The US Cybersecurity and Infrastructure Security Agency (CISA) faces significant challenges in maintaining one of its most important threat-sharing initiatives. A new report from the Department of Homeland Security’s inspectorate shows that participation in the automated indicator-sharing programme (AIS) has fallen to its lowest level since 2017.

Important findings

  • CISA’s AIS program has experienced a 93% decrease in shared cyber threat indicators.
  • Experts are calling for a revision or even the abolition of the AIS programme.
  • Security concerns and lack of recruitment strategies contribute to the crisis.

CISA was established in 2015 by the Cyber Security Act to facilitate the exchange of cyber threat indicators between the public and private sectors in real time. The decline in participation is attributed to CISA’s inability to maintain an effective outreach strategy and communicate with key stakeholders.

Rex Booth, former head of cyber threat analysis at CISA, said the AIS program has been of "questionable utility" since its launch. He stressed that despite considerable efforts to coordinate threat intelligence through the AIS platform, various factors such as connectivity issues and declassification difficulties could disrupt operations.

Challenges for CISA

  • Lack of participation: Participation in the AIS programme has fallen to a record low.
  • Security Concerns: An unnamed federal agency has pulled out of the program due to security concerns.
  • Future of the programme: Professionals call for a review of the objectives and strategies of CISA.

CISA has also launched other threat-sharing initiatives, including the National Cyber Awareness System and Joint Cyber Defense Cooperation. These initiatives have also received criticism, and CISA plans to revise the Joint Cyber Defense Cooperation.

The Authority has responded to the concerns and plans to complete an assessment of the AIS service by 21 July 2025, leading to recommendations for CISA leadership. However, experts have described the time span as “discouraging” and call for a faster revision of operations under the new Threat Intelligence Services (TIES) program.

Outlook

  • New TIES program: CISA announced the TIES program in 2023 to better meet the demands of the cyber security industry.
  • Objective: TIES should provide contextual and precise information, rather than just relying on volume and speed.
  • Future of Threat Sharing: Professionals hope TIES can avoid the problems of the AIS program.

CISA has acknowledged that the cyber security industry has matured significantly since the early days of AIS. The agency is urged to develop strategies to improve federal participation and create accurate spending plans for the program.

The report’s findings may not fully reflect the impact of CISA on improving organizational resilience through cyber threat intelligence. CISA is actively working with private sector partners to highlight the activities of various threat groups, especially regarding recent attacks on critical infrastructure.

Overall, CISA faces the challenge of reforming its threat-sharing initiatives to meet the evolving demands of the cyber security landscape.

Sources

  • Experts Warn CISA’s Threat Sharing is in a ‘Death Spiral’, GovInfoSecurity.