Skip to main content

Cybersecurity Information Sharing Act (CISA) 2015

  • Law: Cybersecurity Information Sharing Act of 2015 (Public Law 114-113, Division N)
  • Passed: December 2015 (attached to the omnibus spending bill)
  • Vote: Senate 74–21; House passed as part of omnibus 316–113
  • Signed by: President Obama
  • Extended through: September 2026, without standalone public debate

They could not pass it as a standalone bill. The public and civil liberties organizations had beaten back earlier versions for years. So they waited for December — the deadline to fund the government — attached it to the 2,000-page spending omnibus at the last minute, and dared Congress to vote no and shut down the government over Christmas. The Electronic Frontier Foundation called it exactly what it was: "Congress snuck a massive surveillance expansion into the omnibus budget." That is how CISA became law. In the middle of the night. With no real debate. And with your data as the price.

How It Passed

CISA had a long, troubled legislative history before its 2015 passage. Earlier versions failed in the Senate in 2012 and 2014 because of strong public opposition, particularly from technology companies that had not yet made their peace with surveillance-state cooperation. Privacy advocates, civil liberties organizations, and security researchers all documented the bill's problems in detail during those earlier fights.

The intelligence community and its congressional allies did not give up. They waited.

In December 2015, Congress faced a deadline to pass an omnibus spending bill to fund the government. At the last moment, CISA was inserted as Division N of the 2,009-page Consolidated Appropriations Act of 2015. The bill was announced and brought to a vote in days. There was no standalone floor debate on CISA's surveillance provisions. Members of Congress who objected to the surveillance expansion had to choose between voting against it and shutting down the government.

Most voted for the spending bill.

The EFF documented the process in a December 2015 analysis: "The bill that was just signed into law is not the one that was publicly debated. The version attached to the omnibus budget contains a number of 'technical corrections' that in fact are significant modifications that make the bill worse."

The surveillance provisions were announced, inserted, and passed in a matter of days. This was not an oversight or a rush to respond to a crisis. It was a deliberate strategy to move a surveillance expansion through Congress while avoiding the public scrutiny that had killed it twice before.

CISA was subsequently extended through September 2026 — again without standalone public debate or hearings on its surveillance implications.

What It Does To You

CISA's official purpose is cybersecurity information sharing — allowing companies to share threat data so the government and private sector can collectively defend against hackers and cyberattacks. That is a reasonable goal. The bill that became law is not that.

The Data Pipeline to Intelligence Agencies

CISA allows any private company — your bank, your internet provider, your mobile carrier, your employer, any technology company you use — to share "cyber threat indicators" and "defensive measures" with the Department of Homeland Security. DHS then distributes this information in near-real-time to the NSA, FBI, CIA, and other intelligence and law enforcement agencies.

The key word is "voluntarily." Companies are not required to share. But CISA grants them complete immunity from lawsuits for anything they share — including sharing data that turns out to have no connection to any cybersecurity threat whatsoever. This is not a small protection. Privacy lawsuits are one of the primary legal mechanisms by which companies face accountability for mishandling user data. CISA removes that accountability entirely for data shared with the government.

The incentive structure is clear: share aggressively, face no legal consequences regardless of what you share. The result is that companies have every financial reason to over-share and no reason to protect user privacy.

"Cyber Threat Indicator" Means Almost Anything

The definition of a "cyber threat indicator" in CISA is deliberately broad. It includes information about malicious code, exploitation techniques, and security vulnerabilities — but also information about any "anomalous activity" that might indicate a security threat, and data associated with "the methods of causing a user with legitimate access to a computer or computer network to exceed or abuse their access."

That last phrase covers an enormous range of ordinary behavior. An employee accessing files outside normal business hours. A user who downloads an unusually large volume of data. Someone using a VPN. Someone visiting websites that the employer or the government considers suspicious. These are all potentially reachable under "anomalous activity."

Under CISA, your employer can hand all of this information to the NSA without a warrant, without notifying you, and with complete immunity from any legal consequence.

The Criminal Investigation Carveout

CISA includes a provision requiring agencies to remove personal information that is "not directly related to a cybersecurity threat" before sharing data further within the government. Privacy advocates pointed out immediately that this provision is largely meaningless because of a broad exception: agencies can retain personal information that they believe relates to any crime — not just cybersecurity crimes — or to any threat of bodily harm.

This exception swallows the protection. Any personal data swept up under CISA that might relate to any crime can be retained and used in prosecution. The cybersecurity justification is the entry point; ordinary criminal prosecution is a permissible destination.

No Transparency, No Accountability

The government is not required to disclose which companies share data under CISA. It is not required to disclose what data it receives. It is not required to report on how that data is used. There is no public audit mechanism. There is no way for the individuals whose data was shared to find out that sharing occurred.

The EFF stated plainly: "The bill fails to provide privacy protections for the millions of Americans who use the Internet and web services every day. The bill contains overbroad immunity from lawsuits for corporations that share information, and the definition of what can be shared is far too broad."

Rights It Strips

Fourth Amendment — The Corporate Intermediary Workaround

The Fourth Amendment prohibits the government from searching your private communications and records without a warrant. CISA constructs a mechanism to accomplish exactly that search without any warrant at all.

