Scarinci Hollenbeck, LLC
The Firm
201-896-4100 info@sh-law.comFirm Insights
Author: Scarinci Hollenbeck, LLC
Date: July 6, 2016
The Firm
201-896-4100 info@sh-law.comThe agencies specifically addressed the procedures for voluntarily sharing “cyber threat indicators,” as well as the application of the law’s immunities provision.
The goal of CISA, which was enacted last December as part of the Cyber Security Act of 2015, is to promote information sharing regarding cyber threats impacting the private sector. Under the new law, federal agencies, such as the DHS, are authorized to alert businesses about potential cyber threats. At the same time, the law also creates procedures for businesses to share information about cyberattacks or data intrusions with both federal agencies and other private entities.
To encourage information sharing, companies that participate in the program are shielded from liability for violating privacy-protection or antitrust laws, provided that the information is shared in accordance with CISA. Most notably, the law requires that companies remove personally identifiable information from any data shared, unless that information is directly related to the threat.
Section 104(c) of CISA allows non-federal entities to share cyber threat indicators and defensive measures with any other entity—private, federal, state, local, territorial, or tribal—for a “cybersecurity purpose.” However, previous guidance did not specifically address how private entities may share cyber threat indicators and defensive measures with each other. As a result, it was unclear whether CISA’s liability protections extended to business to business communications.
The latest CISA guidance from the DOJ/DHS provides a detailed summary of the protections and exemptions that non-governmental entities receive for sharing cyber threat indicators and defensive measures with each other in accordance with CISA. It also expressly states: “CISA authorizes private entities to share cyber threat indicators and defensive measures with other private entities. … It also provides private entities with liability protection for conducting such sharing in accordance with CISA.”
The latest CISA guidance also addresses several other key issues, including how to identify and share cyber threat indicators and defensive measures. For instance, it emphasizes “cyber threat indicators and defensive measures will typically consist of technical information that describes attributes of a cybersecurity threat that generally need not include various categories of information that are considered sensitive and, therefore, protected by privacy laws.”
The guidance provides specific examples of information unlikely to be directly related to a cybersecurity threat and is, therefore, inappropriate to share, including:
Businesses big and small can benefit from these guidelines. The challenge often lies in figuring out what is necessary for your company, what should be a priority, and how best to determine and integrate both technology and training into your operations.
Do you have any feedback, thoughts, reactions or comments concerning this topic? Feel free to leave a comment below for Fernando M. Pinguelo and follow the twitter accounts @CyberPinguelo and @eWHW_Blog for timely comments on related issues. If you have any questions about this post, please contact me or the Scarinci Hollenbeck attorney with whom you work. To learn more about data privacy and security, visit our Cyber Security & Data Protection page.
For more posts dealing with Cybersecurity, check out:
No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

The Fort Monmouth redevelopment has entered its execution phase, and it is repositioning the broader Monmouth County real estate market. When Netflix and the Fort Monmouth Economic Revitalization Authority closed on the 292-acre Mega Parcel in December 2025, the transaction did more than hand over a deed. It marked the moment Fort Monmouth stopped being […]
Author: Donald M. Pepe

Owning a residential rental property in New Jersey involves more than finding tenants and collecting rent. Property owners must comply with a combination of state laws, municipal ordinances, building and housing codes, and zoning and land use regulations. These requirements can affect everything from the number of dwelling units permitted at a property to whether […]
Author: Donald M. Pepe

The five most common real estate disputes are breach of contract claims, landlord-tenant conflicts, zoning and land use disagreements, construction claims, and boundary disputes. Understanding why each arises, and taking preventive steps early, can help property owners, tenants, developers, and investors avoid costly litigation. Key Takeaways: Real estate transactions are complex endeavors involving numerous parties […]
Author: Paul Grossman

Once a child turns 18, parents lose the automatic legal authority to make medical and financial decisions on their behalf, even if the child still lives at home or remains on the family’s insurance. Three documents close that gap: a durable power of attorney, a health care proxy or directive, and a HIPAA authorization. For […]
Author: George McGowan

Business mediation is a confidential, voluntary process in which a neutral third party helps companies negotiate a resolution to a commercial dispute without going to trial. Because working with a mediator is very different from litigating in the courtroom, it is important to understand how commercial mediation works, when it makes sense for your dispute, […]
Author: Paul Grossman

The five most common causes of construction defect litigation are design defects, substandard materials, workmanship defects, code violations, and subsurface defects. Because these flaws can compromise a building’s integrity, functionality, or safety, they frequently lead to disputes involving multiple parties and high financial stakes. Key takeaways: What is Construction Defect Litigation? Construction litigation is complex, […]
Author: Paul Grossman
No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.
Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.
Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.
Let`s get in touch!
Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!