Tweet Cybersecurity

Time for Congress to Act on Cyber Threat Information Sharing

Both public and private sector entities fall victim to cyber criminals and other malicious actors each day. Sharing information about cyber threats is critical to prevent and combat these attacks.

Over the past several years, Congress and the courts have taken steps to clarify and promote information sharing. Last year, the Department of Justice and Federal Trade Commission provided guidance clarifying that private entities can share cyber threat information without raising antitrust concerns — helping to pave the way for more timely cyber threat information sharing. That was a helpful step but there is more that can be done.

For our member companies, ensuring that information networks — their own and those of their partners and customers — are well protected and able to fend off cyber attacks, is critical. The timely and appropriate sharing of information about cybersecurity threats, vulnerabilities, lessons learned, and best practices is imperative to building a collaborative framework to defend networks against attacks. This can and should be done in a manner respectful of privacy as cyber threat information sharing involves the sharing of technical information and rarely, if ever, involves the use of personal information.

To that end, BSA supports six key tenets policymakers should follow in order to usher in an era of effective cyber threat information sharing. These tenets include:

  1. Empowering private entities, through appropriately targeted legislation and policies, to voluntarily share information regarding cyber threat indicators with other private entities or governments, domestically and internationally, by expressly limiting potential legal or regulatory consequences, both for sharing and receiving this information.
  2. Implementing appropriate policies and regulations that protect the privacy of those affected by shared cyber threat information without impeding the ability to share cyber threat indicators in a timely fashion.
  3. Authorizing and encouraging government actors to share relevant cyber threat information with private parties, and accelerating the time periods for sharing such information, including through automated mechanisms.
  4. Facilitating information sharing by private entities with both government and private parties, minimizing contractual terms mandated through laws or regulations to the applicable shared information, and providing flexibility to affected parties to enter into appropriate transactional arrangements.
  5. Establishing a civilian portal for private-to-government information sharing, and ensuring that liability protections be provided for those information-sharing situations. Legislation should also make clear that companies may continue to lawfully share cyber threat indicators with the government in other situations, such as with a law enforcement agency in the event of a potential cybercrime investigation, a regulatory agency, or an agency that is a customer under a government contract.
  6. Ensuring shared cyber threat information is used by the recipient only to promote cybersecurity and for no other purpose, and when information is shared with governments, that the information is used only to promote cybersecurity or for limited law enforcement activities.

The House of Representatives has an opportunity this week to build upon this effort. We expect the House to consider the Protecting Cyber Networks Act (H.R. 1560) and the National Cybersecurity Protection Advancement Act of 2015 (H.R. 1731). Together, these bills go a long way towards breaking down the legal barriers that currently discourage information sharing while ensuring that privacy is protected. We urge the House to send this legislation to the Senate so that it can to pass its own legislation and send a final product to the President for signature.

Author:

Victoria Espinel is a global leader advancing the future of technology innovation.  

As CEO of BSA | The Software Alliance, Victoria has grown the organization’s worldwide presence in over 30 countries, distinguishing BSA as the leader for enterprise software companies on issues including artificial intelligence, privacy, cybersecurity, and digital trade. She launched the Digital Transformation Network and the Global Data Alliance, flagship BSA initiatives to further BSA’s collaboration with 15+ industry sectors globally. Victoria founded Software.org, the enterprise software industry’s nonprofit partner that educates policymakers and the public about the impact of software and careers within the industry. 

Victoria serves on President Biden’s National Artificial Intelligence Advisory Committee (Chair of the International Working Group), served as a member of the President’s USTR Advisory Committee for Trade Policy and Negotiations (ACTPN), and chaired the Future of Software and Society Group at the World Economic Forum. She is a lifetime member of the Council on Foreign Relations. 

 Victoria has testified on multiple occasions before the US Congress, European Parliament, and Japanese Diet. Victoria speaks frequently to groups about AI, cybersecurity, and STEM education, including Latinas in Tech, Girls Rule the Law, the Congressional Staff Hispanic Association, Women’s Congressional Staff Associations, Girls Who Code, EqualAI, CSIS, and numerous academic institutions. She has been featured in a wide range of media outlets, including New York Times, Washington Post, Financial Times, Forbes, C-SPAN, BBC, Bloomberg Business, The New Yorker, and NPR. 

Prior to BSA, Victoria was confirmed by the US Senate to serve as the first White House “IP Czar,” establishing a new office in the White House and advising President Obama on intellectual property. She also served in the Bush Administration as the first chief US trade negotiator for intellectual property and innovation, a role in which she created the office of Intellectual Property and Innovation at USTR and led negotiations with over 70 countries. 

Victoria launched Girls Who Code’s Washington, DC summer program and serves on the Board of Directors for ChIPs, a nonprofit organization advancing women in technology law and policy. 

She holds an LLM from the London School of Economics, a JD from Georgetown University Law School, and a BS in Foreign Service from Georgetown University’s School of Foreign Service. She is a native of Washington, DC, and the proud proprietor of Jewel of the South, a restaurant in New Orleans. 

Leave a Reply

Your email address will not be published.