By Scott Algeier, IT-ISAC Executive Director

Cyber defenders are in a tough spot. The community is no longer dealing with a gradual evolution of cyber risks. Instead, we are experiencing a massive, hyper-speed acceleration. At a time when security budgets are being squeezed, threat actors have access to an arsenal of better, faster technology and tools that automate attacks. Meanwhile, the Cybersecurity and Infrastructure Security Agency (CISA), the nation’s focal point for cyber defense, has experienced budget cuts, government shutdowns, and the loss of experienced staff. Given this environment, defending in isolation is not a viable solution.

While cybersecurity spending continues to rise, with global spending on products and services increasing from $260 billion in 2021 to over $560 billion in 2026, as noted by Dan Lohrmann in a Government Technology piece, outcomes are not improving. Adversary dwell time has increased to 11 days on average, and we’ve seen an over 78% year-over-year jump in ransomware attacks on the IT sector. In total, attackers are causing trillions of dollars in economic damage, demonstrating once again that the economics are heavily stacked against the defenders. It is a lot cheaper to launch attacks than it is to build defenses against them

In this environment, collaboration across industry and government is more essential than ever.  As I testified before the House Committee on Homeland Security Subcommittee on Cybersecurity and Critical Infrastructure Protection last month, we must recommit to build an effective partnership of equals. This will help both industry and government maximize the effective use of limited resources.

The IT-ISAC has worked extensively with the government since our founding over 26 years ago. We are committed to helping CISA and other government partners succeed.  There are several specific actions the government as a whole can take to ensure long-term success of the public-private partnership.

One is to implement a replacement for the CIPAC framework.  When CIPAC was suspended by DHS, it removed the legal framework that helped foster collaboration between CISA and industry. This has impaired the government’s ability to engage with industry to develop risk reduction strategies.

In addition, it is critical to maintain a legal framework that incentivizes voluntary sharing of threat intelligence across industry and government. The current legal framework is widely viewed as being one of our most consequential and effective policy tools. However, the Cybersecurity Information Sharing Act of 2015 (CISA 2015), which provides this framework, is set to expire at the end of the fiscal year.

Another important tenet is institutionalizing the principles and processes that make public-private partnerships successful. In 2012, the IT Sector Coordinating Council conducted a study that identified 12 practices leading to successful partnership outcomes. Adopting these practices would be a good first step in refreshing CISA’s engagement with the industry.

Finally, building a common operating picture among industry and government is essential. We must move beyond sharing one-off alerts and enable organizations across sectors to collectively anticipate risks and proactively shift their defenses. The goal should be for industry and government to have the same set of real-time strategic and tactical threat intelligence.

Our adversaries already know that they are stronger when they pool resources and talent. Defenders, too, are stronger together. By combining the innovation of the private sector with the reach and scope of the federal government, we can flip the script on attackers and better protect our digital economy.

Back to News