Success Stories. Lawfare, 2020. július 15. Online: https://www.lawfaremedia.org/article/cybersecurity-information-sharing-success-stories
WEISS, Errol (2025): Why a Government-Led AI-ISAC Is a Missed Opportunity. LinkedIn, 2025. július 24. Online: https://www.linkedin.com/pulse/why-government-led-ai-isac-missed-opportunity-errol-weiss-2wake/
World Economic Forum (2023): Response to the White House’s Request on Harmonizing Cybersecurity Regulations. Online: https://www3.weforum.org/docs/WEF_Response_to_the_White_House’s_Request_on_Harmonizing_Cybersecurity_Regulations_2023.pdf