The mechanism is simple: instead of the government going to court to get a warrant for your bank records, your browsing history, or your communications metadata, the government creates legal and financial incentives for your bank or your ISP to voluntarily hand that data over. The government never had to get a warrant because a private party — with full immunity — did the sharing for them.

This is a structural end-run around the Fourth Amendment. The Constitution's warrant requirement was designed to prevent exactly this kind of surveillance. CISA creates a legally protected pathway around it.

First Amendment — Chilling Political and Journalistic Activity

When private companies can share data about your online activity with intelligence agencies without a warrant and without liability, the reasonable response for anyone engaged in sensitive communications is to self-censor. Journalists protecting confidential sources, lawyers communicating with clients about sensitive matters, activists organizing around unpopular causes, and ordinary citizens exploring ideas they would prefer to keep private all face the same reality: anything passing through corporate networks may be shared with federal agencies, and you will not know when or whether that happened.

Fifth Amendment — Criminal Use of Surveillance Data

Data obtained under CISA's cybersecurity sharing framework can be used in criminal prosecutions entirely unrelated to cybersecurity. Unlike evidence obtained through a warrant, this data comes without the procedural protections that would normally apply — no probable cause finding by a judge, no specificity requirement, no exclusionary rule for violations. The Fifth Amendment's protections against self-incrimination presuppose some minimal protection against the government building a case from secretly collected private data. CISA undermines that protection.

Documented Abuses

CISA's structural problem is that it was designed to operate without transparency — making specific abuse documentation difficult by design. What is documented:

The EFF's Assessment at Passage

The Electronic Frontier Foundation evaluated the version inserted into the omnibus bill and found it materially worse than the version that had been publicly debated. Specifically, the final version removed a requirement that companies make a "reasonable effort" to remove personal information unrelated to cybersecurity threats before sharing. The final version weakened even that minimal protection.

DHS Distribution to Military Intelligence

Privacy advocates documented that DHS distributes CISA-shared information not just to civilian law enforcement agencies like the FBI, but also to military intelligence agencies including the NSA and the Office of the Director of National Intelligence. The military's involvement in domestic data collection raises concerns about Posse Comitatus Act compliance that have not been resolved.

No Audit, No Count

Because CISA requires no public disclosure of sharing activity, there is no public record of how many Americans' data has been shared with the government under the law's provisions. The absence of documented specific abuses is not evidence that abuses have not occurred — it is evidence that the law was designed so abuses cannot be documented.

Extension Without Review

CISA was extended through September 2026 without any meaningful public assessment of how the program had operated since 2015. No hearings were held on the surveillance implications. No disclosure was required of how the data pipeline had been used. Congress extended a surveillance program of unknown scope and unknown use without asking what it had actually done.

Who Pushed This

The intelligence community and Department of Homeland Security drafted the core provisions of CISA and lobbied for years for its passage. The NSA in particular sought the corporate data pipeline CISA creates, as a supplement to the foreign intelligence collection authorities that are legally more constrained.

Major technology companies and financial institutions ultimately supported CISA after initially opposing earlier versions. The liability shield was the key concession: companies that had faced lawsuits over data handling could now share data with the government with complete immunity. The Chamber of Commerce lobbied in favor of the bill.

Intelligence contractors who build and operate data analysis infrastructure for the NSA, FBI, and DHS have a direct financial interest in expanding the volume of data flowing into government systems. The more data, the more contracts to process, store, and analyze it.

Congress's leadership on the appropriations committees made the decision to insert CISA into the omnibus spending bill. The Chairs of the Senate and House Intelligence Committees — Senator Richard Burr (R-NC) and Representative Devin Nunes (R-CA) — were among CISA's primary sponsors and advocates for the omnibus insertion strategy.

Key Votes

Because CISA was inserted into a must-pass spending bill, the vote record is less clean than a standalone vote would be. The relevant votes:

Senate: 74–21 on the overall omnibus (which included CISA as Division N). The 21 NO votes are the cleanest records — these senators voted against the bill even when the alternative was a government shutdown.

Senate NO votes included Wyden (D-OR), Paul (R-KY), Sanders (I-VT), Lee (R-UT), Warren (D-MA), Merkley (D-OR), and others.

House: 316–113 on the omnibus.

Because many members voted YES on the omnibus without a public position specifically on CISA, the most useful supplementary screening tool is whether a member publicly objected to the CISA rider at the time or issued any statement opposing it. Members who voted YES on the omnibus without any objection to the surveillance provisions bear responsibility for what they funded.

Why This Matters for We The Citizens

CISA is the corporate arm of the surveillance state. It builds the legal pipeline between Silicon Valley — where most Americans' digital lives are stored — and the intelligence and law enforcement agencies that want access to that data without warrants. The immunity shield transforms every major technology company, bank, and telecom into a potential government surveillance contractor, with no legal risk for cooperating and no requirement to disclose cooperation to the individuals whose data was shared.

The method of passage — hidden inside an omnibus spending bill at midnight — is itself a statement. The architects of this law knew it could not survive public scrutiny. That knowledge should tell you everything about what they built.

See also: Bad Laws Overview | PATRIOT Act | FISA Section 702 | USA FREEDOM Act